 main menuhome
forums Show me new threads!
bookmarks
post article
view blogs
vault you must be level 2 to upload files to your vault
downloads you must be logged to access downloads
Rootkit Collection
A news back-end to implement RootKit news into your website is here or more advanced version here.
An XML/RSS feed that includes both NEWS and BLOGS for RootKit is here: XML/RSS.
Beta feed for replied posts here. feedback to admins not forums, we know about times being off...
|
ROOTKIT
Will RE for Cash
|
Saturday July 31st |
| | Featured Article: Nostalgia: n00bk1t, an advanced ring3 rootkit in C by jeffosz | (As Seen On TechTV) VICE - Catch the hookers! By: fuzen_opVICE is a new tool to detect user mode Win32 API hooks and kernel mode hooks. It comes complete with a nice user interface thanks to Greg Hoglund. The user mode detection can take some time, but be patient. It is worth it. Also, if you want to add more checks to the kernel, just extend driver.ini. VICE You will need the Microsoft .NET Framework to run because of the GUI. .NET Framework Warning This software is brand new and is known to throw some false postives, especially with the user-mode rootkit detection. If you scan your system and it informs you that you have a rootkit infection, you may not have a rootkit infection, but instead a false positive - so relax - it would be helpful if you post the results that you obtain so the authors can improve the detection algorithm. Most important is the address of the hook, and the name of the DLL that is performing the hook. Known User API False Positives shim.dll setupapi.dll comctl32.dll (Usually seen with Outlook running) sfc_os.dll and sfc.dll (Used for Microsoft Windows File Protection) adsldpc.dll Known Kernel False Positives 1. IRP's hooked by a file in the sytem root directory named ntoskrnl.exe 2. Functions hooked by vsdataant.sys (Only if you have Zone Alarm) Happy Hunting! Jamie Butler VICE has been tested on 2000/XP, but it should run on NT and 2003. Greetz to: Greg; lonerancher, fin, and the eEye crew; and gcla at enterasys.
. . . |
| |
ROOTKITS, Subverting the Windows Kernel
By: Greg Hoglund and Jamie Butler
Rootkits are powerful tools to compromise computer systems without detection. Get the original and best book on the subject here.
|
active for last 5 minutes
registered users:79912
There are currently 0 registered users and 20 guests browsing the website.
Welcome our latest registered user: Pris
| Jul 31, 12:06 |
| May 09, 04:30 |
| May 08, 15:33 |
| May 04, 15:42 |
| May 02, 03:59 |
| Best Screenshots / Analog |
| the most active news users |
based on the number of news posts for last 30 days
|