 main menuhome
forums Show me new threads!
bookmarks
post article
view blogs
vault you must be level 2 to upload files to your vault
downloads you must be logged to access downloads
Rootkit Collection
A news back-end to implement RootKit news into your website is here or more advanced version here.
An XML/RSS feed that includes both NEWS and BLOGS for RootKit is here: XML/RSS.
Beta feed for replied posts here. feedback to admins not forums, we know about times being off...
|
ROOTKIT
Because the OS isn't enough!
|
Saturday July 31st |
| | Featured Article: Nostalgia: n00bk1t, an advanced ring3 rootkit in C by jeffosz | Klister v0.3 By: joannaok, so you've just downloaded the new fu rootkit and realized that it can hide virtually any process on your system by using some clever tricks? so you would like to know if it is possible to detect it... or maybe you are wondering if somebody have already rooted your box and installed some other rootkit, like hacker defender for example? so, here is the tool intend to list some important kernel structers in order to detect rootkit's activity (like uncovering hidden processes). klister consists of a kernel module and some exemplary userland programs which communicate with the kernel module in order to display some internal kernel data structures. the most interesting ones are thread lists which are used by kernel dispatcher (scheduler) code. when reading such internal list we can be (almost;)) sure that we're getting list of all threads in the system (including those which belong to hidden process) and it also means that we can create complete list of ALL PROCESSESS in the system. can it be cheated? theoretically yes, practically i'm not aware of any rootkit which would be able to hide process in such a way that klister won't find it. some theoretical research has been done to show that it can be cheated, but such rookit, according to my knowledge has not yet been written... please consider it rather as a proof of concept, currently it has very ascetic user interface, but hopefully some improvements will be added. i hope to get your feedback, so i will be able to improve the tool. you can find some papers about rootkit detection in my vault: 1. Windows Rootkit Detection PDF 2. Hivercon03 PPT have fun, joanna. ps. this tool would probably haven't been written if fuzen didn't create fu rookit;)
|
| |
ROOTKITS, Subverting the Windows Kernel
By: Greg Hoglund and Jamie Butler
Rootkits are powerful tools to compromise computer systems without detection. Get the original and best book on the subject here.
|
active for last 5 minutes
registered users:79912
There are currently 0 registered users and 17 guests browsing the website.
Welcome our latest registered user: Pris
| Jul 31, 12:06 |
| May 09, 04:30 |
| May 08, 15:33 |
| May 04, 15:42 |
| May 02, 03:59 |
| Best Screenshots / Analog |
| the most active news users |
based on the number of news posts for last 30 days
|