Section: .. / UNIX / penetration / rootkits /
|
The software in this directory is provided for the use of System Admins only, and is provided to keep them informed on the backdoors that are currently in circulation. We strongly discourage the use of these tools without proper permission.
|
| /// File Name: |
knark-2.4.3.tgz |
Description:
|
Knark v2.4.3 port is a usable kernel-based rootkit for Linux which is based on knark-0.59. Hides files in the filesystem, strings from /proc/net for netstat, processes, and program execution redirects. Also includes a kernel module to protect Linux 2.4 from knark.
| | Author: | Cyberwinds | | File Size: | 59931 | | Last Modified: | May 21 18:23:10 2001 |
| MD5 Checksum: | ca1ebe26ab1138ebe431751f526df817 |
|
| /// File Name: |
kbdis.c |
Description:
|
kbdis.c disables the keyboard on most x86 systems. Useful for locking out root in a pinch.
| | Author: | Sorcerer | | File Size: | 241 | | Last Modified: | May 8 18:55:53 2001 |
| MD5 Checksum: | b993d33d0fe64d76d9829f0ed97d6ab1 |
|
| /// File Name: |
Netstat.zip |
Description:
|
Netstat.zip is a fake windows netstat which can hide certain network connections. Requires renaming the original netstat.
| | Author: | Digital Fire | | File Size: | 15843 | | Last Modified: | Apr 24 20:18:22 2001 |
| MD5 Checksum: | 97d5d9a6abab7e7c5a2b97e38252db12 |
|
| /// File Name: |
Q-2.4.tar.gz |
Description:
|
Q v2.4 is a client / server backdoor which features remote shell access with strong encryption for root and normal users, and a encrypted on-demand tcp relay/bouncer that supports encrypted sessions with normal clients using the included tunneling daemon. Also has stealth features like activation via raw packets, syslog spoofing, and single on-demand sessions with variable ports.
| | Author: | Mixter | | Homepage: | http://mixter.void.ru | | Changes: | Now uses strong RSA/libiSSL encryption for sessions; compatibility with libmix1.2; many bugfixes. | | File Size: | 319968 | | Last Modified: | Apr 15 13:38:37 2001 |
| MD5 Checksum: | 45a5b2c2b2612f6d6703cd984cc1d8e1 |
|
| /// File Name: |
maxty.tar.gz |
Description:
|
Maxty is a small kernel-space tty sniffer. It is a LKM which will attach to read/write syscalls and save incoming/outgoing requests to opened tty devices into separate log files. It provides a way keeping a track what is happening on virtual consoles similar to a keystroke recorder.
| | Author: | Paul | | File Size: | 4867 | | Last Modified: | Apr 6 21:04:31 2001 |
| MD5 Checksum: | 8ed7a10a7153e74d0f1495d65783dc4d |
|
| /// File Name: |
adore-0.34.tgz |
Description:
|
Adore is a linux LKM based rootkit for Linux v2.[24]. Features smart PROMISC flag hiding, persistent file and directory hiding (still hidden after reboot), process-hiding, netstat hiding, rootshell-backdoor, and an uninstall routine. Includes a userspace program to control everything.
| | Author: | Stealth | | Homepage: | http://www.team-teso.net | | Changes: | Improved 2.4 support, better authentication checking, permanent PID removal, configure script, experimental exec redirection for i386. | | File Size: | 13470 | | Last Modified: | Mar 26 19:50:38 2001 |
| MD5 Checksum: | 69b3453f1fb1650388fc63297652d221 |
|
| /// File Name: |
apachebd.tgz |
Description:
|
Apache backdoor - Backdoors apache 1.3.17 / 1.3.19 to spawn a root shell when a certain page is requested.
| | Author: | Venomous | | File Size: | 3026 | | Last Modified: | Mar 19 03:30:44 2001 |
| MD5 Checksum: | 16607a98f128adb61a82b23f660bfc19 |
|
| /// File Name: |
Synapsys-lkm.tar.gz |
Description:
|
Synapsis is a LKM rootkit for Linux which features file hiding, process hiding, user hiding, magic UID, and netstat hiding.
| | Author: | Berserker | | Homepage: | http://www.neural-collapse.org | | File Size: | 5298 | | Last Modified: | Mar 16 17:27:35 2001 |
| MD5 Checksum: | aa9aeedd64b1d79407698c5703d358fc |
|
| /// File Name: |
Rkit-1.01.tgz |
Description:
|
RKit is a Linux LKM backdoor/rootkit which intercepts the SYS_setuid call and ups a specified UID to 0 when that user logs in thereby successfully (and covertly) backdooring the root account.
| | Author: | TBob | | File Size: | 1878 | | Last Modified: | Mar 15 18:58:24 2001 |
| MD5 Checksum: | e6097ee042b27caf6263bec25f484838 |
|
| /// File Name: |
cbd.c.txt |
Description:
|
CBD.c is a simple backdoor which allows machines behind firewalls to be controlled via outgoing connections.
| | Author: | Grazer | | Homepage: | http://www.digit-labs.or | | File Size: | 1160 | | Last Modified: | Feb 20 21:07:05 2001 |
| MD5 Checksum: | 85c194f62635a80b322a0566ac30942e |
|
| /// File Name: |
adore-0.31.tar.gz |
Description:
|
Adore is a linux LKM based rootkit. Features smart PROMISC flag hiding, persistent file and directory hiding (still hidden after reboot), process-hiding, netstat hiding, rootshell-backdoor, and an uninstall routine. Includes a userspace program to control everything.
| | Author: | Stealth | | Homepage: | http://www.team-teso.net | | Changes: | Automatic configuration, bug fixes. | | File Size: | 9738 | | Last Modified: | Jan 9 13:54:45 2001 |
| MD5 Checksum: | 4bdf75cfb7735741285ae82f5b5d4df6 |
|
| /// File Name: |
thclinbd.tar.gz |
Description:
|
THC Backdoor for Linux - This is a simple but useful backdoor for Linux based on a FreeBSD lkm by pragmatic/THC.
| | Author: | bELFaghor | | Homepage: | http://www.s0ftpj.org | | File Size: | 997 | | Last Modified: | Jan 4 19:39:14 2001 |
| MD5 Checksum: | 7855b79979217cd5813788e01a0e1b83 |
|
| /// File Name: |
thcobsdbd.tar.gz |
Description:
|
THC Backdoor ported to OpenBSD - This is a simple but useful backdoor for OpenBSD based on a FreeBSD lkm by pragmatic/THC.
| | Author: | Pigpen | | Homepage: | http://www.s0ftpj.org | | File Size: | 1582 | | Last Modified: | Jan 4 19:37:46 2001 |
| MD5 Checksum: | 11ada1cc8831dc0a793e5b9c3a2c9b78 |
|
| /// File Name: |
aasniff.tar.gz |
Description:
|
Anti Anti Sniffer Patch - Linux kernel patches to hide a sniffer from the most known anti-sniffers.
| | Author: | Vecna | | Homepage: | http://www.s0ftpj.org | | File Size: | 2649 | | Last Modified: | Jan 4 17:55:58 2001 |
| MD5 Checksum: | 864e1c903014d25f0b1e5c91a79785b2 |
|
| /// File Name: |
eshell.c |
Description:
|
Eshell.c is a encrypted bindshell type backdoor which has a server daemon and client with AES encryption via libmix.
| | Author: | Luki Rustianto | | Homepage: | http://www.karet.org | | File Size: | 5667 | | Last Modified: | Jan 4 17:40:11 2001 |
| MD5 Checksum: | 75b97d78a51fdf7a51d4eb6fbd64fd9e |
|
| /// File Name: |
ark-1.0.1.tar.gz |
Description:
|
ARK version 1.0.1 - Ambient's Rootkit for Linux. Binaries only. This package includes backdoored versions of syslogd, login, sshd, ls, du, ps, pstree, killall, and netstat.
| | Author: | Ambient. | | Changes: | sshd backdoor is fixed, and top backdoor is now included. Warning: ARK sends email to a free email account on each system it is installed on - It is backdoored. | | File Size: | 526758 | | Last Modified: | Dec 30 20:34:19 2000 |
| MD5 Checksum: | be9b7c48c5102c32c72b410db8862d05 |
|
| /// File Name: |
asmd.tgz |
Description:
|
ASMD is a local root backdoor which is a wrapper which can wrap any setuid binary.
| | Author: | Ripper | | File Size: | 2132 | | Last Modified: | Dec 16 22:20:36 2000 |
| MD5 Checksum: | cf80ea5f62e7ba91e765a5b5054b23f7 |
|
| /// File Name: |
lbk.tar.gz |
Description:
|
LBK is a local kernel based (kld) backdoor for FreeBSD 4.0 which provides a root shell if the TERM environment variable is set with the password.
| | Author: | Cyrax | | Homepage: | http://www.pkcrew.org | | File Size: | 1190 | | Last Modified: | Dec 11 19:02:06 2000 |
| MD5 Checksum: | 9c0ce7942d25d16b8b7571dc588039f0 |
|
| /// File Name: |
ark-1.0.tar.gz |
Description:
|
ARK version 1.0 - Ambient's Rootkit for Linux. Binaries only. This package includes backdoored versions of syslogd, login, sshd, ls, du, ps, pstree, killall, and netstat. Warning: ARK sends email to a free email account on each system it is installed on - It is backdoored.
| | File Size: | 497089 | | Last Modified: | Dec 8 04:21:14 2000 |
| MD5 Checksum: | e5ccf93c811a9f73166051c1651001e9 |
|
| /// File Name: |
rkit.tar.gz |
Description:
|
Rkit is a backdoor based on blackhole.c which listens on a TCP port and requires a password.
| | Author: | Deathrow | | Homepage: | http://deathr0w.speckz.com/index.html | | File Size: | 2721 | | Last Modified: | Dec 3 11:20:52 2000 |
| MD5 Checksum: | 8cd3dd5deb68b4331d9ef2daaaf04400 |
|
| /// File Name: |
ddb-sfe.tar.gz |
Description:
|
An backdoor that lets you to reach root/user account shells over tcp channel using a procedure of callback initialized by a ICMP packet.
| | Author: | The Recidjvo | | Homepage: | http://www.pkcrew.org | | File Size: | 3447 | | Last Modified: | Dec 2 21:25:51 2000 |
| MD5 Checksum: | 8e1eeb8715c5e2283f2db800d0ef06f7 |
|
| /// File Name: |
ddb.tar.gz |
Description:
|
A backdoor that allows you to keep remote access to a shell on a LAN protected by masquerading, getting rid of the inability for non public address to listen to a port reachable from the Internet.
| | Author: | The Recidjvo | | Homepage: | http://www.pkcrew.org | | File Size: | 6937 | | Last Modified: | Dec 2 21:23:49 2000 |
| MD5 Checksum: | 160a48a5b3c8e479102e10689731737d |
|
| /// File Name: |
Rial.c |
Description:
|
RIAL is a lkm based rootkit which can hide processes, files, directories, LKMs, connections and file parts. While some of these are present in a large number of lkms, connections and file-parts hiding are new ideas, or at least i couldn't find any lkm which had them. All the processes, files, directories and lkms containing in their name the string defined in HIDE are hidden. Reading from /proc/net/tcp is intercepted and read data is filtered to hide some connections.
| | Author: | Technok | | Homepage: | http://www.pkcrew.org | | File Size: | 8893 | | Last Modified: | Dec 2 21:19:05 2000 |
| MD5 Checksum: | 3bb687667a69ddc3cd274eb1ffac0719 |
|
| /// File Name: |
inetdfun.tar.gz |
Description:
|
Inetdfun is a public version of an inetd backdoor which uses ICMP to trigger a remote shell. Includes readme and source diff.
| | Author: | Wildandi | | Homepage: | http://segfault.net/~wildandi | | File Size: | 1861 | | Last Modified: | Nov 11 20:24:47 2000 |
| MD5 Checksum: | 41dd75e78dd7a1d92e340a9a5cfdb0d3 |
|
|
|
|
|