hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Full Version: Vanquish R00tkit
Pages: 1, 2
iWeasel410
thanks for the great kit! works like a charm! one question though, will port hiding from netstat (fport, tcpview, etc) be implemented? I'm always paranoid that the person on the remote comp will run it, find my IP, and screw me over. thanks!
tweakz20
QUOTE (smallcat28 @ Apr 13 2004, 02:30 PM)
I found it in www.rootkit.com already.but i cannt understand the source code,want someone write a help about this source code.

did you try learning the language... or at least looking at a reference to all the commands?
sharky
thx I will test that
Masterace
Thx for this tool.You can call me a lamer,but can anyone tell me where I can find some german tuts for this Stuff?I'm afraid my english could be to bad understandig how it works and the first thing i learnd was: more reading+understanding=less bad mistakes!
totototo
Very good thx.
s3mtexx
thnx m8, just what i needed biggrin.gif:D:D:D
heheheh
LittleHacker
kool
thanks for source!
Is it still Undetected?
Baracuda
QUOTE (Masterace @ Apr 18 2004, 01:03 AM)
Thx for this tool.You can call me a lamer,but can anyone tell me where I can find some german tuts for this Stuff?I'm afraid my english could be to bad understandig how it works and the first thing i learnd was: more reading+understanding=less bad mistakes!

just read the source
leviathan
QUOTE (Masterace @ Apr 18 2004, 01:03 AM)
Thx for this tool.You can call me a lamer,but can anyone tell me where I can find some german tuts for this Stuff?I'm afraid my english could be to bad understandig how it works and the first thing i learnd was: more reading+understanding=less bad mistakes!

Bah, you managed to write that sentence so your english should be good enough to understand the most english tuts, and you'll learn a good lot of English by reading them wink.gif

(German here as well ^^)

That rootkit sounds interesting, I'll give it a try at the weekend, thanks a lot for pointing me towards it.
Qlimax
someone can tell me what is a r00tkit?
willywutz
Hey, just tried the rootkit.

On local machine installed it as administrator everything works fine
files / dirs are hidden and not accessible.
The vanquish part of filenames was hidden.

Next step installed it in my local lan on another machine using a
Bindshell (local system account).

I noticed with Fport / Tlist all process are further visible with full name.

Anyone have same experiences ?
OR does i made anything wrong ?

Thx in advance.


EDIT: I see prob seems to be that i started the rootkit with local system acc.
Should use runas ( rtfm helped )
ivanchin99

i got it..
it hides the file but wont let u access em.. not the kind im finding..
could any1 recomend any rootkit that hide files and allow u to run it??
xcept FU
nackas
QUOTE (ivanchin99 @ Sep 12 2004, 04:53 PM)
could any1 recomend any rootkit that hide files and allow u to run it??
xcept FU

hx-def (Hacker Defender) does a great job at hiding files, reg keys, services. I actually use it myself happy.gif. You may have to do some modding of the source though, as most antivirus nowadays detects it, but there is a tutorial on the board which goes through this.

hxxp://www.rootkit.com/vault/hf/hxdef100.zip <-- bin + source
http://www.governmentsecurity.org/forum/in...topic=6268&st=0 <-- modding tutorial
Gargoyle
Installed it on my local PC.
In the logfile on c:\ was a success message,
but i kann see folder with the "magic string".

Whats wrong??
KoSmO
wow ohmy.gif
Masterace
Think the easiest way to modify hxdef is to pack it with upx and after this use the new version of morphine to make it undetectet.Works fine for me.
Killaloop
QUOTE (Masterace @ Sep 17 2004, 02:37 AM)
Think the easiest way to modify hxdef is to pack it with upx and after this use the new version of morphine to make it undetectet.Works fine for me.

install f-secure and try again smile.gif

this av cracks all versions of morphine and detects even high modified versions of hxdef
very good one
garcia
thank you it well rootkit I was to test it biggrin.gif
macca
thx for the rootkit, i wil play some tomoz.. morphine & upx r the best together at hiding exe`s.. but f-secure is a bitch sad.gif
dd44
QUOTE(macca @ Sep 23 2004, 07:43 PM)
thx for the rootkit, i wil play some tomoz..    morphine & upx r the best together at hiding exe`s.. but f-secure is a bitch sad.gif
*




Hello!

But when u upx and morphine it, hxdef install a .sys drivers who i think is detected by AV isnt it ?
tibbar
yes which is why you need to mod the source to the driver and recompile using DDK
ghost_c
interesting....thnks m8
touk
QUOTE(dd44 @ Oct 16 2004, 04:14 PM)
QUOTE(macca @ Sep 23 2004, 07:43 PM)
thx for the rootkit, i wil play some tomoz..    morphine & upx r the best together at hiding exe`s.. but f-secure is a bitch sad.gif
*




Hello!

But when u upx and morphine it, hxdef install a .sys drivers who i think is detected by AV isnt it ?
*



Yes you r absolutely r8, that's why your have to mod hxdef ressources using the DDK libs and a C editor.
kok
nice tool man
thx
kok
it's a very nice tool ;-)
[N0N4M3]
detected :q
passi
Making it undetectable is your job. There are enough threads about this topic in this board.

Btw: Please stop lame replying.
Neoankt
QUOTE
Making it undetectable is your job. There are enough threads about this topic in this board.

Btw: Please stop lame replying.


passiw is very much correct
for example if you release your version publically then usually within a week AV's will update their sigs and libs in which you version will be detected now if you dont release it and keep it private (or to yourself) its harder
Intox
i think that vanqish doesn't hide any port and connection...
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.