|
Full Version: Redkod Rootkit V1.0
Use it for your str0's against that agressive admins from these days! AND those F*KKING admins with rootkit detectors! enjoy peeps
looks like it has some great features. now, how do we detect it
Thanks for share this rootkit ! and test it work ok!
fprot antivirus detetcts it right away upon starting the download
oops, doubleposted as per accident..
detected by kav too...
but its open source wont be hard making it totally undetectable
thx for the share
intresting, lemme see
looks great thanks for the rootkit! detected by f-secure also.
Don't be surprised .. Not detected by McAfee as of now.
Can someone plz translate the comments in the code to english
has any1 got this 2 work. i compiled it ok and ran. the dll loads but its only folders and files it will hide, i can still view the procesees and regkeys and c the connection in netstat
thank's, fos sharing this rk, anyone can tell me where i can find ms_blaster source code?
hummmm thabkz alot for share your toolz mand, i really to appreciate that.
nice one ..
thanks 4 distributing the source along with it...
its nice r00tkit dude.
tnx for that.
well thats very useful. thanx.
btw use alternative compilers to make it undetected
Hey nice rootkit.... with really nice options.
I will try to modd the surce... Thx for sharing !
Thanks for this. gonna check it out
k...thx for sharing
i tried it ..seems to work but i dont get the "underline" thing... " _ " those should be invisible but when i do fport i can still see my blabla.exe running so i should rename my blabla.exe to _blabla.exe...right? am i doing something wrong here ?!!?
Awesome ! Thanks A LOT for distributing the source code... Pls add this mod 4 simplify configuration :
...or something like this.
thanx sharing that nice rootkit
or u just modify the sozurce and compile a dll for your needs / files.... shouldnt be that hard
hey thanks for posting this rootkit!!!
thankyou, for this new piece of s/w, i will have something diff to test out... much appreciated ..
also not reported by mcafee with latest definitions..
i have to run the rootkit with this command?
or i can choos another -p? like:
or something like that.? and i need to run the rootkit one time? or every time the computer is rebooted?
you can inject every process you want with the dll it will be rootkited, but, you will need the inject every process you want to be rootkited. its not very usefull is it ? ^^
if you inject explorer.exe, each new created process will be automatically injected, since a process is created by explorer.exe calling CreateProcessW from kernel32.dll, this fonction has been of course hooked to automatically inject each new created process. and yes you will need to run the rootkit each time the computer reboot ^^
so its not the best root kit :\ tnx for the answer
what ? injected the dll in explorer.exe is the only (proper) way to have any process automatically rootkited with a pure userland rootkit (well as i know...) mine work in a very similirar way. about the *reboot* problem, its just your job to make it as a system service, or a "run regkey", and its not quite difficult :s
especially when u can hide registry keys ;]
yep ^__^ (but i prefer system service, to give the rootkit/backdoor, nt authority rights)
Big thx this r00tkit is very usefull :]
Thanks for this one
Following my test in remote, it functions very well
Thank you for this rookit !
cheers for the source , code be easy to change and make none detectable version
I read about this somewhere..
Seems to kick arse.. Is it alright? Cheers.
this really looks like kicking ass. Worth a try thx for sharing
hey peeps,
ive tried it to compile but how to do this?.. ive tried it with the rknt.dll already in the package but still my folders beginning with _ are seeable plz helpzor me
I started the Rootkit and injected the explorer.exe.
but i can see folders oder files with "_". The explorer.exe seems not to be injected. started with RkNTLoad -p explorer.exe -d RkNT.dll -l what can be the problem ? many thx
the winini.sys file idea needs more thought put into it. this filename itself is suspicious, and also searching for the file itself could be used to detect presence of this rootkit since the filename is unique to this version. im guessing this isnt an open source project?
wow nice
thx
@Gargoyle
use the full path of the dll: (ex: "c:\rknt.dll") @tonikgin GNU GPL, and well commented (in french) @all this release is a bunch of bug, wait the next release ^^
guys.. can any1 guide me into making this rootkit undetectable???
Wow, thanks for the rootkit!
This should help me out quite a bit, especially with the source code. I am working on making a metasploit payload set that include rootkits, and a non-kernel driver rootkit would be perfect! Thanks for the excellent post
thanks for sharing
rgds
guys.. i need some guide here..
how do i make it err unique, undetectable..? izzit by disassemble it and reassemble it?? do i need programing skills for this? im new to this kind of thing..
Thanx For the rootkit...
Will have a try
for me this rk is not so bad but hxdef si really better !!!
for many thinx, like the disk size modification, et for the possibility to hide that we want, not only all begin by _ because, many exe aren't hexeditable, and so we can't modifi thet service name ...
but a rootkit means nothing if there's not a shell server or sth. like that... or how does it work?
interesting...
miam miam thanks for this soft :]
Thanks, Very good ! :-)
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
|
||||||||||||||||||||||