Forums: Good Rootkit For Linux And Solaris ? - Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Good Rootkit For Linux And Solaris ? you know any good up to date rootkits ?

#1 User is offline   jimmy 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 135
  • Joined: 21-December 03

Posted 16 May 2004 - 03:44 PM

Anyone knows a good rootkit for linux ?
I'm also looking for a rootkit for sparc solaris 2.8.
I know I can google, just wondering anyone had good experiences with some.

Also looking for something to patch the ssh that is running so I have an extra password that is hidden and can be used to enter. Also with logging disable would be nice. I do not look for installs of ssh with such backdoor, I just want to change the ssh that is running already
0

#2 User is offline   SCVirus 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 125
  • Joined: 01-February 04

Posted 16 May 2004 - 05:14 PM

Adore NG and SH are good ones for Linux, never found anything for solaris.
0

#3 Guest_LikeAHurricane_*

  • Group: Guests

Posted 20 May 2004 - 12:12 PM

SucKIT in Linux
no idea about Solaris.
0

#4 User is offline   linoxx 

  • Private
  • Icon
  • Group: Members
  • Posts: 4
  • Joined: 20-July 03

Posted 26 June 2004 - 09:56 PM

www.honeynet.org/tools/sebek - should suit your needs if you don't plan on the server / box in question being powered down.

Thanks

Linoxx
0

#5 User is offline   SCVirus 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 125
  • Joined: 01-February 04

Posted 27 June 2004 - 09:32 PM

hxxp://www.honeynet.org/tools/sebek is the best you'll probably find that works on both, it does have some failings but its open source so you can add a in things you need.
0

#6 Guest_zz76_*

  • Group: Guests

Posted 09 September 2004 - 10:59 PM

my choice

http://stealth.7350.org/rootkits/
0

#7 User is offline   RoscoeT 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 63
  • Joined: 15-October 04

Posted 15 October 2004 - 09:04 PM

I have seem most of those from the wrong end, I found Suckit to be fairly annoying but not impossible to track down and disable. Using root kits is not, imho, a good way to hold a server. The exploit they use should be understood first. I, as an admin, find these right away usually and take the server offline asap. Understanding the exploit will keep you from hanging out the neon "I've been rooted" sign.


Roscoe
0

#8 User is offline   chrystalsky 

  • Private
  • Icon
  • Group: Members
  • Posts: 2
  • Joined: 14-October 04

Posted 26 October 2004 - 06:24 AM

http://www.egocrew.d...category-4.html

Here you can find a few Rootkits for Linux and i like SuckIT and Knark. Never saw a Solaris Rootkit, only for Linux, BSD and Windows.


*greetz*
0

#9 User is offline   SCVirus 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 125
  • Joined: 01-February 04

Posted 07 November 2004 - 03:46 PM

Absolutly use sabek (modified to taste of cource)
0

#10 User is offline   blackwarrior 

  • Private
  • Icon
  • Group: Members
  • Posts: 18
  • Joined: 17-February 04

Posted 03 September 2005 - 09:56 AM

Solaris usually got the telnetd enabled with ALLOW * in the hosts.deny file so you can just
code a little /bin/login backdoor, compile it on one of your solaris box's that got gcc and use it in future hacks.
for linux systems you should use a lkm based backdoor like SK or adore.. ;x
0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting