Posts

Showing posts with the label Rootkit

Tyton - Linux Kernel-Mode Rootkit Hunter For 4.4.0-31+

Image
Linux Kernel-Mode Rootkit Hunter for 4.4.0-31+. For to a greater extent than information, catch Tyton's website . Detected Attacks Hidden Modules Syscall Table Hooking Network Protocol Hooking Netfilter Hooking Zeroed Process Inodes Process Fops Hooking Interrupt Descriptor Table Hooking Additional Features Notifications : Users (including myself) practise non actively monitor their journald logs, too therefore a userland notification daemon has been included to monitor journald logs too display them to the user using libnotify. Notifications are enabled subsequently install past times XDG autorun, too therefore if your DM does non accept /etc/xdg/autostart it volition fail. DKMS : Dynamic Kernel Module Support has been added for Arch too Fedora/CentOS (looking to expand inward the nigh future). DKMS allows the (near) seamless upgrading of Kernel modules during amount upgrades. This is mainly of import for distributions that supply rolling releases or upgrad...

Hiddenwall - Linux Marrow Module Generator For Custom Rules Alongside Netfilter (Block Ports, Hidden Mode, Rootkit Functions, Etc)

Image
HiddenWall is a Linux substance module generator for custom rules alongside netfilter. (block ports, Hidden mode, rootkit functions etc). The motivation: on bad situation, assailant tin position your iptables/ufw to fall... but if you lot receive got HiddenWall, the assailant volition non uncovering the hidden substance module that block external access, because receive got a claw to netfilter on substance land(think similar a mo layer for firewall). My starting fourth dimension purpose at this projection is protect my personal server, straight off is protect the machines of my friends. When i verbalise "friends", i tell peoples that don't know how to write depression degree code. Using the HiddenWall you lot tin generate your custom substance module for your firewall configuration. The depression degree programmer tin write novel templates for modules etc... First step, empathise earlier run Verify if the substance version is 3.x, 4.x or 5.x: uname...