#
Main FAQ Search Member List User Groups Profile Log in to check your messages
Login Register
Return.to/Scheinsicherheit
rootkit detection

 
Post new topic   Reply to topic    Return.to/Scheinsicherheit Forum Index -> Security Software
View previous topic :: View next topic  
Author Message
mike
Guest





PostPosted: Mon Aug 23, 2004 6:53 am    Post subject: rootkit detection Reply with quote

i ran into a couple of interesting tools that could be used to detect some rootkits: klister and VICE.

mike
Back to top
ntl
Site Admin


Joined: 27 Jun 2004
Posts: 60

PostPosted: Mon Aug 23, 2004 7:29 pm    Post subject: Reply with quote

That's true. There are even two more tools which are not mentioned in our rootkit article: the tools are called Kernel PS and Patchfinder2. Kernel PS is driver based and can, for example, detect & terminate an active Hacker Defender rootkit.

We have not mentioned these tools because they must be downloaded from malware/underground websites. But everyone should make up his/her own mind:

See http://www.rootkit.com/ for Klister, Patchfinder2 and VICE.

See http://www.xfocus.net/tools/8.html for Kernel PS (file name is knlps).
Back to top
View user's profile Send message
Spanner intheWorks
Guest





PostPosted: Sat Mar 19, 2005 7:08 pm    Post subject: RootKit Detection Treasure Trove Reply with quote

For those of you who are interested in RK's etc, i thought you might like to know that i've got a thread going over at Wilders called - RootKit Detection Treasure Trove - which you may like to take a look at and follow, and/or even better hopefully contribute to if you wish.

Regards,

Spanner

http://www.wilderssecurity.com/showthread.php?s=95908884f62ac79cc539f5af10599a2a&t=69658
Back to top
Guest






PostPosted: Sun Mar 20, 2005 9:15 am    Post subject: Reply with quote

@Spanner

Good work. How about testing a recent rootkit (like Aphex Rootkit 2005) against all these tools? I understand that, for example, F-Secure Backlight can be bypassed by certain rootkits.

If you need help with testing please let me know.
Back to top
Guest






PostPosted: Mon Mar 21, 2005 7:31 am    Post subject: Reply with quote

To Mystery guest !

Hi there, Thanx glad you appreciate it, cos a Lot of work has gone in to it, but i think it's a worthwhile project.

Yes i heard that it's possible for some Anti RK's to be compromised, but i suppose that's to be expected as of right now. It's sorta early days in a way, even though RK's have been around for a while, Anti RK's havn't !

As for me testing RK's lol, Well as i mentioned in my thread on Wilders, I'm NO expert on this at ALL ! I do though take a keen interest in it as i think it's a fascinating concept/subject.

So all i'm doing is providing what research/info/tools/links etc i am able , to enable others who are more skilled in the art to attack this threat with as much ammunition as possible.

If you feel that you are able to help in testing etc then that'd be great, and if you can contribute in some way to my thread on Wilders i'm sure we'd All love to hear from you.

Regards,

Spanner
Back to top
Guest






PostPosted: Sat Apr 02, 2005 8:19 am    Post subject: Reply with quote

ProAgent 2 (Spysoftware, Keylogger, Password Stealer)

"ABILITIES :
- No Processes are Visible in any Task manager,Process explorer(sysinternals).
- Hiden from sysinternals RootkitRevealer (RootkitRevealer is an advanced root kit detection utility)
- Hidden from by F-Secure BlackLight Rootkit Elimination Technology!
- Not opens a port on system.
- No connection ports are Visible while sending mail in any Tcp Viewer (netstat,fport,CurrPorts,Tcpview etc.)
- No files are Visible in any explorer.
- No registry keys and values are Visible in any registry editor like regedit.exe,msconfig,autorun.exe (sysinternals).
- Firewall bypassing by injecting Dll into default web browser and sending mail.
- New injection technic for new generation firewalls like zone-alarm's last version, etc...
- No need to your own SMTP server. It sends directly to MX.
- Automatic Uninstall."
Back to top
Guest






PostPosted: Thu Jun 09, 2005 10:28 pm    Post subject: Reply with quote

Not at the moment:

modGREPER is a hidden module detector for Windows 2000/XP/2003. It searches through whole kernel memory (0x80000000 – 0xffffffff) in order to find structures which looks like a valid module description objects. Currently two most important objects type are recognized: well known _DRIVER_OBJECT and _MODULE_DESCRIPTION. GREPER has some sort of artificial intelligence built in, which allows it recognize if the given bytes actually describe a module-specific object. The term AI for this algorithm is probably a little bit exaggerated, since it is just a few bunches of logical rules which should be satisfied by the potential fields of the structure in question...

http://invisiblethings.org/tools.html#modgreper


I have tested modGREPER with Hacker Defender only. In respect of this rootkit it works fine.
Back to top
Spanner
Guest





PostPosted: Sat Jun 11, 2005 7:11 pm    Post subject: Rootkit Detection Treasure Trove - Now Here ! Reply with quote

Hi just thought i'd let you know that i'm not on Wilders anymore so my RootKit thread isn't available there anymore.

I have made All the Info/Apps/Links etc available for download. The details are here - http://www.testing.onlytherightanswers.com/modules.php?name=Forums&file=viewtopic&t=20&sid=b0a3c433ecffacbdf772781a77303f5f

Regards,

Spanner
Back to top
Display posts from previous:   
Post new topic   Reply to topic    Return.to/Scheinsicherheit Forum Index -> Security Software All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



zeroSpace Template © Digital-Delusion
Powered by phpBB © 2001, 2002 phpBB Group
Back to Top
</body>