Re: 'rooted' NT/2K boxen?

From: H C (keydet89@yahoo.com)
Date: 05/02/02


Date: Thu, 2 May 2002 13:26:18 -0700 (PDT)
From: H C <keydet89@yahoo.com>
To: zeno <bugtraq@cgisecurity.net>


> I haven't seen any type of windows 'rootkit' myself.
> For example a replacement of netstat, nbtstat,
> route, and other utilities to give proccess
> information etc...
>
> If anyone knows of any let me know I'm interested.
> Of course the problem with getting windows
> source is an issue.
 
Older versions of Hoglund's NTRootkit are available
here:
http://www.megasecurity.org/Tools/Nt_rootkit_all.html

The 'newest' version I've been able to find is here:
http://www.ntndis.com/downloads.shtml

click on "Windows NT Rootkit Source".

Not sure how that applies to my original question, but
there it is...

__________________________________________________
Do You Yahoo!?
Yahoo! Health - your guide to health and wellness
http://health.yahoo.com

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • [REVS] Analysis of a win32 Userland Rootkit
    ... Userland rootkit for Microsoft Windows. ... The hook is able to provide the fastest injection of the DLL into target ... and a real taste for circular double-linked lists. ...
    (Securiteam)
  • RE: rooted NT/2K boxen?
    ... It is completely possible to take over a Windows NT/2K box... ... control there are a bunch of remote administration trojans, ... > Do You Yahoo!? ... Health - your guide to health and wellness ...
    (Focus-Microsoft)
  • Rootkit infection (Popureb) requires Windows reinstall, says Microsoft
    ... I'm still running Windows 98, and I'm still immune to these rootkits. ... Rootkit infection requires Windows reinstall, says Microsoft ... the operating system after the computer's BIOS does its start-up checks. ...
    (alt.comp.anti-virus)
  • Re: Need help removing malware
    ... The free version is only a on-demand scanner. ... Rootkit Revealer but you need to know how it works and it doesn't do ... When you say you could not "find" the folder, and assuming Explorer is configured to show both hidden AND *system* files, did you manually dig through Explorer to navigate through the folders or did you use the Search function in Windows XP? ...
    (alt.comp.anti-virus)
  • Re: SDTable
    ... when you tried using a different router things suddenly improved. ... This is more likely than a PCI rootkit. ... But this rootkit does not care if you reinstall your OS. ... I have installed windows, then installed a debian/ubuntu based Linux ...
    (microsoft.public.windowsupdate)