Re: Non registering shell

From: Brian Hatch (vuln-dev@ifokr.org)
Date: 02/28/03

  • Next message: kim0: "Re: Security contact for Bank Of America"
    Date: Fri, 28 Feb 2003 08:04:52 -0800
    From: Brian Hatch <vuln-dev@ifokr.org>
    To: Rory Savage <rsavage@nandomedia.com>
    
    
    

    > Now that you mention it, I think it was a backdoor (a special
    > rootshell).

    That makes much more sense.

    > Can any provide URLs to example backdoors?

    Uhh, there are boatloads. Try any of the standard exploit
    archives (packetstorm, etc) and you'll be swimming in them.
    You might want to see if chkrootkit has pointers to the source
    of the rootkits it detects.

    Or you could just write your own. Snag the knark rootkit and
    modify it to suit your needs, for example. The code in these
    things are usually pretty easy to follow, except where it's not.

    --
    Brian Hatch                  A closed mouth
       Systems and                gathers no feet.
       Security Engineer
    http://www.ifokr.org/bri/
    Every message PGP signed