Boxer 0.99 BETA3 appears to be a Linux 2.6 series /dev/mem rootkit binary. This binary has not been tested and should be researched/tested with extreme caution.
--
BOXER
This technical information is being provided for evil purposes only
==
VERSION
0.99 BETA3
==
FEATURES
- * Hidden process creation (hidden sockets (tcp/udp/unix/raw), hidden procfs info). Suckit style hidden files.
- * Remote control interface.
- - Authentication using RSA2048 keys.
- - TCP-channel encryption with AES256 and RC4.
- - Multiple (parallel) virtual connections inside one “physical” TCP-connection. Each virtual connection can serve one of the following tasks:
- a. remote command execution
-
- b. shell sessions
- c. file upload/download
- d. Connections with other BOXER-servers and tunneling them to the client (creation connection chains: client->server1->server2).
- * Tty sniffing
- * Reboot-safe
- * Ability to run 3rd party binaries (attached to main agent binary) when server reboots.
- * Run on x86 32bit machines (kernel: 2.4.*, 2.6.* including 2.6.21).
Comentarios
Enviar un comentario nuevo