lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <001a01c58559$004b0ff0$0900000a@devserver>
Date: Sun Jul 10 15:04:48 2005
From: securitynews at wanadoo.fr (securitynews)
Subject: how to hide files,
	services and process in windows 2k/xp/2k3 box

Hi ,
some samples with source code and tips at :
http://www.rootkit.com/index.php

and http://www.osronline.com/
for windows driver development


Stephane.



----- Original Message ----- 
From: "fatb" <fatb@...urity.zz.ha.cn>
To: <full-disclosure@...ts.grok.org.uk>
Sent: Sunday, July 10, 2005 2:08 PM
Subject: [Full-disclosure] how to hide files,services and process in windows 
2k/xp/2k3 box


> hi all guys
>
>    I'm trying to write a rootkit to hide files,services and process
>
> in windows 2k/xp/2k3 box ,and it would not be detected by 
> icesword,rkdetector
>
> and so on.
>
>    Anybody could be kind enough to give me some tips or suggestions , thx 
> alot!
>
>
> BTW: I heard that golden hxdef could be avoid from icesword,rkdetector
>
> and any other anti-rootkit software ,anybody knew something about the 
> golden hxdef ?
>
>


--------------------------------------------------------------------------------


> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/

--------------------------------------------------------------------------------



-- 
No virus found in this outgoing message.
Checked by AVG Anti-Virus.
Version: 7.0.323 / Virus Database: 267.8.11/45 - Release Date: 09/07/2005


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ