NDIS backdoor

作者发现了一个名为Uay的强大Rootkit项目,该项目由一名叫做Uay的开发者编写。该Rootkit钩住了内核中网络层的最低级别,使得它对于软件防火墙来说是不可见的。目前它可以提供类似cmd.exe风格的shell,并支持cd、dir、copy和del等命令。

摘要生成于 C知道 ,由 DeepSeek-R1 满血版支持, 前往体验 >

 

I just spotted a scary looking rootkit project:

http://www.xfocus.net/tools/200602/uay_source.rar

this is written by a guy called Uay, and it has the makings of a powerful rootkit.

He has hooked the lowest level point of networking in the kernel, the ndis layer, which means he is invisible to software firewalls.

The rootkit at the moment will provide a "cmd.exe" style shell that supports commands such as cd, dir copy, del using native api that are exported by ntoskrnl.exe.

I suspect it will also be invisible to most rootkit detectors, as he is not hiding anything like files, ports etc - although a ndis hook detector will find it.

This reminds me of some ideas I had been working on recently - implementing malware purely in the kernel.

I've made a ircbot that runs 100% in ring0 for fun, using Valerino's socket library for the kernel. Perhaps I will post it here some time soon...

Oh and on a closing note, check out Yorn's blog at: http://yorn.wordpress.com/

See ya.

评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值