Rootkit per a l'IOS
De la llista NANOG, es presentarà un rootkit per a l'IOS de Cisco el proper dia 22 dins de l'EUSecWest:
For those of you who haven't heard, Sebastian Muniz of CORE Security will release a proof of concept rootkit for Cisco's IOS.
(…)
The rootkit consists of a binary modification to the IOS image downloaded from the device so it has a pretty big and obvious footprint. More stealth is not needed for the presentation to make the points I want to make.
The main feature of Da IOS Rootkit is the universal password. Every call to the different password validation routines grant access to the user if the unique rootkit password is specified. This is what will be in the public release. Other features such as hiding files, processes and connections will not be included. The core of the rootkit code is written in plain C instead of assembly. It doesn't persist through upgrades yet but future versions probably will.
Entrades aleatòries
Carregant…


Això es perillós, pero molt :S Gracies per l'enllaç.
Comentari by pinger — 21 maig 2008 @ 19:18