Files ≈ Packet Storm Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers http://packetstormsecurity.org/ en-us Mon, 28 May 2012 07:42:13 GMT Packet Storm 144400 http://packetstormsecurity.org/ http://www.google-analytics.com/__utm.gif?utmwv=1.3&utmn=1801831458&utmcs=ISO-8859-1&utmsr=31337x31337&utmsc=32-bit&utmul=en-us&utmje=0&utmfl=-&utmcn=1&utmdt=Files%u2248%20Packet%20Storm&utmhn=packetstormsecurity.org&utmr=-&utmp=%2FUNIX%2Fpenetration%2Frootkits%2F&utmac=UA-18885198-1&utmcc=__utma%3D32867617.1801831458.1338190933.1338190933.1338190933.1%3B%2B__utmz%3D32867617.1338190933.1.1.utmccn%3D(direct)%7Cutmcsr%3D(direct)%7Cutmcmd%3D(none) NetcatPHPShell 1.10 http://packetstormsecurity.org/files/112491/NetcatPHPShell-1.10.zip http://packetstormsecurity.org/files/112491/NetcatPHPShell-1.10.zip http://packetstormsecurity.org/files/112491/NetcatPHPShell-1.10.html Mon, 07 May 2012 19:49:06 GMT NetcatPHPShell is a PHP backdoor that can be leveraged to launch a connect-back shell. Jynx-Kit Release 2 http://packetstormsecurity.org/files/110942/jynx2.tgz http://packetstormsecurity.org/files/110942/jynx2.tgz http://packetstormsecurity.org/files/110942/Jynx-Kit-Release-2.html Sun, 18 Mar 2012 16:22:22 GMT Jynx Kit is a LD_PRELOAD userland rootkit. Fully undetectable from chkrootkit and rootkithunter. Includes magic packet SSL reverse back connect shell. Solid building block for further LD_PRELOAD rootkits. Carbylamine PHP Encoder http://packetstormsecurity.org/files/110815/carbylamine.txt http://packetstormsecurity.org/files/110815/carbylamine.txt http://packetstormsecurity.org/files/110815/Carbylamine-PHP-Encoder.html Thu, 15 Mar 2012 02:49:22 GMT Carbylamine PHP Encoder is a PHP Encoder for obfuscating/encoding PHP files so that antivirus detection signatures can be bypassed. WeBaCoo (Web Backdoor Cookie) 0.2.3 http://packetstormsecurity.org/files/110704/webacoo-0.2.3.tgz http://packetstormsecurity.org/files/110704/webacoo-0.2.3.tgz http://packetstormsecurity.org/files/110704/WeBaCoo-Web-Backdoor-Cookie-0.2.3.html Tue, 13 Mar 2012 00:40:14 GMT WeBaCoo (Web Backdoor Cookie) is a web backdoor script-kit, aiming to provide a stealth terminal-like connection over HTTP between client and web server. It is a post exploitation tool capable to maintain access to a compromised web server. WeBaCoo was designed to operate under the radar of modern up-to-dated AV, NIDS, IPS, Network Firewalls and Application Firewalls, proving a stealth mechanism to execute system commands to the compromised server. The obfuscated communication is accomplished using HTTP header's Cookie fields under valid client HTTP requests and relative web server's responses. darkBC Python Connect-Back Script http://packetstormsecurity.org/files/110192/darkBC.py.txt http://packetstormsecurity.org/files/110192/darkBC.py.txt http://packetstormsecurity.org/files/110192/darkBC-Python-Connect-Back-Script.html Fri, 24 Feb 2012 23:12:28 GMT This is a small connect-back script written in Python. trixd00r 0.0.1 http://packetstormsecurity.org/files/109567/trixd00r-0.0.1.tar.gz http://packetstormsecurity.org/files/109567/trixd00r-0.0.1.tar.gz http://packetstormsecurity.org/files/109567/trixd00r-0.0.1.html Wed, 08 Feb 2012 22:19:13 GMT trixd00r is an advanced and invisible userland backdoor based on TCP/IP for UNIX systems. It consists of a server and a client. The server sits and waits for magic packets using a sniffer. If a magic packet arrives, it will bind a shell over TCP or UDP on the given port or connecting back to the client again over TCP or UDP. The client is used to send magic packets to trigger the server and get a shell. WeBaCoo (Web Backdoor Cookie) 0.2.2 http://packetstormsecurity.org/files/109345/webacoo-0.2.2.zip http://packetstormsecurity.org/files/109345/webacoo-0.2.2.zip http://packetstormsecurity.org/files/109345/WeBaCoo-Web-Backdoor-Cookie-0.2.2.html Thu, 02 Feb 2012 02:03:43 GMT WeBaCoo (Web Backdoor Cookie) is a web backdoor script-kit, aiming to provide a stealth terminal-like connection over HTTP between client and web server. It is a post exploitation tool capable to maintain access to a compromised web server. WeBaCoo was designed to operate under the radar of modern up-to-dated AV, NIDS, IPS, Network Firewalls and Application Firewalls, proving a stealth mechanism to execute system commands to the compromised server. The obfuscated communication is accomplished using HTTP header's Cookie fields under valid client HTTP requests and relative web server's responses. Small Python Backdoor http://packetstormsecurity.org/files/108871/Backdoor.py.txt http://packetstormsecurity.org/files/108871/Backdoor.py.txt http://packetstormsecurity.org/files/108871/Small-Python-Backdoor.html Sat, 21 Jan 2012 04:46:16 GMT This is a very small backdoor written in Python. Log2Command 1.0 http://packetstormsecurity.org/files/108299/log2command-1.0.zip http://packetstormsecurity.org/files/108299/log2command-1.0.zip http://packetstormsecurity.org/files/108299/Log2Command-1.0.html Mon, 02 Jan 2012 15:23:14 GMT log2command is a PHP script that tracks IPs in log files and executes shell commands per each IP. log2command was created as a sort of reverse fail2ban or cheap VPN-firewall: a machine with a closed firewall can be told, by a foreign machine, to accept connections from a specific IP. log2command then keeps track of the webserver log file and watches for inactivity from the user's IP. After an amount of time another command is executed that can remove the user's IP from the firewall, closing down the machine again. The PHP script is a command-line program that can be run in the background. KBeast (Kernel Beast) Linux Rootkit 2012 http://packetstormsecurity.org/files/108286/ipsecs-kbeast-v1.tar.gz http://packetstormsecurity.org/files/108286/ipsecs-kbeast-v1.tar.gz http://packetstormsecurity.org/files/108286/KBeast-Kernel-Beast-Linux-Rootkit-2012.html Sun, 01 Jan 2012 17:33:07 GMT KBeast (Kernel Beast) 2012 is a Linux rootkit that hides the loadable kernel module, hides files and directories, hides processes, hides sockets and connections, performs keystroke logging, has anti-kill functionality and more. WeBaCoo (Web Backdoor Cookie) 0.2 http://packetstormsecurity.org/files/108009/webacoo-0.2.zip http://packetstormsecurity.org/files/108009/webacoo-0.2.zip http://packetstormsecurity.org/files/108009/WeBaCoo-Web-Backdoor-Cookie-0.2.html Mon, 19 Dec 2011 23:01:24 GMT WeBaCoo (Web Backdoor Cookie) is a web backdoor script-kit, aiming to provide a stealth terminal-like connection over HTTP between client and web server. It is a post exploitation tool capable to maintain access to a compromised web server. WeBaCoo was designed to operate under the radar of modern up-to-dated AV, NIDS, IPS, Network Firewalls and Application Firewalls, proving a stealth mechanism to execute system commands to the compromised server. The obfuscated communication is accomplished using HTTP header's Cookie fields under valid client HTTP requests and relative web server's responses. WeBaCoo (Web Backdoor Cookie) 0.1.2 http://packetstormsecurity.org/files/107700/webacoo-0.1.2.tar.gz http://packetstormsecurity.org/files/107700/webacoo-0.1.2.tar.gz http://packetstormsecurity.org/files/107700/WeBaCoo-Web-Backdoor-Cookie-0.1.2.html Fri, 09 Dec 2011 17:24:42 GMT WeBaCoo (Web Backdoor Cookie) is a web backdoor script-kit, aiming to provide a stealth terminal-like connection over HTTP between client and web server. It is a post exploitation tool capable to maintain access to a compromised web server. WeBaCoo was designed to operate under the radar of modern up-to-dated AV, NIDS, IPS, Network Firewalls and Application Firewalls, proving a stealth mechanism to execute system commands to the compromised server. The obfuscated communication is accomplished using HTTP header's Cookie fields under valid client HTTP requests and relative web server's responses. Jynx Kit Userland Rootkit http://packetstormsecurity.org/files/105893/Jynx-Kit-Pub.tar.gz http://packetstormsecurity.org/files/105893/Jynx-Kit-Pub.tar.gz http://packetstormsecurity.org/files/105893/Jynx-Kit-Userland-Rootkit.html Mon, 17 Oct 2011 14:36:06 GMT Jynx Kit is a LD_PRELOAD userland rootkit. Fully undetectable from chkrootkit and rootkithunter. Includes magic packet SSL reverse back connect shell. Solid building block for further LD_PRELOAD rootkits. PHP SST Sheller 1.0 http://packetstormsecurity.org/files/105907/Sst-Sheller.zip http://packetstormsecurity.org/files/105907/Sst-Sheller.zip http://packetstormsecurity.org/files/105907/PHP-SST-Sheller-1.0.html Sun, 16 Oct 2011 17:22:22 GMT This is simply a PHP shell with a bunch of features like spoofing mail, file uploads, and more. Knull Shell Alpha1 http://packetstormsecurity.org/files/105492/knullsh.txt http://packetstormsecurity.org/files/105492/knullsh.txt http://packetstormsecurity.org/files/105492/Knull-Shell-Alpha1.html Sat, 01 Oct 2011 13:11:11 GMT Knull Shell Alpha1 is a PHP shell that has bind, reverse, and backpipe shells. Ani-Shell 1.4 PHP Shell http://packetstormsecurity.org/files/105295/Ani-Shell-1.4.zip http://packetstormsecurity.org/files/105295/Ani-Shell-1.4.zip http://packetstormsecurity.org/files/105295/Ani-Shell-1.4-PHP-Shell.html Thu, 22 Sep 2011 15:53:10 GMT Ani-Shell is a simple PHP shell with some unique features like a mass mailer, ddoser, connect-back shell, bind shell, and various other features. Turtle FreeBSD Rootkit 2 http://packetstormsecurity.org/files/104540/Turtle2.tar.gz http://packetstormsecurity.org/files/104540/Turtle2.tar.gz http://packetstormsecurity.org/files/104540/Turtle-FreeBSD-Rootkit-2.html Sun, 28 Aug 2011 21:30:51 GMT Turtle rootkit for FreeBSD. This kernel module hooks unlink() so the protected file cannot be deleted, hooks kill() so the protected process cannot be killed, and has various other nice bells and whistles. GotRoot Shell Script http://packetstormsecurity.org/files/103820/gotroot.sh.txt http://packetstormsecurity.org/files/103820/gotroot.sh.txt http://packetstormsecurity.org/files/103820/GotRoot-Shell-Script.html Tue, 09 Aug 2011 13:47:26 GMT This post-escalation bash script sanitizes 29 logs, adds a root user, and allows for package installation including hashcat, nmap, and more. Written for Ubuntu. H4ckcity Sheller Code And Tutorial http://packetstormsecurity.org/files/103809/hackcity-shell.tgz http://packetstormsecurity.org/files/103809/hackcity-shell.tgz http://packetstormsecurity.org/files/103809/H4ckcity-Sheller-Code-And-Tutorial.html Sun, 07 Aug 2011 12:12:21 GMT This archive has the H4ckcity PHP backdoor script along with a tutorial written in Persian. SyRiAn Sh3ll 7 http://packetstormsecurity.org/files/102849/syrian-shell.tgz http://packetstormsecurity.org/files/102849/syrian-shell.tgz http://packetstormsecurity.org/files/102849/SyRiAn-Sh3ll-7.html Wed, 06 Jul 2011 15:00:10 GMT SyRiAn Sh3ll is a PHP backdoor that allows for database access, local exploitation of the host, and more. Viper Auto-Rooting Script http://packetstormsecurity.org/files/102380/var.txt http://packetstormsecurity.org/files/102380/var.txt http://packetstormsecurity.org/files/102380/Viper-Auto-Rooting-Script.html Thu, 16 Jun 2011 14:14:14 GMT This is the Viper auto-rooting script that is written for Linux, SunOS, Mac OS X, and FreeBSD. Ncom Libcall Hijacking Rootkit http://packetstormsecurity.org/files/99782/ncom.tar.gz http://packetstormsecurity.org/files/99782/ncom.tar.gz http://packetstormsecurity.org/files/99782/Ncom-Libcall-Hijacking-Rootkit.html Sun, 27 Mar 2011 18:55:26 GMT Included in this archive is a private rootkit found in the wild that uses libcall hijacking. A detailed research analysis of how it functions has been created and is in the ncom.txt file. Rootkit Discovered On Debian Lenny Host Post Exim Compromise http://packetstormsecurity.org/files/96767/rk.tgz http://packetstormsecurity.org/files/96767/rk.tgz http://packetstormsecurity.org/files/96767/Rootkit-Discovered-On-Debian-Lenny-Host-Post-Exim-Compromise.html Fri, 17 Dec 2010 19:40:03 GMT This tarball was discovered on a compromise Debian Lenny host after it was compromised via the recent remote root Exim vulnerability. It includes binaries such as the MIG logcleaner, backdoored versions of top, uptime, free, pgrep and more. Please note that a thorough analysis of these binaries has not been performed and they must be considered unsafe and untrustworthy. Only use the enclosed contents for research purposes. Further details regarding this rootkit can be obtained via the reddit site link. ITSecTeam Shell 2.1 http://packetstormsecurity.org/files/95404/itsecteam_shell_2.1.rar http://packetstormsecurity.org/files/95404/itsecteam_shell_2.1.rar http://packetstormsecurity.org/files/95404/ITSecTeam-Shell-2.1.html Tue, 02 Nov 2010 04:53:21 GMT This is a backdoor PHP shell from ITSecTeam. It can execute system commands, bypass various controls, connects to common databases and edits files and directories. Turtle FreeBSD Rootkit http://packetstormsecurity.org/files/94367/Turtle.tar.gz http://packetstormsecurity.org/files/94367/Turtle.tar.gz http://packetstormsecurity.org/files/94367/Turtle-FreeBSD-Rootkit.html Thu, 30 Sep 2010 02:05:25 GMT Turtle rootkit for FreeBSD. This kernel module hooks unlink() so the protected file cannot be deleted, hooks kill() so the protected process cannot be killed, and has various other nice bells and whistles.