Section: .. / UNIX / audit /
| /// File Name: |
lgool.c |
Description:
|
Lgool is a program that will search Google for a given vulnerability. It does the exact same thing you could do by going to Google and searching for nasty stuff like passwd.cfg, but without all the trouble of actually opening a web browser. It operates in a way that is similar to "gooscan" (written by johnny and presented at defcon this year).
| | Author: | Innate | | File Size: | 6575 | | Last Modified: | Oct 24 16:37:27 2004 |
| MD5 Checksum: | e55503a54689dadbc3579185b250e9d1 |
|
| /// File Name: |
AntiExploit-1.3b5.tar.gz |
Description:
|
AntiExploit is an exploit scanner to detect local intruders. It scans for over 3900 suspicious files, has daily database updates, and will act if a file is accessed. It uses the dazuko kernel module, which is also used by clamAV, Amavis, and other virus scanners.
| | Author: | Enrico Kern | | Homepage: | http://www.hzeroseven.org/projects/aexpl/ | | Changes: | Various bug fixes and feature improvements. | | File Size: | 274728 | | Last Modified: | Oct 13 03:21:43 2004 |
| MD5 Checksum: | 8710cf7990fd876bce108402cb735e0a |
|
| /// File Name: |
AntiExploit-1.3b3.tar.gz |
Description:
|
AntiExploit is an exploit scanner to detect local intruders. It scans for over 3900 suspicious files, has daily database updates, and will act if a file is accessed. It uses the dazuko kernel module, which is also used by clamAV, Amavis, and other virus scanners.
| | Author: | Enrico Kern | | Homepage: | http://www.hzeroseven.org/projects/aexpl/ | | Changes: | Added proxy support, SSL support to the update function, and various other enhancements. | | File Size: | 268841 | | Last Modified: | Sep 17 02:10:12 2004 |
| MD5 Checksum: | 7f9b4827fbcb8d7c98816888e3b9da8c |
|
| /// File Name: |
rkhunter-1.1.8.tar.gz |
Description:
|
Rootkit Hunter scans files and systems for known and unknown rootkits, backdoors, and sniffers. The package contains one shell script, a few text-based databases, and optional Perl modules. It should run on almost every Unix variety except Solaris and NetBSD.
| | Author: | M. Boelen | | Homepage: | http://www.rootkit.nl/ | | Changes: | Added support for Red Hat 6.2 and hashes, Added support for Red Hat Enterprise Linux ES 3, Taroon update 3, Added support for Red Hat Enterprise Linux AS 3, Taroon update 1. Various other improvements and code clean up. | | File Size: | 112615 | | Last Modified: | Sep 13 23:45:09 2004 |
| MD5 Checksum: | 91cae6f04582fb0b27c96784ffe5adae |
|
| /// File Name: |
AntiExploit-1.3b2-hotfix.tar.gz |
Description:
|
AntiExploit is an exploit scanner to detect local intruders. It scans for over 3900 suspicious files, has daily database updates, and will act if a file is accessed. It uses the dazuko kernel module, which is also used by clamAV, Amavis, and other virus scanners.
| | Author: | Enrico Kern | | Homepage: | http://www.hzeroseven.org/projects/aexpl/ | | Changes: | Skipping zero length files, Log shows real exploit count without dups, Fixed double kill of the main thread. | | File Size: | 256133 | | Last Modified: | Sep 9 01:28:41 2004 |
| MD5 Checksum: | abb91ef52cec0a634fe4c1f4ce0e8d95 |
|
| /// File Name: |
rkhunter-1.1.7.tar.gz |
Description:
|
Rootkit Hunter scans files and systems for known and unknown rootkits, backdoors, and sniffers. The package contains one shell script, a few text-based databases, and optional Perl modules. It should run on almost every Unix variety except Solaris and NetBSD.
| | Author: | M. Boelen | | Homepage: | http://www.rootkit.nl/ | | Changes: | Added support for ADM Worm, Added support for MzOzD and spwn backdoor, Added LKM filename check (experimental), Added passwordless user account test. | | File Size: | 108223 | | Last Modified: | Aug 31 00:59:26 2004 |
| MD5 Checksum: | 95e8eeb46f0f2cd928180ac9cfb2dbb0 |
|
| /// File Name: |
AntiExploit-1.3b2.tar.gz |
Description:
|
AntiExploit is an exploit scanner to detect local intruders. It scans for over 3900 suspicious files, has daily database updates, and will act if a file is accessed. It uses the dazuko kernel module, which is also used by clamAV, Amavis, and other virus scanners.
| | Author: | Enrico Kern | | Homepage: | http://www.hzeroseven.org/projects/aexpl/ | | File Size: | 255606 | | Last Modified: | Aug 24 04:03:34 2004 |
| MD5 Checksum: | 065703dd544a43a820597f5e83313916 |
|
| /// File Name: |
rkhunter-1.1.6.tar.gz |
Description:
|
Rootkit Hunter scans files and systems for known and unknown rootkits, backdoors, and sniffers. The package contains one shell script, a few text-based databases, and optional Perl modules. It should run on almost every Unix variety except Solaris and NetBSD.
| | Author: | M. Boelen | | Homepage: | http://www.rootkit.nl/ | | Changes: | Added support for RSHA's rootkit, various other additions and fixes. | | File Size: | 105701 | | Last Modified: | Aug 19 03:57:12 2004 |
| MD5 Checksum: | c8b8aaad07a0f440bc1af5d097ce550c |
|
| /// File Name: |
rkhunter-1.1.5.tar.gz |
Description:
|
Rootkit Hunter scans files and systems for known and unknown rootkits, backdoors, and sniffers. The package contains one shell script, a few text-based databases, and optional Perl modules. It should run on almost every Unix variety except Solaris and NetBSD.
| | Author: | M. Boelen | | Homepage: | http://www.rootkit.nl/ | | Changes: | Discovers the Ni0 rootkit, and has some new tests. Fixes the xinetd.conf false positive and other minor bugs, improved version checker, and updated the databases. | | File Size: | 103822 | | Last Modified: | Aug 11 22:04:07 2004 |
| MD5 Checksum: | 750df8c8ab7855bc81ba10504694a33a |
|
| /// File Name: |
rkhunter-1.1.4.tar.gz |
Description:
|
Rootkit Hunter scans files and systems for known and unknown rootkits, backdoors, and sniffers. The package contains one shell script, a few text-based databases, and optional Perl modules. It should run on almost every Unix variety except Solaris and NetBSD.
| | Author: | M. Boelen | | Homepage: | http://www.rootkit.nl/ | | Changes: | Now supports Debian 3.1, FreeBSD 4.10, SunOS, OpenBSD 3.5, and White Box EL. Adds boot.local/Apache2/mod_rootme support and an application scanner. Display-logfile option was added. Fixes bugs and improves some tests. | | File Size: | 102147 | | Last Modified: | Aug 9 05:36:16 2004 |
| MD5 Checksum: | 08938c110c8363c62c82dad0571517d0 |
|
| /// File Name: |
rkhunter-1.1.3.tar.gz |
Description:
|
Rootkit Hunter scans files and systems for known and unknown rootkits, backdoors, and sniffers. The package contains one shell script, a few text-based databases, and optional Perl modules. It should run on almost every Unix variety except Solaris and NetBSD.
| | Author: | M. Boelen | | Homepage: | http://www.rootkit.nl/ | | Changes: | Added support for SuSE Linux Enterprise Server 8, SuSE Linux Openexchange Server 4.1.1, Fedora Core 2 with 64 bits support, and more. Added bug fixes and code tweaks. | | File Size: | 98309 | | Last Modified: | Jul 21 10:42:00 2004 |
| MD5 Checksum: | 62271204de0fa0d2bf1b8489b1458dc7 |
|
| /// File Name: |
rkhunter-1.1.2.tar.gz |
Description:
|
Rootkit Hunter scans files and systems for known and unknown rootkits, backdoors, and sniffers. The package contains one shell script, a few text-based databases, and optional Perl modules. It should run on almost every Unix variety except Solaris and NetBSD.
| | Author: | M. Boelen | | Homepage: | http://www.rootkit.nl/ | | Changes: | Added support for Mandrake 8.2, 9.0, 9.1, Redhat Enterprise Linux AS, Slackware 10, Gentoo 1.5. Improved various other support and updated hashes. | | File Size: | 94776 | | Last Modified: | Jul 14 12:15:00 2004 |
| MD5 Checksum: | f580ee74e3cbcbe945bfd87e403f3145 |
|
| /// File Name: |
DumpSIS-0.81.zip |
Description:
|
Symbian SIS file dumping utility that allows for analysis of potential malware without actual installation of files. It provides information on file headers (UIDs, Version, Number of Languages, Number of files), file list (Destination name by default, Source filename and file type).
| | Author: | Jimmy Shah | | Changes: | Minor fix for decoding If/Else If statements in SIS files. | | File Size: | 15370 | | Last Modified: | Jun 25 08:59:00 2004 |
| MD5 Checksum: | 18bdc6011d498e6180b07e400c066f9c |
|
| /// File Name: |
syscheck-0.6.3.tgz |
Description:
|
Syscheck version 0.6.3 is a utility for performing sanity checking on system files, services, and ports. It attempts to identify any trojans or rootkits that may be getting used and also looks for vulnerable software installed. ELF binary included.
| | Author: | steveg | | Homepage: | http://stevegcentral.com/ | | File Size: | 723048 | | Last Modified: | Jun 25 08:45:00 2004 |
| MD5 Checksum: | 647cdd7de4f71fdd4db378e98b304412 |
|
| /// File Name: |
rkhunter-1.1.1.tar.gz |
Description:
|
Rootkit Hunter scans files and systems for known and unknown rootkits, backdoors, and sniffers. The package contains one shell script, a few text-based databases, and optional Perl modules. It should run on almost every Unix variety except Solaris and NetBSD.
| | Author: | M. Boelen | | Homepage: | http://www.rootkit.nl/ | | Changes: | Fixed the installer. | | File Size: | 93861 | | Last Modified: | Jun 23 14:59:19 2004 |
| MD5 Checksum: | 89b588aecf35ce34fa5cb737890e37c8 |
|
| /// File Name: |
rkhunter-1.1.0.tar.gz |
Description:
|
Rootkit Hunter scans files and systems for known and unknown rootkits, backdoors, and sniffers. The package contains one shell script, a few text-based databases, and optional Perl modules. It should run on almost every Unix clone.
| | Author: | M. Boelen | | Homepage: | http://www.rootkit.nl/ | | Changes: | Added support for Red Hat Linux Advanced Server 2.1, Slackware 9.0. Thanks to Stan Cosmin, Slackware 9.1, Trustix 2.0, Debian with sparc64 architecture. Added hashes for Slackware 9.0 and Slackware 9.1. | | File Size: | 93832 | | Last Modified: | Jun 22 19:13:35 2004 |
| MD5 Checksum: | 5f4be1beb4f9c4f91064cd9fafa9eadb |
|
| /// File Name: |
DumpSIS-0.8.zip |
Description:
|
Symbian SIS file dumping utility that allows for analysis of potential malware without actual installation of files. It provides information on file headers (UIDs, Version, Number of Languages, Number of files), file list (Destination name by default, Source filename and file type).
| | Author: | Jimmy Shah | | Changes: | Fixes decompress bug and compatibility with Perl on Unix. | | File Size: | 15224 | | Last Modified: | Jun 18 01:21:02 2004 |
| MD5 Checksum: | fb42865d6b83fbc513796adabeedf9d1 |
|
| /// File Name: |
pidentd-3.0.18.tar.gz |
Description:
|
Pidentd v3 is a much improved version of the original Ident daemon both in terms of speed, code quality and features. Features include multithreading, a "configure" script, startup autodetection, much clearer/rewritten C code, doesn't run as root after startup, has a configuration file and can be started from /etc/inittab (on systems using a SysV init).
| | Author: | Peter Eriksson | | Homepage: | http://sf.www.lysator.liu.se/~pen/pidentd/ | | Changes: | Added support for Gcc in 64bit-mode and Solaris 10. Fixed a file descriptor leak in request.c. | | File Size: | 357737 | | Last Modified: | Jun 14 03:33:18 2004 |
| MD5 Checksum: | 3a1edfbabe1cc71401f683e7812f8f04 |
|
| /// File Name: |
aexpl-1.2.tar.gz |
Description:
|
AntiExploit is a small Perl script that scans for well known exploit files. It currently recognizes over 1400 suspicious files, and the database is updated weekly. Useful for a system that has a lot of shell accounts being used.
| | Author: | Enrico Kern | | Homepage: | http://www.h07.org | | Changes: | Added a grsecurity exec log analyzer, last Perl release 1.3 will use dazuko and do realtime checks. | | File Size: | 166782 | | Last Modified: | May 25 19:17:40 2004 |
| MD5 Checksum: | 68c15fb75e8a9a2f183d5b09fae444d6 |
|
| /// File Name: |
rkhunter-1.0.9.tar.gz |
Description:
|
Rootkit Hunter scans files and systems for known and unknown rootkits, backdoors, and sniffers. The package contains one shell script, a few text-based databases, and optional Perl modules. It should run on almost every Unix clone.
| | Author: | M. Boelen | | Homepage: | http://www.rootkit.nl/ | | Changes: | Added support for Balaur rootkit, SuSE 9.1, Fedora Core 2, RHEL 3, PCLinux OS, Mandrake 10, along with various other bug fixes and changes. | | File Size: | 84878 | | Last Modified: | May 25 18:57:19 2004 |
| MD5 Checksum: | ef2eff5b8eafb781cb6080913105e6c7 |
|
| /// File Name: |
rkhunter-1.0.8.tar.gz |
Description:
|
Rootkit Hunter scans files and systems for known and unknown rootkits, backdoors, and sniffers. The package contains one shell script, a few text-based databases, and optional Perl modules. It should run on almost every Unix clone.
| | Author: | M. Boelen | | Homepage: | http://www.rootkit.nl/ | | Changes: | Added support for Mandrake 10 and Slackware 9.1.0. Added hashes for Red Hat Enterprise Linux 2.1. Updated hashes for Red Hat Enterprise Linux 3 and Fedora Core 1. Improved extra Suckit tests. | | File Size: | 77582 | | Last Modified: | May 12 19:34:35 2004 |
| MD5 Checksum: | bc1006d36e5b2674985c9396b5c46c95 |
|
| /// File Name: |
aexpl-1.0.tar.gz |
Description:
|
AntiExploit is a small Perl script that scans for well known exploit files. It currently recognizes over 1400 suspicious files, and the database is updated weekly. Useful for a system that has a lot of shell accounts being used.
| | Author: | Enrico Kern | | Homepage: | http://www.h07.org | | File Size: | 134985 | | Last Modified: | May 1 13:00:58 2004 |
| MD5 Checksum: | 233a203d625b8756342c708530248d4e |
|
| /// File Name: |
rkhunter-1.0.7.tar.gz |
Description:
|
Rootkit Hunter scans files and systems for known and unknown rootkits, backdoors, and sniffers. The package contains one shell script, a few text-based databases, and optional Perl modules. It should run on almost every Unix clone.
| | Author: | M. Boelen | | Homepage: | http://www.rootkit.nl/ | | Changes: | Added support for various rootkits and improvements. | | File Size: | 78437 | | Last Modified: | Apr 28 02:01:39 2004 |
| MD5 Checksum: | 0016af0e5ca9aa486cad90508cf47636 |
|
| /// File Name: |
DumpSIS.zip |
Description:
|
Symbian SIS file dumping utility that allows for analysis of potential malware without actual installation of files. It provides information on file headers (UIDs, Version, Number of Languages, Number of files), file list (Destination name by default, Source filename and file type).
| | Author: | Jimmy Shah | | File Size: | 15083 | | Last Modified: | Apr 14 12:06:00 2004 |
| MD5 Checksum: | 578328fa8e962b2f93f1e82ddbde67da |
|
| /// File Name: |
rkhunter-1.0.6.tar.gz |
Description:
|
Rootkit Hunter scans files and systems for known and unknown rootkits, backdoors, and sniffers. The package contains one shell script, a few text-based databases, and optional Perl modules. It should run on almost every Unix clone.
| | Author: | M. Boelen | | Homepage: | http://www.rootkit.nl/ | | Changes: | Added support for about a dozen Unix variants. | | File Size: | 75095 | | Last Modified: | Apr 12 18:33:00 2004 |
| MD5 Checksum: | 1310df34c65f726e4e449a3f6a3ed54c |
|
|
|
|
|