MOOD-NT - New Linux Kernel Rootkit released
Mood-NT is a linux kernel rootkit suckit2-like for 2.4.x/2.6.x kernels.
It can hide processes, files, connections (unix, raw, and ipv6 too), promisc flag and it allows tty sniffing, exec redirection, exec parameters sniffing, has an internal private init script for starting whatever you want on boot.
It has a lot of anti-detectors engines and a unique hiding engine hardware based (through the debug registers) that makes it completely stealth on x86 machines. If the kernel changes it automatically reinstall itself on boot.
Keep Safe,
regards
Steo
www.antirootkit.com
This entry was posted on Thursday, November 2nd, 2006 at 11:20 pm and is filed under News, New Rootkits, Linux. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.