maK- / Syscall-table-hijack-LKM
This demonstrates the hijacking of the "write" system call and how to set the System Call table to read/write mode via modifying the correct cr0 bit.
☆19Updated 10 years ago
Alternatives and similar repositories for Syscall-table-hijack-LKM:
Users that are interested in Syscall-table-hijack-LKM are comparing it to the libraries listed below
- This rearranges an ELF object file so it can be used as shellcode.☆42Updated 10 years ago
- Proof Of Concept for inserting code in ELF binaries.☆25Updated 10 years ago
- Be able to execute memory snapshots so they can start running where they left off.☆35Updated 9 years ago
- python library for dumping a linux process from memory☆34Updated 14 years ago
- Writeup of the Oracle DSR stack buffer overflow vulnerability (DRA) CVE-2014-6598☆14Updated 10 years ago
- Diaphora, a Free and Open Source program diffing tool☆22Updated 5 years ago
- runtime code injector for Linux☆27Updated 13 years ago
- Stealth's 64bit injectso port☆74Updated 14 years ago
- ☆35Updated 12 years ago
- Resources for reverse engineering Go binaries☆41Updated 10 years ago
- Binary Analysis Platform☆73Updated 11 years ago
- A library for efficient interception of established TCP connections☆19Updated 9 years ago
- Linux kernel JIT spray for SMEP / KERNEXEC bypass☆55Updated 12 years ago
- ROP based Movfuscator VM☆28Updated 8 years ago
- Memory awesomeness.☆29Updated 9 years ago
- Simple ELF tools written to demonstrate libelfmaster capabilities.☆39Updated 6 years ago
- HexPADS, a host-based, Performance-counter-based Attack Detection System☆39Updated 2 years ago
- PoC to append and extract data at the end of an ELF file☆20Updated 7 years ago
- PoC code for our presentation titled "Stackjacking Your Way to grsec/PaX Bypass"☆46Updated 13 years ago
- A rootkit implemented as a linux kernel module☆17Updated 9 years ago
- relros.c applies RELRO to static binaries, and static_to_dyn.c applies ASLR to static binaries.☆33Updated 6 years ago
- simple plugin to detect shellcode on Bro IDS with Unicorn☆33Updated 8 years ago
- A hypervisor or virtual machine monitor (VMM) fuzzer☆28Updated 5 years ago
- CSAW CTF 2015 Linux kernel exploitation challenge☆36Updated 9 years ago
- The plugin is an integration of Virus Battle API to the well known IDA Disassembler.☆20Updated 9 years ago
- Load a .so from network and execute it inside a seccomp sandbox☆19Updated 9 years ago
- A feature-complete reference implementation of a modern Xen VMI debugger. ARCHIVED: Development continues at https://github.com/spencermi…☆75Updated 4 years ago
- Triton based R2 plugin for concolic execution and total control☆30Updated 6 years ago
- Memory forensic tool for process resurrection starting from a memory dump☆20Updated 7 years ago
- A linux rootkit works on kernel 4.0.X or higher☆36Updated 8 years ago