maK- / Syscall-table-hijack-LKMLinks
This demonstrates the hijacking of the "write" system call and how to set the System Call table to read/write mode via modifying the correct cr0 bit.
☆19Updated 11 years ago
Alternatives and similar repositories for Syscall-table-hijack-LKM
Users that are interested in Syscall-table-hijack-LKM are comparing it to the libraries listed below
Sorting:
- Be able to execute memory snapshots so they can start running where they left off.☆35Updated 10 years ago
- runtime code injector for Linux☆27Updated 14 years ago
- ELF binary infector☆32Updated 14 years ago
- This rearranges an ELF object file so it can be used as shellcode.☆42Updated 10 years ago
- Memory forensic tool for process resurrection starting from a memory dump☆20Updated 8 years ago
- Binary Analysis Platform☆74Updated 11 years ago
- A PoC implementation of the meltdown attack described in https://meltdownattack.com/meltdown.pdf☆134Updated 7 years ago
- A hypervisor or virtual machine monitor (VMM) fuzzer☆28Updated 5 years ago
- python library for dumping a linux process from memory☆34Updated 15 years ago
- Stealth's 64bit injectso port☆74Updated 14 years ago
- ☆36Updated 12 years ago
- Script that dumps running process memory from Linux systems using /proc.☆79Updated 11 years ago
- Example code for following along with my "Broken, Abandoned, and Forgotten Code" blog series☆25Updated 6 years ago
- An educational Linux Kernel Rootkit☆33Updated 3 years ago
- Anti live forensic linux LKM rootkit☆17Updated 8 years ago
- Linux rootkit experimentations☆19Updated 10 years ago
- Inject shellcode into running processes in Linux.☆44Updated last year
- PEDAL - Python Exploit Development Assistance for GDB Lite☆35Updated 5 years ago
- Static and Dynamic exploit analysis framework.☆22Updated 10 years ago
- Proof Of Concept for inserting code in ELF binaries.☆26Updated 11 years ago
- ☆10Updated 9 years ago
- Tool to view heap chunks and memory writes (using pintool)☆40Updated 6 years ago
- Writeup of the Oracle DSR stack buffer overflow vulnerability (DRA) CVE-2014-6598☆14Updated 10 years ago
- A linux rootkit works on kernel 4.0.X or higher☆37Updated 9 years ago
- PoC code for our presentation titled "Stackjacking Your Way to grsec/PaX Bypass"☆46Updated 14 years ago
- A rootkit implemented as a linux kernel module☆17Updated 10 years ago
- A library for efficient interception of established TCP connections☆19Updated 9 years ago
- HexPADS, a host-based, Performance-counter-based Attack Detection System☆39Updated 2 years ago
- iknowthis Linux SystemCall Fuzzer☆20Updated 6 years ago
- Diaphora, a Free and Open Source program diffing tool☆23Updated 5 years ago