Friday, August 5, 2011

Beauty Of The Baud: RootRepeal-Rootkit Detector Tool


Rootkit or simply a backdoor and on windows terminology we can call it malware, that allows an attacker to maintain access on a operating system. Rootkit is simply a software and a program that hide itself and continuously connect to it server.
There are different tools available to remove malware, as we have discussed about the best antivirus for windows.

 When we are talking about rootkit it generally means a piece of software than can run on Unix like operating system including Linux and BSD. There are different rootkit remover and detector available to fight against these backdoors, this article will discuss about RootRepeal.

RootRepeal is a new rootkit detector that is available for public now, it has a great features. Easy to use and user friendly if you have a little computer skills you can use it. It is a power tool that can detect all the rootkits that are available on public.


Key Features
  1. Driver Scan - scans the system for kernel-mode drivers.  Displays all drivers currently loaded, and shows if a driver has been hidden, and whether the driver's file is visible on-disk.
  2. Files Scan - scans any fixed drive on the system for hidden, locked or falsified* files.
  3. Processes Scan - scans the system for processes.  Displays all processes currently running, and shows if a processes is hidden or locked.
  4. SSDT Scan - shows whether any of the functions in the System Service Descriptor Table (SSDT) are hooked.
  5. Stealth Objects Scan - attempts to determine if any rootkits are active by looking for typical symptoms.
  6. Hidden Services Scan - scans for hidden system services.
  7. Shadow SSDT Scan - counterpart to the SSDT Scan, but deals mostly with graphics and window-related functions.


There are different version available click on the above link to get the latest version, it is applicable on windows operating system, only x86 version of windows are supported. 


Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.
Posted: 18 Jul 2011 02:09 AM PDT


There are different frameworks available for doing a penetration testing, new development has been made everyday. Let suppose if we combine different tools on a single and we categorized it just like in backtrack than we can create a effective penetration testing framework.
This article will discuss about mantra a dream project that has been done, and it is also listed on backtrack 5.

Basically mantra is nothing but a collection of free and open source tools integrated into a web browser, which can become handy for students, penetration testers, web application developers, security professionals etc. It is portable, ready-to-run, compact and follows the true spirit of free and open source software.


Mantra can be very helpful into all the phases of hacking attack like fingerprinting, enumeration and scanning, gaining access and covering tracks etc.
It contains a list of tools that are used by developers and debuggers, so mantra can be used for attacking as well as defensive way.


Mantra is available on backtrack 5, you can get it by click on Applications-->Backtrack-->Vulnerability assessment-->Vulnerability scanner-->Mantra
It is a user friendly,portable and GUI framework, you can carry it on flash drives and CD/DVD. It is a cross operating system framework that can be run on windows, Linux and MAC as well. It is a open source project so it is available on free of cost.




If you are using other distro of Linux, windows and MAC than you need to download and install mantra, however as said earlier if you are using backtrack 5 you can get it on.
For mantra tutorial it is not possible to discuss here because it can use for multiple purposes depends on the attack, for variety of mantra tutorial click here.
Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

No comments:

Post a Comment