[eNYeSec] Monitor v1.0

Pepelux has made a windows utility to capture all traffic from net card, as a sniffer (promiscuous mode). It is configurable with filters, and captures TCP, UDP, ICMP and ARP protocols. It can export data, and has a login plain text detection mode (ftp, pop3, etc.). It is multilanguage (english + spanish).

Playing with sockets (port scan)

Pepelux has wrote a paper about port scanning at low level. It explains anonymous port scan, playing with net packet headers using raw sockets. It shows most used scan techniques (xmas, fin, etc.), through own raw sockets code and examples. It also explains a little about SO’s detection.

eNYeLKM v1.1

LKM rootkit for Linux x86 with the 2.6 kernel. It inserts salts inside system_call and sysenter_entry handlers, so it does not modify sys_call_table, or IDT content. It hide files, directories, and processes. Hides chunks inside of files, gives remote reverse_shell access, local root, etc.

