f0rb1dd3n / Reptile

LKM Linux rootkit

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

can't hide udp port??

koushui opened this issue · comments

Thanks to the author,Good job,very cool~!
but,can't hide udp port??
i try "/reptile/reptile_cmd conn hide" hiden a udp listen,only hide TCP PORT,hide udp not work!

By the way, if can increase access to SSH, SSHD password keylogger features, the same with command line switch, then a more perfect~!

commented

I'm not clear with the first question. I don't think the feature you mentioned is necessary. SSHD sniffering may increase the possibility which the rootkit would be discovered by the admin. There are many approaches to do that.

Thanks your words man.

So, about the udp connection hiding, I will consider add this feature in next commits. About SSH keylogger, I am not sure yet, even cause you can do some strace and get the clean text password (and hide the strace process with reptile).

I just added UDP hiding feature on this commit 165b539.

so, check it out!

3X ,Test is OK~!