<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for IT Security</title>
	<atom:link href="http://ipsecs.com/web/?feed=comments-rss2" rel="self" type="application/rss+xml" />
	<link>http://ipsecs.com/web</link>
	<description>Who Owns Who Now?</description>
	<lastBuildDate>Thu, 28 Feb 2013 23:23:57 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>Comment on [UPDATE] KBeast &#8211; The New Kernel Rootkit by aerosmith</title>
		<link>http://ipsecs.com/web/?p=277&#038;cpage=1#comment-7237</link>
		<dc:creator>aerosmith</dc:creator>
		<pubDate>Thu, 28 Feb 2013 23:23:57 +0000</pubDate>
		<guid isPermaLink="false">http://ipsecs.com/web/?p=277#comment-7237</guid>
		<description><![CDATA[help me,
my problem same &quot;How can i fix this? I try installing kernel-headers, but not work.&quot;

how fix?
thanks]]></description>
		<content:encoded><![CDATA[<p>help me,<br />
my problem same &#8220;How can i fix this? I try installing kernel-headers, but not work.&#8221;</p>
<p>how fix?<br />
thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Network &amp; Computer Forensics by rifan</title>
		<link>http://ipsecs.com/web/?p=267&#038;cpage=1#comment-7234</link>
		<dc:creator>rifan</dc:creator>
		<pubDate>Fri, 04 Jan 2013 10:31:30 +0000</pubDate>
		<guid isPermaLink="false">http://ipsecs.com/web/?p=267#comment-7234</guid>
		<description><![CDATA[Salam admin ipsec.
Saya sedang mengerjakan skripsi tentang forensik jaringan dan slideshow dari don anto sangat membantu sekali tetapi saya masih sangat awam sekali.
Disini saya mohon untuk penjelasan lebih detail tentang isi dari slideshow pada bahasan tentang mekanisme mencari bukti digital di beberapa media untuk mengumpulkan bukti digital tersebut.
Terima kasih atas bantuannya.
Good luck always.]]></description>
		<content:encoded><![CDATA[<p>Salam admin ipsec.<br />
Saya sedang mengerjakan skripsi tentang forensik jaringan dan slideshow dari don anto sangat membantu sekali tetapi saya masih sangat awam sekali.<br />
Disini saya mohon untuk penjelasan lebih detail tentang isi dari slideshow pada bahasan tentang mekanisme mencari bukti digital di beberapa media untuk mengumpulkan bukti digital tersebut.<br />
Terima kasih atas bantuannya.<br />
Good luck always.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on [UPDATE] KBeast &#8211; The New Kernel Rootkit by tirher</title>
		<link>http://ipsecs.com/web/?p=277&#038;cpage=1#comment-7232</link>
		<dc:creator>tirher</dc:creator>
		<pubDate>Wed, 19 Dec 2012 18:43:56 +0000</pubDate>
		<guid isPermaLink="false">http://ipsecs.com/web/?p=277#comment-7232</guid>
		<description><![CDATA[I have this kernel:

# uname -a
Linux redes-seguridad.com.ar 2.6.32-220.el6.i686 #1 SMP Tue Dec 6 16:15:40 GMT 2011 i686 i686 i386 GNU/Linux

In centos:

# cat /etc/issue
CentOS release 6.3 (Final)
Kernel \r on an \m


And when i run this, obtein an error:

# ./setup build
Checking for Kernel Header : [NOT OK] - Please Install!


How can i fix this? I try installing kernel-headers, but not work.

Tnks]]></description>
		<content:encoded><![CDATA[<p>I have this kernel:</p>
<p># uname -a<br />
Linux redes-seguridad.com.ar 2.6.32-220.el6.i686 #1 SMP Tue Dec 6 16:15:40 GMT 2011 i686 i686 i386 GNU/Linux</p>
<p>In centos:</p>
<p># cat /etc/issue<br />
CentOS release 6.3 (Final)<br />
Kernel \r on an \m</p>
<p>And when i run this, obtein an error:</p>
<p># ./setup build<br />
Checking for Kernel Header : [NOT OK] &#8211; Please Install!</p>
<p>How can i fix this? I try installing kernel-headers, but not work.</p>
<p>Tnks</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on OpenSSH Backdoor With PAM Support by Safee</title>
		<link>http://ipsecs.com/web/?p=295&#038;cpage=1#comment-7229</link>
		<dc:creator>Safee</dc:creator>
		<pubDate>Mon, 10 Dec 2012 02:51:45 +0000</pubDate>
		<guid isPermaLink="false">http://ipsecs.com/web/?p=295#comment-7229</guid>
		<description><![CDATA[Greetings! The site is great. Thank you for a great resource]]></description>
		<content:encoded><![CDATA[<p>Greetings! The site is great. Thank you for a great resource</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on [UPDATE] KBeast &#8211; The New Kernel Rootkit by pxf</title>
		<link>http://ipsecs.com/web/?p=277&#038;cpage=1#comment-5184</link>
		<dc:creator>pxf</dc:creator>
		<pubDate>Fri, 16 Nov 2012 03:07:05 +0000</pubDate>
		<guid isPermaLink="false">http://ipsecs.com/web/?p=277#comment-5184</guid>
		<description><![CDATA[Hi. I tested this on centos6.3(64bit) running 2.6.32 and it didn’t work,on centos6.2 (32bit) is ok.


Last login: Fri Mar  2 19:32:48 2012
/bin/basename: missing operand
Try `/bin/basename --help&#039; for more information.

why?]]></description>
		<content:encoded><![CDATA[<p>Hi. I tested this on centos6.3(64bit) running 2.6.32 and it didn’t work,on centos6.2 (32bit) is ok.</p>
<p>Last login: Fri Mar  2 19:32:48 2012<br />
/bin/basename: missing operand<br />
Try `/bin/basename &#8211;help&#8217; for more information.</p>
<p>why?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on [UPDATE] KBeast &#8211; The New Kernel Rootkit by rex</title>
		<link>http://ipsecs.com/web/?p=277&#038;cpage=1#comment-5182</link>
		<dc:creator>rex</dc:creator>
		<pubDate>Thu, 15 Nov 2012 14:09:17 +0000</pubDate>
		<guid isPermaLink="false">http://ipsecs.com/web/?p=277#comment-5182</guid>
		<description><![CDATA[[root@test1 _h4x_]# make
make -C /lib/modules/2.6.32-279.el6.x86_64/build M=/usr/_h4x_ modules
make[1]: Entering directory `/usr/src/kernels/2.6.32-279.el6.x86_64&#039;
  CC [M]  /usr/_h4x_/ipsecs-kbeast-v1.o
/usr/_h4x_/ipsecs-kbeast-v1.c: In function ‘h4x_read’:
/usr/_h4x_/ipsecs-kbeast-v1.c:239: warning: ignoring return value of ‘copy_from_user’, declared with attribute warn_unused_result
/usr/_h4x_/ipsecs-kbeast-v1.c: In function ‘h4x_write’:
/usr/_h4x_/ipsecs-kbeast-v1.c:476: warning: ignoring return value of ‘copy_from_user’, declared with attribute warn_unused_result
/usr/_h4x_/ipsecs-kbeast-v1.c: In function ‘h4x_getdents’:
/usr/_h4x_/ipsecs-kbeast-v1.c:507: error: dereferencing pointer to incomplete type
/usr/_h4x_/ipsecs-kbeast-v1.c:509: error: dereferencing pointer to incomplete type
/usr/_h4x_/ipsecs-kbeast-v1.c:511: error: dereferencing pointer to incomplete type
/usr/_h4x_/ipsecs-kbeast-v1.c:513: error: dereferencing pointer to incomplete type
/usr/_h4x_/ipsecs-kbeast-v1.c:516: error: dereferencing pointer to incomplete type
/usr/_h4x_/ipsecs-kbeast-v1.c:521: error: dereferencing pointer to incomplete type
/usr/_h4x_/ipsecs-kbeast-v1.c:503: warning: ignoring return value of ‘copy_from_user’, declared with attribute warn_unused_result
/usr/_h4x_/ipsecs-kbeast-v1.c:523: warning: ignoring return value of ‘copy_to_user’, declared with attribute warn_unused_result
/usr/_h4x_/ipsecs-kbeast-v1.c: In function ‘h4x_unlink’:
/usr/_h4x_/ipsecs-kbeast-v1.c:569: warning: ignoring return value of ‘copy_from_user’, declared with attribute warn_unused_result
/usr/_h4x_/ipsecs-kbeast-v1.c: In function ‘h4x_rmdir’:
/usr/_h4x_/ipsecs-kbeast-v1.c:584: warning: ignoring return value of ‘copy_from_user’, declared with attribute warn_unused_result
/usr/_h4x_/ipsecs-kbeast-v1.c: In function ‘h4x_unlinkat’:
/usr/_h4x_/ipsecs-kbeast-v1.c:598: warning: ignoring return value of ‘copy_from_user’, declared with attribute warn_unused_result
/usr/_h4x_/ipsecs-kbeast-v1.c: In function ‘h4x_rename’:
/usr/_h4x_/ipsecs-kbeast-v1.c:613: warning: ignoring return value of ‘copy_from_user’, declared with attribute warn_unused_result
/usr/_h4x_/ipsecs-kbeast-v1.c:614: warning: ignoring return value of ‘copy_from_user’, declared with attribute warn_unused_result
/usr/_h4x_/ipsecs-kbeast-v1.c: In function ‘h4x_open’:
/usr/_h4x_/ipsecs-kbeast-v1.c:630: warning: ignoring return value of ‘copy_from_user’, declared with attribute warn_unused_result
/usr/_h4x_/ipsecs-kbeast-v1.c: In function ‘h4x_delete_module’:
/usr/_h4x_/ipsecs-kbeast-v1.c:664: warning: ignoring return value of ‘copy_from_user’, declared with attribute warn_unused_result
/usr/_h4x_/ipsecs-kbeast-v1.c: In function ‘init’:
/usr/_h4x_/ipsecs-kbeast-v1.c:679: warning: ISO C90 forbids mixed declarations and code
/usr/_h4x_/ipsecs-kbeast-v1.c:686: warning: assignment makes integer from pointer without a cast
/usr/_h4x_/ipsecs-kbeast-v1.c:689: warning: assignment makes integer from pointer without a cast
/usr/_h4x_/ipsecs-kbeast-v1.c:691: warning: assignment makes pointer from integer without a cast
/usr/_h4x_/ipsecs-kbeast-v1.c:692: warning: assignment makes integer from pointer without a cast
/usr/_h4x_/ipsecs-kbeast-v1.c:699: warning: assignment makes pointer from integer without a cast
/usr/_h4x_/ipsecs-kbeast-v1.c:700: warning: assignment makes integer from pointer without a cast
/usr/_h4x_/ipsecs-kbeast-v1.c:701: warning: assignment makes pointer from integer without a cast
/usr/_h4x_/ipsecs-kbeast-v1.c:702: warning: assignment makes integer from pointer without a cast
/usr/_h4x_/ipsecs-kbeast-v1.c:703: warning: assignment makes pointer from integer without a cast
/usr/_h4x_/ipsecs-kbeast-v1.c:704: warning: assignment makes integer from pointer without a cast
/usr/_h4x_/ipsecs-kbeast-v1.c:705: warning: assignment makes pointer from integer without a cast
/usr/_h4x_/ipsecs-kbeast-v1.c:706: warning: assignment makes integer from pointer without a cast
/usr/_h4x_/ipsecs-kbeast-v1.c:707: warning: assignment makes pointer from integer without a cast
/usr/_h4x_/ipsecs-kbeast-v1.c:708: warning: assignment makes integer from pointer without a cast
/usr/_h4x_/ipsecs-kbeast-v1.c:709: warning: assignment makes pointer from integer without a cast
/usr/_h4x_/ipsecs-kbeast-v1.c:710: warning: assignment makes integer from pointer without a cast
/usr/_h4x_/ipsecs-kbeast-v1.c:711: warning: assignment makes pointer from integer without a cast
/usr/_h4x_/ipsecs-kbeast-v1.c:712: warning: assignment makes integer from pointer without a cast
/usr/_h4x_/ipsecs-kbeast-v1.c: At top level:
/usr/_h4x_/ipsecs-kbeast-v1.c:727: warning: conflicting types for built-in function ‘exit’
/usr/_h4x_/ipsecs-kbeast-v1.c: In function ‘exit’:
/usr/_h4x_/ipsecs-kbeast-v1.c:735: warning: assignment makes integer from pointer without a cast
/usr/_h4x_/ipsecs-kbeast-v1.c:737: warning: assignment makes integer from pointer without a cast
/usr/_h4x_/ipsecs-kbeast-v1.c:739: warning: assignment makes integer from pointer without a cast
/usr/_h4x_/ipsecs-kbeast-v1.c:745: warning: assignment makes integer from pointer without a cast
/usr/_h4x_/ipsecs-kbeast-v1.c:746: warning: assignment makes integer from pointer without a cast
/usr/_h4x_/ipsecs-kbeast-v1.c:747: warning: assignment makes integer from pointer without a cast
/usr/_h4x_/ipsecs-kbeast-v1.c:748: warning: assignment makes integer from pointer without a cast
/usr/_h4x_/ipsecs-kbeast-v1.c:749: warning: assignment makes integer from pointer without a cast
/usr/_h4x_/ipsecs-kbeast-v1.c:750: warning: assignment makes integer from pointer without a cast
/usr/_h4x_/ipsecs-kbeast-v1.c:751: warning: assignment makes integer from pointer without a cast
make[2]: *** [/usr/_h4x_/ipsecs-kbeast-v1.o] Error 1
make[1]: *** [_module_/usr/_h4x_] Error 2
make[1]: Leaving directory `/usr/src/kernels/2.6.32-279.el6.x86_64&#039;
make: *** [all] Error 2]]></description>
		<content:encoded><![CDATA[<p>[root@test1 _h4x_]# make<br />
make -C /lib/modules/2.6.32-279.el6.x86_64/build M=/usr/_h4x_ modules<br />
make[1]: Entering directory `/usr/src/kernels/2.6.32-279.el6.x86_64&#8242;<br />
  CC [M]  /usr/_h4x_/ipsecs-kbeast-v1.o<br />
/usr/_h4x_/ipsecs-kbeast-v1.c: In function ‘h4x_read’:<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:239: warning: ignoring return value of ‘copy_from_user’, declared with attribute warn_unused_result<br />
/usr/_h4x_/ipsecs-kbeast-v1.c: In function ‘h4x_write’:<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:476: warning: ignoring return value of ‘copy_from_user’, declared with attribute warn_unused_result<br />
/usr/_h4x_/ipsecs-kbeast-v1.c: In function ‘h4x_getdents’:<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:507: error: dereferencing pointer to incomplete type<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:509: error: dereferencing pointer to incomplete type<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:511: error: dereferencing pointer to incomplete type<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:513: error: dereferencing pointer to incomplete type<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:516: error: dereferencing pointer to incomplete type<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:521: error: dereferencing pointer to incomplete type<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:503: warning: ignoring return value of ‘copy_from_user’, declared with attribute warn_unused_result<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:523: warning: ignoring return value of ‘copy_to_user’, declared with attribute warn_unused_result<br />
/usr/_h4x_/ipsecs-kbeast-v1.c: In function ‘h4x_unlink’:<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:569: warning: ignoring return value of ‘copy_from_user’, declared with attribute warn_unused_result<br />
/usr/_h4x_/ipsecs-kbeast-v1.c: In function ‘h4x_rmdir’:<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:584: warning: ignoring return value of ‘copy_from_user’, declared with attribute warn_unused_result<br />
/usr/_h4x_/ipsecs-kbeast-v1.c: In function ‘h4x_unlinkat’:<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:598: warning: ignoring return value of ‘copy_from_user’, declared with attribute warn_unused_result<br />
/usr/_h4x_/ipsecs-kbeast-v1.c: In function ‘h4x_rename’:<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:613: warning: ignoring return value of ‘copy_from_user’, declared with attribute warn_unused_result<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:614: warning: ignoring return value of ‘copy_from_user’, declared with attribute warn_unused_result<br />
/usr/_h4x_/ipsecs-kbeast-v1.c: In function ‘h4x_open’:<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:630: warning: ignoring return value of ‘copy_from_user’, declared with attribute warn_unused_result<br />
/usr/_h4x_/ipsecs-kbeast-v1.c: In function ‘h4x_delete_module’:<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:664: warning: ignoring return value of ‘copy_from_user’, declared with attribute warn_unused_result<br />
/usr/_h4x_/ipsecs-kbeast-v1.c: In function ‘init’:<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:679: warning: ISO C90 forbids mixed declarations and code<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:686: warning: assignment makes integer from pointer without a cast<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:689: warning: assignment makes integer from pointer without a cast<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:691: warning: assignment makes pointer from integer without a cast<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:692: warning: assignment makes integer from pointer without a cast<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:699: warning: assignment makes pointer from integer without a cast<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:700: warning: assignment makes integer from pointer without a cast<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:701: warning: assignment makes pointer from integer without a cast<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:702: warning: assignment makes integer from pointer without a cast<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:703: warning: assignment makes pointer from integer without a cast<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:704: warning: assignment makes integer from pointer without a cast<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:705: warning: assignment makes pointer from integer without a cast<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:706: warning: assignment makes integer from pointer without a cast<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:707: warning: assignment makes pointer from integer without a cast<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:708: warning: assignment makes integer from pointer without a cast<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:709: warning: assignment makes pointer from integer without a cast<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:710: warning: assignment makes integer from pointer without a cast<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:711: warning: assignment makes pointer from integer without a cast<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:712: warning: assignment makes integer from pointer without a cast<br />
/usr/_h4x_/ipsecs-kbeast-v1.c: At top level:<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:727: warning: conflicting types for built-in function ‘exit’<br />
/usr/_h4x_/ipsecs-kbeast-v1.c: In function ‘exit’:<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:735: warning: assignment makes integer from pointer without a cast<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:737: warning: assignment makes integer from pointer without a cast<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:739: warning: assignment makes integer from pointer without a cast<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:745: warning: assignment makes integer from pointer without a cast<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:746: warning: assignment makes integer from pointer without a cast<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:747: warning: assignment makes integer from pointer without a cast<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:748: warning: assignment makes integer from pointer without a cast<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:749: warning: assignment makes integer from pointer without a cast<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:750: warning: assignment makes integer from pointer without a cast<br />
/usr/_h4x_/ipsecs-kbeast-v1.c:751: warning: assignment makes integer from pointer without a cast<br />
make[2]: *** [/usr/_h4x_/ipsecs-kbeast-v1.o] Error 1<br />
make[1]: *** [_module_/usr/_h4x_] Error 2<br />
make[1]: Leaving directory `/usr/src/kernels/2.6.32-279.el6.x86_64&#8242;<br />
make: *** [all] Error 2</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on [UPDATE] KBeast &#8211; The New Kernel Rootkit by rex</title>
		<link>http://ipsecs.com/web/?p=277&#038;cpage=1#comment-5181</link>
		<dc:creator>rex</dc:creator>
		<pubDate>Thu, 15 Nov 2012 14:07:38 +0000</pubDate>
		<guid isPermaLink="false">http://ipsecs.com/web/?p=277#comment-5181</guid>
		<description><![CDATA[Hi. I tested this on centos6.3(64bit) running 2.6.32-279 and it didn’t work,help me.
[root@test1 kbeast-v1]# uname -a
Linux test1 2.6.32-279.el6.x86_64 #1 SMP Fri Jun 22 12:19:21 UTC 2012 x86_64 x86_64 x86_64 GNU/Linux
[root@test1 kbeast-v1]# ./setup build 1

:::::::::::  :::::::::    ::::::::   ::::::::::   ::::::::    ::::::::
    :+:      :+:    :+:  :+:    :+:  :+:         :+:    :+:  :+:    :+:
    +:+      +:+    +:+  +:+         +:+         +:+         +:+
    +#+      +#++:++#+   +#++:++#++  +#++:++#    +#+         +#++:++#++
    +#+      +#+                +#+  +#+         +#+                +#+
    #+#      #+#         #+#    #+#  #+#         #+#    #+#  #+#    #+#
###########  ###          ########   ##########   ########    ########

Checking for Kernel Beast : [OK]
Checking for sed : /bin/sed
Generating C file from .cc1 : [OK]
Checking for Makefile : [OK]
Checking for Network Daemon : [OK]
Checking for Config File : [OK]
Checking for Kernel Header : [OK]
Checking for gcc : /usr/bin/gcc
Checking for make : /usr/bin/make
Checking for kernel version : [OK]
Creating Install Directory : [OK]
Compiling Kernel Module : [NOT OK]

[root@test1 kbeast-v1]# cat config.h 
/*
Kernel Beast Ver #1.0 - Configuration File
Copyright Ph03n1X of IPSECS (c) 2011
Get more research of ours http://ipsecs.com
*/

/*Don&#039;t change this line*/
#define TRUE 1
#define FALSE 0

/*
Enable keylog probably makes the system unstable
But worth to be tried
*/
#define _KEYLOG_ TRUE

/*Define your module &amp; network daemon name*/
#define KBEAST &quot;kbeast&quot;

/*
All files, dirs, process will be hidden
Protected from deletion &amp; being killed
*/
#define _H4X0R_ &quot;_h4x_&quot;

/*
Directory where your rootkit will be saved
You have to use _H4X0R_ in your directory name
No slash (/) at the end
*/
#define _H4X_PATH_ &quot;/usr/_h4x_&quot;

/*
File to save key logged data
*/
#define _LOGFILE_ &quot;acctlog&quot;

/*
This port will be hidded from netstat
*/
#define _HIDE_PORT_ 13377

/*
Password for remote access
*/
#define _RPASSWORD_ &quot;h4x3d&quot;
#define _MAGIC_NAME_ &quot;xxx&quot;
/*
Magic signal &amp; pid for local escalation
*/
#define _MAGIC_SIG_ 37 //kill signal
#define _MAGIC_PID_ 31337 //kill this pid]]></description>
		<content:encoded><![CDATA[<p>Hi. I tested this on centos6.3(64bit) running 2.6.32-279 and it didn’t work,help me.<br />
[root@test1 kbeast-v1]# uname -a<br />
Linux test1 2.6.32-279.el6.x86_64 #1 SMP Fri Jun 22 12:19:21 UTC 2012 x86_64 x86_64 x86_64 GNU/Linux<br />
[root@test1 kbeast-v1]# ./setup build 1</p>
<p>:::::::::::  :::::::::    ::::::::   ::::::::::   ::::::::    ::::::::<br />
    :+:      :+:    :+:  :+:    :+:  :+:         :+:    :+:  :+:    :+:<br />
    +:+      +:+    +:+  +:+         +:+         +:+         +:+<br />
    +#+      +#++:++#+   +#++:++#++  +#++:++#    +#+         +#++:++#++<br />
    +#+      +#+                +#+  +#+         +#+                +#+<br />
    #+#      #+#         #+#    #+#  #+#         #+#    #+#  #+#    #+#<br />
###########  ###          ########   ##########   ########    ########</p>
<p>Checking for Kernel Beast : [OK]<br />
Checking for sed : /bin/sed<br />
Generating C file from .cc1 : [OK]<br />
Checking for Makefile : [OK]<br />
Checking for Network Daemon : [OK]<br />
Checking for Config File : [OK]<br />
Checking for Kernel Header : [OK]<br />
Checking for gcc : /usr/bin/gcc<br />
Checking for make : /usr/bin/make<br />
Checking for kernel version : [OK]<br />
Creating Install Directory : [OK]<br />
Compiling Kernel Module : [NOT OK]</p>
<p>[root@test1 kbeast-v1]# cat config.h<br />
/*<br />
Kernel Beast Ver #1.0 &#8211; Configuration File<br />
Copyright Ph03n1X of IPSECS (c) 2011<br />
Get more research of ours <a href="http://ipsecs.com" rel="nofollow">http://ipsecs.com</a><br />
*/</p>
<p>/*Don&#8217;t change this line*/<br />
#define TRUE 1<br />
#define FALSE 0</p>
<p>/*<br />
Enable keylog probably makes the system unstable<br />
But worth to be tried<br />
*/<br />
#define _KEYLOG_ TRUE</p>
<p>/*Define your module &amp; network daemon name*/<br />
#define KBEAST &#8220;kbeast&#8221;</p>
<p>/*<br />
All files, dirs, process will be hidden<br />
Protected from deletion &amp; being killed<br />
*/<br />
#define _H4X0R_ &#8220;_h4x_&#8221;</p>
<p>/*<br />
Directory where your rootkit will be saved<br />
You have to use _H4X0R_ in your directory name<br />
No slash (/) at the end<br />
*/<br />
#define _H4X_PATH_ &#8220;/usr/_h4x_&#8221;</p>
<p>/*<br />
File to save key logged data<br />
*/<br />
#define _LOGFILE_ &#8220;acctlog&#8221;</p>
<p>/*<br />
This port will be hidded from netstat<br />
*/<br />
#define _HIDE_PORT_ 13377</p>
<p>/*<br />
Password for remote access<br />
*/<br />
#define _RPASSWORD_ &#8220;h4x3d&#8221;<br />
#define _MAGIC_NAME_ &#8220;xxx&#8221;<br />
/*<br />
Magic signal &amp; pid for local escalation<br />
*/<br />
#define _MAGIC_SIG_ 37 //kill signal<br />
#define _MAGIC_PID_ 31337 //kill this pid</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on [UPDATE] KBeast &#8211; The New Kernel Rootkit by Syd</title>
		<link>http://ipsecs.com/web/?p=277&#038;cpage=1#comment-5176</link>
		<dc:creator>Syd</dc:creator>
		<pubDate>Wed, 14 Nov 2012 01:53:25 +0000</pubDate>
		<guid isPermaLink="false">http://ipsecs.com/web/?p=277#comment-5176</guid>
		<description><![CDATA[I installed KBeast (Linux rootkit 2012) and the package works just as described except for the fact that I can&#039;t seem to see anything in my key logging file (i.e. the file is empty). In particular, below is how I define this file.

/*
File to save key logged data
*/
#define _LOGFILE_ &quot;rootkit.log&quot;

However, when I go to the location of this file &quot;/usr/_h4x_rootKit&quot; I see a file named &quot;rootkit.log.9&quot;. When I attempt to read this file (using vim) I get the message that the file is already opened, and if I open it in &quot;read only&quot; mode (or using cat), its empty. How do I view the data?]]></description>
		<content:encoded><![CDATA[<p>I installed KBeast (Linux rootkit 2012) and the package works just as described except for the fact that I can&#8217;t seem to see anything in my key logging file (i.e. the file is empty). In particular, below is how I define this file.</p>
<p>/*<br />
File to save key logged data<br />
*/<br />
#define _LOGFILE_ &#8220;rootkit.log&#8221;</p>
<p>However, when I go to the location of this file &#8220;/usr/_h4x_rootKit&#8221; I see a file named &#8220;rootkit.log.9&#8243;. When I attempt to read this file (using vim) I get the message that the file is already opened, and if I open it in &#8220;read only&#8221; mode (or using cat), its empty. How do I view the data?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on [UPDATE] KBeast &#8211; The New Kernel Rootkit by rex</title>
		<link>http://ipsecs.com/web/?p=277&#038;cpage=1#comment-5174</link>
		<dc:creator>rex</dc:creator>
		<pubDate>Tue, 13 Nov 2012 23:14:22 +0000</pubDate>
		<guid isPermaLink="false">http://ipsecs.com/web/?p=277#comment-5174</guid>
		<description><![CDATA[if you can replace the bind port backdoor with the reverse-connect backdoor,it would be perfect.]]></description>
		<content:encoded><![CDATA[<p>if you can replace the bind port backdoor with the reverse-connect backdoor,it would be perfect.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on [UPDATE] KBeast &#8211; The New Kernel Rootkit by rex</title>
		<link>http://ipsecs.com/web/?p=277&#038;cpage=1#comment-5171</link>
		<dc:creator>rex</dc:creator>
		<pubDate>Tue, 13 Nov 2012 14:50:07 +0000</pubDate>
		<guid isPermaLink="false">http://ipsecs.com/web/?p=277#comment-5171</guid>
		<description><![CDATA[if you can replace the bind port backdoor with the connect-back backdoor,it would be perfect.]]></description>
		<content:encoded><![CDATA[<p>if you can replace the bind port backdoor with the connect-back backdoor,it would be perfect.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
