Wednesday, December 26, 2012

Rubilyn (OSX Backdoor)
10% coupon

This is a 64bit Mac OS-X kernel rootkit that uses no hardcoded address to hook the BSD subsystem in all OS-X Lion and below. It uses a combination of syscall hooking and DKOM to hide activity on a host. String resolution of symbols no longer works on Mountain Lion as symtab is destroyed during load, this code is portable on all Lion and below but requires re-working for hooking under Mountain Lion.
[ by GM & M Software LLC ]


No comments:

Post a Comment