h3xduck
|
2c7b6b9ecf
|
Final changes and final PDF
|
2022-06-23 15:17:02 -04:00 |
|
h3xduck
|
ff1e92dd6b
|
Corrected caps
|
2022-06-23 14:20:32 -04:00 |
|
h3xduck
|
559136e92e
|
FINAL VERSION
|
2022-06-23 14:04:48 -04:00 |
|
h3xduck
|
caea1e7497
|
Revision of complete document + Abstract
|
2022-06-23 08:57:05 -04:00 |
|
h3xduck
|
42d4ce1d0b
|
Completed chapter 6
|
2022-06-20 22:51:52 -04:00 |
|
h3xduck
|
5d6619ce40
|
Finished section 5. Multiple changes in the code according to the performed tests.
|
2022-06-19 14:35:19 -04:00 |
|
h3xduck
|
bfcbfcfaf2
|
Added multiple small changes to client and code, submitting almost finished chapter 5
|
2022-06-18 10:57:10 -04:00 |
|
h3xduck
|
1b766096bf
|
Corrected grammar and spelling mistakes in the whole document
|
2022-06-17 08:03:26 -04:00 |
|
h3xduck
|
2b719ff0a5
|
Completed chapter 4
|
2022-06-16 20:38:15 -04:00 |
|
h3xduck
|
7f4209299c
|
Completed rootkit user space program
|
2022-06-16 06:35:30 -04:00 |
|
h3xduck
|
e4737b3272
|
Completed rootkit client and rootkit user program ring buffer
|
2022-06-15 22:54:20 -04:00 |
|
h3xduck
|
80f334636a
|
Changed the repository (and the rootkit!) name with TripleCross: https://dictionary.cambridge.org/dictionary/english/double-cross. This is 'triple' because it is a BPF program that betrays you at the userspace, at the kernel, and at the network.
|
2022-06-15 20:33:07 -04:00 |
|
h3xduck
|
75e92445e5
|
Modified terminal names in the client
|
2022-06-15 19:09:58 -04:00 |
|
h3xduck
|
bdda5c4269
|
Modified client options once again for screenshots
|
2022-06-15 18:42:31 -04:00 |
|
h3xduck
|
081a23a44f
|
Modified the help of the client, this is for making some screenshots
|
2022-06-15 17:47:00 -04:00 |
|
h3xduck
|
6f2ef04a92
|
Completed backdoor and c2 section
|
2022-06-15 15:40:08 -04:00 |
|
h3xduck
|
8f844c748b
|
Completed command and control
|
2022-06-15 12:45:59 -04:00 |
|
h3xduck
|
f09d6a6989
|
Continued with c2, bit i didnt like the structure, so it needs to be reformatted
|
2022-06-14 20:31:57 -04:00 |
|
h3xduck
|
9951f3a3fd
|
Completed execution hijacking, completed first subsection of backdoor
|
2022-06-14 15:44:21 -04:00 |
|
h3xduck
|
163f923c55
|
Continued with execve hijacking.
|
2022-06-13 22:16:34 -04:00 |
|
h3xduck
|
a1a41b02df
|
Almost completed section about privilege escalation
|
2022-06-13 15:44:37 -04:00 |
|
h3xduck
|
99ad9c5548
|
New explanation for the injection technique (alternative scanning process) and added flow diagram with full process.
|
2022-06-13 10:57:32 -04:00 |
|
h3xduck
|
71b093141b
|
Further advanced with the library injection, almost finished. Multiple enhancements
|
2022-06-12 22:34:50 -04:00 |
|
h3xduck
|
0aec74e024
|
New diagrams, completed rootkit architecture
|
2022-06-12 08:16:59 -04:00 |
|
h3xduck
|
c14b407644
|
Added new rootkit overall diagram for architecture section
|
2022-06-11 22:20:27 -04:00 |
|
h3xduck
|
e5bb65925d
|
Updated document structure, reformatted multiple chapters, updated chapter and section intros. Separated hardening features into two. Other changes suggested at the meeting,
|
2022-06-11 13:07:10 -04:00 |
|