Section: .. / groups / s0ftpj /
Disclaimers: s0ftpr0ject 99 is a security team founded in the summer of 1997. Its research team is fully dedicated to study, describe and resolve security problems related to the network and digital worlds. Tools and documentation available on this site are meant to be used only in order to improve your security and privacy, and not as a way to harm anybody. Any use of the available material that goes against the laws of any state is not condoned by s0ftpr0ject 99, which also cannot be held responsible for any misuse. s0ftpr0ject 99 absolutely dissociates itself from any cracking/hacking/phreaking group that may claim to be in any way collaborating with us. If YOU are going against the law, WE will never have any relation with you. Any remark should be addressed to staff@s0ftpj.org, and abuses reported immediately, with all the necessary informations, to abuse@s0ftpj.org. Also, due to recent facts happened in our country, we point out that we strictly dissociate from any terroristic or eversive groups and their destabilizing and highly deprecable actions. If you, the visitor, are somehow offended by the contents of the site, we ask you to leave this site immediately, and don't go on accessing, reading or downloading anything here. On the other hand, by accessing the main page, you agree with this disclaimer and must consider yourself responsible for any use you make of the informations contained inside. Also, who is currently hosting our page and our mirrors cannot be legally sued for its content.
|
| /// File Name: |
spf.c |
Description:
|
Simple Packet Forwarder for Linux on the datalink level. Uses Libvsk.
| | Author: | Vecna | | Homepage: | http://www.s0ftpj.org | | File Size: | 5439 | | Last Modified: | Jan 4 18:11:58 2001 |
| MD5 Checksum: | 621f5cd81e4b6086bfe950368778e6a6 |
|
| /// File Name: |
libvsk-1.0.tar.gz |
Description:
|
Libvsk is a set of libraries for network traffic manipulation from userlevel, with some functions of filtering/sniffing.
| | Author: | Vecna | | Homepage: | http://www.s0ftpj.org | | File Size: | 10569 | | Last Modified: | Jan 4 18:07:59 2001 |
| MD5 Checksum: | 03b859947702e03b90805a396d85183f |
|
| /// File Name: |
smonitor.tar.gz |
Description:
|
Syscall Monitor for FreeBSD - Using this tool you are allowed to monitor the use of the syscalls on your system and to prevent their execution for the specified users/groups.
| | Author: | Pigpen | | Homepage: | http://www.s0ftpj.org | | File Size: | 7682 | | Last Modified: | Jan 4 18:06:18 2001 |
| MD5 Checksum: | aeb3c22d03b85b81f229dea7e57eb14c |
|
| /// File Name: |
securelvl.tgz |
Description:
|
Securelevel Bypass - This kld gives you permission to load/unload a kld and modify a sysctl value even if you aren't root and securelevel is higher than 0.
| | Author: | Pigpen | | Homepage: | http://www.s0ftpj.org | | File Size: | 3523 | | Last Modified: | Jan 4 17:57:49 2001 |
| MD5 Checksum: | 7e09e9214328484326990e89f0fb198f |
|
| /// File Name: |
aasniff.tar.gz |
Description:
|
Anti Anti Sniffer Patch - Linux kernel patches to hide a sniffer from the most known anti-sniffers.
| | Author: | Vecna | | Homepage: | http://www.s0ftpj.org | | File Size: | 2649 | | Last Modified: | Jan 4 17:55:58 2001 |
| MD5 Checksum: | 864e1c903014d25f0b1e5c91a79785b2 |
|
| /// File Name: |
kstat.tar.gz |
Description:
|
Kstat is a tool for Linux which can find an attacker in your system by a direct analysis of the kernel via /dev/kmem, bypassing the hiding techniques of the intruder (kernel static recompilation/use of LKMs). Kstat can find the syscalls which were modified by a LKM, list the linked LKMs, query one or all the network interfaces of the system, list all the processes and much more.
| | Author: | Fusys | | Homepage: | http://www.s0ftpj.org | | File Size: | 14523 | | Last Modified: | Jan 4 17:54:20 2001 |
| MD5 Checksum: | f6314c81beecea2df666f5c49f166c38 |
|
| /// File Name: |
ksec.tar.gz |
Description:
|
Ksec (Kernel Security Checker) is a tool for FreeBSD and OpenBSD which can find an attacker by direct analysis of the kernel via /dev/mem, bypassing the hiding techniques of the intruder (kernel static recompilation/use of LKMs). KSec can find the modified syscalls from userspace, detect the promisc interfaces, find the modifications applied to a protocol and much more.
| | Author: | Pigpen | | Homepage: | http://www.s0ftpj.org | | File Size: | 18238 | | Last Modified: | Jan 4 17:50:24 2001 |
| MD5 Checksum: | d084d77610110ba6fa0784418443629b |
|
| /// File Name: |
sinto.c |
Description:
|
Sinto.c is an interactive tty hijacker for Linux.
| | Author: | Vecna | | Homepage: | http://www.s0ftpj.org | | File Size: | 7054 | | Last Modified: | Nov 29 03:03:02 2000 |
| MD5 Checksum: | a74319ef64630e2a3d3494dcd6f96e72 |
|
| /// File Name: |
spj-004-000.txt |
Description:
|
S0ftpj Security Advisory SPJ-004-000 - Multiple remote CGI vulnerabilities in MailStudio2000. Users can view any file on the system, as well as execute commands remotely as root. Major search engines can be used to locate vulnerable hosts. Exploit descriptions included.
| | Author: | Fusys | | Homepage: | http://www.s0ftpj.org | | File Size: | 10078 | | Last Modified: | Jun 13 16:48:32 2000 |
| MD5 Checksum: | 8a9281a0c39e117d2596d7473d567816 |
|
| /// File Name: |
obsd_ipfhack.c |
Description:
|
LKM for OpenBSD which makes ipfilter always accept packets from a certain IP.
| | Author: | Pigpen. | | Homepage: | http://www.s0ftpj.org | | File Size: | 3071 | | Last Modified: | May 25 07:35:57 2000 |
| MD5 Checksum: | 152172a4150816265d58039a7e404402 |
|
| /// File Name: |
obsd_nospoof.c |
Description:
|
Anti-spoofing lkm for OpenBSD via setsockopt() - detects and logs IP header manipulation.
| | Author: | Pigpen. | | Homepage: | http://www.s0ftpj.org | | File Size: | 2931 | | Last Modified: | May 23 17:09:19 2000 |
| MD5 Checksum: | 29ccce542461940624e0353917b43a0f |
|
| /// File Name: |
obsd_obscura.c |
Description:
|
Total obscurity for BPF Promisc Mode. OpenBSD Port.
| | Author: | Pigpen. | | Homepage: | http://www.s0ftpj.org | | File Size: | 2749 | | Last Modified: | May 23 14:14:24 2000 |
| MD5 Checksum: | 2a1531337ab8059845db579358fa3212 |
|
| /// File Name: |
sock.c |
Description:
|
SRaw for FreeBSD ( sock.c ) - Enables all users to open raw sockets.
| | Author: | pIGpEN | | Homepage: | http://www.s0ftpj.org | | File Size: | 3639 | | Last Modified: | May 22 13:34:44 2000 |
| MD5 Checksum: | fe4b6efeed4426441e7e3672834666b6 |
|
| /// File Name: |
ipfhack.c |
Description:
|
LKM for FreeBSD which makes ipfilter always accept packets from a certain IP.
| | Author: | Pigpen. | | Homepage: | http://www.s0ftpj.org | | File Size: | 3210 | | Last Modified: | May 22 13:30:19 2000 |
| MD5 Checksum: | 3eeebbc3a32fda0cfed1a8b824b91b12 |
|
| /// File Name: |
oMBRa.c |
Description:
|
Linux kernel 2.2.x implementation of the CaRoGNa 2.0.x module Secret technique of the divine HOKUHACKO school [ Hokuto No Ken rules ;)] Sacred Strike of the Modular Renewal that bumps root down.
| | Author: | FuSyS | | Homepage: | http://www.s0ftpj.org | | File Size: | 14069 | | Last Modified: | May 5 16:14:51 2000 |
| MD5 Checksum: | 42718d42c8967fcdf62650d647e4424a |
|
| /// File Name: |
N0Sp00f.c |
Description:
|
Simple module to prevent lame people from using your box as a launch base for spoofed ip packets. Intercepts the socketcall() system call looking for the IP_HDRINCL parameter passed via setsockopt().
| | Author: | FuSyS | | Homepage: | http://www.s0ftpj.org | | File Size: | 7324 | | Last Modified: | May 5 16:12:47 2000 |
| MD5 Checksum: | d75f42fbe84717789145d2ac2bdf1c4c |
|
| /// File Name: |
LuCe.c |
Description:
|
Linux Loadable Kernel Module to keep an eye on the system, and add security 'on the fly' to a prexisting running box. Contains a simple implementation of BSD securelevels, while waiting for the official 'in-distro' arrival of Linux Capabilities [POSIX 1.e] in 2.4.x and strong ACLs.
| | Author: | FuSyS | | Homepage: | http://www.s0ftpj.org/bfi | | File Size: | 9785 | | Last Modified: | May 5 16:11:19 2000 |
| MD5 Checksum: | 6d45601756c7bd61466fd81365d98854 |
|
| /// File Name: |
udp_spoof_detect.c |
Description:
|
DETECT UDP SP00FiNG ON OUR FREEBSD BOX VIA KLD.
| | Author: | Pigpen. | | Homepage: | http://www.s0ftpj.org | | File Size: | 6943 | | Last Modified: | May 4 18:36:17 2000 |
| MD5 Checksum: | 60ca24d54f0af45281bd803a2872f1bb |
|
| /// File Name: |
sec_lkm.c |
Description:
|
LKM Detector - This module lets you a compare between a syscall & its kernel function, so you can detect any lkm which modifies your system. More documentation available here.
| | Author: | Pigpen. | | Homepage: | http://www.s0ftpj.org | | File Size: | 3373 | | Last Modified: | May 4 18:36:14 2000 |
| MD5 Checksum: | 4e1b0504e4fda8949438eef407231207 |
|
| /// File Name: |
scns.c |
Description:
|
s0ftpj snmp community name sniffer.
| | Author: | Pigpen. | | Homepage: | http://www.s0ftpj.org | | File Size: | 3010 | | Last Modified: | May 4 18:36:10 2000 |
| MD5 Checksum: | 64d11e37b41195d8296d46a08b78702f |
|
| /// File Name: |
raw_ip.c.diff |
Description:
|
IP_HDRINCL protection beta version 1.
| | Author: | Pigpen. | | Homepage: | http://www.s0ftpj.org | | File Size: | 1419 | | Last Modified: | May 4 18:36:07 2000 |
| MD5 Checksum: | ba2fa75ab5d9b47db5ec5f72b25f67dc |
|
| /// File Name: |
obscura.c |
Description:
|
Total obscurity for BPF Promisc Mode.
| | Author: | Pigpen. | | Homepage: | http://www.s0ftpj.org | | File Size: | 3895 | | Last Modified: | May 4 18:36:00 2000 |
| MD5 Checksum: | 65900333453657ee11bb728a1ca18714 |
|
| /// File Name: |
knstat_freebsd.c |
Description:
|
This simple source code uses sysctlbyname() to fetch statistics for a protocol that you can use for security purposes or for kernel testing.
| | Author: | Pigpen. | | Homepage: | http://www.s0ftpj.org | | File Size: | 10616 | | Last Modified: | May 4 18:35:56 2000 |
| MD5 Checksum: | fbb0c43d5b6b7a83551bd7c3a6665bc7 |
|
| /// File Name: |
kcheck.c |
Description:
|
IGMP/ICMP/IPIP/IDP/RSVP/IPIP/IPPROTO_RAW KERNEL CHECKER.
| | Author: | Pigpen. | | Homepage: | http://www.s0ftpj.org | | File Size: | 4739 | | Last Modified: | May 4 18:35:53 2000 |
| MD5 Checksum: | f1bd4cdbfbaff4500c5d2246177a3151 |
|
| /// File Name: |
fbsdnospoof.c |
Description:
|
Anti-spoofing lkm for FreeBSD via setsockopt() - detects and logs IP header manipulation.
| | Author: | Pigpen. | | Homepage: | http://www.s0ftpj.org | | File Size: | 3612 | | Last Modified: | May 4 18:35:46 2000 |
| MD5 Checksum: | 28aa34facd8f7a86b9811e2bb464b061 |
|
|
|
|
|