Section: .. / groups / teso /
| /// File Name: |
adore-ng-0.41.tgz |
Description:
|
Adore is a Linux LKM based rootkit for Linux v2.[246]. Features smart PROMISC flag hiding, persistent file and directory hiding (still hidden after reboot), process-hiding, netstat hiding, rootshell-backdoor, and an uninstall routine. Includes a userspace program to control everything.
| | Author: | Stealth | | Homepage: | http://www.team-teso.net | | Changes: | Ported to 2.6 and fixed a buffer overflow from version 0.32. | | File Size: | 18877 | | Last Modified: | Mar 12 02:34:01 2004 |
| MD5 Checksum: | 3295d45f24060914c411d1d75343660a |
|
| /// File Name: |
adore-ng-0.31.tgz |
Description:
|
Adore is a Linux LKM based rootkit for Linux v2.[24]. Features smart PROMISC flag hiding, persistent file and directory hiding (still hidden after reboot), process-hiding, netstat hiding, rootshell-backdoor, and an uninstall routine. Includes a userspace program to control everything.
| | Author: | Stealth | | Homepage: | http://www.team-teso.net | | Changes: | Syslog filtering, wtmp/utmp/lastlog filtering, relinking of LKMs as described in Phrack #61. | | File Size: | 18140 | | Last Modified: | Jan 6 01:33:29 2004 |
| MD5 Checksum: | 4a925181db7030c1e9b67225a88abbe0 |
|
| /// File Name: |
objobf-0.5.0.tar.bz2 |
Description:
|
objobf is an obfuscater for x86/Linux ELF relocatable object files (.o files) that can produce fancy graphs to visualize function structures. Released at CCCAMP 2k3.
| | Author: | scut | | Homepage: | http://www.team-teso.net | | File Size: | 188352 | | Last Modified: | Aug 11 01:28:01 2003 |
| MD5 Checksum: | ba6b6f098f2c1e48c6946c6b13f568bb |
|
| /// File Name: |
loaded-0.21.tgz |
Description:
|
loaded version 0.21 is an IPv4 load balancer for Linux. It requires netfilter and the QUEUE target enabled in the kernel.
| | Author: | Sebastian Krahmer | | Homepage: | http://www.team-teso.net | | File Size: | 6444 | | Last Modified: | May 28 11:06:24 2003 |
| MD5 Checksum: | d467ee59815b3f7befd3c46911940c80 |
|
| /// File Name: |
reducebind.c |
Description:
|
This utility converts a dynamically link Linux IA32 ELF binary to a static binary.
| | Author: | scut | | Homepage: | http://www.team-teso.net/ | | File Size: | 6743 | | Last Modified: | Jan 27 20:06:14 2003 |
| MD5 Checksum: | 51bd11bc0ce5e38a9cb6933d910de716 |
|
| /// File Name: |
sparc.c |
Description:
|
Remote root exploit for Solaris Napalm heap overflow - SPARC version. Tested against SunOS 5.6, 5.7, 5.8, and 5.9. Attempts to add a root shell to inetd.conf.
| | Author: | Scut | | File Size: | 9655 | | Last Modified: | Jan 5 15:25:05 2003 |
| MD5 Checksum: | 34c08bb66b18e41b75d2c0287149d5ad |
|
| /// File Name: |
epta.tgz |
Description:
|
Execution Path Timing Analysis of Unix Daemons - White paper on how to determine if a username is valid remotely by timing remote responses of login programs. OpenSSH diff against v2.99p2 which determines if a username exists even on the newest versions of OpenSSH included.
| | Author: | Sebastian Krahmer | | Homepage: | http://www.team-teso.net | | File Size: | 75700 | | Last Modified: | Dec 3 07:20:53 2002 |
| MD5 Checksum: | 3652eb952d213483c1e22f10b941883d |
|
| /// File Name: |
hack.pl |
Description:
|
Suidperl v5.00503 and others tmp race local root exploit.
| | Author: | Sebastian Krahmer | | Homepage: | http://www.team-teso.net | | File Size: | 5580 | | Last Modified: | Nov 30 21:39:50 2002 |
| MD5 Checksum: | 8041a1da62bd891ae9e65c3a2871a6c2 |
|
| /// File Name: |
7350pippi.pl |
Description:
|
7350pippi is a x86/Linux ipppd local root exploit.
| | File Size: | 2573 | | Last Modified: | Nov 30 21:38:04 2002 |
| MD5 Checksum: | 0c635de06e7fd0738cf3c235e1b74c8c |
|
| /// File Name: |
7350lapsus.pl |
Description:
|
7350lapsus is a lpr-3.0.48 Local root exploit. Requires root on a host counted in hosts.lpd and local account on lpd box. This is proof of concept, chown()ing /etc/passwd to a user named 'stealth'.
| | File Size: | 1234 | | Last Modified: | Nov 30 21:36:37 2002 |
| MD5 Checksum: | 85d373c856befc7da5b6d2727b6291af |
|
| /// File Name: |
7350cowboy.c |
Description:
|
7350cowboy.c is supposedly a PHP/3.0.12, 3.0.15, and 3.0.16 with apache 1.3.12 remote format string exploit for FreeBSD 3.4, Slackware Linux 4.0, and 7.0. Very similar to http://packetstormsecurity.org/0010-exploits/phploit.c.
| | File Size: | 19629 | | Last Modified: | Nov 17 15:04:24 2002 |
| MD5 Checksum: | 49cb24b3e1a3f7c0b7a27e6879c6d0a2 |
|
| /// File Name: |
adore-0.42.tgz |
Description:
|
Adore is a linux LKM based rootkit for Linux v2.[24]. Features smart PROMISC flag hiding, persistent file and directory hiding (still hidden after reboot), process-hiding, netstat hiding, rootshell-backdoor, and an uninstall routine. Includes a userspace program to control everything.
| | Author: | Stealth | | Homepage: | http://www.team-teso.net | | Changes: | Added devpts fix, fixed is_secret64() to properly hide files, and fixed a memory leak. | | File Size: | 14749 | | Last Modified: | Sep 20 00:18:14 2002 |
| MD5 Checksum: | 156ded13d5e16b84a9e31193bc9bc417 |
|
| /// File Name: |
teso_crew_99_at_ccc-camp.jpg |
Description:
|
TESO at CCC.
| | File Size: | 200472 | | Last Modified: | Sep 15 05:38:06 2002 |
| MD5 Checksum: | 38dcfc807b4384b2828156c0f51b981d |
|
| /// File Name: |
chap.pdf |
Description:
|
Weaknesses in the CHAP protocol as used within PPP and PPTP. Allows authentication in PPTP networks without knowing valid login/password combinations. This authentication scheme is widely used at universities (WLAN networks). A link to a special pppd which is able to authenticate without valid /etc/ppp/chap-secrets is included.
| | Author: | Sebastian Krahmer | | Homepage: | http://www.team-teso.net | | File Size: | 488807 | | Last Modified: | Feb 26 07:28:20 2002 |
| MD5 Checksum: | 6b4b918f410d855855fdaab340232b39 |
|
| /// File Name: |
teso-advisory-012.txt |
Description:
|
TESO Security Advisory - LIDS Linux Intrusion Detection System vulnerability. The "Linux Intrusion Detection System" security patch for the Linux kernel creates a security vulnerability. Exploitation is easy and local users may be able to gain unrestricted root privileges.
| | Homepage: | http://www.team-teso.net | | File Size: | 2404 | | Last Modified: | Feb 5 08:21:07 2002 |
| MD5 Checksum: | 798dd3ba6b7227152566567c49b9423c |
|
| /// File Name: |
formatstring-1.2.tar.gz |
Description:
|
Exploiting Format String Vulnerabilities v1.2 - Includes over 30 pages of well organized information along with several examples.
| | Author: | Scut | | Homepage: | https://www.team-teso.net | | File Size: | 214530 | | Last Modified: | Oct 11 06:41:48 2001 |
| MD5 Checksum: | b83261bd868fa46874290b59915bda58 |
|
| /// File Name: |
iob-0.1.tar.gz |
Description:
|
IOB stands for I/O bridge, a simple tty chaining program. It can be used to log almost any session, including ssh, gpg, pgp, cfsattach, losetup, etc.
| | Author: | Scut | | Homepage: | https://www.team-teso.net | | File Size: | 5899 | | Last Modified: | Oct 11 06:40:44 2001 |
| MD5 Checksum: | e5014222fec4c7375e3f66dbb8edb43a |
|
| /// File Name: |
teso-advisory-011.txt |
Description:
|
TESO Security Advisory #11 - Multiple vendor Telnet Daemon vulnerability. Most current telnet daemons in use today contain a buffer overflow in the telnet option handling. Under certain circumstances it may be possible to exploit it to gain root privileges remotely. Affected systems include BSDI 4.x, FreeBSD, IRIX, Linux with netkit-telnetd < 0.14, NetBSD, OpenBSD 2.x, and Solaris.
| | Author: | Scut | | Homepage: | https://www.team-teso.net | | File Size: | 5544 | | Last Modified: | Jul 29 11:59:35 2001 |
| MD5 Checksum: | 56fb4e5983fdf5c58663113d30bc8c33 |
|
| /// File Name: |
adore-0.39b4.tgz |
Description:
|
Adore is a linux LKM based rootkit for Linux v2.[24]. Features smart PROMISC flag hiding, persistent file and directory hiding (still hidden after reboot), process-hiding, netstat hiding, rootshell-backdoor, and an uninstall routine. Includes a userspace program to control everything.
| | Author: | Stealth | | Homepage: | http://www.team-teso.net | | Changes: | Now includes open()/stat() redirection and improved netstat hiding. Removed execution redirection. | | File Size: | 14678 | | Last Modified: | Jul 29 11:48:33 2001 |
| MD5 Checksum: | 777cbd2a59268b394b79da2bda910a40 |
|
| /// File Name: |
ldistfp-0.1.4.tar.gz |
Description:
|
Ldistfp is an identd fingerprinting tool which works well with all Linux and most *BSD hosts that have their auth service running.
| | Author: | Scut | | Homepage: | https://www.team-teso.net | | Changes: | Bugfixes, new fingerprints, and an auto-update facility to get new fingerprints. | | File Size: | 14856 | | Last Modified: | May 30 21:00:31 2001 |
| MD5 Checksum: | b346840d28141773178c81fd900b2fad |
|
|
|
|
|