Get a Pentest and security assessment of your IT network.

Uncategorized

Rubilyn 0.0.1 – This is a 64bit Mac OS-X kernel rootkit that uses no hardcoded address to hook the BSD subsystem in all OS-X Lion and below.

This is a 64bit Mac OS-X kernel rootkit that uses no hardcoded address to hook the BSD subsystem in all OS-X Lion and below. It uses a combination of syscall hooking and DKOM to hide activity on a host. String resolution of symbols no longer works on Mountain Lion as symtab is destroyed during load, this code is portable on all Lion and below but requires re-working for hooking under Mountain Lion.

 

You can download it from the following link: https://packetstormsecurity.com/files/download/117177/rubilyn-0.0.1.tar.gz

Source: https://packetstormsecurity.com/files/117177/Rubilyn-0.0.1.html