Rheya - a FreeBSD Kernel Backdoor ================================= Version: 0.1 Author: Siliziumleben Rheya is a FreeBSD Kernel Backdoor. It is used to keep root on an owned system. -> A practical implementation of theoretical covert channels -> Damn IDS, analyze this (and analyze that too) --[ Rheya - how can you speak with her if she aint there? a) Use client1 (communication over chardevice) b) Use client2 (communication with syscalls) c) Use client3 (communication over network) --[ Rheya - she cant be here - but she is Antidetection Features: Version 0.1: none, it's just in the Kernel --[ Rheya - you can shoot her into outer space - but shell'be back. Mechanismns to make sure the Rheya is loaded after reboot: Version 0.1: none ( ( ) ( ( ) ) ( ( ) ( / ) ( ( \\ ) ( | // ) | | (__) (---------------------------------) | | (^^) . . . ( *cow is hidingz behind kernalz* ) | | ----\/ (---------------------------------) | | || **| | ---|| ``'--------- Cow Hide