· Регистрация 
софт скрипты драйвера форумы блоги  
Пример: windows
Софт
Новости софта
Обзоры
Статьи
Авторам
Софт
Mac Linux PDA/Mobile
Linux Программирование Отладчики

Страница программы Fakebust 0.02b

Fakebust provides a malicious exploit discriminator.


  Описание программы   Комментарии (0)   Скриншоты (0)   Файлы (1)  
АвторMichal Zalewski
СайтПерейти
Обновление28.02.2007, 15:05
НазваниеFakebust
ВерсияFakebust 0.02b
ЯзыкиАнглийский
ЛицензияLGPL
СтоимостьБесплатно
СистемыLinux
Размер?
Рейтинг
Голосов: 1

Скачать бесплатно Fakebust
Закачек: 0
найти или купить на Allsoft.ru
софт в Allsoft.ru 




Описание программы Fakebust
Fakebust provides a malicious exploit discriminator.
Fakebust is a program that assists with the rapid assessment and supervised execution of potentially malicious programs such as exploits or utilities of unknown origin, programs recovered during OS forensics, or acquired from a honeypot.
Fakebust is there to provide an ugly but viable compromise between extensive
analysis and blind execution. It is an interactive "bounding box" debugger,
under which the program is allowed to run for as long as certain boundary
I/O conditions are not violated.
Whenever the program attempts to gain access to a new, security-relevant resource, or tries to otherwise extend its permissions to a degree that would affect the system, the code is stopped, and the user is presented with an informative description and a choice what to do next. Typical choices are:
- Deny the request and abort the program - typically picked as soon as
you conclude it is malicious,
- Permit the program to perform action once - picked once the request
is deemed to be justified, and the resource does not yield any
undesirable information,
- Permit this and future access of this type to this resource - when
accesses to a file or connections to a host are expected to recur,
- Deny the request, but do not abort the program; the syscall will
not execute, and a value closest to "success" will be passed back to
the program as a simulated result. A good option whenever it is
apparent that the program is misbehaving, but it is not clear yet what
its goal is.
In other words, under fakebust, you can finally run the elusive Apache 0-day
exploit and be automatically warned if it attempts to execute shellcode
locally rather than remotely, or attempts to dial a host in China with your
/etc/passwd in hand; or attempts to write to /etc/ld.so.preload; fiddles
with /dev/kmem, etc. You will be able to stop an undesirable action before
it is carried out.
· Ключевые особенности и характеристики Fakebust 0.02b
Не определены
· Ограничения Fakebust 0.02b
Ограничения не определены
· Специальные требования Fakebust 0.02b
Специальные требования не определены
· История версий и изменений Fakebust
Версия: 0.02b
· proper handling of sigreturn;
· payload dumps on sendto/recvfrom.
· Описание и дополнения от редакторов и пользователей сайта
Пока нет
Связанные статьи, обзоры и новости
Нет относящихся к программе статей и обзоров.


Другие программы от Michal Zalewski

DIX 0.6a1
DIX project is an experimental game engine.
14.11.2006, 09:05 | ? | Freely Distributable | 0


fl0p 0.0.1
fl0p is a passive L7 flow fingerprinter that examines TCP/UDP/ICMP packet sequences.
06.12.2006, 03:05 | ? | GPL (GNU GPL) | 0


evil finder 1.1
evil finder project is a tool for finding evil.
26.02.2007, 11:05 | ? | Freely Distributable | 0


snowdrop 0.02b
snowdrop provides a stenographic text/code watermarking tool.
28.02.2007, 13:05 | ? | GPL (GNU GPL) | 1


Stompy 0.04
Stompy provides a tool to check the security of Web session IDs and other tokens.
28.02.2007, 13:05 | ? | LGPL | 0

     
Похожие программы

Accerciser 0.1.3
Accerciser is an interactive Python accessibility explorer for the GNOME desktop.
11.05.2007, 21:35 | ? | GPL (GNU GPL) | 4


Guarded Memory Move 0.6
Guarded Memory Move tool is useful for studying buffer overflows and catching them together with a 'good' stack image.
24.04.2007, 05:23 | ? | GPL (GNU GPL) | 3


radare 0.8
radare is a toolchain that aims to create a complete set of utilities for handling binary files from the command line.
10.04.2007, 09:01 | ? | GPL (GNU GPL) | 1


Elvyx 1.0.23.1
Elvyx is a tool designed to monitor and profile the jdbc activity.
06.03.2007, 02:44 | ? | The Apache License 2.0 | 1

Разделы