<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>火星信息安全研究院BootKit</title>
	<atom:link href="http://www.h4ck.org.cn/tag/bootkit/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.h4ck.org.cn</link>
	<description>Hack-Crack  信息安全 【Institute Of Information Serurity From Mars】</description>
	<lastBuildDate>Sat, 04 Feb 2012 13:59:16 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Tuluka v1.0.394.77</title>
		<link>http://www.h4ck.org.cn/2011/02/tuluka-v1-0-394-77/</link>
		<comments>http://www.h4ck.org.cn/2011/02/tuluka-v1-0-394-77/#comments</comments>
		<pubDate>Thu, 17 Feb 2011 04:40:37 +0000</pubDate>
		<dc:creator>obaby</dc:creator>
				<category><![CDATA[软件共享『SoftWare』]]></category>
		<category><![CDATA[BootKit]]></category>

		<guid isPermaLink="false">http://www.h4ck.org.cn/?p=2513</guid>
		<description><![CDATA[Tuluka is a new powerful AntiRootkit, which has the following features:
Detects hidden processes, drivers and devices
Detects IRP hooks
Identifies the substitution of certain fields in DRIVER_OBJECT structure]]></description>
			<content:encoded><![CDATA[<p><a rel="lightbox" href="http://www.h4ck.org.cn/wp-content/uploads//2011/02/Tuluka.png" title="Tuluka"><img title="Tuluka" src="http://www.h4ck.org.cn/wp-content/uploads//2011/02/Tuluka.png" alt="" width="644" height="495" /></a></p>
<p><a href="http://dl.dbank.com/c0zx7w7uc4" target="_blank">Click here to download it~</a></p>
<p>Tuluka is a new powerful <span style="color: #ff0000;">AntiRootkit</span>, which has the following features:<br />
Detects hidden processes, drivers and devices<br />
Detects IRP hooks<br />
Identifies the substitution of certain fields in DRIVER_OBJECT structure<br />
Checks driver signatures<br />
<span id="more-2513"></span><br />
Detects and restores SSDT hooks<br />
Detects suspicious descriptors in GDT<br />
IDT hook detection<br />
SYSENTER hook detection<br />
Displays list of system threads and allows you to suspend them<br />
IAT and Inline hook detection<br />
Shows the actual values of the debug registers, even if reading these registers is controlled by someone<br />
Allows you to find the system module by the address within this module<br />
Allows you to display contents of kernel memory and save it to disk<br />
Allows you to dump kernel drivers and main modules of all processes<br />
Allows you to terminate any process<br />
Is able to dissasemble interrupt and IRP handlers, system services, start routines of system threads and many more<br />
Allows to build the stack for selected device<br />
Much more..</p>
<p>Tuluka 是一个新的、功能强大的反rootkit工具。</p>
<p>Tuluka is tested on the following operating systems(32-bit):</p>
<p>Windows XP SP0 SP1 SP2 SP3<br />
Windows Server 2003 SP0 SP1 SP2 R2<br />
Windows Vista SP0 SP1 SP2<br />
Windows Server 2008 SP0 SP1 SP2<br />
Windows 7 SP0 SP1</p>
<p>Work on other versions of the operating system is not guaranteed.<br />
You use this software at your own risk. The author makes no warranty.</p>
<p>它具有如下特色：</p>
<p>检测隐藏进程，驱动和设备(Detects hidden processes, drivers and devices)</p>
<p>检测IRP HOOK(Detects IRP hooks)</p>
<p>鉴别DRIVER_OBJECT结构中被替换的项(Identifies the substitution of certain fields in DRIVER_OBJECT structure)</p>
<p>检查驱动签名(Checks driver signatures)</p>
<p>检测和恢复 SSDT HOOK(Detects and restores SSDT hooks)</p>
<p>检测全局描述符表中的恶意描述符(Detects suspicious descriptors in GDT)</p>
<p>IDT HOOK检测(IDT hook detection)</p>
<p>SYSENTER hook 检测(SYSENTER hook detection)</p>
<p>显示列举系统中的所有线程并允许你终止它们(Displays list of system threads and allows you to suspend them)</p>
<p>IAT和 Inline hook检测 (IAT and Inline hook detection)</p>
<p>显示调试寄存器的值,即使这些寄存器正被人控制(Shows the actual values of the debug registers, even if reading these registers is controlled by someone)</p>
<p>可以通过地址找出模块中的系统模块地址(Allows you to find the system module by the address within this module)</p>
<p>可以显示内核内存的内容并可以将其保存至磁盘(Allows you to display contents of kernel memory and save it to disk)</p>
<p>可以dump内核驱动和所有进程的主要模块(Allows you to dump kernel drivers and main modules of all processes)</p>
<p>可以终止任何进程(Allows you to terminate any process)<br />
<h3>相关文章</h3>
<ul class="related_posts">
<li><a href="http://www.h4ck.org.cn/2009/09/stoned-bootkit/" title="Stoned BootKit" rel="bookmark inlinks">Stoned BootKit</a><span class="count">( 0 )</span></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.h4ck.org.cn/2011/02/tuluka-v1-0-394-77/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Stoned BootKit</title>
		<link>http://www.h4ck.org.cn/2009/09/stoned-bootkit/</link>
		<comments>http://www.h4ck.org.cn/2009/09/stoned-bootkit/#comments</comments>
		<pubDate>Mon, 21 Sep 2009 02:59:15 +0000</pubDate>
		<dc:creator>obaby</dc:creator>
				<category><![CDATA[临时目录『Temp』]]></category>
		<category><![CDATA[BootKit]]></category>

		<guid isPermaLink="false">http://www.h4ck.org.cn/?p=173</guid>
		<description><![CDATA[相关文章 Tuluka v1.0.394.77( 2 )]]></description>
			<content:encoded><![CDATA[<p><iframe src="http://docs.google.com/gview?url=http://www.h4ck.org.cn/wp-content/uploads/2009/09/Paper.pdf&#038;embedded=true" style="width:555px; height:400px;" frameborder="0"></iframe><br />
<h3>相关文章</h3>
<ul class="related_posts">
<li><a href="http://www.h4ck.org.cn/2011/02/tuluka-v1-0-394-77/" title="Tuluka v1.0.394.77" rel="bookmark inlinks">Tuluka v1.0.394.77</a><span class="count">( 2 )</span></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.h4ck.org.cn/2009/09/stoned-bootkit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

