Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 60 guests online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Malwarearrow REMnux: A Linux Distribution for Reverse-Engineering Malware
EH-Net
May 25, 2012, 10:14:28 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: REMnux: A Linux Distribution for Reverse-Engineering Malware  (Read 6030 times)
0 Members and 2 Guests are viewing this topic.
nebu10uz
Sr. Member
****
Offline Offline

Posts: 363



View Profile WWW
« on: July 08, 2010, 04:04:20 PM »


This just came out today:

Quote
REMnux is a lightweight Linux distribution for assisting malware analysts in reverse-engineering malicious software. The distribution is based on Ubuntu and is maintained by Lenny Zeltser.

Download it here.
Logged

Security+, OSCP, CEH
H1t M0nk3y
Hero Member
*****
Offline Offline

Posts: 660



View Profile
« Reply #1 on: July 09, 2010, 07:09:24 AM »

Very interesting, thanks nebu10z!

This distro can do more than Reverse Engineering:

Quote
Malware Analysis Tools Set Up On REMnux

Analyzing Flash malware: swftools, flasm, flare

Analyzing IRC bots: IRC server (Inspire IRCd) and client (Irssi). To launch the IRC server, type "ircd start"; to shut it down "ircd stop". To launch the IRC client, type "irc".

Network-monitoring and interactions: Wireshark, Honeyd, INetSim, fakedns and fakesmtp scripts, NetCat

JavaScript deobfuscation: Firefox with Firebug, NoScript and JavaScript Deobfuscator extensions, Rhino debugger, two versions of patched SpiderMonkey, Windows Script Decoder, Jsunpack-n

Interacting with web malware in the lab: TinyHTTPd, Paros proxy

Analyzing shellcode: gdb, objdump, Radare (hex editor+disassembler), shellcode2exe

Dealing with protected executables: upx, packerid, bytehist, xorsearch, TRiD

Malicious PDF analysis: Dider's PDF tools, Origami framework, Jsunpack-n, pdftk

Memory forensics: Volatility Framework and malware-related plugins

Miscellaneous: unzip, strings, ssdeep, feh image viewer, SciTE text editor, OpenSSH server

I will take a look at it soon...
Logged

GPEN, GSEC, CEH, CISSP, PMP
Bane
Guest
« Reply #2 on: July 09, 2010, 09:52:34 AM »

Lenny has been giving this out at his GREM courses for quite awhile. Nice to see that it is now publicly available.
Logged
H0nd0CSI
Newbie
*
Offline Offline

Posts: 17


H0nd0


View Profile WWW
« Reply #3 on: September 30, 2010, 08:53:44 AM »

Very Coooool thanks for the info  Wink
Logged

"If the only tool you have is a hammer, you tend to see every problem as a nail"
Abraham Maslow
dante
Jr. Member
**
Offline Offline

Posts: 58



View Profile
« Reply #4 on: September 30, 2010, 09:20:08 AM »

Even old posts in ethical-hacker.net are valuable.. Will download it right away... Thanks for bring this up back again  H0nd0CSI
Logged
putosusio
Newbie
*
Offline Offline

Posts: 26


View Profile
« Reply #5 on: October 28, 2010, 01:20:24 AM »

Unfortunately, I may need to this soon.

Curse you chinese hackers ... well thank you in a sort of twisted way.  At least the malware is on a test system.
Logged

Its not the fixing that's the hard part, its knowing what needs fixing.
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.226 seconds with 22 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.