Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 41 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Malwarearrow REMnux: A Linux Distribution for Reverse-Engineering Malware
EH-Net
May 24, 2013, 02:26:09 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: REMnux: A Linux Distribution for Reverse-Engineering Malware  (Read 8324 times)
0 Members and 1 Guest are viewing this topic.
nebu10uz
Sr. Member
****
Offline Offline

Posts: 368



View Profile WWW
« on: July 08, 2010, 04:04:20 PM »


This just came out today:

Quote
REMnux is a lightweight Linux distribution for assisting malware analysts in reverse-engineering malicious software. The distribution is based on Ubuntu and is maintained by Lenny Zeltser.

Download it here.
Logged

Security+, OSCP, CEH
H1t M0nk3y
Hero Member
*****
Offline Offline

Posts: 865



View Profile
« Reply #1 on: July 09, 2010, 07:09:24 AM »

Very interesting, thanks nebu10z!

This distro can do more than Reverse Engineering:

Quote
Malware Analysis Tools Set Up On REMnux

Analyzing Flash malware: swftools, flasm, flare

Analyzing IRC bots: IRC server (Inspire IRCd) and client (Irssi). To launch the IRC server, type "ircd start"; to shut it down "ircd stop". To launch the IRC client, type "irc".

Network-monitoring and interactions: Wireshark, Honeyd, INetSim, fakedns and fakesmtp scripts, NetCat

JavaScript deobfuscation: Firefox with Firebug, NoScript and JavaScript Deobfuscator extensions, Rhino debugger, two versions of patched SpiderMonkey, Windows Script Decoder, Jsunpack-n

Interacting with web malware in the lab: TinyHTTPd, Paros proxy

Analyzing shellcode: gdb, objdump, Radare (hex editor+disassembler), shellcode2exe

Dealing with protected executables: upx, packerid, bytehist, xorsearch, TRiD

Malicious PDF analysis: Dider's PDF tools, Origami framework, Jsunpack-n, pdftk

Memory forensics: Volatility Framework and malware-related plugins

Miscellaneous: unzip, strings, ssdeep, feh image viewer, SciTE text editor, OpenSSH server

I will take a look at it soon...
Logged

OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
Bane
Guest
« Reply #2 on: July 09, 2010, 09:52:34 AM »

Lenny has been giving this out at his GREM courses for quite awhile. Nice to see that it is now publicly available.
Logged
H0nd0CSI
Newbie
*
Offline Offline

Posts: 17


H0nd0


View Profile WWW
« Reply #3 on: September 30, 2010, 08:53:44 AM »

Very Coooool thanks for the info  Wink
Logged

"If the only tool you have is a hammer, you tend to see every problem as a nail"
Abraham Maslow
dante
Jr. Member
**
Offline Offline

Posts: 58



View Profile
« Reply #4 on: September 30, 2010, 09:20:08 AM »

Even old posts in ethical-hacker.net are valuable.. Will download it right away... Thanks for bring this up back again  H0nd0CSI
Logged
putosusio
Newbie
*
Offline Offline

Posts: 26


View Profile
« Reply #5 on: October 28, 2010, 01:20:24 AM »

Unfortunately, I may need to this soon.

Curse you chinese hackers ... well thank you in a sort of twisted way.  At least the malware is on a test system.
Logged

Its not the fixing that's the hard part, its knowing what needs fixing.
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.071 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.