Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
linux-root-kit — End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full memory and network forensic analysis. | Kitploit
Tools/GitHubGitHub/ic3-512/linux-root-kit
Privilege EscalationExploit FrameworksMemory ForensicsPersistence MechanismsNetwork ForensicsReverse EngineeringDigital ForensicsCommand and ControlSupply Chain SecurityLearning & EducationLabs & Practice
101231 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHubic3-512/linux-root-kit

linux-root-kit

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full memory and network forensic analysis.

View Repository

About This Project

This project was developed as part of the Digitale Forensik course at the Technische Hochschule Deggendorf.

It demonstrates a full forensic investigation and attack simulation involving:

  • A Python dependency confusion attack using a malicious PyPI package

  • Privilege escalation via a vulnerable version of sudo (CVE-2025-32463)

  • Deployment of a Sliver C2 beacon

  • A custom rootkit with kernel module loading, syscall hooking, and udev-based persistence

  • Complete analysis of memory and network artifacts using tools like Volatility, NetworkMiner, and manual reversing

The repository contains scripts, setup instructions, artifacts , and detailed analysis steps to replicate both the attack and the forensic investigation.

TOC

  • Privilege Escalation
  • Exploit Chain
  • Artifact Generation
    • Create Memory Dump
    • Prepare Network Dump on Ubuntu
  • Setup Developer Ubuntu Client (shell)
    • 1. Clone the repository and execute
    • 2. Once the VM is up, SSH in
    • 3. Install the vulnerable sudo and Python venv
    • 4. Build the userland loader binary (shell)
    • 5. Send the shell to the Kali to later serve it from there.
  • Setup Kali (192.168.56.101)
    • 1. Start Sliver server
    • 2. Generate a HTTP Beacon
    • 3. Rename and serve beacon
    • 4. Start listener
  • Simulate Developer
    • 1. Clone the PoC
    • 2. Create and activate a Python venv
    • 3. Install dependencies
    • 4. Run the malicious package
  • Simulate the Attacker
    • 1. Wait for the Beacon and inspect the sudo version
    • 2. Upload exploit and loader
    • 3. Execute Sudo Exploit
    • 4. Load kernel module
    • 5. Setting up a udev rule
    • 6. Reboot
    • 7. Catch shell on reboot
  • Analysis
    • Overview of Collected Artefacts
    • Quick Network Overview with NetworkMiner
    • Detailed Traffic Analysis
      • GitHub Download
      • PyPI Download
      • Malicious “lilux” Binary Retrieval
    • Post‑Download Behavior
      • Sliver Beaconing
      • Unencrypted Reverse Shell
    • Summary
      • Key Findings
      • Forensic Implications
  • Memory Analysis
    • Environment and Setup
    • Memory Dump Acquisition
    • Install Debug Symbols
    • Generate the Volatility Symbol File
    • Run Volatility with Symbols
    • (Optional) Faster Searching with fzf
    • Finding Interesting Files
    • Loaded Modules
    • Udev Rule
    • Extracting the shell
  • Reversing of shell binary
    • load_module Branch
    • rsh Branch
      • daemonize Function
      • Reverse Shell
    • Summary of Behavior
      • Behavioral Summary
  • Reversing of Kernel Module
    • Python script to extract Kernel Module
      • 1. Create Range
      • 2. Compare the target address
      • 3. Continue until a match is found
    • rkit_init
    • Hooked Functions
      • Kill Hook
      • Getdents(64) Hook
    • Module Hiding
    • Debug Messages
    • Reverse Shell Loader
    • rkit_exit
  • Checksums
  • Tools and Versions Used

Privilege Escalation

CVE-2025-32463
NVD Details
POC Github

[!NOTE]
You must install a vulnerable Sudo version (with chroot support—see privesc/setup.sh)

Exploit Chain

sequenceDiagram
    autonumber
    participant Attacker
    participant PyPI
    participant IntDep as Internal Dep Server
    participant Dev as Developer
    participant C2 as C2 Server

    Attacker->>PyPI: Publish package with version v1.0.3
    Dev->>IntDep: pip install
    IntDep-->>Dev: Returns v1.0.1
    Dev->>PyPI: Fallback pip install package==v1.0.3
    PyPI-->>Dev: Returns malicious v1.0.3 (stager)
    Dev->>Dev: Executes stager (package_evil)
    Dev->>C2: Beacon/Sliver implant calls home
    Note right of C2: Attacker now has RCE

    Attacker->>Dev: Enumerates sudo version (1.9.16p2)
    Attacker->>Dev: Runs CVE-2025-32463 exploit
    Note right of Dev: PE to root

    Dev->>Dev: Downloads & runs rootkit loader binary
    Dev->>Dev: Loader installs kernel module & configures udev rule
    Dev->>Dev: Schedules reboot
    Note right of Dev: Attacker established persistence 

    Dev->>Dev: System reboots
    Dev->>Dev: Udev loads kernel module on boot
    Dev->>C2: Kernel-stage beacon calls C2

Artifact Generation

All artifacts are generated manually. You will use two machines:

  • Attacker machine (Kali Linux)
  • Developer machine (Ubuntu)

We will produce three artifacts:

  • PCAP (before reboot)
  • Memory dump (after reboot)

Create Memory Dump

How to dump VirtualBox memory

On the host system:

vboxmanage list vms
"linux-root-kit_default_1752261916398_20346" {c2d4b5bc-d87f-4dcb-af01-85b78c163fef}
virtualboxvm --startvm "linux-root-kit_default_1752261916398_20346" --dbg

Goto interface --> Debug In the Debug Console (VMMR0> prompt):

.pgmphystofile 'dumpmem_linux_root_kit'

Prepare Network Dump on Ubuntu

Start before simulating the developer. The ! port 22 is useful to not log the vagrant ssh connection.

sudo tcpdump -w output.pcap ! port 22

Setup Developer Ubuntu Client (shell)

1. Clone the repository and execute:

vagrant up

This can take a while --> downloads an entire vm that was build with Bento.

2. Once the VM is up, SSH in:

vagrant ssh

3. Install the vulnerable sudo and Python venv:

sudo bash /vagrant/privesc/setup.sh
sudo apt install python3.12-venv

4. Build the userland loader binary (shell):

You can also execute the make file to build the userland binary shell. This the easiest way to do it - otherwise you would need to install the correct headers first :P.

5. Send the shell to the Kali to later serve it from there.

Setup Kali (192.168.56.101)

1. Start Sliver server

Download Tool