Re: Anti-Rootkit app
- From: Tim Clewlow <tim1timau@xxxxxxxxx>
- Date: Mon, 14 Jan 2008 16:15:49 -0800 (PST)
--- Dan Lukes <dan@xxxxxxxxx> wrote:
I need to install an anti-rootkid
If I understand correctly, an intruder need to be superuser to be able
to install a rootkit.
If our intruders has superuser privileges, they can tamper any
anti-rootkit.
Is the main reason to install anti-rootkit we count the intruders are
so dumb to look for one of port's anti-rootkit package before they do
it's dirt work ?
Or I miss something important ?
Dan
One solution would be to have /var/log/auth.log being tailed out via a serial
port to another computer that is not accessable via a network - or have it sent
to a printer for a permanent hard-copy. It all depends on how much you really
want to do in regard to security.
Cheers, Tim.
____________________________________________________________________________________
Never miss a thing. Make Yahoo your home page.
http://www.yahoo.com/r/hs
_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"
- Follow-Ups:
- Re: Anti-Rootkit app
- From: Jan Münther
- Re: Anti-Rootkit app
- References:
- Re: Anti-Rootkit app
- From: Dan Lukes
- Re: Anti-Rootkit app
- Prev by Date: Re: Anti-Rootkit app
- Next by Date: Re: Anti-Rootkit app
- Previous by thread: Re: Anti-Rootkit app
- Next by thread: Re: Anti-Rootkit app
- Index(es):
Relevant Pages
|
|