Re: RPM aware rootkits?

From: dewt (
Date: 02/13/02

From: dewt <>
To: Anton Chuvakin <>,
Date: Wed, 13 Feb 2002 13:26:47 -0600

On Tuesday 12 February 2002 12:44 pm, Anton Chuvakin wrote:
> Hello all,
> After spending some time in, I decided to ask it here.
> Do you know any of the RPM-aware rootkits for Linux which will not be
> detected by "rpm --verify". I would prefer direct edit of /var/lib/rpm
> rather to trojaned rpm binary, but what the heck - whatever will do.
> I need to deploy something on Linux which will pass the "rpm -V", but will
> involve replacing some binaries. I can rebuild the stuff from source
> RPMs, recreate the package and then replace the stock RPM., but it is too
> messy (GPG sig will be different, but that will hopefully be OK for the
> honeypot).
> Thanks a lot for responses!
> Best regards,
i'm not aware of one, but making a small spec file for the trojaned binaries
and making your own rpm package could work, of course that wont pass the -Vp
option but not many people do that.

Relevant Pages

  • Weird issue using rpm -qaV
    ... Running a rpm -qaV with root privilege I found that it changes the ... rpm package version rpm- ... The result is my aide output prints a lot of noise. ...
  • Re: [opensuse] building RPMs
    ... The "make install" procedure has some obvious drawbacks you might have ... of your system (RPM database) is a problem, ... checkinstall is a useful tool but has also some drawbacks. ... RPM package on your local system which can then be installed. ...
  • Re: PHP on RH 7.0
    ... can use to test if PHP is running. ... php-4.3.4.tar.gz.tar does not appear to be a RPM package ... confirmation email one time only to let the "good guys/gals through" :-) ...
  • Re: Building RPM in RHEL 5
    ... First link is a pdf and a decent starting point. ... How do we build a .rpm package in RHEL 5? ... System Analyst ...
  • Re: Can I retrieve just one file from an rpm archive?
    ... Which type of RPM package do you have? ... then unpack the _whole_ ... Thus, before you force the install, do ...