Re: RPM aware rootkits?

From: Seth Arnold (sarnold@wirex.com)
Date: 02/14/02


Date: Wed, 13 Feb 2002 15:13:59 -0800
From: Seth Arnold <sarnold@wirex.com>
To: focus-linux@securityfocus.com


On Wed, Feb 13, 2002 at 01:26:47PM -0600, dewt wrote:
> > Do you know any of the RPM-aware rootkits for Linux which will not be
> > detected by "rpm --verify". I would prefer direct edit of /var/lib/rpm
> > rather to trojaned rpm binary, but what the heck - whatever will do.

> i'm not aware of one, but making a small spec file for the trojaned binaries
> and making your own rpm package could work, of course that wont pass the -Vp
> option but not many people do that.

If this is for one of your own machines, wouldn't it be far simpler to
replace rpm's --verify handler with a function that always returns "this
package looks fine" ?

-- 
Join the fight against terrorism by giving up your liberties today!




Relevant Pages

  • Re: Preparing an Oracle Database XE port/package -- any tips ?
    ... After having to deploy an Oracle Database XE installation (with Linux ... 32bit binaries from the official RPM package) on a production FreeBSD ...
    (freebsd-isp)
  • Re: Preparing an Oracle Database XE port/package -- any tips ?
    ... After having to deploy an Oracle Database XE installation (with Linux ... 32bit binaries from the official RPM package) on a production FreeBSD ...
    (freebsd-hackers)
  • Re: MPE News - VFX Forth for Linux Alpha6
    ... Linux version is available in rpm and deb packages for 32 bit and ... 64 bit x86 Linux variants. ... Got the rpm package and installed on my Toshiba Satelite P4, ... version on this laptop, ...
    (comp.lang.forth)
  • Re: GRUB issue
    ... to Linux and seem to have burnt my fingers over this. ... I downloaded the rpm package from the site you mentioned. ...
    (comp.os.linux.misc)
  • Re: GRUB issue
    ... to Linux and seem to have burnt my fingers over this. ... I downloaded the rpm package from the site you mentioned. ...
    (comp.os.linux)