Re: RPM aware rootkits?

From: jon schatz (jon@divisionbyzero.com)
Date: 02/14/02


From: jon schatz <jon@divisionbyzero.com>
To: Anton Chuvakin <anton@chuvakin.org>
Date: 13 Feb 2002 15:39:31 -0800


On Wed, 2002-02-13 at 14:56, Anton Chuvakin wrote:
> Hmm, that was the point of my question, to some extent. How would an
> attacker (possesing the md5sums for valid packages and md5sumes for hacked
> packages) go about updating the rpm database to pass the ? Are there any
> tools (in rootkits or elsewhere) to accomplish it?

well, why not just create new rootkit rpms? perhaps with the same
version string even? the `rpm --force --nodeps -ivh` the package.

anyone doing a rpm -Va would see everything as being fine, unless some
tripwire-esque filesystem check was used.

-jon

-- 
jon@divisionbyzero.com || www.divisionbyzero.com
gpg key: www.divisionbyzero.com/pubkey.asc
think i have a virus?: www.divisionbyzero.com/pgp.html
"You are in a twisty little maze of Sendmail rules, all confusing." 




Relevant Pages

  • Re: How to install Java/Frefox in FC6 -
    ... as the Fedora Extras guidelines suggest. ... There are numerous guides to rpm on the net. ... There are far too many broken tarballs out there for that. ... able to see from rpms downloaded and installed as binary packages. ...
    (Fedora)
  • SUSE Security Announcement: Linux Kernel (SuSE-SA:2004:001)
    ... installable through rpm, because of a bug in RPM (update of ... the kernel source is not ... sources that the binary kernel rpm packages are made from. ... are being offered to install from the maintenance web. ...
    (Bugtraq)
  • [Full-Disclosure] SUSE Security Announcement: Linux Kernel (SuSE-SA:2004:001)
    ... installable through rpm, because of a bug in RPM (update of ... the kernel source is not ... sources that the binary kernel rpm packages are made from. ... are being offered to install from the maintenance web. ...
    (Full-Disclosure)
  • Re: [SLE] libphp4.so?
    ... > base on which all other packages build: ... rpm -qa | grep cpp ... yast the NVIDIA drivers won't install via the installer, ...
    (SuSE)
  • [Full-Disclosure] SUSE Security Announcement: kernel (SuSE-SA:2004:010)
    ... The update packages for the SuSE Linux Enterprise Server 7 ... contain any binary kernel in bootable form. ... sources that the binary kernel rpm packages are made from. ... are being offered to install from the maintenance web. ...
    (Full-Disclosure)