Re: RPM aware rootkits?

From: Jeff Hedgpeth (jeff.hedgpeth@edwardjones.com)
Date: 02/14/02


Date: Thu, 14 Feb 2002 10:22:27 -0600
From: Jeff Hedgpeth <jeff.hedgpeth@edwardjones.com>
To: focus-linux@securityfocus.com

if you just want to pass rpm verify, I believe you can just delete the
rpm db entry with something like 'rpm -e <pkgs> --justdb --nodeps'. the
pkg won't show as installed, but it shouldn't be corrupt either. I
haven't verified this, tho.

jeff

> Do you know any of the RPM-aware rootkits for Linux which will not be
> detected by "rpm --verify". I would prefer direct edit of /var/lib/rpm
> rather to trojaned rpm binary, but what the heck - whatever will do.
>
> I need to deploy something on Linux which will pass the "rpm -V", but will
> involve replacing some binaries. I can rebuild the stuff from source
> RPMs, recreate the package and then replace the stock RPM., but it is too
> messy (GPG sig will be different, but that will hopefully be OK for the
> honeypot).



Relevant Pages

  • Re: Check RPM database?
    ... database is corrupt that I must do something about it, ... rpm database. ... Is there a tool or command to check the RPM database for being corrupt? ...
    (Fedora)
  • Advisory: Corrupt RPM Query Vulnerability
    ... Subject: Advisory: Corrupt RPM Query Vulnerability ... Arbitrary command executing on query of corrupt RPM files ...
    (Bugtraq)
  • Re: Segmentation fault
    ... it is regarding the rpm package..it may be corrupted.. ... Is this a hardware or software problem? ... I am suspecting that this means I had a corrupt download. ...
    (Fedora)
  • [UNIX] Arbitrary Command Executing on Query of Corrupt RPM Files
    ... Arbitrary Command Executing on Query of Corrupt RPM Files ...
    (Securiteam)
  • Re: corupted kernel
    ... Assuming you are correct and it is really corrupt (I doubt it but I have been ... Boot into rescue mode and reinstall the kernel rpm. ...
    (Fedora)