NTRootkit

From: zero (zeroboy_at_arrakis.es)
Date: 06/19/03

  • Next message: Jake Frost: "Filtering DHCP Assignments by MAC Address"
    Date: Thu, 19 Jun 2003 19:39:30 +0200
    To: full-disclosure@lists.netsys.com
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    Hi all,
              I was wondering, if NTRootkit hooks syscalls, many of the current
    programs used to detect running procs and hidden keys in register will
    fail. So, how could you actually detect if syscalls have been hooked? I
    belive you could see if new native calls have been added, but how can you
    detect hooked and modified native calls?

    Thxs in advance

    www.citfi.org
    www.podergeek.com
    **********************************
    "The further backward you look, the further forward you can see" Winston
    Churchill
    "Access is GOD..."

    -----BEGIN PGP SIGNATURE-----
    Version: PGPfreeware 6.5.8 for non-commercial use <http://www.pgp.com>

    iQA/AwUBPvHnQw0R8jZM93x8EQIW+gCcCQc/N5j4wq6yjAiZi0bQsKYVMegAoI90
    F2Zp7FOM8O0q3EeZHFLj7Rv6
    =r6/w
    -----END PGP SIGNATURE-----

    -----------------------------------------------------------------------------
    ------------------------------------------------------------------------------


  • Next message: Jake Frost: "Filtering DHCP Assignments by MAC Address"

    Relevant Pages

    • [Full-Disclosure] NTRootkit
      ... programs used to detect running procs and hidden keys in register will ... fail. ... how could you actually detect if syscalls have been hooked? ...
      (Full-Disclosure)
    • [Full-Disclosure] NTRootkit
      ... programs used to detect running procs and hidden keys in register will ... fail. ... how could you actually detect if syscalls have been hooked? ...
      (Full-Disclosure)
    • Re: Rename 2K3 Domain - DNS Issues
      ... FAIL or WARN messages. ... cannot register for THEMSELVES if you change that -- if they are ... Name" tab, the domain name is listed, and it is the "DNS Suffix for this ... The new zone is set up to allow secure dynamic updates only; ...
      (microsoft.public.windows.server.active_directory)
    • Re: HP49G+ - strengths and weakneses?
      ... update it was failing randomly to register some keys. ... now registering randomly keys as several strokes of the same key. ... too), I thought, that TI will also either fail to solve it or would require ... The TI keyboard was such a pleasure to work with when I suddenly switched ...
      (comp.sys.hp48)
    • Called program fails to fail when DISPLAY is added
      ... fail when I want it to succeed and to fail ... CALL "ISF43" USING LDB-BASENAMES, ... Schroder Investment Management Limited is entered on the FSA register under the following register number: ...
      (comp.sys.hp.mpe)

  • Quantcast