Re: Exploit or trojan

From: dav (dav_at_r00tworld.com)
Date: 12/19/03

  • Next message: Steve Bremer: "Re: Exploit or trojan"
    Date: Fri, 19 Dec 2003 15:36:57 +0100
    To: Felipe Franciosi <ozzybugt@terra.com.br>
    
    

    Felipe Franciosi [ozzybugt@terra.com.br] a écrit:
    > > Oops.
    > >
    > > Such kind of kernel backdoors (e.g. loadable kernel modules) are also
    > > present for Solaris, *BSD and Windows systems. If you are unsure whether
    > > someone has compromised your system, don't trust the system's kernel!
    >
    > Yeah you are right! I was just reading about coding solaris kernel
    > modules. It is pretty easy, actually. Anyone can find a lot of
    > documents on google.
    >
    > A little addition here: Some Linux backdoors (Suckit, for example)
    > doesn't work as a kernel module. It just opens /dev/kmem and patch
    > it on the fly. It is still detectable, though, trought some imple-
    > mentation flaws or checking mechanisms that verify the kernel
    > syscall table integrity.

            For solaris systems, you can look at papillon kernel module. This module
    try to make same than gr-security for linux kernel...
            I'm using it on production servers, and I've no trouble to report after
    one year.

    http://www.roqe.org/papillon/

    dav.

    -- 
    PGP: http://www.r00tworld.com/~dav/dav.gpg
    

  • Next message: Steve Bremer: "Re: Exploit or trojan"

    Relevant Pages

    • Re: Please release a stable kernel Linux 3.0
      ... RedHat or Google more than Microsoft or Apple. ... You seem to misunderstand kernel development. ... If you don't trust the distro, ... stable/development kernels. ...
      (Linux-Kernel)
    • Re: [PATCH] x86/paravirt: revert exports to restore old behaviour
      ... __flush_tlband friends suffer, too. ... Yeah, I guess they can be expected to play with pagetables. ... inclusion of linux kernel headers, but it is really ugly and hacky. ... I think removing the difference between PARAVIRT and non-PARAVIRT ...
      (Linux-Kernel)
    • Re: [PATCH] x86/paravirt: revert exports to restore old behaviour
      ... __flush_tlband friends suffer, too. ... Yeah, I guess they can be expected to play with pagetables. ... inclusion of linux kernel headers, but it is really ugly and hacky. ... that's a separate decision which can be applied uniformly to PARAVIRT ...
      (Linux-Kernel)
    • Re: The GPL: No shelter for the Linux kernel?
      ... I don't actually want people to need to trust anybody - and that very much ... And somebody chooses anoter license, ... compatible with the GPLv2 for the kernel. ... in case of mr. Alan Cox i do care. ...
      (Linux-Kernel)
    • Re: hiding a counter
      ... kernel has been modified to keep a particular application within 'a ... You have made a rash assumption that the program is intended to run on every conceivable configuration and that is was programed to do so without some sort of configuration process. ... all you need to do it use your eyes and see a crime, if you don't want to trust someone else telling you of a crime they saw. ... Now as for blackbox software I doubt you realize there is no other kind. ...
      (comp.unix.programmer)