AW: nouser - rootkit ?

From: vogt@hansenet.com
Date: 03/12/02


From: vogt@hansenet.com
To: kr@roqe.org, incidents@securityfocus.com
Date: Tue, 12 Mar 2002 10:21:27 +0100


> I am just curious about the "red herring"-part of the story and the
> term "real rootkit"...
>
> I wonder if there are really attackers out there installing
> bogus-rootkits in order to protect the real ones. Has anybody on this list

> detected such kind of "feints"?

Not directly, but I have found multiple rootkits installed on a compromised
server late last year. I can think of a number of reasons why the attacker
would want to install more than one, but staying in control even if one is
discovered is surely a plausible option.

On the other hand, this strikes me as a very dumb move. If the sysadmin is
bright enough to find the rootkit, I sure do hope that he also realizes that
the only way to a clean system is through a full reinstall.

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: Administration password
    ... >>An alternative way of installing a keylogger would be to boot from a dos ... Imagine how slow your system would get if anytime a dll should be ... Ntfspro would have been an option to resolve that matter. ... And activate some protection in the BIOS (protect the BIOS ...
    (alt.computer.security)
  • Re: firewall
    ... usually when installing "FREE" software or ... download the mandatory "free" viewer they are infected with dialer programs ... obviously dubious web site, leave the web site. ... NAT-capable routers do nothing to protect ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Windows updates and Conficker ?
    ... If "Security Update for Windows XP " AKA MS08-038 is installed, you should be OK, assuming you... ... Protect Your PC! ... So my easy question here is without installing SP3 for XP on the machines ... remaining that I have not gotten to yet do I have the updates to protect me ...
    (microsoft.public.windowsupdate)
  • Re: ie6 sp1 update fails->"wfp: unrecognized version"
    ... programs before installing anything. ... Protect Your PC ... > Consistently the "Cumulative Security Update for Outlook Express 6 Service ... > update and attempts to download it again. ...
    (microsoft.public.windowsupdate)
  • Re: ie6 sp1 update fails->"wfp: unrecognized version"
    ... programs before installing anything. ... Protect Your PC ... > Consistently the "Cumulative Security Update for Outlook Express 6 Service ... > update and attempts to download it again. ...
    (microsoft.public.windowsxp.general)