Re: fun with posiden rootkit

From: Skip Carter (skip@taygeta.com)
Date: 03/25/02


To: Alvin Oga <alvin.sec@Mail.Linux-Consulting.com>
Date: Mon, 25 Mar 2002 14:48:10 -0800
From: Skip Carter <skip@taygeta.com>


> - sometimes checking failed script-kiddies can be entertaining if time
> permits to look around for any funny stuff

  I had one incident that I investigated for a client recently.

  It was the usual: gain entry, install rootkit, install password
  scanner, etc. Except he did it in the wrong order, so that his
  password scanner caught his own connection back to his rootkit
  archive; so when I started my investigation I was able to log in
  to his archive and pick up his entire stash of tools.

-- 
 Dr. Everett (Skip) Carter      Phone: 831-641-0645 FAX:  831-641-0647
 Taygeta Scientific Inc.        INTERNET: skip@taygeta.com
 1340 Munras Ave., Suite 314    WWW: http://www.taygeta.com
 Monterey, CA. 93940            

---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: Staging errors during shutdown/reboot in Windows Update
    ... I'll keep you informed as to what I find out about the incident. ... Willem Overbeeke wrote: ... were no errors in the install log file (only these entries in the event ... into the staging state" entries in the event log. ...
    (microsoft.public.windowsupdate)
  • Re: Staging errors during shutdown/reboot in Windows Update
    ... Willem Overbeeke wrote: ... were no errors in the install log file (only these entries in the event ... I did not open an incident this time, ... into the staging state" entries in the event log. ...
    (microsoft.public.windowsupdate)
  • Xvid codec
    ... after playing around with 8.2 for 6 months, ... 'interesting' incident with an XP upgrade, I've decided to try to move ... anyway) BUT when I tried to install avidemux Yast told me that ...
    (alt.os.linux.suse)
  • Re: Error 0x643
    ... The installation process took forever and ... If I get a failed installation, I go back to Windows Update and try ... update history says it failed to install KB922770 ... I think that your incident is sufficiently different from the OP ...
    (microsoft.public.windowsupdate)