Re: chkrootkit and LKM?

From: Tim Greer (chatmaster_at_charter.net)
Date: 06/18/03

  • Next message: Golden Faron P Contr HQ SSG/SWSN: "One observed pattern of Win 55808 packets"
    To: "Rob Shein" <shoten@starpower.net>, 'Janus N. Tøndering' <janus@bananus.dk>, <incidents@securityfocus.com>
    Date: Wed, 18 Jun 2003 09:21:45 -0700
    
    

    > ----- Original Message -----
    > From: "Rob Shein" <shoten@starpower.net>
    > To: "'Tim Greer'" <chatmaster@charter.net>; "'Janus N. Tøndering'"
    <janus@bananus.dk>; <incidents@securityfocus.com>
    > Sent: Wednesday, June 18, 2003 12:47 AM
    > Subject: RE: chkrootkit and LKM?
    >

    > This won't help if it's an LKM...LKM stands for "Linux Kernel Module,"

    For some reason, I just saw 'chrootroot' and not LKM; hence my response.
    Anyway, I always recommend people not compile in loadable module support if
    they want a more secure kernel and to avoid this type of problem in the
    future.

    --
    Regards,
    Tim Greer  chatmaster@charter.net
    Server administration, security, programming, consulting.
    ----------------------------------------------------------------------------
    Attend the Black Hat Briefings & Training, July 28 - 31 in Las Vegas, the 
    world's premier technical IT security event! 10 tracks, 15 training sessions, 
    1,800 delegates from 30 nations including all of the top experts, from CSO's to 
    "underground" security specialists.  See for yourself what the buzz is about!  
    Early-bird registration ends July 3.  This event will sell out. www.blackhat.com
    ----------------------------------------------------------------------------
    

  • Next message: Golden Faron P Contr HQ SSG/SWSN: "One observed pattern of Win 55808 packets"

    Relevant Pages

    • RE: Cisco IOS vulnerability
      ... Subject: Cisco IOS vulnerability ... On a perimeter router you should be implementing RFC1918 and RFC2827 ... Although these security measures in themselves will not prevent the attack, ... world's premier technical IT security event! ...
      (Incidents)
    • RE: Need some help and guidance, please....RE: TROJAN: Symantec: New Serious Virus found. (fwd)
      ... which will bring up lots of pop up windows like window ... > Norton Security Response, has detected a new virus in the Internet. ... > world's premier technical IT security event! ... > Early-bird registration ends July 3. ...
      (Incidents)
    • Re: Standards for developing secure software
      ... > there's a tradeoff between performance and security in most cases. ... >> language, or a library, without a lot of bloat and code slowness. ... can write my code any way I want, and it will compile. ... entire business and development environment to suit a programming language ...
      (SecProg)
    • RE: Cisco IOS vulnerability
      ... Subject: Cisco IOS vulnerability ... On a perimeter router you should be implementing RFC1918 and RFC2827 ... Although these security measures in themselves will not prevent the attack, ... world's premier technical IT security event! ...
      (Incidents)
    • Need some help and guidance, please....RE: TROJAN: Symantec: New Serious Virus found. (fwd)
      ... scan when I rebooted and found the virus and quarantined it. ... > Norton Security Response, has detected a new virus in the Internet. ... > world's premier technical IT security event! ... > Early-bird registration ends July 3. ...
      (Incidents)