Re: Incident investigation methodologies

From: Jon Coller (jon_at_coller.org)
Date: 06/04/04

  • Next message: Valdis.Kletnieks_at_vt.edu: "Re: Incident investigation methodologies"
    Date: Fri, 04 Jun 2004 14:35:07 -0600
    To: Paul Schmehl <pauls@utdallas.edu>
    
    

    Paul Schmehl wrote:
    <snip>
    > For example, a statically compiled copy of ls on a CD is going to show
    > you what's on the hard drive of a unix machine no matter what the
    > rootkit may have done.
    <snip>

    This is most definitely not true!

    How do you think ls gets the contents of a directory? (here's a hint,
    the kernel via the getdents system call)

    take a read of this for a decent example of how trivial it is to make
    user land tools lie:
    http://packetstormsecurity.com/groups/thc/LKM_HACKING.html

    -Jon


  • Next message: Valdis.Kletnieks_at_vt.edu: "Re: Incident investigation methodologies"

    Relevant Pages

    • Re: all this talk of clothing made in china...
      ... campaign in Britain; it did help to prolong the decline of a few marginal ... it convinced my generation that if you wanted something decent ... lower priced consumer goods all seemed to be Japanese (hence Matsui ...
      (uk.people.support.depression)
    • Re: Should Apple do away with OS X?
      ... A decent one allows you to scroll past text quickly. ... Yeah, first off, I'll say that one should probably snip extraneous ... 'It is Mac OS X, ... "It's BSD Unix with Apple's APIs and GUI on top of it' -- 'nothing but BSD Unix' ...
      (comp.sys.mac.advocacy)
    • Re: Haydn string quartets (complete)
      ... Johannes Roehl wrote: ... quite decent, certainly better than what I have heard of the Kodaly. ... They lack sometimes a certain "depth", i.e. they play most of the pieces in a rather lightweight fashion. ...
      (rec.music.classical.recordings)
    • Re: Haydn string quartets (complete)
      ... Bob Harper wrote: ... quite decent, certainly better than what I have heard of the Kodaly. ... range of mood and expression would be preferable. ...
      (rec.music.classical.recordings)
    • Re: whats the quickest way to get a woman into bed
      ... No exceptions: all were polite, ... kind, and decent. ...
      (uk.people.support.depression)