Re: No Defense Against Windows Rootkits?

From: Winged (Winged_at_nofollow.com)
Date: 09/30/05


Date: Thu, 29 Sep 2005 20:17:46 -0500

speeder wrote:
> On 28 Sep 2005 23:25:59 GMT, "nemo_outis" <abc@xyz.com> wrote:
>
>
>>PPS The only complete protection (passing over hardware tampering such as
>>compromised BIOSs) is something like hash-checking essential files after
>>booting from a known-good CD.
>
>
> Something like Tripwire? What would be the equivalent for Windows?
Tripwire



Relevant Pages

  • Re: Freeware Anti virus programs !
    ... I will get started with ClamAV and all check on other info everyone provided. ... For Linux systems antivirus is not as important as it is under windows. ... Tripwire takes a snapshot of the files on your system ...
    (Fedora)
  • Re: Tripwire for Windows machines ?
    ... Anyone successfully running Tripwire or other checker against rootkits on ... The thing is that Tripwire is not free for Windows, as it is for Linux, ... None of these tools do a lot to help with Windows root kits. ...
    (microsoft.public.security)
  • Re: Very strange: the code was good for the last 10 years and now it is stumbling!!!
    ... The code writing to Windows registry was good and working perfectly for the last 10 years and now suddenly it stops working ... the value you pass for the cbData parameter of RegSetValueEx must be 1 more than the length of the ... cbData must include the size of the terminating null character or characters.") So, you should be passing Len+1. ...
    (microsoft.public.vb.general.discussion)
  • Re: Freeware Anti virus programs !
    ... For Linux systems antivirus is not as important as it is under windows. ... Tripwire takes a snapshot of the files on your system ... You can also use things like snort that will monitor network traffic ...
    (Fedora)
  • Re: [Full-disclosure] Microsoft GhostBuster Opionions
    ... Tripwire is far more ... and since have used Samhain and Osiris. ... great tools for checking the integrety of the files. ... as far as I can tell Tripwire for Windows isn't ...
    (Full-Disclosure)