Re: chkrootkit warning

From: Nils Petter Vaskinn (no@spam.for.me.invalid)
Date: 01/31/03


From: Nils Petter Vaskinn <no@spam.for.me.invalid>
Date: Fri, 31 Jan 2003 11:36:37 GMT

On Fri, 31 Jan 2003 11:52:34 +0100, Bit Twister wrote:

> Think about that paragraph.
> You cannot use ANY of your pc's utilities to see if your box is cracked
> and find what addtional files are installed.
>
> What you can do is have a dual boot system. You install a second copy of
> your OS and label it Auditor. You never, EVER mount it from the internet
> OS.

You can not trust a second installation. If a cracker has got root on your
computer what is going to stop him for checking for it, mount the Auditor
partition(s) and then put trojaned binaries in there too?
Think about the first quoted paragraph. You can't trust any of your pc's
utilities - even if they are on a partition that you never mount. Simply
because a cracker could mount it.

> Some have suggested install on a seperate disk which is left unplugged
> until you want to use it.

That would prevent a cracker from tampering with it. I don't know if any
of the "boot from cd distros" come with specific tools for checking an
installation for tampering, but I guess you could use one to check the
binaries against those on your installation cds.

NP



Relevant Pages

  • Re: Software Protection and Anti Crack code
    ... > Even though everyone of us knows that if a cracker wants to break into the ... from hacking the installation file).... ... use of debugging systems for code developers? ...
    (comp.lang.asm.x86)
  • Re: sshd vunerability compromise
    ... Ron Parker schrieb: ... I think there are possibly hundred of place on which the cracker ... - make an almost identical copy of your installation from the distris CD ... copy this tripwire-database to the infected system ...
    (comp.os.linux.security)
  • Re: Installing SQL205 in a cluster with mount points
    ... Most of the installation goes somewhere such as C:\Program ... Anyway, to summarise, the base drive isn't just for mount points as the ... am trying to set up a 2 node cluster with a single instance of sql2005. ... disks which are mounted in there. ...
    (microsoft.public.sqlserver.clustering)
  • Re: Anyone using a Roland GK3?
    ... way to get the pickup balanced across strings. ... bridge and the back of the bridge pickup from the pix because you need ... about 3/4" to use the ABR bridge mount piece, ... it perfect with a non-intrusive installation. ...
    (rec.music.makers.guitar.jazz)
  • Re: Cant install Suse9 - kernel panic at install
    ... > original post) which has a working Linux installation on it from my 'old' ... when trying to mount the root filesystem I get a panic yet again. ... I'm not sure if the installation program on Suse tries to mount ...
    (alt.os.linux.suse)

Loading