Re: Urgent!!! My computer seems to be hacked, pls HELP!!!
- From: Chris Mattern <syscjm@xxxxxxx>
- Date: Fri, 15 Sep 2006 12:24:37 -0400
Randy Yates wrote:
Chris Mattern <syscjm@xxxxxxx> writes:
René Berber wrote:
Darren Dunham wrote:
Unless the CD nukes any unknown (read non-OS) executable on the drive or
you have some known state to compare against (a la tripwire), I don't
see how you can effectively check a drive. It's certainly possible, but
requires you've done work before the attack. Afterward is too late.
Not true, and it really makes no sense continuing to discuss this.
Yes, true. Once a hacker gains root access to your box, you cannot
trust *any* program or library on it again. I thought this would've
been almost self-evident, but I guess it isn't to some people.
Instead of both sides making empty claims, why not back the claims up
with some specific, concrete examples or possibilities? I for one
would love to see how these "rootkits" accomplish their nasty tricks,
and would like to try my mind at defeating them.
Specific concrete examples are easy to see. You use lsof and ps
to see what's running on your box and what processes are running.
But lsof and ps are program files writable by anyone who has root;
the rootkit can rewrite them to its own specification. You use
ls to look at the files--the rootkit can rewrite this as well.
Every OS program on your system uses libc, which, once again, the
rootkit can rewrite so that you see only what it wants you to see.
In short, every bit of program code on your box can be rewritten
by the hacker so that it shows you only what he wants you to see.
If he reboots your box, he can even subvert the kernel itself. In
fact, he can subvert the kernel even *without* rebooting the box by
careful manipulation of memory. How can any of it be trusted?
--
Christopher Mattern
"Which one you figure tracked us?"
"The ugly one, sir."
"...Could you be more specific?"
.
- Follow-Ups:
- Re: Urgent!!! My computer seems to be hacked, pls HELP!!!
- From: Ignoramus17640
- Re: Urgent!!! My computer seems to be hacked, pls HELP!!!
- References:
- Urgent!!! My computer seems to be hacked, pls HELP!!!
- From: Jenny
- Re: Urgent!!! My computer seems to be hacked, pls HELP!!!
- From: Todd H.
- Re: Urgent!!! My computer seems to be hacked, pls HELP!!!
- From: René Berber
- Re: Urgent!!! My computer seems to be hacked, pls HELP!!!
- From: Todd H.
- Re: Urgent!!! My computer seems to be hacked, pls HELP!!!
- From: René Berber
- Re: Urgent!!! My computer seems to be hacked, pls HELP!!!
- From: Darren Dunham
- Re: Urgent!!! My computer seems to be hacked, pls HELP!!!
- From: René Berber
- Re: Urgent!!! My computer seems to be hacked, pls HELP!!!
- From: Chris Mattern
- Re: Urgent!!! My computer seems to be hacked, pls HELP!!!
- From: Randy Yates
- Urgent!!! My computer seems to be hacked, pls HELP!!!
- Prev by Date: Re: Urgent!!! My computer seems to be hacked, pls HELP!!!
- Next by Date: Re: Urgent!!! My computer seems to be hacked, pls HELP!!!
- Previous by thread: Re: Urgent!!! My computer seems to be hacked, pls HELP!!!
- Next by thread: Re: Urgent!!! My computer seems to be hacked, pls HELP!!!
- Index(es):
Relevant Pages
|
|