
miguel.filipe at gmail
Feb 4, 2005, 3:34 PM
Post #6 of 6
(759 views)
Permalink
|
|
Re: tools for detecting linux kernel rootkits? tools to prevent its injection?
[In reply to]
|
|
Thanks for the info, samhain is just what I want. Samhain should have more publicity, it looks that its "the thing"! On Fri, 4 Feb 2005 20:22:24 +0000, Barry Dunn <lists [at] soylent> wrote: > On Fri, Feb 04, 2005 at 07:59:34PM +0000, Miguel Filipe wrote: > > I've now tried both rkhunter and chkrootkit on a known to be infected system. > > It seems that a linux kernel rootkit isn't detected by any of those tools. > > > > Are there any IDSs or tools that perform routine checks on system call > > table addresses, and other funcion pointer addresses for changes..? > > > > Looking for _known_ rootkits isn't good enough sometimes... > > > > TIA > > > > -- > > Miguel Sousa Filipe > > > > Haven't tried this aspect of it myself, but Samhain can be configured to > check for rootkits, including syscall modifications. > > http://la-samhna.de/samhain/manual/kerneldef.html > > > -- > gentoo-security [at] gentoo mailing list > > -- Miguel Sousa Filipe -- gentoo-security [at] gentoo mailing list
|