★ wanayoo — archive 1999 http://www.linuxsecurity.com/articles/host_security_article-4167.htmlNouvelle recherche | Portail wanayoo
Advertise Here

   
Documentation
Security Sources
Forums
Firewalls
Host Security
Cryptography
Network Security
Intrusion Detection
Organizations/Events
Server Security
Vendors/Products
Projects
General
Privacy
Government
Hacks/Cracks
 
News: Host Security 12/16/2001 17:07

Understanding Rootkits

O'Reilly Network
Posted By: Nick DeClario
12/16/2001

A rootkit is a collection of tools an intruder brings along to a victim computer after gaining initial access. A rootkit generally contains network sniffers, log-cleaning scripts, and trojaned replacements of core system utilities such as ps, netstat, ifconfig, and killall. Although the intruders still need to break into a victim system before they can install their rootkits, the ease-of-use and the amount of destruction they cause make rootkits a big threat for system administrators.

The main purpose of a rootkit is to allow intruders to come back to the compromised system later and access it without being detected. A rootkit makes this very easy by installing a backdoor remote-access daemon, such as a modified version of telnetd or sshd. These will often run on a different port than the one that these daemons listen on by default.


Click here to go to this article.

California supreme court will hear DVD-copying appeal
Dec 17

Is Linux Immune to E-Mail Viruses?
Dec 17

Paving the way for 'uncrackable' codes
Dec 17

The Survivor's Guide to 2002
Dec 17

Linux Security Week - December 17th 2001
Dec 17

Understanding Rootkits
Dec 16

Crypto-Gram December 15, 2001
Dec 15

Contact Us | Legal Notice | About Our Site
© Guardian Digital, Inc., 2000