Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
You may already be hacked.
Jon Lasser, 2001-07-25

Rootkits help hackers play hide-and-seek.

Comments Mode:
LOVE YOU MAN!!! 2001-07-25
elliptic (5 replies)
John, John, John....

If ONLY you knew how many times I've heard the exact same thing. Way to tackle this issue! I only wish there was a way of sharing my frustration with the ignorant morons working in the likes of places like uunet and other large providers, who regularly deny *their* systems ...

[ more ]  [ reply ]
Ports 2001-07-26
Zer0
The best thing to do, is to shut off sshd & in.telnetd type daemons. Only run what you need. Ive never run telnet visible to the outside. I leave it binded to a specific interface behind IP_MASQ. Because of TCP/IP itself, it is impossible to break that, unless there is a bug present in the OS, or so...

[ more ]  [ reply ]
LOVE YOU MAN!!! 2001-08-01
cds@hotmail.com
thank you for the comment...

[ more ]  [ reply ]
LOVE YOU MAN!!! 2001-08-02
logarithm
i'm pretty sure that you're seeing attacks from a 63.* address off uunets Backbone... you dumb ass.. teach me how to hack a dial up account..
and quit running black ice..
...

[ more ]  [ reply ]
LOVE YOU MAN!!! 2001-08-07
Anonymous
Even when the 'hacker' in question is a dumb script kiddie unable to write his own tools to penetrate the kernel?...

[ more ]  [ reply ]
LOVE YOU MAN!!! 2001-08-13
Dark Spaniel
No man, we really love you.

At last, an unvoiced frustration has found a voice. The clueless reply "Well, netstat shows all the same ports.." shall no longer be heard in the land....

[ more ]  [ reply ]
Fuq1n l0zer 2001-07-26
gr4nd 1nqu1z1t0r (1 replies)
u kn0w n0th1ng 4b0ut c0unt3r 1nt3ll1g3nc3, ur n0th1ng bu+ 4n elektr0n m0nk3y. t3ll1ng pe0pl3 th4t f1r3w4llz w1ll pr0tekt th3m, i supp0ze ull alz0 try t0 t3ll m3 th4t VPNz r a g00d th1ng, r1ght? 1f ur g0ing t0 b3 c0nd3sc3nd1ng t0w4rdz th3 cl00l3zz 4dm1nz 1n ur 0wn c0mp4ny, 4tl34s+ pr3t3nd u kn0w wh...

[ more ]  [ reply ]
mmm? 2002-02-08
Anonymous
What happened to your keyboard?...

[ more ]  [ reply ]
bugs 2001-07-30
walterp@fuse.net
my browser chrashes at times and says there has been an error in such and such dll...

[ more ]  [ reply ]
Why surf as root 2001-08-03
Rodrigo Ramos <ramos@ipad.com.br>
Another big problem is that the system and network administrators still surfing the web as root. Why?
If they do not change the concept of security, they won't be ever secury.

"a false sense of security, is worst than insecurity " Steve Gibson

Rodrigo Ramos...

[ more ]  [ reply ]
great article. 2001-08-05
Gonçalo Gomes
Good article, but nowadays most "script kidies" have known of systems like tripwire, it is quite easy to change / remove a tripwire like system, or even change its database, i don't think tripwire would be the best solution, you have a lot a others and tripwire has a strict license and is damn slow....

[ more ]  [ reply ]
what about strace 2001-08-10
arne.peer@appelmoes.xs4all.be
Hi,

when i get a customer who want me to check for rootkits, i allway run the program with strace... if I see that the program access'es strange /dev/xxx or other files, I'm almost sure there is a rootkit. Many rootkits just use some /dev/xxx files to hide the information that is in those files.....

[ more ]  [ reply ]
You may already be hacked - by a script? 2002-01-08
Anonymous
Greetings.

I recently put together a box for running an IP chains-based linux firewall.

Being rahter naive about how rapidly the system could get hacked, I opened an Internet-facing interface for testing purposes. The system was compromised in less than 24 hours! and get this - I was logged in...

[ more ]  [ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus