Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Windows rootkits of 2005, part three
James Butler, Sherri Sparks

The third and final article in this series explores five different rootkit detection techniques used to discover Windows rootkit deployments. Additionally, nine different tools designed for administrators are discussed.

Comments Mode:
Correction re: tripwire 2006-01-06
Anonymous
Tripwire doesn't use CRC checksums. CRC has no cryptographic value - it's meant for detecting accidental file corruption and the like. It is trivial to alter a file and have it keep the same CRC

Tripwire uses cryptographic hashes - in a somewhat older version (all I could quickly find the documentation for), the available hashes were MD5 and Snefru. I wouldn't be expect that SHA-1 might have been added and Snefru dropped in more recent versions

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/infocus/1854/74#74
Windows rootkits of 2005, part three 2006-06-21
david gunnells







 

Privacy Statement
Copyright 2007, SecurityFocus