Full Disclosure mailing list archives

Re: [inbox] Re: RE: Linux (in)security


From: KF <dotslash () snosoft com>
Date: Sat, 25 Oct 2003 00:23:11 -0400

Sven Hoexter wrote:

On Fri, Oct 24, 2003 at 06:09:12AM -0700, dwr3ck () hushmail com wrote:


I can determine when a Windows box has been owned fairly easily.


Can you? Really? Hm maybe I should use windows.

can you still determine that it has been owned when a windows root kit has been installed on it? this would be the win32 equivilant of a malicious LKM.
www.rootkit.com I think has some LKM like functionality.
-KF




_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: