Security Incidents mailing list archives

Re: Break-in attempt from 203.197.38.247


From: Valdis Kletnieks <Valdis.Kletnieks () VT EDU>
Date: Thu, 24 Aug 2000 14:28:58 -0400

On Thu, 24 Aug 2000 11:23:48 -0000, Nick Phillips <nwp () CHECKAPRICE COM>  said:
On Wed, Aug 23, 2000 at 01:09:08PM -0400, Valdis Kletnieks wrote:
You may wish to re-try the 'ls' with a known good 'ls' binary retrieved
off the installation CD or someplace.
Not sufficient. Everything that ls depends on needs to be known good too...
this includes libs, kernel... ;)

Well.. Yeah.  but I've not seen TOO many rootkits that trojan libc.a or
the kernel (although I've seen a few Linux-based loadable modules)...

Do you trust your install CD?  This is actually a serious question.

@ARTICLE{Trusting.Trust,
        author={Ken Thompson},
        title={Reflections on Trusting Trust},
        journal={Communications of the ACM},
        volume=27,
        number=8,
        month=Aug,
        year=1984,
        pages="761-763"
}

--
                                Valdis Kletnieks
                                Operating Systems Analyst
                                Virginia Tech


Attachment: _bin
Description:


Current thread: