Vulnerability Development mailing list archives

Positive uses for rootkits


From: Daniel McCranie <sfml () SNEAKERNETSECURITY COM>
Date: Wed, 21 Mar 2001 12:58:31 -0600

Hi,

I was wondering that since intruders can modify system commands to
not display certain things, couldn't admins modified the commands
like cp, mv, rm...  so that they would not be able to replace any
of the included commands?  These could be made in such a way only to
work unlimited in single user mode or have the disk mounted to
another system when there is a legitimate need to change one.

I have just enough UNIX knowledge to be dangerous to myself so be
gentle :)

Questions:

1. Are most rootkits simply shell scripts or real programs?

2. Would there be anyway to stop programs from overwriting those
files with programming calls?  (Maybe making them read-only and
modifying chmod...)

3,4,5: I know that this probably wouldn't be good in a standard
distro but what about a hardening kit?  Has this been tried before?
Is there something blatantly wrong?


Dan


Current thread: