Re: Exploit or trojan

Felipe Franciosi <[email protected]>
Newsgroups gmane.comp.security.sun
Message-ID <[email protected]>
> Oops.
> 
> Such kind of kernel backdoors (e.g. loadable kernel modules) are also
> present for Solaris, *BSD and Windows systems. If you are unsure whether
> someone has compromised your system, don't trust the system's kernel!

Yeah you are right! I was just reading about coding solaris kernel
modules.  It is pretty easy,  actually.  Anyone can find a lot  of
documents on google.

A little addition here: Some Linux backdoors (Suckit, for example)
doesn't work as a kernel module. It just opens /dev/kmem and patch
it on the fly. It is still detectable, though, trought some imple-
mentation flaws or checking  mechanisms  that  verify  the  kernel
syscall table integrity.

Best regards,
Felipe

-- 
Felipe Franciosi <[email protected]>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.