Re: Exploit or trojan

dav <[email protected]>
Newsgroups gmane.comp.security.sun
Message-ID <[email protected]>
Felipe Franciosi [[email protected]] a écrit:
> > Oops.
> > 
> > Such kind of kernel backdoors (e.g. loadable kernel modules) are also
> > present for Solaris, *BSD and Windows systems. If you are unsure whether
> > someone has compromised your system, don't trust the system's kernel!
> 
> Yeah you are right! I was just reading about coding solaris kernel
> modules.  It is pretty easy,  actually.  Anyone can find a lot  of
> documents on google.
> 
> A little addition here: Some Linux backdoors (Suckit, for example)
> doesn't work as a kernel module. It just opens /dev/kmem and patch
> it on the fly. It is still detectable, though, trought some imple-
> mentation flaws or checking  mechanisms  that  verify  the  kernel
> syscall table integrity.

	For solaris systems, you can look at papillon kernel module. This module
try to make same than gr-security for linux kernel... 
	I'm using it on production servers, and I've no trouble to report after
one year.

http://www.roqe.org/papillon/

dav.

-- 
PGP: http://www.r00tworld.com/~dav/dav.gpg
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.