LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-16-2011, 05:55 AM   #1
rosv
Member
 
Registered: Jul 2008
Distribution: Slackware, ubuntu
Posts: 53

Rep: Reputation: 15
Localhost scans with rkhunter and chkrootkit - what's the use?


Hi,

Let's say you have a host with some kind of locally installed root kit detector/scanner.

If someone managed to get root access to that box. Wouldn't the first thing to do, before installing a root kit, be to remove any kind root kit detector?
 
Old 02-16-2011, 06:01 AM   #2
salasi
Senior Member
 
Registered: Jul 2007
Location: Directly above centre of the earth, UK
Distribution: SuSE, plus some hopping
Posts: 4,070

Rep: Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897
A good point and an argument for not permanently installing that kind of security program, but coming along with some media with a 'known good' copy which includes, eg, a .rpm and using that instead.
 
Old 02-16-2011, 06:25 AM   #3
rosv
Member
 
Registered: Jul 2008
Distribution: Slackware, ubuntu
Posts: 53

Original Poster
Rep: Reputation: 15
I guess one way to handle this is to use centralized root kit scanning.

But on the other hand, the centralized scanning service must be able to connect to the host in some way. So if someone got root, she would probably disable that remote possibility anyways.

Back to square one....
 
Old 02-16-2011, 08:23 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
In addition to what's said already:
Quote:
Originally Posted by rosv View Post
Let's say you have a host with some kind of locally installed root kit detector/scanner. If someone managed to get root access to that box. Wouldn't the first thing to do, before installing a root kit, be to remove any kind root kit detector?
Chkrootkit and Rootkit Hunter are post-incident diagnostic tools: they may complement but do not replace system hardening. So anyone who relies on these tools alone for "security" (or asks questions based on that) is doing things wrong.


Quote:
Originally Posted by rosv View Post
the centralized scanning service must be able to connect to the host in some way
Check out how for instance Samhain does things.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
av in addition to rkhunter and chkrootkit qwertyjjj Linux - Security 2 02-12-2011 08:51 AM
rkhunter vs. chkrootkit, which is better? abefroman Linux - Security 3 09-09-2009 04:47 AM
Which one is better, Chkrootkit or Rkhunter? ComputerHermit_ Linux - Security 7 04-16-2007 10:17 PM
Scheduling scans for ClamAV and chkRootkit BoxUnclever Linux - Newbie 3 09-11-2004 09:24 AM
rkhunter or chkrootkit? marlor Linux - Security 2 08-28-2004 08:26 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:58 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration