LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-02-2002, 09:13 PM   #1
X11
Member
 
Registered: Dec 2001
Location: Brisie, Australia
Distribution: Slackware 8.1
Posts: 324

Rep: Reputation: 30
Question Trojan Detection - How can you trust it


I've got a few questions about Trojan dectetion program for linux:

1) How can you be sure the trojan detection program is really working?

2) How can you be sure the trojan detection program is not a trojan itself?

3) Wouldn't there be ways for trojans to bypass, trojan detection programs.
 
Old 03-03-2002, 04:49 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
if [ ! ${LIFE} = "" ]; then echo "Ok, we're alive.."; else echo "Hmm. What's sure in life again? :-]"; fi

1. By testing it against trojaned binaries from rootkits?
*Requires LRK's. Not all are easy to come by. High possibility for testing to make sure, depending on what you got. Hope you have a spare box to test it on :-]
2. By performing md5sum/PGP/GPG verification? Performing an audit on the code? Requesting a copy of the tarball signed to your PGP key?
*Requires coding knowledge, more paranoia than usual and a good set of eyes. Trust tru key/md5 usual option when D/L from well known source. Low possibility for faking, I'd say 10%, cuz if trojaned it'll be uncovered and pubicised soon (for instance; Wietse Venema, trojaned TCP Wrappers at hungarian ftp archive).
3. Yes, like kernel modification. Read some here (Silvio) and here (CERT).
*Requires skilled cracker doing this neat trick at your box. Chance this happens (non-commercial home box with nothing interesting to get) %10.

Just my 2 cents, and I'm not even sure of those :-]

Last edited by unSpawn; 03-03-2002 at 05:02 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
is this evidence of a trojan? tom_from_van Linux - Security 6 08-25-2005 08:28 PM
chkrootkit and possible trojan Whitestone Linux - Security 2 11-26-2004 06:04 AM
LKM trojan? help! synaptical Linux - Security 3 03-07-2004 07:16 AM
lkm trojan nullpt Linux - Security 3 12-26-2003 06:42 PM
Possible Trojan ! FreeFox Linux - General 4 08-03-2003 08:52 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:43 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration