OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: IDS: Windows rootkit detection
From: Keiji Takeda (keijisfc.keio.ac.jp)
Date: Fri Dec 01 2000 - 22:21:32 CST


Archive: http://msgs.securepoint.com/ids
FAQ IDS: http://www.sans.org/newlook/resources/IDFAQ/ID_FAQ.htm
FAQ NIDS: http://www.ticm.com/kb/faq/idsfaq.html
IDS: http://www-rnks.informatik.tu-cottbus.de/~sobirey/ids.html
HELP: Having problems... email questions to ids-owneruow.edu.au
NOTE: Remove this section from reply msgs otherwise the msg will bounce.
SPAM: DO NOT send unsolicted mail to this list.
UNSUBSCRIBE: email "unsubscribe ids" to majordomouow.edu.au
-----------------------------------------------------------------------------
Hello,

It seems that there have been discussion on
the detection of rootkit(www.rootkit.com).

Pedestalsoftware (http://www.pedestalsoftware.com/)
claims that their Intact can detect rootkit
but rootkit developpers say noone can detect it.

Is there anyone who examined this issue?

Keiji Takeda ( http://www.sfc.keio.ac.jp/~keiji/ )