OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Exploit or trojan

From: Steve Bremer (stevebnebcoinc.com)
Date: Fri Dec 19 2003 - 09:16:10 CST


> A little addition here: Some Linux backdoors (Suckit, for example)
> doesn't work as a kernel module. It just opens /dev/kmem and patch it
> on the fly.

Using this method also requires more precision. If it's not done
properly, it can create stability problems as was the case when some
of the Debian servers were compromised.

Steve Bremer
NEBCO, Inc.
System & Security Administrator