[Wolves] chkrootkit command

Steve Parkes sparkes at westmids.biz
Thu Mar 17 09:23:29 GMT 2005


fizzy wrote:

>
>
>You'll also need to burn the file signatures onto a
>cd, if you keep them on a hdd they can be easily
>overwritten :)
>
>  
>
If chkrootkit is compremised you are shafted ;-)  Install a dodgy kernel 
module or fubar the clibs and replace chkrootkit with your own version 
and a little knowledge becomes a dangerous thing.  It's worse to rely on 
tools you don't trust than not use them at all.

I wonder if certain financial companies are explaining this to thier 
staff this morning?  Just how hard is it to install keyloggers in a bank 
these days?

>fizz
>
>  
>
sparkes



More information about the Wolves mailing list