Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RE: Finding hidden backdoors

From: Michael Silk <michaels(at)phg.com.au>
Date: Thu Jul 31 2003 - 20:06:53 EDT


Well backdoors don't always have to have a port open waiting for connections, one such different variation could be:

        A simple port-search wouldn't pick that up :)

  • Michael

-----Original Message-----
From: Tim Greer [mailto:chatmaster@charter.net] Sent: Friday, 1 August 2003 8:26 AM
To: Daniel B. Cid; security-basics@securityfocus.com Subject: Re: Finding hidden backdoors

The backdoor could easily only accept connections from non local sources, or a specific source. It's probably easier to just run netstat, lsof, etc. from a clean. trusted media... or also boot into single user mode from a trusted kernel image. In fact, you should always have trusted kernel images on the server anyway, for purposes of being able to boot if the other image is corrupted or modified. As for LKM, I don't compile with lkm support in my kernels for many reasons (security being one of them), but a lot of people do, so...

--
Regards,
Tim Greer  chatmaster@charter.net
Server administration, security, programming, consulting.


----- Original Message -----
From: "Daniel B. Cid" 
To: 
Sent: Thursday, July 31, 2003 1:18 PM
Subject: Finding hidden backdoors

> I saw some people talking about rootkits that hidden process/ports.
-
> --------------------------------------------------------------------------
--
>
--------------------------------------------------------------------------- ---------------------------------------------------------------------------- CAUTION: This email message and accompanying data may contain information that is confidential and/or subject to legal privilege. If you are not the intended recipient, you are notified that any use, dissemination, distribution or copying of this message or data is prohibited. If you have received this email message in error, please notify us immediately and erase all copies of this message and attachments. Thank you. This email is for your convenience only, you should not rely on any information contained herein for contractual or legal purposes. You should only rely on information and/or instructions in writing and on company letterhead signed by authorised persons. --------------------------------------------------------------------------- ----------------------------------------------------------------------------
Received on Fri Aug 1 12:12:41 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:06:48 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library