[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] chkrootkit output show possible ambient



"Richard Siddall" <cobalt@xxxxxxxxxxx> wrote:
> "alan@" wrote:
> >
> > Hi again,
> >
> > I have checked out the filestamps on traceroute and netstat and they
both
> > have the same stamp as every other (un-updated) file on the server, ie
June
> > 20 2000, so I think they are probably ok.
> >
>
> It's easy to fake timestamps.  You'd be better off comparing the size
> and MD5 sum against a known good copy.

And if Alan is checking with ls from /bin/ls all bets are off.  IIRC that's
one of the programs the rootkit replaces.

--
Steve Werby
President, Befriend Internet Services LLC
http://www.befriend.com/