<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://lions.teledyn.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title> - Rootkit Detection with gdb - Comments</title>
 <link>http://lions.teledyn.com/node/565</link>
 <description>Comments for &quot;Rootkit Detection with gdb&quot;</description>
 <language>en</language>
<item>
 <title>Rootkit Detection with gdb</title>
 <link>http://lions.teledyn.com/node/565</link>
 <description>&lt;p&gt;Simple and effective tools strung together as needed, this one of the strongest attractors luring technical people into unix-like operating systems and keeping them there.  For example, consider the real-world example, &quot;&lt;i&gt;generate a list of all files below this directory where any of the specified XML tag attributes are null or only numeric, and sort the list by filename paths, grouped by the specific attribute error&lt;/i&gt;&quot; ... the concept of global actions across potentially thousands of files is completely alien in some operating system philosophies -- in unix it&#039;s a short shell script binding a handfull of text and file utilities, easily prototyped at the command line, ready for production use within the hour.&lt;/p&gt;
&lt;p&gt;Mariusz Burdach gives us yet another example of small tools for direct solutions in a excellent tutorial on using the lowly GNU debugger to verify the integrity of your O/S, check for system-call exploits and some tips on ways to automate the audit.&lt;/p&gt;
&lt;p&gt;&lt;cite class=&quot;blog-source&quot;&gt;we will make use of just one tool, gdb, the GNU debugger, to detect whether a Linux operating system has been compromised. The package that includes this tool can be found in almost every Linux distribution by default.&lt;/cite&gt;&lt;/p&gt;
&lt;p&gt;His paper also surveys the methods these intruders use to patch the kernel and how to relate this knowledge into appropriate detection tests.&lt;/p&gt;
&lt;p&gt;&lt;i class=&quot;blog-source&quot;&gt;[ via &lt;a href=&quot;http://www.securityfocus.com/infocus/1811&quot;&gt;SecurityFocus HOME Infocus: Detecting Rootkits And Kernel-level Compromises I&lt;/a&gt; ]&lt;/i&gt;&lt;/p&gt;
</description>
 <comments>http://lions.teledyn.com/node/565#comments</comments>
 <category domain="http://lions.teledyn.com/taxonomy/term/10">GNU</category>
 <category domain="http://lions.teledyn.com/taxonomy/term/17">Tech</category>
 <pubDate>Sat, 04 Dec 2004 10:17:20 -0500</pubDate>
 <dc:creator>garym</dc:creator>
 <guid isPermaLink="false">565 at http://lions.teledyn.com</guid>
</item>
</channel>
</rss>
