Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » RootKit Detectors - Not all = !
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Fun with ( ÿþ ) well sort of ? »
« Selling through FUD and severity ratings  
AuthorAll Replies


phoneboy2

@shawcable.net

reply to SpannerITWks
Re: RootKit Detectors - Not all = !

If a Rootkit detector does not boot from it's own CD it will NEVER be trustworthy. Having said that, for a basic perliminary test, I like the no nonsense raw design of sysinternals rootkit revealer. They like to try keep it simple which is usually the best approach.


EP_X0FF

@rol.ru
that is very disputable words

fyi next generation of hardwired rootkits will be not detected even from external scanning like boot cd.


2kmaro
Think
Premium,ExMod 1 BC
join:2000-07-11
ColossalCave
clubs:

reply to phoneboy2
said by phoneboy2 :

If a Rootkit detector does not boot from it's own CD it will NEVER be trustworthy. Having said that, for a basic perliminary test, I like the no nonsense raw design of sysinternals rootkit revealer. They like to try keep it simple which is usually the best approach.
MY opinion is that once you've been rootkit'd, best thing to do is scrub and rebuild from ground up. I know of no sure and certain way to absolutely assure that things are as they should be once it's happened. You might find one piece of it, or one of several - but how do you KNOW that things are all well again.

Personally, I'd be satisfied with a product that simply provided no-false-positive indication that you'd been rooted and give you an indication of the source/name of the rootkit.
--
...then THINK! again!!
Forums » Up and Running » Security » SecurityFun with ( ÿþ ) well sort of ? »
« Selling through FUD and severity ratings  


Tuesday, 10-Nov 05:09:39 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [83] VoIP Over 3G Still Not Working For iPhone
· [81] Verizon Keeps Swinging At AT&T
· [33] Bill Would Force ISPs To Block Financial Scams
· [24] Mediacom Hints At 50, 100 Mbps Speeds
· [14] Clearwire To Get Another $1.5 Billion
· [11] Monday Morning Links
· [9] 15 States Have Now Gotten Broadband Mapping Money
· [5] AT&T Launching New 7.2 Mbps 3G Modem
Most people now reading
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· How in the world am I going to get into college? [General Questions]
· [SU] Apple Releases Mac OS X 10.6.2 [All Things Macintosh]
· Windows 7 boot manager editing questions [Microsoft Help]
· Framed for child porn 151; by a PC virus [Security]
· My cat is reluctant to exercise. [General Questions]
· MI424WR-GEN2 Rev E Configuration Thread [Verizon Fiber Optics]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· Maximizing Rogue DPS for 3.1 [World of Warcraft]
· 60 Minutes piece on cyber security last night [Security]