Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » RootKit Detectors - Not all = !
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Fun with ( ÿþ ) well sort of ? »
« Selling through FUD and severity ratings  
AuthorAll Replies


2kmaro
Think
Premium,ExMod 1 BC
join:2000-07-11
ColossalCave
clubs:

reply to phoneboy2
Re: RootKit Detectors - Not all = !

said by phoneboy2 :

If a Rootkit detector does not boot from it's own CD it will NEVER be trustworthy. Having said that, for a basic perliminary test, I like the no nonsense raw design of sysinternals rootkit revealer. They like to try keep it simple which is usually the best approach.
MY opinion is that once you've been rootkit'd, best thing to do is scrub and rebuild from ground up. I know of no sure and certain way to absolutely assure that things are as they should be once it's happened. You might find one piece of it, or one of several - but how do you KNOW that things are all well again.

Personally, I'd be satisfied with a product that simply provided no-false-positive indication that you'd been rooted and give you an indication of the source/name of the rootkit.
--
...then THINK! again!!


EP_X0FF

@rol.ru
reply to phoneboy2
that is very disputable words

fyi next generation of hardwired rootkits will be not detected even from external scanning like boot cd.


phoneboy2

@shawcable.net

reply to SpannerITWks
If a Rootkit detector does not boot from it's own CD it will NEVER be trustworthy. Having said that, for a basic perliminary test, I like the no nonsense raw design of sysinternals rootkit revealer. They like to try keep it simple which is usually the best approach.
Forums » Up and Running » Security » SecurityFun with ( ÿþ ) well sort of ? »
« Selling through FUD and severity ratings  


Friday, 04-Dec 08:15:55 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [163] Comcast Releasing Promised Usage Meter
· [142] Avast Antivirus Has Gone Mad
· [105] Comcast Makes NBC Universal Acquisition Official
· [104] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [88] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [81] Latest Consumer Reports Survey Not Kind To AT&T
· [70] Baltimore To Ban Lazy Cable Installs
· [67] Sprint Defuses GPS Privacy Media Bomb
· [67] FCC Ponders Moving From PSTN To IP Voice
· [64] Broadband Killed The Game Console
Most people now reading
· False positive in Avast! or is it real? [Security]
· Windows 7 boot manager editing questions [Microsoft Help]
· Extjs grid combo box. [Webmasters and Developers]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· Warrior tank seem underpowered these days [World of Warcraft]
· I'd like some info on this Genset [Home Repair & Improvement]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Using AirMax to provide triple play services? [Wireless Service Providers]
· [Rant] Disrespect of PTO [Rants, Raves, and Praise]
· What do you do to keep kids safe while online? [Verizon Fiber Optics]