Re: 'rooted' NT/2K boxen?

From: zeno (bugtraqat_private)
Date: Thu May 02 2002 - 13:06:30 PDT

  • Next message: William N. Zanatta: "Re: 'rooted' NT/2K boxen?"

    > Recently, there have been several messages posted to
    > this list about rooted Linux boxen.  My question is
    > this...has anyone seen NT/2K boxen 'rooted', in the
    > sense that a Linux box is usually rooted...completely
    > taken over, trojaned binaries, backdoors, users
    > installed, rootkit(s), tools copied over?
    > If so, what, if any, info would you be willing to
    > share about the system?
    I haven't seen any type of windows 'rootkit' myself. For example a replacement of netstat, nbtstat, route, and other utilities to give proccess information etc...
    If anyone knows of any let me know I'm interested. Of course the problem with getting windows
    source is an issue. 
    - zenoat_private
    > I'm trying to get an idea of how prevalant this sort
    > of thing is, and also to see what's being done, so as
    > to not only better protect my systems, but to assist
    > me in building a better incident response methodology.
    > Thanks.
    > __________________________________________________
    > Do You Yahoo!?
    > Yahoo! Health - your guide to health and wellness
    > ----------------------------------------------------------------------------
    > This list is provided by the SecurityFocus ARIS analyzer service.
    > For more information on this free incident handling, management 
    > and tracking system please see:
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see:

    This archive was generated by hypermail 2b30 : Thu May 02 2002 - 14:26:56 PDT