Re: Shadow Shell?

This is a discussion on Re: Shadow Shell? within the Linux Security forums, part of the System Security and Security Related category; Dnia Wed, 18 Jun 2003 15:59:17 GMT, Kenneth A Kauffman napisał(a): > What happens is that each ...


Go Back   Usenet Forums > System Security and Security Related > Linux Security

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 06-24-2003
Wojtek Walczak
 
Posts: n/a
Default Re: Shadow Shell?

Dnia Wed, 18 Jun 2003 15:59:17 GMT, Kenneth A Kauffman napisał(a):
> What happens is that each script will execute the binary and remove your
> username from the output via grep -v.

....but it's easy to detect.
Here's a simple patch for procps-3.1.9 package (well, to be exact for
libproc library):

<http://underground.org.pl/gminick/patches/procps-hide.patch>

....and now you're invisible for w, ps, top and all the stuff using
(in case of default installation) /lib/libproc.so.3.1.9
It won't work for 'who' because 'who' is only reading from utmp file.
It's really easy to patch who, but if you are not able to do
it yourself - simply - remove who from your system ;]

HTH. ;>

--
[ Wojtek Walczak - gminick (at) underground.org.pl ]
[ <http://gminick.linuxsecurity.pl/> ]
[ "...rozmaite zwroty, matowe od patyny dawnosci." ]

Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 03:18 PM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0