Re: Rootkit signatures?

2009-06-25 Thread Paul Lussier
Seth Cohn writes: > Kenny, you've answered your own question why the rootkit detectors are > all aged badly: Tripwire does this, without the need for updating > rootkit signatures. > > You need to just go back and answer the initial request with: > > This was already implemented on XX/XX/200X by

Re: Rootkit signatures?

2009-06-25 Thread Alan Johnson
On Thu, Jun 25, 2009 at 8:56 AM, Kenny Lussier wrote: > I have a mandate to install "anti-virus and anti-malware software on > all servers". Since all of our servers are Linux, this was further > clarified to mean "rootkit detection software". I have looked at > several rootkit detectors, and the

Re: Rootkit signatures?

2009-06-25 Thread Seth Cohn
Kenny, you've answered your own question why the rootkit detectors are all aged badly: Tripwire does this, without the need for updating rootkit signatures. You need to just go back and answer the initial request with: This was already implemented on XX/XX/200X by the installation of Tripwire on

Re: Rootkit signatures?

2009-06-25 Thread Kenny Lussier
On Thu, Jun 25, 2009 at 9:26 AM, Ted Roche wrote: > Kenny: > > You might want to check out http://www.chkrootkit.org/ - the software is > simple to install and run from cron (see the FAQs) and the site has "Related > Links" to some good resources. Ted, I probably should have listed the rootkit d

Re: Rootkit signatures?

2009-06-25 Thread Alex Hewitt
Kenny Lussier wrote: > On Thu, Jun 25, 2009 at 9:05 AM, Alex Hewitt wrote: > >> Kenny, if you have a mandate to install anti-virus/anti-malware does that >> mean that whoever mandated this wants to scan all files on the servers for >> PC infections? Although these things typically have no effect

Re: Rootkit signatures?

2009-06-25 Thread Ted Roche
Kenny Lussier wrote: > The mandate actually isn't that intelligent. It was a broad statement > of "You have to have anti-virus and anti-malware software on all of > your servers", and when we wrote a compensating control that stated > "This is not needed on Linux servers", someone Googled Linux +vi

Re: Rootkit signatures?

2009-06-25 Thread Kenny Lussier
On Thu, Jun 25, 2009 at 9:05 AM, Alex Hewitt wrote: >> > > Kenny, if you have a mandate to install anti-virus/anti-malware does that > mean that whoever mandated this wants to scan all files on the servers for > PC infections? Although these things typically have no effect on Linux > systems they m

Re: Rootkit signatures?

2009-06-25 Thread Alex Hewitt
Kenny Lussier wrote: > Hi All, > > I have a mandate to install "anti-virus and anti-malware software on > all servers". Since all of our servers are Linux, this was further > clarified to mean "rootkit detection software". I have looked at > several rootkit detectors, and they all appear to be fair

Rootkit signatures?

2009-06-25 Thread Kenny Lussier
Hi All, I have a mandate to install "anti-virus and anti-malware software on all servers". Since all of our servers are Linux, this was further clarified to mean "rootkit detection software". I have looked at several rootkit detectors, and they all appear to be fairly old. My guess is, it isn't re