1 |
On Thu, Mar 25, 2004 at 06:01:55PM -0600, Andrew Gaffney wrote: |
2 |
> > |
3 |
> > |
4 |
> >I suggest that you look at samhain: |
5 |
> > |
6 |
> >http://la-samhna.de/samhain |
7 |
> > |
8 |
> >It's an excellent file integrity and host-based intrusion detection system |
9 |
> >with advanced features that solves the "chicken-and-egg" problem along with |
10 |
> >other cool gizmos :). |
11 |
> |
12 |
> From the site: |
13 |
> |
14 |
> Support for a stealth mode of operation |
15 |
> |
16 |
> Is there a way to make a process not show up in 'ps' output? |
17 |
|
18 |
Yes, there is a kernel module that allows you to do that. You can also |
19 |
automatically change the name of the binary and related paths. |
20 |
|
21 |
|
22 |
-- |
23 |
Andrea Barisani <lcars@g.o> .*. |
24 |
Gentoo Linux Infrastructure Developer V |
25 |
( ) |
26 |
GPG-Key 0x864C9B9E http://dev.gentoo.org/~lcars/pubkey.asc ( ) |
27 |
0A76 074A 02CD E989 CE7F AC3F DA47 578E 864C 9B9E ^^_^^ |
28 |
|
29 |
-- |
30 |
gentoo-security@g.o mailing list |