Aquawheel.com Aquawheel.com Aquawheel.com
Index Page >> About Us >> Place Your Link >> Privacy >> Terms of Service >> Submit Article
Search:   
Add Url
 
 

Drink & Food

 

People & Society

 

Events & News

 

Shopping Online

 

Home & Garden

 

Entertainment

 

Realty & Property

 

Science & Research

 

Art & Culture

 

Self Enhancement

 

Hygiene & Health

 

Tour & Travel

 

Jobs & Employment

 

Investment & Finance

 

Politics & Government

 

Online & Board Games

 

Lifestyle & Fashion

 

Education & Reference

 

Medical Care

 

Software & Networking

 

Vehicles & Automotive

 

Companies & Business

 

Sports & Adventure

 

Children & Teens

 

Index Page › Software & Networking › Security & Firewalls
 

What's a Root Kit and How Hackers Are Getting Into Your Computer With It

 

A root kit is a set of tools used by an intruder after cracking a computer system. These tools can help the attacker maintain his or her access to the system and use it for malicious purposes. Root kits exist for a variety of operating systems such as Linux, Solaris, and versions of Microsoft Windows.

The term "root kit" (also written as "rootkit") originally referred to a set of recompiled Unix tools such as "ps", "netstat", "w" and "passwd" that would carefully hide any trace of the cracker that those commands would normally display, thus allowing the crackers to maintain "root" on the system without the system administrator even seeing them.

Generally now the term is not restricted to Unix based operating systems, as tools that perform a similar set of tasks now exist for non-Unix operating systems such as Microsoft Windows (even though such operating systems may not have a "root" account). It is common for the term 'rootkit' to refer to a "kernel-mode" program (that is, acting as part of the operating system), as opposed to a "user-mode" program (that is, programs that operate as normal applications or tools).

The key distinction between a computer virus and a root kit relates to propagation. Like a root kit a computer virus modifies core software components of the system, inserting code which attempts to hide the "infection" and provides some additional feature or service to the attacker (the "payload" of a virus).

In the case of the root kit the payload may attempt to maintain the integrity of the root kit (the compromise to the system) --- for example every time one runs the root kit's ps command it may check the copies of init and inetd on the system to ensure that they are still compromised, and "re-infecting" them as necessary. The rest of the payload is there to ensure that the cracker (attacker) can continue to control the system. This generally involves having backdoors in the form of hard-coded username/password pairs, hidden command-line switches or magic environment variable settings which subvert the normal access control policies of the uncompromised versions of the programs. Some root kits may add port knocking checks to existing network daemons (services) such as inetd or the sshd

A computer virus can have any sort of payload. However, the computer virus also attempts to spread to other systems. In general a root kit limits itself to maintaining control of one system.

A program or suite of programs that attempts to automatically scan a network for vulnerable systems and to automatically exploit those vulnerabilities and compromise those systems is referred to as a computer worm. Other forms of computer worms work more passively, sniffing for usernames and passwords and using those to compromise accounts, installing copies of themselves into each such account (and usually relaying the compromise account information back to the cracker/attacker through some sort of covert channel).

Of course there are hybrids. A worm can install a root kit, and a root kit might include copies of one or more worms, packet sniffers or port scanners. Also many of the e-mail worms to which MS Windows platforms are uniquely vulnerable are commonly referred to as "viruses." So all of these terms have somewhat overlapping usage and can be easily conflated.

A number of new rootkit detection tools have been created including Blacklight (windows), rkhunter (unix/linux).

Author: Ken Savage
 
Author Bio:

Ken Savage

Since the Dot Com Boom it's been difficult for me to keep a web design position so I've resorted to writing my own articles and maintaining my own blog websites. As a Father and Husband it's my way of keeping ahead to current technology as well as making a little ad money from adsense and some client web work.

This article can be searched using: network security, firewalls, computer network security, network security software, free firewalls
 
 
 

Related Articles

 
Shopping Cart Abandonment - Discover 5 Things you can do to Lower Cart Abandonment
 
Building Web Communities With Free Forums
 
The Basics of Blogging and Web Site Creation - Part Two: Introduction To Keywords
 
Q: What Does Keyword Traffic Have to Do with Online Event Promotion and Your Brand?
 
The Money's in the List!
 
5 Reasons that Ebooks are Effective Communication Tools
 
A Web Site That Sells Is All One Needs To Have A Successful Online Business!
 
Nimh Batteries Last 2 - 3 times Longer Than NiCad And NiMH Batteries.
 
Sex, ICANN, and Your Domain Name
 
Internet Advertising and Traditional Advertising ? Two in the Same
 
 
 
 

Small Business Enterpreneurs use Search Engines for Branding

For small business companies, online marketing is the easiest way to generate business leads. The se ... - Rajiv Menon
 

How to Use Autoresponders With Your Articles

Now that you see that articles are the number one way to promote your business, think again about ho ... - Judy Cullins
 

Commission Junction: the Perfect Affiliate Resource for Niche Markets

You need to know where to find affiliate programs for your niche markets? Well, I tell you about Com ... - Fred Farah
 
 

Top 2 Myths of Search Engine Optimization (SEO)

Most business owners do not want to admit that "staying up on top" of the Google search results is a ... - Ugur Akinci
 

Samsung E900: With versatile features

Designed for simplicity and convenience, the Samsung E900 mobile phone is sure to cater to your ever ... - jennifer_lopaz
 

The Other Side of the Search God's Abracadabra!

Primarily, what you need to digest is the fact that search engines fall short of Mandrake?s magic me ... - Liji Elizabeth Thomas
 

10 Tips to Keep Your PC in Tiptop Shape

Your PC represents a large investment for you. But hands up, those of you who worry about your PC cr ... - Gary Hendricks
 

How Google Detects Invalid Clicks, A Must Know For AdSense Publisher

A lot of Google AdSense publishers are banned from the Google AdSense program for invalid clicks. Ho ... - Casey Yew
 
 
Index Page >> Privacy >> Terms of Service
© 2008 www.aquawheel.com All Rights Reserved.