Full Disclosure mailing list archives

Re: Rootkit For Spyware? Hide your adware from


From: Darren Reed <avalon () cairo anu edu au>
Date: Thu, 23 Sep 2004 19:24:57 +1000 (EST)

In some mail from Matt, sie said:

GuidoZ wrote:
Interesting indeed. Although, I imagine this was a spam email, and I
never believe (nor buy) anything from spam. I wondr how credible this
really is. If there was such a way to do what they claim, don't you
think it would have been big news?  >One would think you wouldn't first
hear about it through spam.

It is quite possible to hide processes, reg keys and files, and is often 
done by various malware.

Are they capable of hiding from "ps" when using the posix shell from
"Windows Services for Unix" ?

Darren

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: