Hiding a root kit in the NIC


 
Thread Tools Search this Thread
Special Forums Cybersecurity Hiding a root kit in the NIC
# 1  
Old 11-24-2010
But ...

Quote:
Originally Posted by pludi
Presentation at Hack.lu: Reversing the Broacom NetExtreme's firmware - Sogeti ESEC Lab

Quite interesting idea, that. No trace in the OS, undetectable by any AV or Spyware scanner, and perfectly hidden communication.
If used a sniffer, for a given data to be written to the network wire; it could be easily detected.

So a new requirment for integrity check would be to device such kind of sniffer based automated test in addition to the chacksum maintainance, to gurentee integrity, using appropriate hash algorithm (SHA1 or above).
Login or Register to Ask a Question

Previous Thread | Next Thread

9 More Discussions You Might Find Interesting

1. Linux

Add two different subnet public IPs to single NIC or two different NIC on same box

Hello Admins, My ask is how can I add two different subnet IPs to same box with two different gateways? The issue is I can connect to the box when I am on ethernet LAN, but I am not able to connect to the same IP when I am on wifi. The server is RHEL 7 VM on vmware. How can I get connected... (4 Replies)
Discussion started by: snchaudhari2
4 Replies

2. Red Hat

I want to tune NIC's rps, rfs and xps value. which NIC device should I modify.

Dear All I want tune my NIC's rps, rfs and xps value. In my system I have two NIC (eth0, eth1) and I have a bond0 ( eth0, eth1). Here is the question? Which device should I modify ? eth0 and eth1? or just modify bond0 or modify all device (eth0, eth1, bond0) Any advice is welcome.... (0 Replies)
Discussion started by: nnnnnnine
0 Replies

3. Solaris

Migration of system having UFS root FS with zones root to ZFS root FS

Hi All After downloading ZFS documentation from oracle site, I am able to successfully migrate UFS root FS without zones to ZFS root FS. But in case of UFS root file system with zones , I am successfully able to migrate global zone to zfs root file system but zone are still in UFS root file... (2 Replies)
Discussion started by: sb200
2 Replies

4. IP Networking

squid proxy: one NIC for inbound & one NIC for outbound?

I am new in squid proxy. My question is how to (and if it's necessary) to set one NIC for inbound traffic (http requests) and one NIC for outbound traffic (http answers)? Thank you in advance! (4 Replies)
Discussion started by: aixlover
4 Replies

5. Solaris

x86 Solaris 10 nic driver added but not attached. NIC is not detected.

I couldn't install my nic in solaris 10. I compiled and added the driver but failed to attach the driver and ifconfig output shows only loopback dev. Please see the following output and tell me whether my nic has been detected and why the driver failed to attach? My nic is detected in linux... (0 Replies)
Discussion started by: vectrum
0 Replies

6. Solaris

root-kit

Dear Guys, I want to know more about root-kit in Solaris.. If I'm not mistaken, root-kit is a bunch of scripts nor executable program that can manipulate root-privileges. And sometimes, root-kit is defined as malware.. Is that right? How to check whether my system got root-kit installed?... (2 Replies)
Discussion started by: frankoko
2 Replies

7. Shell Programming and Scripting

Hiding the Directory

Hi, I have a directory i want to just hide this directory. Could you please tell me the command to hide directory. (2 Replies)
Discussion started by: shivanete
2 Replies

8. HP-UX

how can I determine which NIC card is virtual NIC Card

how can I determine which NIC card is virtual NIC Card which condition can make a decision Does HP UX have Virtual Network Adapter Concept if ,it has where I can Find if I Install Virutal Network Adapter or which command that i can get it or which software can generate thanks (2 Replies)
Discussion started by: alert0919
2 Replies

9. Shell Programming and Scripting

Hiding password from ps

I'm calling a program with a command line arguement containing a password. while the process is running anyone on the system can ps -ef and see the password. Is there a way to prevent this from happening. example PROGRAM USERNAME/PASSWD I've also tried PROGRAM `cat passfile` ... (7 Replies)
Discussion started by: sudojo
7 Replies
Login or Register to Ask a Question
sane-epjitsu(5) 					   SANE Scanner Access Now Easy 					   sane-epjitsu(5)

NAME
sane-epjitsu - SANE backend for Epson-based Fujitsu USB scanners. DESCRIPTION
The sane-epjitsu library implements a SANE (Scanner Access Now Easy) backend which provides basic access the Fujitsu fi-60F and ScanSnap S300/S1300 scanners. HARDWARE SUPPORT
These scanners are fairly limited, only supporting a couple of modes and resolutions, and always scanning full width. The backend supports missing modes (binary, grayscale) in software, but makes no effort to offer intermediate resolutions or scan area controls. See KNOWN ISSUES. This backend may support other scanners. If physical inspection reveals an Epson chipset, please contact the author for instructions on collecting a USB trace under Windows to verify. OPTIONS
A limited effort has been made to expose the standard options to the API. This allows a frontend to set resolution, color mode, and choose the ADF setting. The epjitsu backend supports the following basic options for most scanners: source s Selects the source for the scan. Options may include "Flatbed", "ADF Front", "ADF Back", "ADF Duplex". mode m Selects the mode for the scan. Options may include "Lineart", "Gray", "Color". resolution, y-resolution Controls scan resolution. Setting --resolution also sets --y-resolution, though this behavior is overridden by some frontends. Other options will be available based on the capabilities of the scanner. Use 'scanimage --help' to get a list. Be aware that some options may appear only when another option has been set, and that advanced options may be hidden by the frontend. CONFIGURATION FILE
The configuration file "/etc/sane.d/epjitsu.conf" is used to tell the backend how to look for scanners, and provide options controlling the operation of the backend. This file is read each time the frontend asks the backend for a list of scanners, generally only when the fron- tend starts. If the configuration file is missing, the backend will not work. Scanners can be specified in the configuration file in two ways: "usb 0x04c5 0x10c7" (or other vendor/product ids) Requests backend to search all usb busses in the system for a device which uses that vendor and product id. The device will then be queried to determine if it is a supported scanner. "usb /dev/usb/scanner0" (or other device file) Some systems use a kernel driver to access usb scanners. This method is untested. The only configuration option supported is "firmware /PATH/TO/FILE", allowing you to set the location of the firmware file you have extracted from the Windows driver. Note: This firmware is a copyrighted work of Fujitsu, so cannot be provided by the backend or the author. Please do not ask. Note: These scanners REQUIRE a firmware file to function. See the supplied configuration file for more detail. Note: This option may appear multiple times in the configuration file. It only applies to scanners discovered by 'usb' lines that follow this option. ENVIRONMENT
The backend uses a single environment variable, SANE_DEBUG_EPJITSU, which enables debugging output to stderr. Valid values are: 5 Errors 10 Function trace 15 Function detail 20 Option commands 25 USB trace 30 USB detail 35 Useless noise KNOWN ISSUES
No scan area options are exposed. fi-60F hardware grayscale mode is not used. CREDITS
S300 support funded by Microdea, Inc. and Archivista, GmbH. fi-60F support funded by TrueCheck, Inc. Improved calibration code provided by Richard Goedeken. SEE ALSO
sane(7), sane-usb(5) AUTHOR
m. allan noah: <kitno455 a t gmail d o t com> 09 Feb 2010 sane-epjitsu(5)