<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: rootkits in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/rootkits/m-p/4997368#M738985</link>
    <description>I believe the HP IDS9000 does some of this.  Marks and monitors for changes in listed files.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Freely included with your OS distribution.&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Tue, 15 Aug 2006 09:33:20 GMT</pubDate>
    <dc:creator>Tim Nelson</dc:creator>
    <dc:date>2006-08-15T09:33:20Z</dc:date>
    <item>
      <title>rootkits</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/rootkits/m-p/4997365#M738982</link>
      <description>Our security admin asked me if there was any HPUX programs/security tools to detect/protect us from rootkits. I have not seen anything regarding this in the forums. I subscribe to the HP security lists and have not seen anything there either. Is this a legitimate concern or paranoia. I do not want to miss any thing pertinent.&lt;BR /&gt;Thanks&lt;BR /&gt;Tommy</description>
      <pubDate>Tue, 15 Aug 2006 09:05:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/rootkits/m-p/4997365#M738982</guid>
      <dc:creator>Tommy Brown</dc:creator>
      <dc:date>2006-08-15T09:05:46Z</dc:date>
    </item>
    <item>
      <title>Re: rootkits</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/rootkits/m-p/4997366#M738983</link>
      <description>Hi Tommy,&lt;BR /&gt;&lt;BR /&gt;Snort offers lightweight network intrusion detection.  The HP-UX port is available here:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://hpux.connect.org.uk/hppd/hpux/Networking/Admin/snort-2.4.5/" target="_blank"&gt;http://hpux.connect.org.uk/hppd/hpux/Networking/Admin/snort-2.4.5/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;PCS</description>
      <pubDate>Tue, 15 Aug 2006 09:23:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/rootkits/m-p/4997366#M738983</guid>
      <dc:creator>spex</dc:creator>
      <dc:date>2006-08-15T09:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: rootkits</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/rootkits/m-p/4997367#M738984</link>
      <description>Tommy,&lt;BR /&gt;in my opinion not a real concern.&lt;BR /&gt;&lt;BR /&gt;On a PC you may install downloaded software, relying on virus check etc. However on HPUX you tend to only installed software from reputable sources. If you want to you could create a list of executable to be 'protected' and generate checksums, which you could compare on a regular basis.&lt;BR /&gt;&lt;BR /&gt;Keep your root account safe and with the right file protection there should be no cause for alarm.</description>
      <pubDate>Tue, 15 Aug 2006 09:27:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/rootkits/m-p/4997367#M738984</guid>
      <dc:creator>Peter Godron</dc:creator>
      <dc:date>2006-08-15T09:27:26Z</dc:date>
    </item>
    <item>
      <title>Re: rootkits</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/rootkits/m-p/4997368#M738985</link>
      <description>I believe the HP IDS9000 does some of this.  Marks and monitors for changes in listed files.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Freely included with your OS distribution.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 15 Aug 2006 09:33:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/rootkits/m-p/4997368#M738985</guid>
      <dc:creator>Tim Nelson</dc:creator>
      <dc:date>2006-08-15T09:33:20Z</dc:date>
    </item>
    <item>
      <title>Re: rootkits</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/rootkits/m-p/4997369#M738986</link>
      <description>There's also tripwire for monitoring file checksums.&lt;BR /&gt;&lt;BR /&gt;Note that when an OS is compromised with unknown-origin software... there's really nothing you can do to be sure you can detect the effects, if the installer was root/admin.  On the PC, the rootkit "detectors" just detect known signatures.  That's fine until the next one, or until someone builds one just for you.  I was at blackhat, and there was an announced "undetectable" rootkit for Vista...&lt;BR /&gt;&lt;BR /&gt;So in short on the PC Mac, Linux, and HP-UX... don't install from untrusted sources... regardless of what the "rootkit detector" vendors claim.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 16 Aug 2006 07:22:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/rootkits/m-p/4997369#M738986</guid>
      <dc:creator>Robert Fritz</dc:creator>
      <dc:date>2006-08-16T07:22:40Z</dc:date>
    </item>
    <item>
      <title>Re: rootkits</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/rootkits/m-p/4997370#M738987</link>
      <description>Shalom Tommy,&lt;BR /&gt;&lt;BR /&gt;Yes, there is a rootkit protection kit as part of Internet Express.&lt;BR /&gt;&lt;BR /&gt;Inerenet Express is offered by &lt;A href="http://software.hp.com" target="_blank"&gt;http://software.hp.com&lt;/A&gt; for 11iv1 and 11iv2&lt;BR /&gt;&lt;BR /&gt;Just search for Internet Express and you will see the rootkit protection among the 69 components of Internet Express.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Wed, 16 Aug 2006 08:17:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/rootkits/m-p/4997370#M738987</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2006-08-16T08:17:36Z</dc:date>
    </item>
    <item>
      <title>Re: rootkits</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/rootkits/m-p/4997371#M738988</link>
      <description>Thanks All,&lt;BR /&gt;I hope to download and test out Stephen's solution when I get a chance.</description>
      <pubDate>Fri, 18 Aug 2006 12:09:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/rootkits/m-p/4997371#M738988</guid>
      <dc:creator>Tommy Brown</dc:creator>
      <dc:date>2006-08-18T12:09:05Z</dc:date>
    </item>
  </channel>
</rss>

