Linked by Thom Holwerda on Wed 31st Mar 2010 14:41 UTC
Thread beginning with comment 416492
To view parent comment, click here.
To read all comments associated with this story, please click here.
To view parent comment, click here.
To read all comments associated with this story, please click here.
News
Linked by Thom Holwerda on 05/18/13 21:06 UTC
Linked by Thom Holwerda on 05/18/13 7:37 UTC
Linked by fran on 05/18/13 1:38 UTC
Linked by Thom Holwerda on 05/17/13 23:35 UTC, submitted by kragil
Linked by MOS6510 on 05/17/13 22:22 UTC
Linked by Thom Holwerda on 05/17/13 22:15 UTC, submitted by Tom
Linked by Thom Holwerda on 05/16/13 21:41 UTC
Linked by Thom Holwerda on 05/16/13 17:04 UTC
Linked by Thom Holwerda on 05/16/13 13:17 UTC
Linked by Thom Holwerda on 05/16/13 12:06 UTC
More News »
Sponsored Links



Member since:
2005-07-20
The advantage of malware being forced into user mode is that it is detectable.
Something opening a network connection? root can see it. Something added to the startup items? root can see it. Want an audit listing of what files were modified, when and by what program? root can do that.
Now, if the malware is running as root, it can insert its code into the OS driver level where it has the power to do anything. Detecting rootkits is very difficult and is a race between the latest rootkit and the latest detector.