The Seattle SAGE Group (SSG)
Seattle based special interest group for system and network administrators.
Hiding Attacks

- Hackers getting real good at hiding intrusions
- A modified /etc/login:
- was the correct length,
- had the same checksum,
- had correct permissions and
- had correct last-mod date
- Only detectable by
- Comparing against read only install media (if the vender wasn't compromised as well)
- Using cryptographic signatures (MD5)