Robert Hensing's Blog
Home of the "Fail Open Goat" Award
March 2005 - Posts
Robert Hensing’s Incident Response Blog – Reloaded
After nearly 7 years in Product Support Services helping our customers on issues ranging from debugging IIS failures, to identifying performance issues to helping customers with security investigations I have taken on a new challenge and accepted a job
Read More...
New Rootkit Revealer available!
Sysinternals yesterday released a new version of Rootkit revealer after receiving feedback that people using rootkits were starting to add Rootkit Revealer to the 'root process' to continue to avoid detection. The new version uses a randomly named executable
Read More...
New weapon in the war - F-Secure reveals Blacklight - an anti-rootkit tool - try it today (remember to rename it <G>)
F-Secure has finally taken the wraps off a new anti-rootkit tool they call Blacklight (I dig the name): http://www.f-secure.com/blacklight/try.shtml It seems to do a file system scan and may employ a similar technique to that of Rootkit Revealer and the
Read More...
Rootkit Revealer vs. Hacker Defender - How the miscreants are defeating Rootkit Revealer and how to fight back
So over the last week we've started to get cases where Rootkit Revealer (having been downloaded by the customer) is not detecting any hidden files / folders / registry entries on the customers machine; yet our own rootkit tools we supply with our IR toolkit
Read More...
Search
Go
This Blog
Home
Email
Tags
No tags have been created or used yet.
Archives
July 2008 (10)
June 2008 (24)
May 2008 (11)
April 2008 (15)
March 2008 (15)
February 2008 (11)
January 2008 (7)
December 2007 (9)
November 2007 (15)
October 2007 (23)
September 2007 (18)
August 2007 (8)
July 2007 (13)
June 2007 (10)
May 2007 (12)
April 2007 (8)
March 2007 (5)
February 2007 (4)
January 2007 (7)
December 2006 (5)
November 2006 (6)
September 2005 (1)
July 2005 (1)
March 2005 (4)
February 2005 (6)
January 2005 (8)
November 2004 (1)
October 2004 (2)
August 2004 (2)
July 2004 (1)
Syndication
RSS 2.0
Atom 1.0