Root Kit in General
The term "root kit" (also written as "rootkit") originally referred to a set of recompiled Unix tools such as "ps", "netstat", "w" and "passwd" that would carefully hide any trace of the cracker that those commands would normally display...
Generally now the term is not restricted to Unix based operating systems,
as tools that perform a similar set of tasks now exist for non-Unix
operating systems such as Microsoft Windows (even though such operating
systems may not have a "root" account). It is common for the term
'rootkit' to refer to a "kernel-mode" program (that is, acting as part
of the operating system), as opposed to a "user-mode" program (that is,
programs that operate as normal applications or tools). (from the Wikipedia)
7:25:20 PM
|
|