Hack Proofing Linux: A Guide to Open Source Security
By Edgar Danielyan, Technical Editor
Solutions Fast Track
Solutions Fast Track
Scanning for Viruses Using the AntiVir Antivirus Application
Virus scanners will perform the following tasks: check the system s boot record; search directories and subdirectories; automatically delete infected files; save scans into a log file; use an internal scheduler, or an external scheduler, such as at or cron; scan NFS-mounted drives; delete infected files; and move infected files to a central, quarantine area of your own choosing.
The AntiVir for Servers binary is a truly impressive command-line virus scanner sold by H+BDEV. It is capable of searching for and deleting macro viruses, boot sector viruses, e-mail viruses, and DDoS daemons.
An antivirus application is only as useful as its virus definition file. Your application should provide you with frequent updates.
Scanning Systems for DDoS Attack Software Using a Zombie Zapper
Attackers wage denial of service (DoS) attacks by first finding and hacking into insecure systems on the Internet. Then, they install programs such as Tribe Flood Network 2000 (Tfn2k), stacheldraht, and others. The compromised systems now have illicit programs installed on them called zombies.
Once a zombie is commanded to attack a victim, it will generally continue the attack until it is forced to stop. If you notice large amounts of unknown traffic when you monitor your network or network perimeter, you can use a zombie zapper against the host or hosts generating this traffic.
Limitations of a zombie zapper can include the following: they are programmed to shut down only certain DDoS servers;
Copyright Syngress Publishing, Inc. 2001 under license agreement with Books24x7