Rootkit
A toolset used by crackers to keep control of a compromised host over a network. Once a cracker finds a system to which he can gain access, he uploads a rootkit consisting of several applications or scripts that erase traces of his activity from standard system reporting tools (for example, last and login files on Unix systems) and which even hide the presence of his applications (for example, ls in Unix or dir in Windows will not show these scripts).
Additional resources
Invisible intruders: rootkits in practice
Discusses rootkits in more detail.
chkrootkit
A tool for detecting the presence of rootkits on Unix systems.
Intrusion detection and prevention research center
The latest intrusion news, analysis and links from Network World.
Add a comment