3 ms·
> A rootkit is a stealthy type of software, typically malicious, designed to hide the existence of certain processes or programs from normal methods of detectio
by AnIrishDuck 12y ago
> A rootkit is a stealthy type of software, typically malicious, designed to hide the existence of certain processes or programs from normal methods of detection
These are the primary characteristic of a rootkit. To wit, from that same article:
> Rootkit detection is difficult because a rootkit may be able to subvert the software that is intended to find it. Detection methods include using an alternative and trusted operating system, behavioral-based methods, signature scanning, difference scanning, and memory dump analysis. Removal can be complicated or practically impossible, especially in cases where the rootkit resides in the kernel; reinstallation of the operating system may be the only available solution to the problem.[2] When dealing with firmware rootkits, removal may require hardware replacement, or specialized equipment.
These problems are what rootkits are associated with. The backdoored SSH described in the paper does not qualify. Detecting it is fairly straightforward, and on its own it makes no attempt to hide any programs that it spawns. EDIT: further, as described it makes no efforts to avoid removal.
> enable continued privileged access to a computer
If you strip away the rest of the definition and only look at this part, then by your definition the vanilla SSH server is a rootkit.