Comment Re:See: Integrity (Score 0) 248
Syslog being down for seconds is not obvious, on the other hand it's very easy to say... inject into syslogd to hide your modifications in real time. I hook libc functions using trampolines to write LD_PRELOAD rootkits myself. I just don't get the point, it seems like a really shitty half-measure.