Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
chkrootkit
by Milamber
Platforms: FreeBSD, Linux, OpenBSD, Solaris
Categories: Auditing, Backdoors
Version: v0.41
URL: http://www.chkrootkit.org/
chkrootkit is a tool to locally check for signs of a rootkit. It contains a chkrootkit: shell script that checks system binaries for rootkit modification. The following tests are made: aliens, asp, bindshell, lkm, rexedcs, sniffer, wted, z2, amd, basename, biff, chfn, chsh, cron, date, du, dirname, echo, egrep, env, find, fingerd, gpm, grep, hdparm, su, ifconfig, inetd, inetdconf, identd, killall, login, ls, mail, mingetty, netstat, named, passwd, pidof, pop2, pop3, ps, pstree, rpcinfo, rlogind, rshd, slogin, sendmail, sshd, syslogd, tar, tcpd, top, telnetd, timed, traceroute, and write. ifpromisc.c checks whether the interface is in promiscuous mode, chklastlog.c checks for lastlog deletions, chkwtmp.c checks for wtmp deletions, check_wtmpx.c checks for wtmpx deletions (Solaris only), and chkproc.c checks for signs of LKM trojans.

Comments Mode:
chkrootkit 2002-01-22
Night Hawk
Just tried this for the first time and noticed on my one machine that it's ethernet is set to promiscuous mode, this program failed to detect it.

I'm using ntop on this box.

So that makes me wonder how well it really detects for other problems?

[ reply ]
chkrootkit 2003-09-20
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus