Install and use chkrootkit
What is chkrootkit?
chkrootkit is a tool to locally check for signs of a rootkit. It
contains:
* chkrootkit: a shell script that checks system binaries for
rootkit modification.
* ifpromisc.c: checks if the network interface is in promiscuous
mode.
* chklastlog.c: checks for lastlog deletions.
* chkwtmp.c: checks for wtmp deletions.
* check_wtmpx.c: checks for wtmpx deletions. (Solaris only)
* chkproc.c: checks for signs of LKM trojans.
* chkdirs.c: checks for signs of LKM trojans.
* strings.c: quick and dirty strings replacement.
* chkutmp.c: checks for utmp deletions.
How to install chkrootkit
- Login to your server as root
- Download chkrootkit and extract the archive
- Install chkrootkit
- Now lets run chkrootkit
wget ftp://ftp.pangeia.com.br/pub/seg/pac/chkrootkit.tar.gz
tar xvzf chkrootkit.tar.gz
cd chkrootkit-0.47
make sense
/root/chkrootkit-0.47/chkrootkit
Make sure you run it on a regular basis, perhaps you can include the scan in a cron job.
If you enjoyed this post, make sure you subscribe to my RSS feed!
- September 17th


(1 votes, average: 4.00 out of 5)










[...] Install chkrootkit [...]
4 step: Now lets run chkrootkit
./chkrootkit
How to work chkrootki ?
plese send me to a basic security details …..
good work configuration in this web site