It appears you have not registered with our community. To register please click here ...

Author Topic: [HOW TO] chkrootkit  (Read 2687 times)

David

  • Global Moderator
  • Newbie
  • *****
  • Posts: 49
  • Karma: +10/-0
    • ICQ Messenger - 229947748
    • MSN Messenger - figigicom@hotmail.com
    • AOL Instant Messenger - D Welling 23
    • Yahoo Instant Messenger - dwellingjr
    • View Profile
    • Email
[HOW TO] chkrootkit
« on: January 28, 2005, 08:21:56 PM »
chkrootkit: shell script that checks system binaries for rootkit modification. The following tests are made:
 

  • aliens asp bindshell lkm rexedcs sniffer wted w55808 scalper slapper z2 amd basename biff chfn chsh cron date du dirname echo egrep env find fingerd gpm grep hdparm su ifconfig inetd inetdconf init identd killall ldsopreload login ls lsof mail mingetty netstat named passwd pidof pop2 pop3 ps pstree rpcinfo rlogind rshd slogin sendmail sshd syslogd tar tcpd tcpdump top telnetd timed traceroute vdir w write
First we will download the source to your server.
Code: [Select]
wget [url=ftp://ftp.pangeia.com.br/pub/seg/pac/chkrootkit.tar.gz]ftp://ftp.pangeia.com.br/pub/seg/pac/chkrootkit.tar.gz[/url]
We will then extract the source and change to directory.
Code: [Select]
tar zxvf chkrootkit.tar.gz
Code: [Select]
cd chkrootkit
Now to run chkrootkit
Code: [Select]
./chkrootkit
Thats it! Please be aware if your running cpanel that bindshell WILL show up as an infected port.
Can I run chkrootkit from cron?
 
 
Yes. For example, to run chkrootkit every day at 3am and mail the output to you@yoursite.com:
Code: [Select]
0 3 * * * (cd /path/to/chkrootkit; ./chkrootkit 2>&1 | mail -s "chkrootkit output" [email=you@yoursite.com)]you@yoursite.com)[/email]Thank you over at http://www.chkrootkit.org/
« Last Edit: January 28, 2005, 08:27:38 PM by David »
The All New Turbo Forums. Talk Boost.

dynaweb

  • <b>Canine Deamon</b>
  • Administrator
  • Sr. Member
  • *****
  • Posts: 493
  • Karma: +10/-0
  • Generic personal text here ...
    • MSN Messenger - danno_d_manno@yahoo.com
    • View Profile
    • DynaWeb Designs
    • Email
[HOW TO] chkrootkit
« Reply #1 on: July 30, 2005, 06:18:53 PM »
ChRootKit is a Great script to run, especially if you are probing a server for suspicious activity.
Those who cannot learn from history are doomed to repeat it. -- Linux learns.

 

Related Topics

  Subject / Started by Replies Last post
0 Replies
1326 Views
Last post March 03, 2006, 08:41:45 AM
by dynaweb