Monday, January 26, 2009

Checking Rootkits for Linux

Chkrootkit - chkrootkit is a tool to locally check for signs of a rootkit. Type the following command to install chkrootkit
$ sudo apt-get install chkrootkit

Start looking for rootkits, enter:
$ sudo chkrootkit

Look for suspicious strings, enter:
$ sudo chkrootkit -x | less

You need to specify the path for the external commands used by chkrootkit such as awk, grep and others. Mount /mnt/safe using nfs in read-only mode and set /mnt/safe binaries PATH as trusted one, enter:
$ sudo chkrootkit -p /mnt/safe


rkhunter -is a Unix-based tool that scans for rootkits, backdoors and possible local exploits.

ype the following command to install rkhunter:
$ sudo apt-get install rkhunter

The following command option tells rkhunter to perform various checks on the local system:
$ sudo rkhunter --check
The following command option causes rkhunter to check if there is a later version of any of its text data files:

$ sudo rkhunter --update

The following option tells rkhunter which directories to look in to find the various commands it requires:
$ sudo rkhunter --check --bindir /mnt/safe


0 comments: