📑 Table of Contents
chkrootkit
DeveloperNelson Murilo Klaus Steding-Jessen
Stable release
0.57 / Jan 13 2023
Operating systemLinux, FreeBSD, OpenBSD, NetBSD, Solaris, HP-UX, Tru64, BSD/OS, Mac OS X
TypeRootkit Detector
Websitewww.chkrootkit.org
Repository

chkrootkit (Check Rootkit) is a Unix-based program intended to help system administrators check their system for local signs of known rootkits.[1] It is a shell script using common UNIX/Linux tools like the strings and grep commands to search core system programs for signatures and for comparing a traversal of the /proc filesystem with the output of the ps (process status) command to look for discrepancies.[2][3]

It can be used from a rescue disc (typically a live CD) or it can optionally use an alternative directory from which to run all of its commands. These techniques allow chkrootkit to trust the commands upon which it depends a bit more.

There are inherent limitations to the reliability of any program that attempts to detect compromises (such as rootkits and computer viruses). Newer rootkits may specifically attempt to detect and compromise copies of the chkrootkit programs or take other measures to evade detection by them.

See also

edit

References

edit
  1. ^ Emms, Steve (2023-11-05). "chkrootkit - locally checks for signs of a rootkit". LinuxLinks. Retrieved 2025-03-13.
  2. ^ Turnbull, James (2006-11-01). Hardening Linux. Apress. ISBN 978-1-4302-0005-5.
  3. ^ Hatch, Brian; Lee, James; Kurtz, George (2003). Hacking Linux Exposed. McGraw-Hill/Osborne. ISBN 978-0-07-222564-8.
edit

📚 Artikel Terkait di Wikipedia

Host-based intrusion detection system comparison

Retrieved 2017-05-31. Snort in the CentOS Repositories "ChkRootkit". Ubuntu. Retrieved 2017-04-19. ChkRootkit in the Ubuntu Repositories lastlog, wtmp, utmp,

Linux Malware Detect

packages are available, such as rootkit detectors such as Rootkit Hunter and chkrootkit, and auditing systems like lynis. Malware detection software such as LMD

Linux malware

29 April 2007. Retrieved 7 March 2009. "chkrootkit -- locally checks for signs of a rootkit". www.chkrootkit.org. Archived from the original on 13 January

Rkhunter

similar should always be exercised. Free and open-source software portal chkrootkit Lynis OSSEC Samhain (software) Host-based intrusion detection system comparison

Lynis

additional guidance for auditors. Free and open-source software portal chkrootkit Host-based intrusion detection system comparison List of free and open-source

Rootkit

indicate hidden processes. Unix rootkit detection offerings include Zeppoo, chkrootkit, rkhunter and OSSEC. For Windows, detection tools include Microsoft Sysinternals

Tiger (security software)

check_trusted (for HPUX), check_rootkit (which can interact with the chkrootkit tool), check_xinetd, and, finally, aide_run and integrit_run (integrity