chkrootkit
Details
| Size: | 36K |
| Last Update: | 2008-05-14 23:53:52 |
| Version: | 0.45 |
| OS Support: | Linux |
| License/Program Type: | GPL (GNU General Public License) |
| Publisher: | Nelson Murilo |
| Price: | $0.00 |
Description:
chkrootkit 0.45 is security software developed by Nelson Murilo.
chkrootkit is a tool to locally check for signs of a rootkit.
It contains:
chkrootkit: shell script that checks system binaries for rootkit modification.
ifpromisc.c: checks if the interface is in promiscuous mode.
chklastlog.c: checks for lastlog deletions.
chkwtmp.c: checks for wtmp deletions.
check_wtmpx.c: checks for wtmpx deletions. (Solaris only)
chkproc.c: checks for signs of LKM trojans.
chkdirs.c: checks for signs of LKM trojans.
strings.c: quick and dirty strings replacement.
chkutmp.c: checks for utmp deletions.
The following tests are made:
aliens asp bindshell lkm rexedcs sniffer w55808 wted scalper slapper z2 chkutmp amd basename biff chfn chsh cron date du dirname echo egrep env find fingerd gpm grep hdparm su ifconfig inetd inetdconf identd init killall ldsopreload login ls lsof mail mingetty netstat named passwd pidof pop2 pop3 ps pstree rpcinfo rlogind rshd slogin sendmail sshd syslogd tar tcpd tcpdump top telnetd timed traceroute vdir w write
The following rootkits, worms and LKMs are currently detected:
01. lrk3, lrk4, lrk5, lrk6 (and variants);
02. Solaris rootkit;
03. FreeBSD rootkit;
04. t0rn (and variants);
05. Ambient's Rootkit (ARK);
06. Ramen Worm;
07. rh[67]-shaper;
08. RSHA;
09. Romanian rootkit;
10. RK17;
11. Lion Worm;
12. Adore Worm;
13. LPD Worm;
14. kenny-rk;
15. Adore LKM;
16. ShitC Worm;
17. Omega Worm;
18. Wormkit Worm;
19. Maniac-RK;
20. dsc-rootkit;
21. Ducoci rootkit;
22. x.c Worm;
23. RST.b trojan;
24. duarawkz;
25. knark LKM;
26. Monkit;
27. Hidrootkit;
28. Bobkit;
29. Pizdakit;
30. t0rn v8.0;
31. Showtee;
32. Optickit;
33. T.R.K;
34. MithRa's Rootkit;
35. George;
36. SucKIT;
37. Scalper;
38. Slapper A, B, C and D;
39. OpenBSD rk v1;
40. Illogic rootkit;
41. SK rootkit.
42. sebek LKM;
43. Romanian rootkit;
44. LOC rootkit;
45. shv4 rootkit;
46. Aquatica rootkit;
47. ZK rootkit;
48. 55808.A Worm;
49. TC2 Worm;
50. Volc rootkit;
51. Gold2 rootkit;
52. Anonoying rootkit;
53. Shkit rootkit;
54. AjaKit rootkit;
55. zaRwT rootkit;
56. Madalin rootkit;
57. Fu rootkit;
58. Kenga3 rootkit;
59. ESRK rootkit;
chkrootkit has been tested on: Linux 2.0.x, 2.2.x, 2.4.x and 2.6.x, FreeBSD 2.2.x, 3.x, 4.x and 5.x, OpenBSD 2.x and 3.x., NetBSD 1.6.x, Solaris 2.5.1, 2.6, 8.0 and 9.0, HP-UX 11, Tru64 and BSDI.
What's New in This Release:
chkutmp.c (Thanks to Jeremy Miller)
the idea of this program is to display users that may have wiped themselves from the utmp log
chkproc.c
fix: better support for Linux threads
chkrootkit
new test: chkutmp
new rootkits detected: Fu, Kenga3, ESRK
some bug fixes
homepage redesign (Thanks to Cristine Hoepers)
navigability improvement
the page now validates as strict XHTML
still lynx friendly
chkrootkit 0.45 supports different languages (including english). It works with Linux.
Downloading chkrootkit 0.45 will take several seconds if you use fast ADSL connection.
0 comments
Add to
chkrootkit Version History
Related Software
|
|
From category: Security |
| Console Password Manager 0.23 Beta is security software developed by Harry Brueckner. Console Password Manager is a small console tool to manage passwords and store them public key encrypted in a f... |
|
|
From category: Antivirus |
| Win Spy Software Pro is a Complete Stealth Monitoring Software that can both monitor your Local PC and Remote PC. Win Spy Software also includes Remote Install. Win Spy Software will capture anything... |
|
|
From category: Other-Tools |
| Kremlin builds a wall around your data, protecting your data from intruders. You can encrypt/decrypt files with RC4 and Blowfish in one click and securely delete files by dragging them to the Kremlin... |
|
|
From category: Other-Tools |
| updated on Mon, 09 Jun 2008 10:01:35 CDT
- Hitonic MIDlet Protector sets various limitations on launching MIDlets.... |
|
|
From category: Firewalls |
| updated on Wed, 21 May 2008 01:37:08 CDT - Server application for user internet access control and network security... |
|
|
From category: Other-Tools |
| AVIRA Antivirus for WebGate reliably secures plain HTTP and FTP connections, being placed either between a client computer and the Internet or between a client computer, proxy and the Internet. The pr... |
|
|
From category: Other-Tools |
| AVIRA Antivirus for Exim is a comprehensive antivirus solution for Linux mailservers, functioning at high speed and filtering against malicious contents by checking both incoming and outgoing emails.... |
|
|
From category: Security |
| Gringotts is a small utility that allows you to jot down sensitive data (passwords, PINs, small files, etc.).... |
|
|
From category: Security |
| Apso 0.1.0 is security software developed by J. Pellegrini. Apso project is a framework for adding secrecy to version control systems. Usually, version control systems support transfer of encrypted... |
|
|
From category: Other-Tools |
| F-Prot Antivirus for Linux Workstations is designed for workstations running the Linux operating system. F-Prot Antivirus for Linux Workstations is free when used by personal users on personal worksta... |
|
|
From category: Security |
| Advchk 1.02 is security software developed by Stephan Schmieder. Advchk (Advisory Check) reads security advisories so you don&039;t have to. Advchk gathers security advisories using RSS fee... |
|
|
From category: Encryption |
| 1 Click Sweep brings to you 10 + utilities that work together or separate so that no important traces are left after using the World Wide Web or your PC and other service that involves private data, i... |
|
|
From category: Security |
| F-Prot Antivirus for Linux Workstations 4.6.7 is security software developed by FRISK Software International. F-Prot Antivirus security software package has various components that help keep your s... |
|
|
From category: Security |
| Password Manager Daemon is a daemon that serves data to application via a socket.... |
|
|
From category: Security |
| Digital Invisible Ink Toolkit 1.5 is security software developed by Kathryn H. The Digital Invisible Ink Toolkit is a Java steganography tool that can hide any sort of file inside a digital image (... |
Leave a comment