Scientific Linux 6
Sponsored Link

ChkrootKit - Detect RootKit2011/05/14

  Install ChkrootKit to detect rootkit on your Server.
# install from EPEL

[root@dlp ~]#
yum --enablerepo=epel -y install chkrootkit
[root@dlp ~]#
chkrootkit
 
# run

ROOTDIR is `/'
Checking `amd'... not found
Checking `basename'... not infected
Checking `biff'... not found
Checking `chfn'... not infected
Checking `chsh'... not infected
Checking `cron'... not infected
Checking `crontab'... not infected
Checking `date'... not infected
Checking `du'... not infected
Checking `dirname'... not infected
Checking `echo'... not infected
Checking `egrep'... not infected
Checking `env'... not infected
Checking `find'... not infected
.....
.....
Checking `asp'... not infected
Checking `bindshell'... not infected
Checking `lkm'... chkproc: nothing detected
chkdirs: nothing detected
Checking `rexedcs'... not found
Checking `sniffer'... eth1: not promisc and no PF_PACKET sockets
Checking `w55808'... not infected
Checking `wted'... chkwtmp: nothing deleted
Checking `scalper'... not infected
Checking `slapper'... not infected
Checking `z2'... chklastlog: nothing deleted
Checking `chkutmp'... chkutmp: nothing deleted
Checking `OSX_RSPLUG'... not infected

# show only INFECTED results like follows

[root@dlp ~]#
chkrootkit | grep INFECTED

[root@dlp ~]#  
# no ploblem if nothing shows
Matched Content