Debian 7.0
Sponsored Link

Detect rootKit - ChkrootKit
2013/05/29
  Install ChkrootKit to detect rootkit on your Server.
root@dlp:~#
aptitude -y install chkrootkit
root@dlp:~#
chkrootkit
 
# execute
ROOTDIR is `/'
Checking `amd'...             not found
Checking `basename'...        not infected
Checking `biff'...            not found
Checking `chfn'...            not infected
Checking `chsh'...            not infected
Checking `cron'...            not infected
Checking `crontab'...         not infected
Checking `date'...            not infected
Checking `du'...              not infected
Checking `dirname'...         not infected
Checking `echo'...            not infected
Checking `egrep'...           not infected
Checking `env'...             not infected
Checking `find'...            not infected
Checking `fingerd'...         not found
Checking `gpm'...             not found
Checking `grep'...            not infected
Checking `hdparm'...          not infected
Checking `su'...              not infected
Checking `ifconfig'...        not infected
Checking `inetd'...           not infected
Checking `inetdconf'...       not found
Checking `identd'...          not found
Checking `init'...            not infected
Checking `killall'...         not found
Checking `ldsopreload'...     not infected
Checking `login'...           not infected
Checking `ls'...              not infected
Checking `lsof'...            not found
Checking `mail'...            not found
Checking `mingetty'...        not found
Checking `netstat'...         not infected
Checking `named'...           not found
Checking `passwd'...          not infected
Checking `pidof'...           not infected
Checking `pop2'...            not found
Checking `pop3'...            not found
Checking `ps'...              not infected
Checking `pstree'...          not found
Checking `rpcinfo'...         not infected
Checking `rlogind'...         not found
Checking `rshd'...            not found
Checking `slogin'...          not infected
Checking `sendmail'...        not found
Checking `sshd'...            not infected
Checking `syslogd'...         not tested
Checking `tar'...             not infected
Checking `tcpd'...            not infected
Checking `tcpdump'...         not infected
Checking `top'...             not infected
Checking `telnetd'...         not found
Checking `timed'...           not found
Checking `traceroute'...      not infected
Checking `vdir'...            not infected
Checking `w'...               not infected
Checking `write'...           not infected
Checking `aliens'...          no suspect files
Searching for sniffer's lo    nothing found
Searching for rootkit HiDr    nothing found
Searching for rootkit t0rn    nothing found
Searching for t0rn's v8 de    nothing found
Searching for rootkit Lion    nothing found
Searching for rootkit RSHA    nothing found
Searching for rootkit RH-S    nothing found
Searching for Ambient's rodirs... nothing found
Searching for suspicious fhile... nothing found
Searching for LPD Worm fil    nothing found
Searching for Ramen Worm f    nothing found
Searching for Maniac files    nothing found
Searching for RK17 files a    nothing found
Searching for Ducoci rootk    nothing found
Searching for Adore Worm..    nothing found
Searching for ShitC Worm..    nothing found
Searching for Omega Worm..    nothing found
Searching for Sadmind/IIS     nothing found
Searching for MonKit...       nothing found
Searching for Showtee...      nothing found
Searching for OpticKit...     nothing found
Searching for T.R.K...        nothing found
Searching for Mithra...       nothing found
Searching for LOC rootkit.    nothing found
Searching for Romanian roo    nothing found
Searching for Suckit rootk    nothing found
Searching for Volc rootkit    nothing found
Searching for Gold2 rootki    nothing found
Searching for TC2 Worm def    nothing found
Searching for Anonoying ro.   nothing found
Searching for ZK rootkit d    nothing found
Searching for ShKit rootki    nothing found
Searching for AjaKit rootk    nothing found
Searching for zaRwT rootki    nothing found
Searching for Madalin root    nothing found
Searching for Fu rootkit d    nothing found
Searching for ESRK rootkit    nothing found
Searching for rootedoor...    nothing found
Searching for ENYELKM root    nothing found
Searching for common ssh-s    nothing found
Searching for suspect PHP     nothing found
Searching for anomalies in    nothing found
Checking `asp'...             not infected
Checking `bindshell'...       not infected
Checking `lkm'...             chkproc: nothing detected
chkdirs: nothing detected
Checking `rexedcs'...         not found
Checking `sniffer'...         lo: not promisc and no packet sniffer sockets
eth1: not promisc and no p
Checking `w55808'...          not infected
Checking `wted'...            chkwtmp: nothing deleted
Checking `scalper'...         not infected
Checking `slapper'...         not infected
Checking `z2'...              chklastlog: nothing deleted
Checking `chkutmp'...         chkutmp: nothing deleted
Checking `OSX_RSPLUG'...      not infected

# show only INFECTED results like follows

root@dlp:~#
chkrootkit | grep INFECTED

root@dlp:~#
# no ploblem if nothing shows
Matched Content