介紹
???????? chkrootkit是用于在本地檢查rootkit跡象的工具。
依賴安裝包
???????? # yum install gcc gcc-c++ make glibc-static
下載安裝包
???????? # wget ftp://ftp.pangeia.com.br/pub/seg/pac/chkrootkit.tar.gz
解壓并編譯
???????? # tar -zxf chkrootkit.tar.gz
???????? # cd chkrootkit-0.53
???????? # make sense
嘗試掃描
???????? # cd
???????? # cd chkrootkit-0.53
???????? # ./chkrootkit
???????? # mkdir /var/log/chkrootkit
???????? # /root/chkrootkit-0.53/chkrootkit >> /var/log/chkrootkit/chkrootkit.log 2>&1
確認(rèn)方法:查看輸入log中是否包含INFECTED、Warning、Possible關(guān)鍵字
???????? # grep -e "INFECTED|Warning|Possible"? /var/log/chkrootkit/chkrootkit.log
關(guān)聯(lián)URL
???????? https://github.com/Magentron/chkrootkit
???????? http://www.chkrootkit.org/