Re: chkrootkit and rkhunter are too old ?
On Tue, Jul 10, 2007 at 02:54:04PM +0000, KLEIN Stéphane wrote:
> I look for root kit checker. I found this tools :
> * chkrootkit (http://www.chkrootkit.org/)
> * rkhunter (http://rkhunter.sourceforge.net/)
> chkrootkit last version date from 30/09/2006 (1.2.9) and rkhunter date
> from 10/10/2006. This tools are near two year old. There aren't new
> rootkit since this date ? if yes, there aren't other tools to check my
> box ?
Well sometimes upstream development stops for some reason. To be honest
those tools hat a lot of false-positives over the years whenever some
kernel based process changed its name and other things like that.
> Else, what can I use to test integrity of my system ?
apt-get install aide, tripwire or one of the similar tools and learn how
to use them.
If you won't forgive me the rest of my life
Let me apologize while I'm still alive
I know it's time to face all of my past mistakes
[Less than Jake - Rest Of My Life]