[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: chkrootkit and rkhunter are too old ?



On Tue, Jul 10, 2007 at 02:54:04PM +0000, KLEIN Stéphane wrote:
> Hello,
> 
> I look for root kit checker. I found this tools :
> 
> * chkrootkit (http://www.chkrootkit.org/)
> * rkhunter (http://rkhunter.sourceforge.net/)
> 
> chkrootkit last version date from 30/09/2006 (1.2.9) and rkhunter date 
> from 10/10/2006. This tools are near two year old. There aren't new 
> rootkit since this date ? if yes, there aren't other tools to check my 
> box ?
Well sometimes upstream development stops for some reason. To be honest
those tools hat a lot of false-positives over the years whenever some
kernel based process changed its name and other things like that.
 
> Else, what can I use to test integrity of my system ?
apt-get install aide, tripwire or one of the similar tools and learn how
to use them.

Cheers,
Sven
-- 
If you won't forgive me the rest of my life
Let me apologize while I'm still alive
I know it's time to face all of my past mistakes
  [Less than Jake - Rest Of My Life]



Reply to: