Various Ways of Detecting Rootkits in GNU/Linux

“A rootkit is a collection of tools a hacker installs on a victim computer after gaining initial access. It generally consists of network sniffers, log-cleaning scripts, and trojaned replacements of core system utilities such as ps, netstat, ifconfig, and killall. I know of two programs which aid in detecting whether a rootkit has been installed on your machine. They are Rootkit Hunter and Chkrootkit.”

16 Comments

  1. 2006-12-26 5:10 pm
  2. 2006-12-26 6:24 pm
    • 2006-12-26 7:17 pm
      • 2006-12-27 3:20 pm
        • 2006-12-27 4:55 pm
          • 2006-12-27 6:11 pm
  3. 2006-12-26 7:47 pm
    • 2006-12-27 3:46 am
    • 2006-12-27 3:18 pm
  4. 2006-12-26 9:26 pm
  5. 2006-12-26 10:58 pm
    • 2006-12-27 12:29 am
      • 2006-12-28 1:30 am
      • 2006-12-28 2:42 am
  6. 2006-12-27 6:34 pm
    • 2006-12-28 2:39 am