chkrootkit是一个检测系统中rootkit的工具。
http://www.chkrootkit.org/这里可以下载
可以检测的rootkit有:
01. lrk3, lrk4, lrk5, lrk6 (and variants); | 02. Solaris rootkit; | 03. FreeBSD rootkit; |
04. t0rn (and variants); | 05. Ambient's Rootkit (ARK); | 06. Ramen Worm; |
07. rh[67]-shaper; | 08. RSHA; | 09. Romanian rootkit; |
10. RK17; | 11. Lion Worm; | 12. Adore Worm; |
13. LPD Worm; | 14. kenny-rk; | 15. Adore LKM; |
16. ShitC Worm; | 17. Omega Worm; | 18. Wormkit Worm; |
19. Maniac-RK; | 20. dsc-rootkit; | 21. Ducoci rootkit; |
22. x.c Worm; | 23. RST.b trojan; | 24. duarawkz; |
25. knark LKM; | 26. Monkit; | 27. Hidrootkit; |
28. Bobkit; | 29. Pizdakit; | 30. t0rn v8.0; |
31. Showtee; | 32. Optickit; | 33. T.R.K; |
34. MithRa's Rootkit; | 35. George; | 36. SucKIT; |
37. Scalper; | 38. Slapper A, B, C and D; | 39. OpenBSD rk v1; |
40. Illogic rootkit; | 41. SK rootkit. | 42. sebek LKM; |
43. Romanian rootkit; | 44. LOC rootkit; | 45. shv4 rootkit; |
46. Aquatica rootkit; | 47. ZK rootkit; | 48. 55808.A Worm; |
49. TC2 Worm; | 50. Volc rootkit; | 51. Gold2 rootkit; |
52. Anonoying rootkit; | 53. Shkit rootkit; | 54. AjaKit rootkit; |
55. zaRwT rootkit; | 56. Madalin rootkit; | 57. Fu rootkit; |
58. Kenga3 rootkit; | 59. ESRK rootkit; | 60. rootedoor rootkit; |
61. Enye LKM; | 62. Lupper.Worm; | 63. shv5; |
64. OSX.RSPlug.A; |
哇哇,真多啊。
说说怎么用吧。
1、安装
安装这个肯定要用到编译器咯,怎么安编译器,请参照上文http://blog.csdn.net/tingirl/archive/2009/12/29/5096263.aspx
然后,
tar zxvf *.tar.gz
我装的是chkrootkit-0.49
cp -r chkrootkit-0.49 /usr/local/chkrootkit
拷贝在/usr/local/chkrootkit目录下
make
2、测试
进入到安装目录下
cd ~/usr/local/chkrootkit
./chkrootkit
检查服务或文件是否被感染
检查系统中的蠕虫和rootkit~
3、其他命令
[root@localhost chkrootkit]# ./chkrootkit -l
./chkrootkit: tests: aliens asp bindshell lkm rexedcs sniffer w55808 wted scalper slapper z2 chkutmp OSX_RSPLUG amd basename biff chfn chsh cron crontab date du dirname echo egrep env find fingerd gpm grep hdparm su ifconfig inetd inetdconf identd init killall ldsopreload login ls lsof mail mingetty netstat named passwd pidof pop2 pop3 ps pstree rpcinfo rlogind rshd slogin sendmail sshd syslogd tar tcpd tcpdump top telnetd timed traceroute vdir w write
[root@localhost chkrootkit]# ./chkrootkit -x
chkrootkit将在专家模式(expert mode)运行.
果然是专家模式,显示的信息偶完全看不懂~