LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-21-2003, 10:53 AM   #1
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
FYI: Chkrootkit 0.41 out


chkrootkit 0.41 is now available! This version includes:

* chkproc.c
- Fix for NPTL threading mechanisms; (thanks to Michael Griego)
- minor corrections;

* chkrootkit
- new test added: vdir
- new worm detected
- 55808.A Worm
- TC2 Worm
- new rootkits detected
- Volc
- Gold2
- Anonoying
- Suckit (improved)
- ZK (improved)
- minor corrections;

chkrootkit is a tool to locally check for signs of a rootkit. More
information about chkrootkit and rootkits can be found at
http://www.chkrootkit.org/.

chkrootkit's tarball and its MD5 checksum are available at:
* ftp://ftp.pangeia.com.br/pub/seg/pac/chkrootkit.tar.gz
* ftp://ftp.pangeia.com.br/pub/seg/pac/chkrootkit.md5

or at the chkrootkit's homepage, at:
* http://www.chkrootkit.org/

//moderator.note:
WARNING.
I would urge anyone running a system with the following characteristics:
- ethernet devices *not* ifconfig'ed for promiscuous mode and,
- libpcap-based apps running in promiscuous mode
to use /sbin/ip from the "ip2route" package to check interface promiscuous mode manually.

Unfortunately Chkrootkit-0.41 hasn't fixed the problem, even tho the problem was discussed early april and a temporary solution presented to the Chkrootkit developer.

If you somehow trust me, you could try and apply a patch as a temporary fix.
My patch was made against chkrootkit-0.40 but since you only see plusses, you should be able to insert the code manually.
See unspawn/packaging/chkrootkit for more info.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
when I ./chkrootkit it says .... chemichael Fedora 2 08-18-2005 11:48 PM
chkrootkit ? jmanjeff Linux - Security 2 05-31-2005 11:15 PM
FYI: Chkrootkit 0.40 release unSpawn Linux - Security 2 04-05-2003 06:31 PM
FYI: chkrootkit-0.39a released unSpawn Linux - Security 0 02-02-2003 01:20 PM
FYI: [ Announce - chkrootkit 0.35 is now available ] unSpawn Linux - Security 1 01-21-2002 12:13 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:09 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration