| RKHunter - RootKit Hunter |
|
|
| Friday, 20 July 2007 00:57 | ||||||||||
Rootkit scanner is scanning tool to ensure you for about 99.9%* you're
clean of nasty tools. This tool scans for rootkits, backdoors and local
exploits by running tests like:
# wget http://downloads.rootkit.nl/rkhunter-1.1.4.tar.gz
Receive e-mail everyday with the result Rootkit Hunter For Root user # crontab -e For any user # crontab -e -u usernameand add
0 3 * * * (./usr/local/bin/rkhunter checkall 2>&1 | mail -s "chkrootkit output" -c
This e-mail address is being protected from spambots. You need JavaScript enabled to view it
,
This e-mail address is being protected from spambots. You need JavaScript enabled to view it
This e-mail address is being protected from spambots. You need JavaScript enabled to view it
)
* the correct path can be found with which rkhunter This will run Rootkit Hunter at 3:00 am every day, and e-mail the output to
This e-mail address is being protected from spambots. You need JavaScript enabled to view it
and copies to
This e-mail address is being protected from spambots. You need JavaScript enabled to view it
and
This e-mail address is being protected from spambots. You need JavaScript enabled to view it
NotaIf you ever get a positive alarm, you can try to remove the rootkit, but all professionals would advice you to reinstall the server from scratch, and restore a previous backup (that mean saving nothing from server as soon as the rootkit is revealed....) Links http://www.rootkit.nl/projects/rootkit_hunter.html
Powered by !JoomlaComment 3.20
3.20 Copyright (C) 2007 Alain Georgette / Copyright (C) 2006 Frantisek Hliva. All rights reserved."
|
| Another articles: |
|---|
|


























Tags






