- Chkrootkit
Infobox Software
name = chkrootkit
caption = chrootkit onMac OS X
developer =Pangeia Informatica
latest_release_version = 0.48
latest_release_date =December 17 th,2007
operating_system =Linux ,FreeBSD ,OpenBSD ,NetBSD , Solaris,HP-UX ,Tru64 ,BSDI ,Mac OS X
genre =Rootkit Detector
license =
website = http://www.chkrootkit.org/chkrootkit (Check Rootkit) is a common
Unix -based program intended to helpsystem administrators check their system for knownrootkit s. It is ashell script using common UNIX/Linux tools like the "strings" and "grep " commands to search core system programs for signatures and for comparing a traversal of the "/proc " filesystem with the output of the "ps" (process status) command to look for discrepancies.It can be used from a "
rescue disc " (typically aLive CD ) or it can optionally use an alternative directory from which to run all of its own commands. These techniques allow chkrootkit to trust the commands upon which it depends a bit more.There are inherent limitations to the reliability of any program that attempts to detect compromises (such as
rootkit s andcomputer virus es). Newer rootkits may specifically attempt to detect and compromise copies of the chkrootkit programs or take other measures to evade detection by them.ee also
*
rkhunter External links
* [http://www.chkrootkit.org/ Site for Chkrootkit]
* [http://freshmeat.net/projects/chkrootkit/ Chkrootkit Freshmeat Project page]
Wikimedia Foundation. 2010.