![]() |
||
|
Guide to Chkrootkit - checking for intruders Chkrootkit is a powerful tool to scan your Linux server for trojans. We'll show you how to install it, scan your server and setup a daily automated scanning job that emails you the report. Installing CHKROOTKIT Version 0.42b (Sept. 20 2003) SSH as admin to your server. DO NOT use telnet, it should be disabled anyways. #Change to root #Type the following # Check the MD5 SUM of the download for security: md5sum chkrootkit.tar.gz #Unpack the tarball using the command #Change to the directory it created #Compile by typing #To use chkrootkit, just type the command #Everything it outputs should be 'not found' or 'not infected'... Important Note: If you see 'Checking `bindshell'... INFECTED (PORTS: 465)' read on. #Now, Daily Automated System Scan that emails you a report While in SSH run the following: Insert the following to the new file: Important: Now save the file in SSH: Change the file permissions so we can run it Now if you like you can run a test report manually in SSH to see how it looks. ./chkrootkit.sh You'll now receive a nice email with the report! This will now happen everyday so you don't have to run it manually.
Similar Articles : Compile 2.6.7, 2.6.8, 2.6.8.1, 2.6.9, 2.6.10, 2.6.11.6 Kernel w/module-init-tools, Rkhunter Installation, Detect and Clean a hacked server T0rnkit Tutorial, How to install KISS Firewall, How to Disable Telnet, How to install mod_security for Apache, How to install BFD (Brute Force Detection), How to install APF (Advanced Policy Firewall), E-mail Alert on Root SSH Login, Mask Your Web Server for Enhanced Security, Guide to Chkrootkit - checking for intruders, Creating a Welcome message for SSH logins, Disable Direct Root Login, RootCheck - Root Check, Changing APF log for TDP/UDP drop's |
||
Quick Links: Debian Dedicated Servers, Direct Deposit Hosting, Unmetered Dedicated Servers, Virtual Dedicated Servers, Windows Server Management, High Traffic Web Hosting - Load Balanced Clusters, Windows 2008 Server Virtual Dedicated Servers © Copyright 2003-2008 ABN 97 125 618 662 |
||