LWN.net Logo

chkrootkit 0.37 is now available

From:  Klaus Steding-Jessen <jessen@nic.br>
To:  sectools@securityfocus.com
Subject:  Announce: chkrootkit 0.37 is now available!
Date:  Mon, 16 Sep 2002 20:55:11 -0300

chkrootkit 0.37 is now available!  This version includes:


  * chklastlog.c fix; (thanks to Gerard van Wageningen)

  * chkproc.c improvements; (thanks to Morohoshi Akihiko, Kostya
                             Kortchinsky and Aaron Sherman)

  * new rootkits detected
    - OpenBSD rk v1
    - Illogic rootkit (thanks to Andrey Chernomyrdin)
    - SK rootkit (thanks to Razvan Cosma)

  * new worms detected
    - scalper (FreeBSD.Scalper.worm)
    - slapper (Apache/mod_ssl Worm)

  * minor bug fix in chkrootkit script;
  * NetBSD 1.5.2 support;


chkrootkit is a tool to locally check for signs of a rootkit.  More
information about chkrootkit and rootkits can be found at
http://www.chkrootkit.org/.

The package was successfully tested on the following systems: Linux
2.0.x, 2.2.x and 2.4.x (any distribution), FreeBSD 2.2.x, 3.x and 4.x,
OpenBSD 2.6, 2.7, 2.8, 2.9, 3.0 and 3.1, NetBSD 1.5.2 and Solaris
2.5.1, 2.6 and 8.0.

chkrootkit's tarball and its MD5 checksum are available at:

  * ftp://ftp.pangeia.com.br/pub/seg/pac/chkrootkit.tar.gz
  * ftp://ftp.pangeia.com.br/pub/seg/pac/chkrootkit.md5

or at the chkrootkit's homepage, at:

  * http://www.chkrootkit.org/

More info about rootkits can be found at:

  * http://www.chkrootkit.org/index.html#related_links


Enjoy,

Klaus Steding-Jessen


(Log in to post comments)

Copyright © 2002, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds