[ Site Map ]


Member Login

Rootkit Detection E-mail
User Rating: / 0
PoorBest 
Sunday, 17 July 2011 00:06
Rootkit detection for the linux live environment. If you believe or feel that your system was attacked by a rootkit, this shell script will run and install the appropriate applications to detect such activities. Please note that this application was scripted for the Ubuntu environment. Modifications will be needed for other systems. THE SAME PRINCIPALS HERE CAN BE UTILIZED FOR THE LINUX ENVIRONMENT, TOO!

Introduction:


The script you are about to download is a script which can be run from a live CD distribution. It's intention for detection relies solely upon the live CD methods to boot up in a safe environment where a scan for such malicious applications can be conducted without bias to the programs being installed.


Although the application can also be run from the live host, this may deter and hamper detections mechanisms if a rootkit IS IN FACT on the system. Please use caution when running this application. In regard to this script, please review the source code which accompanies the download.


By default, clamav will delete any infected applications, sound a bell, and output the information to the screen. Each application is run two times. This assures that malicious code is removed, and that if any warnings are not printed to the terminal, they are shown in visible mode (as all scans will be output to the /root/Desktop/ location of the live CD).


 


© 2007 Network Defense Solutions, Inc.
All Rights Reserved