linux By jim, 2 months ago
A Debian administrator might want to install…
  • debsums  - check installed files for tampering, not complete, but a good start.
  • rkhunter - look for root kits.
  • chkrootkit - look for root kits.
Think about running these regularly to catch your basic root kitter.

You could cron them, but I prefer to run them manually, since I know I'd pull the cron entry if I rooted you.

I suppose you could do a forced reinstall before running for a little extra comfort.

comment by jim, 2 months ago
I think a better tool would be one that used a central repository with a copy of each package and called on the observed machine to generate on the fly signatures of files with a random seed.

A truly nasty rooter could still thwart that by faking things in either the C runtime library or the appropriate system calls.
The femtoblogger software is being written by Jim Studt. The content of this page is provided by anonymous individuals. If you believe something on this page is innapropriate contact Jim Studt.

Contribute

login
logout
post
create account (12 seconds)
recent comments

Filter

everything
coding
femtoblogger
language
linux

Search

Browsers

googlebot28.7%
yahoobot22.7%
IE 615.8%
Safari9.1%
msnbot8.5%
Firefox5.5%
hiding4.3%
IE 73.9%
Opera1.1%
iPhone0.1%
jeevesbot0.1%
Konqueror0.0%
unknown0.0%

Archives

2008August1
July2
June3
May3
April4
February1
January4
2007December1
November3
October8
September18