Fedora Linux Support Community & Resources Center
  #1  
Old 3rd April 2004, 03:28 PM
fedora-package-announce-admin@fedora.us
Guest
 
Posts: n/a
Update: chkrootkit 0.43 (RH 8.0, RH 9, FC 1, stable)

Name : chkrootkit
Version : 0.43
Release : 0.fdr.4.1
Group : Applications/System
Size : 516176
License : COPYRIGHTED
Signature : DSA/SHA1, Fri 02 Apr 2004 04:13:56 CEST, Key ID 29d5ba248df56d05
Packager : Fedora Linux, <http://fedora.us>
URL : http://www.chkrootkit.org
Summary : A tool to locally check for signs of a rootkit


Description :
chkrootkit is a tool to locally check for signs of a rootkit. It contains:

* chkrootkit: shell script that checks system binaries for rootkit
modification. The following tests are made:

o aliens asp bindshell lkm rexedcs sniffer wted scalper slapper z2 amd
basename biff chfn chsh cron date du dirname echo egrep env find fingerd
gpm grep hdparm su ifconfig inetd inetdconf init identd killall ldsopreload
login ls lsof mail mingetty netstat named passwd pidof pop2 pop3 ps pstree
rpcinfo rlogind rshd slogin sendmail sshd syslogd tar tcpd tcpdump top
telnetd timed traceroute vdir w write

* ifpromisc.c: checks if the interface is in promiscuous mode.
* chklastlog.c: checks for lastlog deletions.
* chkwtmp.c: checks for wtmp deletions.
* check_wtmpx.c: checks for wtmpx deletions. (Solaris only)
* chkproc.c: checks for signs of LKM trojans.
* chkdirs.c: checks for signs of LKM trojans.
* strings.c: quick and dirty strings replacement.


* Sat Mar 13 2004 Michael Schwendt <mschwendt[AT]users.sf.net> - 0:0.43-0.fdr.4

- rh80 doesn't have sed -i, use perl instead (#1326).
- Obsolete chkrootkit-strings patch due to soft-link since 0.43-0.fdr.1.

* Fri Feb 27 2004 Michael Schwendt <mschwendt[AT]users.sf.net> - 0:0.43-0.fdr.3

- Make in %build section (#1326).

* Fri Feb 27 2004 Michael Schwendt <mschwendt[AT]users.sf.net> - 0:0.43-0.fdr.2

- Substitute a few hardcoded paths (#1326).

* Thu Feb 26 2004 Michael Schwendt <mschwendt[AT]users.sf.net> - 0:0.43-0.fdr.1

- Update to 0.43.
- Add dependency on consolehelper binary.
- Drop patched chkrootkit script due to change in 0.42-0.fdr.3.b.
- Make available "strings-static" as "strings", too.

* Wed Dec 10 2003 Michael Schwendt <mschwendt[AT]users.sf.net> - 0:0.42-0.fdr.3.b

- Make /usr/bin/chkrootkit enter chkrootkit home directory.
This puts its own helper tools into its search path.

* Thu Dec 04 2003 Phillip Compton <pcompton[AT]proteinmedia.com> - 0.42-0.fdr.2.b

- Move binaries out of %{_datadir}.





Attached Files
File Type: (190 Bytes, 130 views)
 

Tags
043, chkrootkit, stable, update

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Update: firestarter 0.9.3 (FC1,FC2,stable) fedora-package-announce-admin@fedora.us Advisories & Updates 0 9th May 2004 03:25 AM
Update: gkrellmms-2.1.19 (FC1, stable) fedora-package-announce-admin@fedora.us Advisories & Updates 0 8th May 2004 06:31 PM
Update: lua-5.0-0.fdr.2 (RH9,FC1/stable) fedora-package-announce-admin@fedora.us Advisories & Updates 0 9th December 2003 10:36 PM
Update: gpa 0.7.0 (RH9,FC1/stable) fedora-package-announce-admin@fedora.us Advisories & Updates 0 8th December 2003 09:57 PM
Update: tpb-0.6.0-0.fdr.3 (RH9,FC1/stable) fedora-package-announce-admin@fedora.us Advisories & Updates 0 1st December 2003 07:13 PM


Current GMT-time: 23:56 (Sunday, 19-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat