- definition:rkhunter(RootkitHunterfor) is aUnixprogramthat can detectrootkits,backdoorsandexploitsdoors.To do this,it compares thehashSHA-256, SHA-512,MD5andSHA1important fileswith knownhash, which areaccessed froma databaseonline.Thus, it can detectdirectoriestypically used byrootkit, abnormalpermissions,hidden files,suspiciousstrings in thekerneland canperform specificteststoGNU/ LinuxandFreeBSD.
- Installtion :
apt-get install rkhunter
rkhunter –update
configure rkhunter :
. /etc/rkhunter.conf et /etc/default/rkhunter,add email to receive logs.
CRON_DAILY_RUN= »yes
0 comments:
Post a Comment