How to do it...

In this section, we will see how to install and configure Linux rootkit scanning tools and use as per our requirements:

  1. To begin with, we will install chkrootkit, a classic rootkit scanner for Linux, as shown here:

  1. Once the software has been installed, we can check the path where the software has been installed by running the following command:

  1. Next, we check the Help menu to understand the options that can be used to run the tool:

  1. If we want to see the list of available tests in chkrootkit, we can run the following command:

  1. Now, let's start the scan as shown here:

  1. As we can see in the scan output, the software is checking for all known rootkit signatures:

  1. Another well-know tool that can be used for scanning rootkits is rkhunter. Install the tool by running the following command:

  1. Next, check the Help menu to see the options that can be used when running the software:

  1. Now, start the scan as shown here:

  1. As seen in the output, all known rootkit signatures have been checked and none were found:

  1. Finally, when the scan completes, the tool will show a scan summary as seen here:

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
3.133.108.241