[REDHAT] Re: LKM rootkits (fwd)

David Kramer david at thekramers.net
Tue Jul 24 17:13:47 EDT 2001


This is from the Red Hat mailing list.  Looks interesting.

-------------------------------------------------------------------
DDDD   David Kramer                   http://thekramers.net
DK KD
DKK D        On a cellular level, I'm actually quite busy!
DK KD
DDDD

---------- Forwarded message ----------
I built an RPM for chkrootkit-0.33 (http://www.chkrootkit.org/), and put
it on one of my web sites.  It's supposed to detect lkm.  As for removing
it, once you have found out that a system was compromised I'd only
recommend to reformat and reinstall.  Here is the URL where you can find
the RPMs.  I hope it helps.

http://nitebirdz.openboxgroup.com/code/info/chkrootkit.html

-
Subcription/unsubscription/info requests: send e-mail with
"subscribe", "unsubscribe", or "info" on the first line of the
message body to discuss-request at blu.org (Subject line is ignored).



More information about the Discuss mailing list