This is debian specific and was mentioned in the recent debian announce list:
Developers who are worried about their own machines should at least run chkrootkit and watch its output. Matt Taggert maintains a backport of the current version for woody at the following address:
deb http://lackof.org/taggart/debian woody/chkrootkit main deb-src http://lackof.org/taggart/debian woody/chkrootkit main
Additionally, a detailed list of precaution issues is provided by Wichert Akkerman and Matt Taggart at:
http://www.wiggy.net/debian/developer-securing/
On 12/4/2003 12:03 PM, Bopolissimus Platypus wrote:
hello all,
given the recent debian, gentoo and fsf/savannah cracks, is there a constantly updated root kit detection kit somewhere? something like antivirus, intending to detect everything and doing its best to
be continually updated. i know that something like this, in binary, can be dangerous in itself since generally it'll run as root so it can read everything on the disk... so of course i'm looking for source,
something distributed by someone ethical, and audited by paranoid people who don't trust the maintainer :).
if there isn't one, there should be... there's a project for all those college
kids who hang out on cracker IRC channels and mailing lists :). monitor
for all the new rootkits, add them to the database, help secure the net :).
tiger
-- Philippine Linux Users' Group (PLUG) Mailing List [EMAIL PROTECTED] (#PLUG @ irc.free.net.ph) Official Website: http://plug.linux.org.ph Searchable Archives: http://marc.free.net.ph . To leave, go to http://lists.q-linux.com/mailman/listinfo/plug . Are you a Linux newbie? To join the newbie list, go to http://lists.q-linux.com/mailman/listinfo/ph-linux-newbie
