{"id":93,"date":"2016-10-26T12:32:10","date_gmt":"2016-10-26T03:32:10","guid":{"rendered":"http:\/\/jook.pe.kr\/?p=93"},"modified":"2016-10-26T12:32:10","modified_gmt":"2016-10-26T03:32:10","slug":"chkrootkit-%ec%9d%84-%ec%82%ac%ec%9a%a9%ed%95%b4%ec%84%9c-rootkit-%ea%b2%80%ec%82%ac%ed%95%98%ea%b8%b0","status":"publish","type":"post","link":"http:\/\/jook.pe.kr\/?p=93","title":{"rendered":"chkrootkit \uc744 \uc0ac\uc6a9\ud574\uc11c rootkit \uac80\uc0ac\ud558\uae30"},"content":{"rendered":"<p>1. <a href=\"http:\/\/www.chkrootkit.org\/\">http:\/\/www.chkrootkit.org<\/a> \uc5d0\uc11c chkrootkit-0.43.tar.gz \uc744 \ub2e4\uc6b4\ub85c\ub4dc \ubc1b\ub294\ub2e4.<\/p>\n<p>2. \uc555\ucd95\uc744 \ud47c\ub2e4.<br \/>\n[root@localhost src]# tar xvfzp chkrootkit-0.43.tar.gz<br \/>\nchkrootkit-0.43\/<br \/>\nchkrootkit-0.43\/ACKNOWLEDGMENTS<br \/>\nchkrootkit-0.43\/chkproc.c<br \/>\nchkrootkit-0.43\/README<br \/>\nchkrootkit-0.43\/chklastlog.c<br \/>\nchkrootkit-0.43\/README.chkwtmp<br \/>\nchkrootkit-0.43\/COPYRIGHT<br \/>\nchkrootkit-0.43\/Makefile<br \/>\nchkrootkit-0.43\/check_wtmpx.c<br \/>\nchkrootkit-0.43\/strings.c<br \/>\nchkrootkit-0.43\/ifpromisc.c<br \/>\nchkrootkit-0.43\/chkdirs.c<br \/>\nchkrootkit-0.43\/chkrootkit.lsm<br \/>\nchkrootkit-0.43\/chkwtmp.c<br \/>\nchkrootkit-0.43\/chkrootkit<br \/>\nchkrootkit-0.43\/README.chklastlog<\/p>\n<p>3. make \uba85\ub839\uc73c\ub85c chkrootkit \uc124\uce58.<br \/>\n[root@localhost chkrootkit-0.43]# make<br \/>\n*** stopping make sense ***<br \/>\nmake[1]: Entering directory `\/usr\/local\/src\/chkrootkit-0.43&#8242;<br \/>\ngcc -DHAVE_LASTLOG_H -o chklastlog chklastlog.c<br \/>\ngcc -DHAVE_LASTLOG_H -o chkwtmp chkwtmp.c<br \/>\ngcc -DHAVE_LASTLOG_H -o ifpromisc ifpromisc.c<br \/>\ngcc -o chkproc chkproc.c<br \/>\ngcc -o chkdirs chkdirs.c<br \/>\ngcc -o check_wtmpx check_wtmpx.c<br \/>\ngcc -static -o strings-static strings.c<br \/>\nmake[1]: Leaving directory `\/usr\/local\/src\/chkrootkit-0.4<\/p>\n<p>[root@localhost chkrootkit-0.43]# ll<br \/>\ntotal 604<br \/>\n-r&#8211;r&#8211;r&#8211; 1 1000 1000 3966 Dec 27 03:02 ACKNOWLEDGMENTS<br \/>\n-rwxr-xr-x 1 root root 2704 Jun 3 13:21 check_wtmpx<br \/>\n-r&#8211;r&#8211;r&#8211; 1 1000 wheel 7195 Dec 27 03:26 check_wtmpx.c<br \/>\n-rwxr-xr-x 1 root root 6052 Jun 3 13:21 chkdirs<br \/>\n-r&#8211;r&#8211;r&#8211; 1 1000 wheel 6781 Dec 27 03:27 chkdirs.c<br \/>\n-rwxr-xr-x 1 root root 6640 Jun 3 13:21 chklastlog<br \/>\n-r&#8211;r&#8211;r&#8211; 1 1000 wheel 7729 Dec 27 03:30 chklastlog.c<br \/>\n-rwxr-xr-x 1 root root 6488 Jun 3 13:21 chkproc<br \/>\n-r&#8211;r&#8211;r&#8211; 1 1000 wheel 6676 Dec 27 03:35 chkproc.c<br \/>\n-rwxr-xr-x 1 1000 1000 67736 Dec 29 01:48 chkrootkit<br \/>\n-r&#8211;r&#8211;r&#8211; 1 1000 1000 565 Dec 27 21:35 chkrootkit.lsm<br \/>\n-rwxr-xr-x 1 root root 3936 Jun 3 13:21 chkwtmp<br \/>\n-r&#8211;r&#8211;r&#8211; 1 1000 1000 1945 Dec 25 02:37 chkwtmp.c<br \/>\n-r&#8211;r&#8211;r&#8211; 1 1000 1000 1343 Dec 25 02:37 COPYRIGHT<br \/>\n-rwxr-xr-x 1 root root 6836 Jun 3 13:21 ifpromisc<br \/>\n-r&#8211;r&#8211;r&#8211; 1 1000 1000 8771 Dec 27 09:09 ifpromisc.c<br \/>\n-r&#8211;r&#8211;r&#8211; 1 1000 1000 1448 Dec 27 06:34 Makefile<br \/>\n-r&#8211;r&#8211;r&#8211; 1 1000 1000 12387 Dec 27 21:40 README<br \/>\n-r&#8211;r&#8211;r&#8211; 1 1000 1000 1323 Dec 25 02:37 README.chklastlog<br \/>\n-r&#8211;r&#8211;r&#8211; 1 1000 1000 1292 Dec 25 02:37 README.chkwtmp<br \/>\n-r&#8211;r&#8211;r&#8211; 1 1000 1000 2437 Dec 25 02:38 strings.c<br \/>\n-rwxr-xr-x 1 root root 402496 Jun 3 13:21 strings-static<br \/>\nYou have new mail in \/var\/spool\/mail\/root<\/p>\n<p>4. chkrootlit \uba85\ub839\uc73c\ub85c \ub8e8\ud2b8\ud0b7 \uccb4\ud06c<\/p>\n<p>[root@localhost chkrootkit-0.43]# .\/chkrootkit<br \/>\nROOTDIR is `\/&#8217;<br \/>\nChecking `amd&#8217;&#8230; not found<br \/>\nChecking `basename&#8217;&#8230; not infected<br \/>\nChecking `biff&#8217;&#8230; not found<br \/>\nChecking `chfn&#8217;&#8230; not infected<br \/>\nChecking `chsh&#8217;&#8230; not infected<br \/>\nChecking `cron&#8217;&#8230; not infected<br \/>\nChecking `date&#8217;&#8230; not infected<br \/>\nChecking `du&#8217;&#8230; not infected<br \/>\nChecking `dirname&#8217;&#8230; not infected<br \/>\nChecking `echo&#8217;&#8230; not infected<br \/>\nChecking `egrep&#8217;&#8230; not infected<br \/>\nChecking `env&#8217;&#8230; not infected<br \/>\nChecking `find&#8217;&#8230; not infected<br \/>\nChecking `fingerd&#8217;&#8230; not infected<br \/>\nChecking `gpm&#8217;&#8230; not infected<br \/>\nChecking `grep&#8217;&#8230; not infected<br \/>\nChecking `hdparm&#8217;&#8230; not infected<br \/>\nChecking `su&#8217;&#8230; not infected<br \/>\nChecking `ifconfig&#8217;&#8230; not infected<br \/>\nChecking `inetd&#8217;&#8230; not tested<br \/>\nChecking `inetdconf&#8217;&#8230; not found<br \/>\nChecking `identd&#8217;&#8230; not found<br \/>\nChecking `init&#8217;&#8230; not infected<br \/>\nChecking `killall&#8217;&#8230; not infected<br \/>\nChecking `ldsopreload&#8217;&#8230; not infected<br \/>\nChecking `login&#8217;&#8230; not infected<br \/>\n.<br \/>\n.<\/p>\n<p>5. \ud2b9\uc815 \ud30c\uc77c\uac80\uc0ac.<br \/>\n[root@localhost chkrootkit-0.43]# .\/chkrootkit ps ls netstat<br \/>\nROOTDIR is `\/&#8217;<br \/>\nChecking `ps&#8217;&#8230; not infected<br \/>\nChecking `ls&#8217;&#8230; not infected<br \/>\nChecking `netstat&#8217;&#8230; not infected<\/p>\n","protected":false},"excerpt":{"rendered":"<p>1. http:\/\/www.chkrootkit.org \uc5d0\uc11c chkrootkit-0.43.tar.gz \uc744 \ub2e4\uc6b4\ub85c\ub4dc \ubc1b\ub294\ub2e4. 2. \uc555\ucd95\uc744 \ud47c\ub2e4. [root@localhost src]# tar xvfzp chkrootkit-0.43.tar.gz chkrootkit-0.43\/ chkrootkit-0.43\/ACKNOWLEDGMENTS chkrootkit-0.43\/chkproc.c chkrootkit-0.43\/README chkrootkit-0.43\/chklastlog.c<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,7],"tags":[],"_links":{"self":[{"href":"http:\/\/jook.pe.kr\/index.php?rest_route=\/wp\/v2\/posts\/93"}],"collection":[{"href":"http:\/\/jook.pe.kr\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/jook.pe.kr\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/jook.pe.kr\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/jook.pe.kr\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=93"}],"version-history":[{"count":0,"href":"http:\/\/jook.pe.kr\/index.php?rest_route=\/wp\/v2\/posts\/93\/revisions"}],"wp:attachment":[{"href":"http:\/\/jook.pe.kr\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=93"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/jook.pe.kr\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=93"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/jook.pe.kr\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=93"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}