25 Sept 2011

Rootkit Hunter sous Mac OS X

Voici comment installer, mettre à jour et exécuter rkhunter sous Mac OS-X…
Below you’ll find how to  install, update and execute rkhunter under Mac OS-X…
Télécharger Rootkit Hunter de Sourceforge (download link for rkhunter)

tar xvfz rkhunter-1.3.8.tar.gzsudo ./installer.sh --layout default --install

$ sudo rkhunter --propupd

$ sudo rkhunter --update
 [ Rootkit Hunter version 1.3.8 ]
 Checking rkhunter data files...
 Checking file mirrors.dat                                  [ No update ]
 Checking file programs_bad.dat                             [ No update ]
 Checking file backdoorports.dat                            [ No update ]
 Checking file suspscan.dat                                 [ No update ]
 Checking file i18n/cn                                      [ No update ]
 Checking file i18n/de                                      [ No update ]
 Checking file i18n/en                                      [ No update ]
 Checking file i18n/zh                                      [ No update ]
 Checking file i18n/zh.utf8                                 [ No update ]

$ sudo rkhunter -c -sk
 [ Rootkit Hunter version 1.3.8 ]
Checking system commands...
[...]
Checking for rootkits...
Performing check of known rootkit files and directories
 55808 Trojan - Variant A                                 [ Not found ]
 ADM Worm                                                 [ Not found ]
 AjaKit Rootkit                                           [ Not found ]
 [...]
System checks summary
 =====================
File properties checks...
 Files checked: 90
 Suspect files: 3
Rootkit checks...
 Rootkits checked : 160
 Possible rootkits: 1 Rootkit names    : Dica-Kit Rootkit 
(NB: Don't mind the above, this is a known false-positive)
Applications checks...
 Applications checked: 6
 Suspect applications: 2
The system checks took: 2 minutes and 16 seconds
All results have been written to the log file (/var/log/rkhunter.log)
One or more warnings have been found while checking the system.
 Please check the log file (/var/log/rkhunter.log)