chkrootkit 0.49
Last updated
Last updated
Investigate the /bin/check-down
binary
📌 The
/usr/local/bin/chkrootkit/chkrootkit
binary is executed every 60 seconds.
Check chkrootkit
version
Background both the shell and the meterpreter session with CTRL+Z
The technique will depend on the version of the target Linux Kernel and the distribution version.
It is necessary to manually enumerate a privesc vulnerable program, Chkrootkit v.0.49
in this case
- locally checks for signs of a rootkit
Chkrootkit < 0.50 is vulnerable to