PDA

View Full Version : RootKit Files


allan
07-27-03, 10:58 AM
I am trying to make a backup of files that are commonly replaced by rootkits. So far I am including:

ls
ps
find
wget
top
kill
killall
tcpd
syslogd
ifconfig

Any others?

no1v2
07-27-03, 12:14 PM
Netstat, lsof, and possibly (ba)sh come to mind.

Edit: Make that possibly *sh.

Another Edit: Ssh too.

suppleSupport
08-06-03, 02:47 PM
grep
pstree
locate
w