Traditional RootKits in Use
¨http://packetstorm/security.com/UNIX/penetration/rootkits
¨Linux RootKit 5 (krk5)
–Contains Trojan horse versions of chfn,chsh, crontab, du, find, ifconfig, inetd, killall, login, ls, netstat, passwd, pidof, ps, rshd, syslogd, tcpd, top, sshd, su
¨T0rnkit for Linux and Solaris
–Contains Trojan horse versions of login, ifconfig, ps, du, ls, netstat, in.fingerd, find, top