Top Qs
Timeline
Chat
Perspective
Rkhunter
Unix-based computer security tool From Wikipedia, the free encyclopedia
Remove ads
rkhunter (Rootkit Hunter) is a Unix-based tool that scans for rootkits, backdoors and possible local exploits.[1] It does this by comparing SHA-1 hashes of important files with known good ones in online databases, searching for default directories (of rootkits), wrong permissions, hidden files, suspicious strings in kernel modules, and special tests for Linux and FreeBSD. rkhunter is notable due to its inclusion in popular operating systems (Fedora,[2] Debian,[3] etc.)
Remove ads
The tool has been written in Bourne shell, to allow for portability. It can run on almost all UNIX-derived systems.
Remove ads
Development
In 2003, developer Michael Boelen released the version of Rootkit Hunter. After several years of development, early 2006, he agreed to hand over development to a development team. Since that time eight people have been working to set up the project properly and work towards the much-needed maintenance release. The project has since been moved to SourceForge.
As of May 2025 there has not been an official software release for 7 years. However, recent changes have seen the setting up of new but incomplete website at https://www.rkhunter.dev and a lot of late 2024 development code being committed https://github.com/Rootkit-Hunter/rkhunter/commits/develop/
Both the GitHub and the Sourceforge web resources seem to be sponsored by 'dogsbody' while code work seems to be being carried out by John Horne. This appears to be 'work-in-progress' but caution for Website_spoofing and similar should always be exercised.[4]
Remove ads
See also
References
External links
Wikiwand - on
Seamless Wikipedia browsing. On steroids.
Remove ads