|
Auditor: The Linux security tools Live CD |
 vote
 |
|
In addition to providing a handy delivery mechanism for security tools, a live security CD also lets you examine a system without disturbing any evidence that may be on the drives.
You can take your Auditor CD and start running the chkrootkit utility to see if any known rootkits are installed on the server. If you find any suspicious activity, you can take a disk image with the dd command and examine it for any possible rootkits or strange processes. You can also use the Autopsy Forensic Browser, a graphical interface that can analyze Windows, Linux, and BSD file systems (NTFS, FAT, Ext2/3) to search for files.
| | |
| |
|
| | read more | mail this link | score:8450 | -Ray, September 24, 2005 |
| |
|
More Sysadmin articles... |
|
|