Re: strange output from chkrootkit

From: zeno (bugtraqat_private)
Date: Fri Sep 13 2002 - 05:23:09 PDT

  • Next message: Rico Gloeckner: "Re: possible ssh hack"

    Install the  newest version. I haven't seen this myself. Do you happen to run tripwire?
    If so compare md5 sums. the boot dir could be showing up if you recompiled your kernel
    recently. Any LKM's show up in the kit output by any chance?
    
    - zenoat_private
    
    
    
    > 
    > I have chkrootkit setup to run every hour, and I'm getting some strange
    > warnings:
    > Warning: `//boot/vmlinuz
    > //boot/System.map
    > //boot/module-info
    > //boot/grub/menu.lst
    > //usr/X11R6/bin/X
    > //usr/X11R6/bin/ghostview
    > //usr/X11R6/bin/RunWM.Fvwm95
    > //usr/X11R6/bin/RunWM.MWM
    > //usr/X11R6/bin/RunWM.WindowMaker
    > //usr/X11R6/bin/xsetbg
    > //usr/X11R6/bin/xview
    >        .
    >        .
    >        .
    > .//sbin/modemconf
    > //sbin/netconf
    > //sbin/userconf
    > //sbin/uucpconf
    > //sbin/vregistry
    > //cdrom' is linked to another file
    > 
    > Besides that, everything else checked ok or not vulnerable.
    > 
    > Linux 2.4.9-34 #1 Sat Jun 1 06:25:16 EDT 2002 i686 unknown
    > 
    > Red Hat Linux release 7.2 (Enigma)
    > 
    > I'm completly up2date, since no new packages for my installation are
    > available.
    > Anyone seen this before?
    > 
    > Thanks,
    > 
    > Raśl
    > 
    > 
    > 
    > 
    > 
    > ----------------------------------------------------------------------------
    > This list is provided by the SecurityFocus ARIS analyzer service.
    > For more information on this free incident handling, management 
    > and tracking system please see: http://aris.securityfocus.com
    > 
    > 
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Fri Sep 13 2002 - 11:06:46 PDT