SliTaz SliTaz Forum

You are not logged in.

#1 2011-10-18 18:22:03

trufighter
Member
Registered: 2011-08-26
Posts: 14

chkrootkit found login & netcat to be infected!!!

wgetpaste source = http://paste.pocoo.org/show/494461/

-----------------------------------------------

After running chkrootkit from the package manager,

I found "login" & "netcat" to be infected. Strange

part of this is that the two programs still report

to be infected even with a fresh install. Could it

be that stable 3.0 comes with the files already

infected, or is this a false positive.

-----------------------------------------------

---------------

INFECTED FILES:

---------------

line 28

-Checking `login'... INFECTED

line 33

-Checking `netstat'... INFECTED

-------------

ROOTKIT ALERT

-------------

line 86:

Searching for Suckit rootkit... Warning: /sbin/init INFECTED

-----------------------------------------------------

rkhunter shown no rootkits, but chkrootkit did.......

-----------------------------------------------------

SucKIT: did some reasearch, chkroot is known for

false positives, I aslo used "rkhunter" which returned

no rootkits installed.

check this out...

Searching for anomalies in shell history files...

Warning: `//root/.bash_history' file size is zero

This is enough to make anyone weary, so what gives???

Any intelligent advice & wisdom would greatly be

appreciated at this time of questionable

activity.......

-[tru_fighter]-

Offline

#2 2011-10-18 18:58:10

claudinei
Administrator
Registered: 2011-03-29
Posts: 102

Re: chkrootkit found login & netcat to be infected!!!

Hi,

A full string search on google for "Searching for Suckit rootkit... Warning: /sbin/init INFECTED" returns about 3.000 pages reporting this as a false positive. See:

https://bugzilla.redhat.com/show_bug.cgi?id=636231

Offline

#3 2011-10-18 21:31:33

Trixar_za
Administrator
Registered: 2011-03-29
Posts: 1,506

Re: chkrootkit found login & netcat to be infected!!!

Yeah... It's be in trouble if it was. The problem is that it tries to detect them being symlinked to another application (rootkit) that pretends to be the applications that are called this way. Since this is how BusyBox works, the scanner will gives this false positives with regards to it. It's ultimately down a bad detection technique used by the checker.

Offline

#4 2011-10-20 05:10:21

trufighter
Member
Registered: 2011-08-26
Posts: 14

Re: chkrootkit found login & netcat to be infected!!!

Thanks guys, you mentioned that SucKIT was a false positive.

But what about "login" and "netstat", would these also fall

along lines of a false positive?

tru_fight3r

Offline

#5 2011-10-20 09:02:15

claudinei
Administrator
Registered: 2011-03-29
Posts: 102

Re: chkrootkit found login & netcat to be infected!!!

The warnings about login and netstat are false positives. Chkrootkit doesn't like busybox, as @Trixar_za pointed, that's why it is patched when packaged:

http://mirror.slitaz.org/hg/hgwebdir.py/wok/raw-file/8f3891f72b54/chkrootkit/stuff/chkrootkit.u

I GUESS the real issue is that the patch isn't avoiding the warnings about netstat and init.

Offline

#6 2011-10-20 17:41:55

trufighter
Member
Registered: 2011-08-26
Posts: 14

Re: chkrootkit found login & netcat to be infected!!!

Thanx guys, chkrootkit can worry someone esle from now on........RESOLVED!!!

Offline

Registered users online in this topic: 0, guests: 1
[Bot] ClaudeBot

Board footer

Powered by FluxBB
Modified by Visman

[ Generated in 0.025 seconds, 7 queries executed - Memory usage: 1.54 MiB (Peak: 1.77 MiB) ]