public inbox for gentoo-amd64@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-amd64] rkhunter results
@ 2010-09-28  9:34 Paul Stear
  2010-10-09  9:28 ` Thanasis
  2010-10-10 13:43 ` [gentoo-amd64] " Lie Ryan
  0 siblings, 2 replies; 4+ messages in thread
From: Paul Stear @ 2010-09-28  9:34 UTC (permalink / raw
  To: gentoo-amd64

Hi all,
rkhunter runs every day and reports the following:-

System checks summary
=====================

File properties checks...
    Files checked: 142
    Suspect files: 141

Rootkit checks...
    Rootkits checked : 246
    Possible rootkits: 2
    Rootkit names    : Xzibit Rootkit, Dica-Kit Rootkit

Any idea how I find and remove these Rootkits?

thanks for any help
Paul
-- 
This message has been sent using kmail on gentoo.



^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [gentoo-amd64] rkhunter results
  2010-09-28  9:34 [gentoo-amd64] rkhunter results Paul Stear
@ 2010-10-09  9:28 ` Thanasis
  2010-10-10 11:10   ` [gentoo-amd64] " Duncan
  2010-10-10 13:43 ` [gentoo-amd64] " Lie Ryan
  1 sibling, 1 reply; 4+ messages in thread
From: Thanasis @ 2010-10-09  9:28 UTC (permalink / raw
  To: gentoo-amd64; +Cc: Paul Stear

 on 09/28/2010 12:34 PM Paul Stear wrote the following:
> Hi all,
> rkhunter runs every day and reports the following:-
>
> System checks summary
> =====================
>
> File properties checks...
>     Files checked: 142
>     Suspect files: 141
>
> Rootkit checks...
>     Rootkits checked : 246
>     Possible rootkits: 2
>     Rootkit names    : Xzibit Rootkit, Dica-Kit Rootkit
>
> Any idea how I find and remove these Rootkits?
>
> thanks for any help
> Paul
Did you check the log file (/var/log/rkhunter.log)?



^ permalink raw reply	[flat|nested] 4+ messages in thread

* [gentoo-amd64] Re: rkhunter results
  2010-10-09  9:28 ` Thanasis
@ 2010-10-10 11:10   ` Duncan
  0 siblings, 0 replies; 4+ messages in thread
From: Duncan @ 2010-10-10 11:10 UTC (permalink / raw
  To: gentoo-amd64

Thanasis posted on Sat, 09 Oct 2010 12:28:26 +0300 as excerpted:

> on 09/28/2010 12:34 PM Paul Stear wrote the following:
>> Hi all,
>> rkhunter runs every day and reports the following:-
>>
>> System checks summary
>> =====================
>>
>> File properties checks...
>>     Files checked: 142
>>     Suspect files: 141
>>
>> Rootkit checks...
>>     Rootkits checked : 246
>>     Possible rootkits: 2
>>     Rootkit names    : Xzibit Rootkit, Dica-Kit Rootkit
>>
>> Any idea how I find and remove these Rootkits?
>>
>> thanks for any help
>> Paul
> Did you check the log file (/var/log/rkhunter.log)?

If rkhunter is based on recorded file checksums, it's obviously going to 
have false-positives every time you update the files it checks, which 
tends to be reasonably frequently for many gentoo users (especially ~arch 
users), since given gentoo's rolling update nature.

That's very possibly why it's saying 141 out of 142 files are suspect.  A 
possible workaround would be running it before every update, to be sure, 
then running it after the update to update its checksums.

But that doesn't explain the possible rootkits detected.  Of course, 
depending on how it detects specific rootkits, that too may have false 
positives.  If it happens to the big AV folks like Norton and McAfee, and 
it does, it's going to happen to everyone, occasionally.

-- 
Duncan - List replies preferred.   No HTML msgs.
"Every nonfree program has a lord, a master --
and if you use the program, he is your master."  Richard Stallman




^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [gentoo-amd64] rkhunter results
  2010-09-28  9:34 [gentoo-amd64] rkhunter results Paul Stear
  2010-10-09  9:28 ` Thanasis
@ 2010-10-10 13:43 ` Lie Ryan
  1 sibling, 0 replies; 4+ messages in thread
From: Lie Ryan @ 2010-10-10 13:43 UTC (permalink / raw
  To: gentoo-amd64

On Tue, Sep 28, 2010 at 7:34 PM, Paul Stear <gentoo@appjaws.plus.com> wrote:
> Hi all,
> rkhunter runs every day and reports the following:-
>
> System checks summary
> =====================
>
> File properties checks...
>    Files checked: 142
>    Suspect files: 141
>
> Rootkit checks...
>    Rootkits checked : 246
>    Possible rootkits: 2
>    Rootkit names    : Xzibit Rootkit, Dica-Kit Rootkit
>
> Any idea how I find and remove these Rootkits?

FYI, some info about Dica-Kit from Sophos:
http://www.sophos.com/security/analyses/viruses-and-spyware/trojdicakit.html

and a quick google search about Xzibit seems to say that rkhunter
often give false positive for Xzibit. You might want to research about
Xzibit, and assess whether or not your case is false positive.



^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2010-10-10 14:04 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-09-28  9:34 [gentoo-amd64] rkhunter results Paul Stear
2010-10-09  9:28 ` Thanasis
2010-10-10 11:10   ` [gentoo-amd64] " Duncan
2010-10-10 13:43 ` [gentoo-amd64] " Lie Ryan

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox