public inbox for gentoo-user@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-user] sys-forensics/chkrootkit finds INFECTED binaries on ~amd64
@ 2011-03-27 21:09 walt
  2011-03-28  8:05 ` Mick
  2011-03-28 14:24 ` Paul Hartman
  0 siblings, 2 replies; 4+ messages in thread
From: walt @ 2011-03-27 21:09 UTC (permalink / raw
  To: gentoo-user

I just got an email from cron on my ~amd64 machine, containing these lines:

Checking 'find'... INFECTED
Checking 'netstat'... INFECTED

Took me a few minutes to deduce that sys-forensics/chkrootkit was the source
of those messages.  I ran chkrootkit manually and found the same messages in
the output.

I then nervously re-emerged findutils and net-tools, but chkrootkit again found
the same binaries to be "INFECTED".

Running chkrootkit on my ~x86 machine turns up no such infections even though
the same packages are installed on both machines.

Anyone have any insight into how chkrootkit works, or why the different results?

Or, can anyone reproduce my problem?

Thanks.




^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2011-03-28 23:50 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-03-27 21:09 [gentoo-user] sys-forensics/chkrootkit finds INFECTED binaries on ~amd64 walt
2011-03-28  8:05 ` Mick
2011-03-28 14:24 ` Paul Hartman
2011-03-28 23:48   ` [gentoo-user] " walt

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox