Re: Argh, infected!

Dan Osterrath <[email protected]>
Newsgroups gmane.linux.lfs.security,gmane.linux.lfs.support
Message-ID <[email protected]>
Am Montag, 13. Oktober 2003 13:53 schrieb Sam Barnett-Cormack:
> On Mon, 13 Oct 2003, Sam Barnett-Cormack wrote:
> > [root@mnementh chkrootkit-0.42b]# ./chkrootkit | grep INFECTED
> > Checking `netstat'... INFECTED
> >
> > Okay, so I think I understand that... now what the heck do I do about
> > it? Anyone know?
>
> Further: false alarm. chkrootkit was checking for addr.h, and this was
> in the binary *only* until it was stripped. I stripped it, and now all
> is fine.

1. Why does chkrootkit think that there is a root kit in netstat when it was 
compiled with addr.h? - Seems that it normaly does not do so and that there 
exists a root kit that does.
2. When you strip a binary you remove some extra information such as this 
binary was compiled with addr.h. If you strip it the extra information gets 
lost but it is still compiled with it and the root kit is still inside. 
Unfortunately chkrootkit can not see it anymore.

So don't be too optimistic that you are safe.

Probably you yould give us your lfs version and we could verify our results 
with yours...

-- 
----------------------------------------------------------------------
%> ln -s /dev/null /dev/brain
%> ln -s /dev/urandom /dev/world
%> dd if=/dev/world of=/dev/brain

-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQA/ipcF9NbB8EM160MRAuncAKDeRy6ehhvHOYhz7KtnSzyIG+mM9QCg92Uj
wWjYm0HrFRJOunENgzgdg8o=
=CODF
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.