Re: Argh, infected!
Dan Osterrath <[email protected]>
| Newsgroups | gmane.linux.lfs.security,gmane.linux.lfs.support |
|---|---|
| Message-ID | <[email protected]> |
Am Montag, 13. Oktober 2003 13:53 schrieb Sam Barnett-Cormack: > On Mon, 13 Oct 2003, Sam Barnett-Cormack wrote: > > [root@mnementh chkrootkit-0.42b]# ./chkrootkit | grep INFECTED > > Checking `netstat'... INFECTED > > > > Okay, so I think I understand that... now what the heck do I do about > > it? Anyone know? > > Further: false alarm. chkrootkit was checking for addr.h, and this was > in the binary *only* until it was stripped. I stripped it, and now all > is fine. 1. Why does chkrootkit think that there is a root kit in netstat when it was compiled with addr.h? - Seems that it normaly does not do so and that there exists a root kit that does. 2. When you strip a binary you remove some extra information such as this binary was compiled with addr.h. If you strip it the extra information gets lost but it is still compiled with it and the root kit is still inside. Unfortunately chkrootkit can not see it anymore. So don't be too optimistic that you are safe. Probably you yould give us your lfs version and we could verify our results with yours... -- ---------------------------------------------------------------------- %> ln -s /dev/null /dev/brain %> ln -s /dev/urandom /dev/world %> dd if=/dev/world of=/dev/brain -- http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page
signature.asc
(application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.1 (GNU/Linux) iD8DBQA/ipcF9NbB8EM160MRAuncAKDeRy6ehhvHOYhz7KtnSzyIG+mM9QCg92Uj wWjYm0HrFRJOunENgzgdg8o= =CODF -----END PGP SIGNATURE-----