ForumFalscher Alarm mit chkrootkit????
Matthias Mente – Montag, 28. Februar 2005 19:51 Uhr

zu Hülf!!!

Betriebssystem Fedora Core 3 Gnome 2.8/KDE 3.3.0
Beim Test mit chkrootkit Version 0.45 ist angeblich ein Prozess versteckt sowie Warnung vor lkm Trojaner (siehe unten).

Test mit installiertem chkrootkit 0.45 unter
Befehl: chkrootkit -r /
.
Checking `asp’… not infected
Checking `bindshell’… not infected
Checking `lkm’… You have 1 process hidden for readdir command
You have 1 process hidden for ps command
chkproc: Warning: Possible LKM Trojan installed
Checking `rexedcs’… not found
Checking `sniffer’… Checking `w55808’… not infected

Test mit chkrootkit 0.45 direkt aus Verzeichnis gestartet unter
Befehl: ./chkrootkit -r /
.
Checking `asp’… not infected
Checking `bindshell’… not infected
Checking `lkm’… Checking `rexedcs’… not found
Checking `sniffer’… not tested: can’t exec ./ifpromisc

Test mit Befehl: ./chkrootkit ps ls sniffer
root@localhost ~]# chkrootkit ps ls sniffer
ROOTDIR is `/’
Checking `ps’… not infected
Checking `ls’… not infected
Checking `sniffer’… [root@localhost ~]#

Auch Nachprüfung der Binärdateien auf Veränderung mit Befehl:
rpm -V procps

bringt keine Ergebnisse.

Und noch ein Test: Portscan auf der Seite
http://scan.sygatetech.com/
Ergebnis: Sowohl bei Quickscan, als auch bei Stealthscan sind alle
getesteten Ports perfekt ge”blocked” – also geschlossen UND versteckt.

Besteht Anlass zur Beunruhigung, oder kann ich jetzt ruhig schlafen???
Wäre für jede Hilfe dankbar!
Mats

1 Antwort
Lars S. – Dienstag, 01. März 2005 16:12 Uhr

Wenn du nptl aktiviert hast ist das normal und kein Grund zur Besorgnis.
Google mal nach ‘nptl +chkrootkit’ da gibt es viele Seiten und Threads zu.