2022年8月、ホームページを全面リニューアルしました! 情報を分かりやすくお伝えできるサイト作りを目指してまいります。

rkhunterでシステムチェック!

ここ のネタの最新のバージョンでのインストールとシステムチェックの方法を伝授する。
最新情報は、少々インストール方法が変わったので、その旨見ていただきたい。今回のインストールマシンのOSは、Debian GNU/Linuxであり、Debianでは本来debパッケージにrkhunterが有るのでaptitudeやapt-getでインストール可能であるが、あえてソースインストールを実行しているのでその旨、了解いただきたい。

インストール環境:
[root@infosystem ~]# lspci
00:00.0 Host bridge: Intel Corporation 440BX/ZX/DX – 82443BX/ZX/DX Host bridge (rev 03)
00:01.0 PCI bridge: Intel Corporation 440BX/ZX/DX – 82443BX/ZX/DX AGP bridge (rev 03)
00:07.0 ISA bridge: Intel Corporation 82371AB/EB/MB PIIX4 ISA (rev 02)
00:07.1 IDE interface: Intel Corporation 82371AB/EB/MB PIIX4 IDE (rev 01)
00:07.2 USB Controller: Intel Corporation 82371AB/EB/MB PIIX4 USB (rev 01)
00:07.3 Bridge: Intel Corporation 82371AB/EB/MB PIIX4 ACPI (rev 02)
00:0d.0 Ethernet controller: 3Com Corporation 3c905C-TX/TX-M [Tornado] (rev 78)
01:00.0 VGA compatible controller: nVidia Corporation NV5 [RIVA TNT2/TNT2 Pro] (rev 11)

[root@infosystem ~]# more /proc/cpuinfo
processor : 0
vendor_id : GenuineIntel
cpu family : 6
model : 7
model name : Pentium III (Katmai)
stepping : 3
cpu MHz : 598.645
cache size : 512 KB
fdiv_bug : no
hlt_bug : no
f00f_bug : no
coma_bug : no
fpu : yes
fpu_exception : yes
cpuid level : 2
wp : yes
flags : fpu vme de pse tsc msr pae mce cx8 mtrr pge mca cmov pat pse36 mmx fxsr sse
bogomips : 1198.39

[root@infosystem ~]# uname -a
Linux infosystem 2.6.9-55.0.12.EL #1 Fri Nov 2 10:57:39 EDT 2007 i686 i686 i386 GNU/Linux

1.インストール
1)rkhunterソースのゲット
ここ
 からrkhunterのソースをゲットする。2007年11月現在では、 rkhunter-1.3.0.tar.gz が最新であった。
[root@infosystem ~]# cd /usr/local/src/
[root@infosystem src]# wget http://downloads.sourceforge.net/rkhunter/rkhunter-1.3.0.tar.gz
–11:34:36– http://downloads.sourceforge.net/rkhunter/rkhunter-1.3.0.tar.gz
=> `rkhunter-1.3.0.tar.gz’
Resolving fifo… 192.168.0.12
Connecting to fifo|192.168.0.12|:8080… connected.
Proxy request sent, awaiting response… 302 Moved Temporarily
Location: http://nchc.dl.sourceforge.net/sourceforge/rkhunter/rkhunter-1.3.0.tar.gz [following]
–11:34:37– http://nchc.dl.sourceforge.net/sourceforge/rkhunter/rkhunter-1.3.0.tar.gz
=> `rkhunter-1.3.0.tar.gz’
Connecting to fifo|192.168.0.12|:8080… connected.
Proxy request sent, awaiting response… 200 OK
Length: 252,011 (246K) [application/x-gzip]

100%[================================>] 252,011 628.20K/s

11:34:39 (627.59 KB/s) – `rkhunter-1.3.0.tar.gz’ saved [252011/252011]

2)ソースの展開
ゲットしたソースを展開する。
[root@infosystem src]# tar zxvf rkhunter-1.3.0.tar.gz
rkhunter-1.3.0/
rkhunter-1.3.0/files/
rkhunter-1.3.0/files/contrib/
rkhunter-1.3.0/files/contrib/README.txt
rkhunter-1.3.0/files/contrib/rkhunter_remote_howto.txt
rkhunter-1.3.0/files/contrib/run_rkhunter.sh
rkhunter-1.3.0/files/ACKNOWLEDGMENTS
rkhunter-1.3.0/files/CHANGELOG
rkhunter-1.3.0/files/FAQ
rkhunter-1.3.0/files/LICENSE
rkhunter-1.3.0/files/README
rkhunter-1.3.0/files/WISHLIST
rkhunter-1.3.0/files/backdoorports.dat
rkhunter-1.3.0/files/check_modules.pl
rkhunter-1.3.0/files/check_port.pl
rkhunter-1.3.0/files/check_update.sh
rkhunter-1.3.0/files/defaulthashes.dat
rkhunter-1.3.0/files/filehashmd5.pl
rkhunter-1.3.0/files/filehashsha1.pl
rkhunter-1.3.0/files/md5blacklist.dat
rkhunter-1.3.0/files/mirrors.dat
rkhunter-1.3.0/files/os.dat
rkhunter-1.3.0/files/programs_bad.dat
rkhunter-1.3.0/files/programs_good.dat
rkhunter-1.3.0/files/readlink.sh
rkhunter-1.3.0/files/rkhunter
rkhunter-1.3.0/files/rkhunter.8
rkhunter-1.3.0/files/rkhunter.conf
rkhunter-1.3.0/files/rkhunter.spec
rkhunter-1.3.0/files/showfiles.pl
rkhunter-1.3.0/files/stat.pl
rkhunter-1.3.0/files/suspscan.dat
rkhunter-1.3.0/files/development/
rkhunter-1.3.0/files/development/createfilehashes.pl
rkhunter-1.3.0/files/development/createhashes.sh
rkhunter-1.3.0/files/development/createhashesall.sh
rkhunter-1.3.0/files/development/i18nchk
rkhunter-1.3.0/files/development/osinformation.sh
rkhunter-1.3.0/files/development/rpmhashes.sh
rkhunter-1.3.0/files/development/rpmprelinkhashes.sh
rkhunter-1.3.0/files/development/search_dead_sysmlinks.sh
rkhunter-1.3.0/files/i18n/
rkhunter-1.3.0/files/i18n/cn
rkhunter-1.3.0/files/i18n/en
rkhunter-1.3.0/files/testing/
rkhunter-1.3.0/files/testing/rkhunter.conf
rkhunter-1.3.0/files/testing/rootkitinfo.txt
rkhunter-1.3.0/files/testing/stringscanner.sh
rkhunter-1.3.0/files/tools/
rkhunter-1.3.0/files/tools/README
rkhunter-1.3.0/files/tools/update_client.sh
rkhunter-1.3.0/files/tools/update_server.sh
rkhunter-1.3.0/installer.sh

[root@infosystem src]# chown -R root.root rkhunter-1.3.0

3)シェルスクリプトによるインストーラの起動
ソース中にインストーラーが用意されているので、それを使ってインストールする。
[root@infosystem rkhunter-1.3.0]# cd rkhunter-1.3.0

[root@infosystem rkhunter-1.3.0]# ./installer.sh –layout default –install
Checking system for:
Rootkit Hunter installer files: found. OK
Available file retrieval tools:
wget: found. OK
Starting installation/update

Checking PREFIX /usr/local: exists, and is writable. OK
Checking installation directories:
Directory /usr/local/share/doc/rkhunter-1.3.0: creating: OK.
Directory /usr/local/share/man/man8: exists, and is writable. OK
Directory /etc: exists, and is writable. OK
Directory /usr/local/bin: exists, and is writable. OK
Directory /usr/local/lib: exists, and is writable. OK
Directory /var/lib: exists, and is writable. OK
Directory /usr/local/lib/rkhunter/scripts: creating: OK.
Directory /var/lib/rkhunter/db: creating: OK.
Directory /var/lib/rkhunter/tmp: creating: OK.
Directory /var/lib/rkhunter/db/i18n: creating: OK.
Installing check_modules.pl: OK.
Installing check_update.sh: OK.
Installing check_port.pl: OK.
Installing filehashmd5.pl: OK.
Installing filehashsha1.pl: OK.
Installing showfiles.pl: OK.
Installing stat.pl: OK.
Installing readlink.sh: OK.
Installing backdoorports.dat: OK.
Installing mirrors.dat: OK.
Installing os.dat: OK.
Installing programs_bad.dat: OK.
Installing programs_good.dat: OK.
Installing defaulthashes.dat: OK.
Installing md5blacklist.dat: OK.
Installing suspscan.dat: OK.
Installing rkhunter.8: OK.
Installing ACKNOWLEDGMENTS: OK.
Installing CHANGELOG: OK.
Installing FAQ: OK.
Installing LICENSE: OK.
Installing README: OK.
Installing WISHLIST: OK.
Installing language support files: OK.
Installing rkhunter: OK.
Installing rkhunter.conf: OK.
Installation finished.

4)設定は・・・・
デフォルトでは、rkhunter.confが/etcディレクトリへ突っ込まれているので、パラメータの変更は随時行う。
しかし、ほとんどの場合は、何もいじらなくてもすむと思う。

2.実際の運用
1)まずは定義ファイルのアップデート
新しいチェック用定義ファイルが更新されているかも知れないので、運用の前にアップデートチェックを実行する。
[root@infosystem rkhunter-1.3.0]# /usr/local/bin/rkhunter –update
[ Rootkit Hunter version 1.3.0 ]

Checking rkhunter data files…
Checking file mirrors.dat [ No update ]
Checking file programs_bad.dat [ No update ]
Checking file backdoorports.dat [ No update ]
Checking file suspscan.dat [ No update ]
Checking file i18n/cn [ No update ]
Checking file i18n/en [ Updated ]

2)運用
以下のようにオプション付きコマンドを実行する。
[root@infosystem rkhunter-1.3.0]# /usr/local/bin/rkhunter -c –createlogfile
/usr/bin/tail [ OK ]
/usr/bin/test [ OK ]
/usr/bin/top [ OK ]
/usr/bin/tr [ OK ]
/usr/bin/uniq [ OK ]
/usr/bin/users [ OK ]
/usr/bin/vmstat [ OK ]
/usr/bin/w [ OK ]
/usr/bin/watch [ OK ]
/usr/bin/wc [ OK ]
/usr/bin/wget [ OK ]
/usr/bin/whatis [ Warning ]
/usr/bin/whereis [ OK ]
/usr/bin/which [ OK ]
/usr/bin/who [ OK ]
/usr/bin/whoami [ OK ]
/usr/bin/gawk [ OK ]
/sbin/chkconfig [ OK ]
/sbin/depmod [ OK ]
/sbin/ifconfig [ OK ]
/sbin/ifdown [ Warning ]
/sbin/ifup [ Warning ]
/sbin/init [ OK ]
/sbin/insmod [ OK ]
/sbin/ip [ OK ]
/sbin/lsmod [ OK ]
/sbin/modinfo [ OK ]
/sbin/modprobe [ OK ]
/sbin/nologin [ OK ]
/sbin/rmmod [ OK ]
/sbin/runlevel [ OK ]
/sbin/sulogin [ OK ]
/sbin/sysctl [ OK ]
/sbin/syslogd [ OK ]
/usr/sbin/adduser [ OK ]
/usr/sbin/chroot [ OK ]
/usr/sbin/groupadd [ OK ]
/usr/sbin/groupdel [ OK ]
/usr/sbin/groupmod [ OK ]
/usr/sbin/grpck [ OK ]
/usr/sbin/kudzu [ OK ]
/usr/sbin/lsof [ OK ]
/usr/sbin/prelink [ OK ]
/usr/sbin/pwck [ OK ]
/usr/sbin/sestatus [ OK ]
/usr/sbin/tcpd [ OK ]
/usr/sbin/useradd [ OK ]
/usr/sbin/userdel [ OK ]
/usr/sbin/usermod [ OK ]
/usr/sbin/vipw [ OK ]
/usr/sbin/xinetd [ OK ]
/usr/local/bin/rkhunter [ OK ]

[Press <ENTER> to continue]


Checking for rootkits…

Performing check of known rootkit files and directories
55808 Trojan – Variant A [ Not found ]
ADM Worm [ Not found ]
AjaKit Rootkit [ Not found ]
aPa Kit [ Not found ]
Apache Worm [ Not found ]
Ambient (ark) Rootkit [ Not found ]
Balaur Rootkit [ Not found ]
BeastKit Rootkit [ Not found ]
beX2 Rootkit [ Not found ]
BOBKit Rootkit [ Not found ]
CiNIK Worm (Slapper.B variant) [ Not found ]
Danny-Boy’s Abuse Kit [ Not found ]
Devil RootKit [ Not found ]
Dica-Kit Rootkit [ Not found ]
Dreams Rootkit [ Not found ]
Duarawkz Rootkit [ Not found ]
Enye LKM [ Not found ]
Flea Linux Rootkit [ Not found ]
FreeBSD Rootkit [ Not found ]
Fuck`it Rootkit [ Not found ]
GasKit Rootkit [ Not found ]
Heroin LKM [ Not found ]
HjC Kit [ Not found ]
ignoKit Rootkit [ Not found ]
ImperalsS-FBRK Rootkit [ Not found ]
Irix Rootkit [ Not found ]
Kitko Rootkit [ Not found ]
Knark Rootkit [ Not found ]
Li0n Worm [ Not found ]
Lockit / LJK2 Rootkit [ Not found ]
Mood-NT Rootkit [ Not found ]
MRK Rootkit [ Not found ]
Ni0 Rootkit [ Not found ]
Ohhara Rootkit [ Not found ]
Optic Kit (Tux) Worm [ Not found ]
Oz Rootkit [ Not found ]
Phalanx Rootkit [ Not found ]
Phalanx Rootkit (strings) [ Not found ]
Portacelo Rootkit [ Not found ]
R3dstorm Toolkit [ Not found ]
RH-Sharpe’s Rootkit [ Not found ]
RSHA’s Rootkit [ Not found ]
Scalper Worm [ Not found ]
Sebek LKM [ Not found ]
Shutdown Rootkit [ Not found ]
SHV4 Rootkit [ Not found ]
SHV5 Rootkit [ Not found ]
Sin Rootkit [ Not found ]
Slapper Worm [ Not found ]
Sneakin Rootkit [ Not found ]
Suckit Rootkit [ Not found ]
SunOS Rootkit [ Not found ]
SunOS / NSDAP Rootkit [ Not found ]
Superkit Rootkit [ Not found ]
TBD (Telnet BackDoor) [ Not found ]
TeLeKiT Rootkit [ Not found ]
T0rn Rootkit [ Not found ]
Trojanit Kit [ Not found ]
Tuxtendo Rootkit [ Not found ]
URK Rootkit [ Not found ]
VcKit Rootkit [ Not found ]
Volc Rootkit [ Not found ]
X-Org SunOS Rootkit [ Not found ]
zaRwT.KiT Rootkit [ Not found ]

Performing additional rootkit checks
Suckit Rookit additional checks [ OK ]
Checking for possible rootkit files and directories [ None found ]
Checking for possible rootkit strings [ None found ]

Performing malware checks
Checking running processes for suspicious files [ None found ]
Checking for login backdoors [ None found ]
Checking for suspicious directories [ None found ]
Checking for sniffer log files [ None found ]

Performing trojan specific checks
Checking for enabled xinetd services [ None found ]

Performing Linux specific checks
Checking kernel module commands [ OK ]
Checking kernel module names [ OK ]

[Press <ENTER> to continue]


Checking the network…

Performing check for backdoor ports
Checking for UDP port 2001 [ Not found ]
Checking for TCP port 2006 [ Not found ]
Checking for TCP port 2128 [ Not found ]
Checking for TCP port 14856 [ Not found ]
Checking for TCP port 47107 [ Not found ]
Checking for TCP port 60922 [ Not found ]

Performing checks on the network interfaces
Checking for promiscuous interfaces [ None found ]

[Press <ENTER> to continue]


Checking the local host…

Performing system boot checks
Checking for local host name [ Found ]
Checking for local startup files [ Found ]
Checking local startup files for malware [ None found ]
Checking system startup files for malware [ None found ]

Performing group and account checks
Checking for passwd file [ Found ]
Checking for root equivalent (UID 0) accounts [ None found ]
Checking for passwordless accounts [ None found ]
Checking for passwd file changes [ None found ]
Checking for group file changes [ None found ]
Checking root account shell history files [ OK ]

Performing system configuration file checks
Checking for SSH configuration file [ Found ]
Checking if SSH root access is allowed [ Warning ]
Checking if SSH protocol v1 is allowed [ Warning ]
Checking for running syslog daemon [ Found ]
Checking for syslog configuration file [ Found ]
Checking if syslog remote logging is allowed [ Not allowed ]

Performing filesystem checks
Checking /dev for suspicious file types [ None found ]
Checking for hidden files and directories [ Warning ]

[Press <ENTER> to continue]


Checking application versions…

Checking version of GnuPG [ Warning ]
Checking version of OpenSSL [ Warning ]
Checking version of Procmail MTA [ OK ]
Checking version of OpenSSH [ OK ]


System checks summary
=====================

File properties checks…
Required commands check failed
Files checked: 127
Suspect files(疑わしいファイル): 6

Rootkit checks…
Rootkits checked : 114
Possible rootkits(仕掛けれらているrootkit): 0

Applications checks…
Applications checked: 4
Suspect applications(疑わしいアプリケーション): 2

The system checks took: 2 minutes and 35 seconds

All results have been written to the logfile (/var/log/rkhunter.log)

One or more warnings have been found while checking the system.
Please check the log file (/var/log/rkhunter.log)
以上のような結果が出た。この結果のlogは、/var/log/rkhunter.logに出力される。さらに、結果はroot宛にメール送信される。

3)logの確認
rkhunter.logを確認してみる。
[root@infosystem rkhunter-1.3.0]# more /var/log/rkhunter.log
[11:59:49] Running Rootkit Hunter version 1.3.0 on infosystem
[11:59:49]
[11:59:49] Info: Start date is Tue Nov 27 11:59:49 JST 2007
[11:59:49]
[11:59:49] Checking configuration file and command-line options…
[11:59:49] Info: Detected operating system is ‘Linux’
[11:59:49] Info: Uname output is ‘Linux infosystem 2.6.9-55.0.12.EL #1 Fri Nov 2 10:57:39 EDT 2007 i686 i686 i386 GNU/Linux’
[11:59:50] Info: Command line is /usr/local/bin/rkhunter -c –createlogfile
[11:59:50] Info: Environment shell is /bin/bash; rkhunter is using bash
[11:59:50] Info: Using configuration file ‘/etc/rkhunter.conf’
[11:59:50] Info: Installation directory is ‘/usr/local’
[11:59:50] Info: Using language ‘en’
[11:59:50] Info: Using ‘/var/lib/rkhunter/db’ as the database directory
[11:59:50] Info: Using ‘/usr/local/lib/rkhunter/scripts’ as the support script directory
[11:59:50] Info: Using ‘/usr/kerberos/sbin /usr/kerberos/bin /usr/local/sbin /usr/local/bin /sbin /bin /usr/sbin /usr/bin /usr/X11R6/bin /root/bin /bin /usr/bin /sbin /usr/sbin /usr/local/bin /usr/local/sbin /usr/libexec /usr/local/libexec’ as the command directories
[11:59:50] Info: Using ‘/’ as the root directory
[11:59:50] Info: Using ‘/var/lib/rkhunter/tmp’ as the temporary directory
[11:59:50] Info: No mail-on-warning address configured
[11:59:50] Info: X will automatically be detected
[11:59:50] Info: Found the ‘diff’ command: /usr/bin/diff
[11:59:50] Info: Found the ‘file’ command: /usr/bin/file
[11:59:50] Info: Found the ‘find’ command: /usr/bin/find
[11:59:50] Info: Found the ‘ifconfig’ command: /sbin/ifconfig
[11:59:50] Info: Found the ‘ip’ command: /sbin/ip
[11:59:50] Info: Found the ‘ldd’ command: /usr/bin/ldd
[11:59:50] Info: Found the ‘lsattr’ command: /usr/bin/lsattr
[11:59:50] Info: Found the ‘lsmod’ command: /sbin/lsmod
[11:59:50] Info: Found the ‘lsof’ command: /usr/sbin/lsof
[11:59:51] Info: Found the ‘mktemp’ command: /bin/mktemp
[11:59:51] Info: Found the ‘netstat’ command: /bin/netstat
[11:59:51] Info: Found the ‘perl’ command: /usr/bin/perl
[11:59:51] Info: Found the ‘ps’ command: /bin/ps
[11:59:51] Info: Found the ‘pwd’ command: /bin/pwd
[11:59:51] Info: Found the ‘readlink’ command: /usr/bin/readlink
[11:59:51] Info: Found the ‘sort’ command: /bin/sort
[11:59:51] Info: Found the ‘stat’ command: /usr/bin/stat
[11:59:51] Info: Found the ‘strings’ command: /usr/bin/strings
[11:59:51] Info: Found the ‘uniq’ command: /usr/bin/uniq
[11:59:51] Info: System is using prelinking
[11:59:51] Info: Found the ‘prelink’ command: /usr/sbin/prelink
[11:59:51] Info: Found the ‘sestatus’ command: /usr/sbin/sestatus
[11:59:51] Info: SELinux is disabled
[11:59:51] Info: Using prelink command (with SHA1) for file hash checks
[11:59:51] Info: The hash function field index is set to 1
[11:59:51] Info: No package manager specified: using prelink command with ‘SHA1’
[11:59:51] Info: Previous file attributes were stored
[11:59:52] Info: Enabled tests are: all
[11:59:52] Info: Disabled tests are: suspscan hidden_procs deleted_files packet_cap_apps
[11:59:52] Info: Found ksym file ‘/proc/kallsyms’
[11:59:52]
[11:59:52] Starting system checks…
[11:59:52]
[11:59:52] Checking system commands…
[11:59:52] Info: Starting test name ‘system_commands’
[11:59:52]
[11:59:52] Performing ‘strings’ command checks
[11:59:52] Info: Starting test name ‘strings’
[11:59:52] Scanning for string /usr/sbin/ntpsx [ OK ]
[11:59:52] Scanning for string /usr/lib/…/ls [ OK ]
[11:59:52] Scanning for string /usr/lib/…/netstat [ OK ]
[11:59:52] Scanning for string /usr/lib/…/lsof [ OK ]
[11:59:53] Scanning for string /usr/lib/…/bkit-ssh/bkit-shdcfg [ OK ]
[11:59:53] Scanning for string /usr/lib/…/bkit-ssh/bkit-shhk [ OK ]
[11:59:53] Scanning for string /usr/lib/…/bkit-ssh/bkit-pw [ OK ]
[11:59:53] Scanning for string /usr/lib/…/bkit-ssh/bkit-shrs [ OK ]
[11:59:53] Scanning for string /usr/lib/…/uconf.inv [ OK ]
[11:59:53] Scanning for string /usr/lib/…/psr [ OK ]
[11:59:53] Scanning for string /usr/lib/…/find [ OK ]
[11:59:53] Scanning for string /usr/lib/…/pstree [ OK ]
[11:59:53] Scanning for string /usr/lib/…/slocate [ OK ]
[11:59:54] Scanning for string /usr/lib/…/du [ OK ]
[11:59:54] Scanning for string /usr/lib/…/top [ OK ]
[11:59:54] Scanning for string /usr/lib/… [ OK ]
[11:59:54] Scanning for string /usr/lib/…/bkit-ssh [ OK ]
[11:59:54] Scanning for string /usr/lib/.bkit- [ OK ]
[11:59:54] Scanning for string /tmp/.bkp [ OK ]
[11:59:54] Scanning for string /tmp/.cinik [ OK ]
[11:59:54] Scanning for string /tmp/.font-unix/.cinik [ OK ]
[11:59:54] Scanning for string /lib/.sso [ OK ]
[11:59:55] Scanning for string /lib/.so [ OK ]
[11:59:55] Scanning for string /var/run/…dica/clean [ OK ]
[11:59:55] Scanning for string /var/run/…dica/xl [ OK ]
[11:59:55] Scanning for string /var/run/…dica/xdr [ OK ]
[11:59:55] Scanning for string /var/run/…dica/psg [ OK ]
[11:59:55] Scanning for string /var/run/…dica/secure [ OK ]
[11:59:55] Scanning for string /var/run/…dica/rdx [ OK ]
[11:59:55] Scanning for string /var/run/…dica/va [ OK ]
[11:59:55] Scanning for string /var/run/…dica/cl.sh [ OK ]
[11:59:55] Scanning for string /usr/bin/.etc [ OK ]
[11:59:56] Scanning for string /usr/lib/.fx/sched_host.2 [ OK ]
[11:59:56] Scanning for string /usr/lib/.fx/random_d.2 [ OK ]
[11:59:56] Scanning for string /usr/lib/.fx/set_pid.2 [ OK ]
[11:59:56] Scanning for string /usr/lib/.fx/cons.saver [ OK ]
[11:59:56] Scanning for string /usr/lib/.fx/adore/adore/adore.ko [ OK ]
[11:59:56] Scanning for string /bin/sysback [ OK ]
[11:59:56] Scanning for string /usr/local/bin/sysback [ OK ]
[11:59:56] Scanning for string /usr/lib/.tbd [ OK ]
[11:59:56] Scanning for string /dev/.lib/lib/lib/t0rns [ OK ]
[11:59:57] Scanning for string /dev/.lib/lib/lib/du [ OK ]
[11:59:57] Scanning for string /dev/.lib/lib/lib/ls [ OK ]
[11:59:57] Scanning for string /dev/.lib/lib/lib/t0rnsb [ OK ]
[11:59:57] Scanning for string /dev/.lib/lib/lib/ps [ OK ]
[11:59:57] Scanning for string /dev/.lib/lib/lib/t0rnp [ OK ]
[11:59:57] Scanning for string /dev/.lib/lib/lib/find [ OK ]
[11:59:57] Scanning for string /dev/.lib/lib/lib/ifconfig [ OK ]
[11:59:57] Scanning for string /dev/.lib/lib/lib/pg [ OK ]
[11:59:57] Scanning for string /dev/.lib/lib/lib/ssh.tgz [ OK ]
[11:59:58] Scanning for string /dev/.lib/lib/lib/top [ OK ]
[11:59:58] Scanning for string /dev/.lib/lib/lib/sz [ OK ]
[11:59:58] Scanning for string /dev/.lib/lib/lib/login [ OK ]
[11:59:58] Scanning for string /dev/.lib/lib/lib/in.fingerd [ OK ]
[11:59:58] Scanning for string /dev/.lib/lib/lib/1i0n.sh [ OK ]
[11:59:58] Scanning for string /dev/.lib/lib/lib/pstree [ OK ]
[11:59:58] Scanning for string /dev/.lib/lib/lib/in.telnetd [ OK ]
[11:59:58] Scanning for string /dev/.lib/lib/lib/mjy [ OK ]
[11:59:58] Scanning for string /dev/.lib/lib/lib/sush [ OK ]
[11:59:59] Scanning for string /dev/.lib/lib/lib/tfn [ OK ]
[11:59:59] Scanning for string /dev/.lib/lib/lib/name [ OK ]
[11:59:59] Scanning for string /dev/.lib/lib/lib/getip.sh [ OK ]
[11:59:59] Scanning for string /usr/info/.torn/sh* [ OK ]
[11:59:59] Scanning for string /usr/src/.puta/.1addr [ OK ]
[11:59:59] Scanning for string /usr/src/.puta/.1file [ OK ]
[11:59:59] Scanning for string /usr/src/.puta/.1proc [ OK ]
[11:59:59] Scanning for string /usr/src/.puta/.1logz [ OK ]
[11:59:59] Scanning for string /usr/info/.t0rn [ OK ]
[12:00:00] Scanning for string /dev/.lib [ OK ]
[12:00:00] Scanning for string /dev/.lib/lib [ OK ]
[12:00:00] Scanning for string /dev/.lib/lib/lib [ OK ]
[12:00:00] Scanning for string /dev/.lib/lib/lib/dev [ OK ]
[12:00:00] Scanning for string /dev/.lib/lib/scan [ OK ]
[12:00:00] Scanning for string /usr/src/.puta [ OK ]
[12:00:00] Scanning for string /usr/man/man1/man1 [ OK ]
[12:00:00] Scanning for string /usr/man/man1/man1/lib [ OK ]
[12:00:00] Scanning for string /usr/man/man1/man1/lib/.lib [ OK ]
[12:00:00] Scanning for string /usr/man/man1/man1/lib/.lib/.backup [ OK ]
[12:00:01]
[12:00:01] Performing ‘shared libraries’ checks
[12:00:01] Info: Starting test name ‘shared_libs’
[12:00:01] Checking for preloading variables [ None found ]
[12:00:01] Checking for preload file [ Not found ]
[12:00:01] Info: Starting test name ‘shared_libs_path’
[12:00:01] Checking LD_LIBRARY_PATH variable [ Not found ]
[12:00:01]
[12:00:01] Performing file properties checks
[12:00:01] Info: Starting test name ‘properties’
[12:00:01] Warning: Checking for prerequisites [ Warning ]
[12:00:01] The file of stored file properties (rkhunter.dat) does not exist, and so must be created. To do this type in ‘rkhunter –propupd’.
[12:00:02]
[12:00:02] Warning: WARNING! It is the users responsibility to ensure that when the ‘–propupd’ option
is used, all the files on their system are known to be genuine, and installed from a
reliable source. The rkhunter ‘–check’ option will compare the current file properties
against previously stored values, and report if any values differ. However, rkhunter
cannot determine what has caused the change, that is for the user to do.
[12:00:02] /bin/awk [ OK ]
[12:00:02] /bin/basename [ OK ]
[12:00:02] /bin/bash [ OK ]
[12:00:02] /bin/cat [ OK ]
[12:00:02] /bin/chmod [ OK ]
[12:00:02] /bin/chown [ OK ]
[12:00:03] /bin/cp [ OK ]
[12:00:03] /bin/csh [ OK ]
[12:00:03] /bin/cut [ OK ]
[12:00:03] /bin/date [ OK ]
[12:00:03] /bin/df [ OK ]
[12:00:03] /bin/dmesg [ OK ]
[12:00:03] /bin/echo [ OK ]
[12:00:04] /bin/ed [ OK ]
[12:00:04] /bin/egrep [ OK ]
[12:00:04] /bin/env [ OK ]
[12:00:04] /bin/fgrep [ OK ]
[12:00:04] /bin/grep [ OK ]
[12:00:04] /bin/kill [ OK ]
[12:00:04] /bin/login [ OK ]
[12:00:05] /bin/ls [ OK ]
[12:00:05] /bin/mail [ OK ]
[12:00:05] /bin/mktemp [ OK ]
[12:00:05] /bin/more [ OK ]
[12:00:05] /bin/mount [ OK ]
[12:00:05] /bin/mv [ OK ]
[12:00:06] /bin/netstat [ OK ]
[12:00:06] /bin/ps [ OK ]
[12:00:06] /bin/pwd [ OK ]
[12:00:06] /bin/rpm [ OK ]
[12:00:06] /bin/sed [ OK ]
[12:00:06] /bin/sh [ OK ]
[12:00:06] /bin/sort [ OK ]
[12:00:07] /bin/su [ OK ]
[12:00:07] /bin/touch [ OK ]
[12:00:07] /bin/uname [ OK ]
[12:00:07] /bin/gawk [ OK ]
[12:00:07] /bin/tcsh [ OK ]
[12:00:07] /usr/bin/awk [ OK ]
[12:00:08] /usr/bin/chattr [ OK ]
[12:00:08] /usr/bin/curl [ OK ]
[12:00:08] /usr/bin/cut [ OK ]
[12:00:08] /usr/bin/diff [ OK ]
[12:00:08] /usr/bin/dirname [ OK ]
[12:00:08] /usr/bin/du [ OK ]
[12:00:08] /usr/bin/env [ OK ]
[12:00:09] /usr/bin/file [ OK ]
[12:00:09] /usr/bin/find [ OK ]
[12:00:09] /usr/bin/GET [ Warning ]
[12:00:09] Warning: The command ‘/usr/bin/GET’ has been replaced by a script: /usr/bin/GET: perl script text executable
[12:00:09] /usr/bin/groups [ Warning ]
[12:00:09] Warning: The command ‘/usr/bin/groups’ has been replaced by a script: /usr/bin/groups: Bourne shell script text executable
[12:00:09] /usr/bin/head [ OK ]
[12:00:09] /usr/bin/id [ OK ]
[12:00:10] /usr/bin/kill [ OK ]
[12:00:10] /usr/bin/killall [ OK ]
[12:00:10] /usr/bin/last [ OK ]
[12:00:10] /usr/bin/lastlog [ OK ]
[12:00:10] /usr/bin/ldd [ Warning ]
[12:00:10] Warning: The command ‘/usr/bin/ldd’ has been replaced by a script: /usr/bin/ldd: Bourne shell script text executable
[12:00:10] /usr/bin/less [ OK ]
[12:00:10] /usr/bin/locate [ OK ]
[12:00:11] /usr/bin/logger [ OK ]
[12:00:11] /usr/bin/lsattr [ OK ]
[12:00:11] /usr/bin/md5sum [ OK ]
[12:00:11] /usr/bin/newgrp [ OK ]
[12:00:11] /usr/bin/passwd [ OK ]
[12:00:11] /usr/bin/perl [ OK ]
[12:00:12] /usr/bin/pstree [ OK ]
[12:00:12] /usr/bin/readlink [ OK ]
[12:00:12] /usr/bin/runcon [ OK ]
[12:00:12] /usr/bin/sha1sum [ OK ]
[12:00:12] /usr/bin/size [ OK ]
[12:00:12] /usr/bin/slocate [ OK ]
[12:00:12] /usr/bin/stat [ OK ]
[12:00:13] /usr/bin/strace [ OK ]
[12:00:13] /usr/bin/strings [ OK ]
[12:00:13] /usr/bin/sudo [ OK ]
[12:00:13] /usr/bin/tail [ OK ]
[12:00:13] /usr/bin/test [ OK ]
[12:00:13] /usr/bin/top [ OK ]
[12:00:13] /usr/bin/tr [ OK ]
[12:00:14] /usr/bin/uniq [ OK ]
[12:00:14] /usr/bin/users [ OK ]
[12:00:14] /usr/bin/vmstat [ OK ]
[12:00:14] /usr/bin/w [ OK ]
[12:00:14] /usr/bin/watch [ OK ]
[12:00:14] /usr/bin/wc [ OK ]
[12:00:15] /usr/bin/wget [ OK ]
[12:00:15] /usr/bin/whatis [ Warning ]
[12:00:15] Warning: The command ‘/usr/bin/whatis’ has been replaced by a script: /usr/bin/whatis: Bourne shell script text executable
[12:00:15] /usr/bin/whereis [ OK ]
[12:00:15] /usr/bin/which [ OK ]
[12:00:15] /usr/bin/who [ OK ]
[12:00:15] /usr/bin/whoami [ OK ]
[12:00:15] /usr/bin/gawk [ OK ]
[12:00:16] /sbin/chkconfig [ OK ]
[12:00:16] /sbin/depmod [ OK ]
[12:00:16] /sbin/ifconfig [ OK ]
[12:00:16] /sbin/ifdown [ Warning ]
[12:00:16] Warning: The command ‘/sbin/ifdown’ has been replaced by a script: /sbin/ifdown: Bourne-Again shell script text executable
[12:00:16] /sbin/ifup [ Warning ]
[12:00:16] Warning: The command ‘/sbin/ifup’ has been replaced by a script: /sbin/ifup: Bourne-Again shell script text executable
[12:00:16] /sbin/init [ OK ]
[12:00:17] /sbin/insmod [ OK ]
[12:00:17] /sbin/ip [ OK ]
[12:00:17] /sbin/lsmod [ OK ]
[12:00:17] /sbin/modinfo [ OK ]
[12:00:17] /sbin/modprobe [ OK ]
[12:00:17] /sbin/nologin [ OK ]
[12:00:18] /sbin/rmmod [ OK ]
[12:00:18] /sbin/runlevel [ OK ]
[12:00:18] /sbin/sulogin [ OK ]
[12:00:18] /sbin/sysctl [ OK ]
[12:00:18] /sbin/syslogd [ OK ]
[12:00:18] /usr/sbin/adduser [ OK ]
[12:00:18] /usr/sbin/chroot [ OK ]
[12:00:19] /usr/sbin/groupadd [ OK ]
[12:00:19] /usr/sbin/groupdel [ OK ]
[12:00:19] /usr/sbin/groupmod [ OK ]
[12:00:19] /usr/sbin/grpck [ OK ]
[12:00:19] /usr/sbin/kudzu [ OK ]
[12:00:19] /usr/sbin/lsof [ OK ]
[12:00:20] /usr/sbin/prelink [ OK ]
[12:00:20] /usr/sbin/pwck [ OK ]
[12:00:20] /usr/sbin/sestatus [ OK ]
[12:00:20] /usr/sbin/tcpd [ OK ]
[12:00:20] /usr/sbin/useradd [ OK ]
[12:00:20] /usr/sbin/userdel [ OK ]
[12:00:20] /usr/sbin/usermod [ OK ]
[12:00:21] /usr/sbin/vipw [ OK ]
[12:00:21] /usr/sbin/xinetd [ OK ]
[12:00:21] /usr/local/bin/rkhunter [ OK ]
[12:00:23]
[12:00:23] Checking for rootkits…
[12:00:23] Info: Starting test name ‘rootkits’
[12:00:23]
[12:00:23] Performing check of known rootkit files and directories
[12:00:23] Info: Starting test name ‘known_rkts’
[12:00:23]
[12:00:23] Checking for 55808 Trojan – Variant A…
[12:00:23] Checking for file ‘/tmp/…/r’ [ Not found ]
[12:00:23] Checking for file ‘/tmp/…/a’ [ Not found ]
[12:00:23] 55808 Trojan – Variant A [ Not found ]
[12:00:23]
[12:00:23] Checking for ADM Worm…
[12:00:23] Checking for string ‘w0rm’ [ Not found ]
[12:00:24] ADM Worm [ Not found ]
[12:00:24]
[12:00:24] Checking for AjaKit Rootkit…
[12:00:24] Checking for file ‘/dev/tux/.addr’ [ Not found ]
[12:00:24] Checking for file ‘/dev/tux/.proc’ [ Not found ]
[12:00:24] Checking for file ‘/dev/tux/.file’ [ Not found ]
[12:00:24] Checking for file ‘/lib/.libgh-gh/cleaner’ [ Not found ]
[12:00:24] Checking for file ‘/lib/.libgh-gh/Patch/patch’ [ Not found ]
[12:00:24] Checking for file ‘/lib/.libgh-gh/sb0k’ [ Not found ]
[12:00:24] Checking for directory ‘/dev/tux’ [ Not found ]
[12:00:25] Checking for directory ‘/lib/.libgh-gh’ [ Not found ]
[12:00:25] AjaKit Rootkit [ Not found ]
[12:00:25]
[12:00:25] Checking for aPa Kit…
[12:00:25] Checking for file ‘/usr/share/.aPa’ [ Not found ]
[12:00:25] aPa Kit [ Not found ]
[12:00:25]
[12:00:25] Checking for Apache Worm…
[12:00:25] Checking for file ‘/bin/.log’ [ Not found ]
[12:00:25] Apache Worm [ Not found ]
[12:00:25]
[12:00:25] Checking for Ambient (ark) Rootkit…
[12:00:25] Checking for file ‘/usr/lib/.ark?’ [ Not found ]
[12:00:25] Checking for file ‘/dev/ptyxx/.log’ [ Not found ]
[12:00:26] Checking for file ‘/dev/ptyxx/.file’ [ Not found ]
[12:00:26] Checking for directory ‘/dev/ptyxx’ [ Not found ]
[12:00:26] Ambient (ark) Rootkit [ Not found ]
[12:00:26]
[12:00:26] Checking for Balaur Rootkit…
[12:00:26] Checking for file ‘/usr/lib/liblog.o’ [ Not found ]
[12:00:26] Checking for directory ‘/usr/lib/.kinetic’ [ Not found ]
[12:00:26] Checking for directory ‘/usr/lib/.egcs’ [ Not found ]
[12:00:26] Checking for directory ‘/usr/lib/.wormie’ [ Not found ]
[12:00:26] Balaur Rootkit [ Not found ]
[12:00:27]
[12:00:27] Checking for BeastKit Rootkit…
[12:00:27] Checking for file ‘/usr/sbin/arobia’ [ Not found ]
[12:00:27] Checking for file ‘/usr/sbin/idrun’ [ Not found ]
[12:00:27] Checking for file ‘/usr/lib/elm/arobia/elm’ [ Not found ]
[12:00:27] Checking for file ‘/usr/lib/elm/arobia/elm/hk’ [ Not found ]
[12:00:27] Checking for file ‘/usr/lib/elm/arobia/elm/hk.pub’ [ Not found ]
[12:00:27] Checking for file ‘/usr/lib/elm/arobia/elm/sc’ [ Not found ]
[12:00:27] Checking for file ‘/usr/lib/elm/arobia/elm/sd.pp’ [ Not found ]
[12:00:27] Checking for file ‘/usr/lib/elm/arobia/elm/sdco’ [ Not found ]
[12:00:27] Checking for file ‘/usr/lib/elm/arobia/elm/srsd’ [ Not found ]
[12:00:27] Checking for directory ‘/lib/ldd.so/bktools’ [ Not found ]
[12:00:28] BeastKit Rootkit [ Not found ]
[12:00:28]
[12:00:28] Checking for beX2 Rootkit…
[12:00:28] Checking for directory ‘/usr/include/bex’ [ Not found ]
[12:00:28] beX2 Rootkit [ Not found ]
[12:00:28]
[12:00:28] Checking for BOBKit Rootkit…
[12:00:28] Checking for file ‘/usr/sbin/ntpsx’ [ Not found ]
[12:00:28] Checking for file ‘/usr/lib/…/ls’ [ Not found ]
[12:00:28] Checking for file ‘/usr/lib/…/netstat’ [ Not found ]
[12:00:28] Checking for file ‘/usr/lib/…/lsof’ [ Not found ]
[12:00:28] Checking for file ‘/usr/lib/…/bkit-ssh/bkit-shdcfg’ [ Not found ]
[12:00:29] Checking for file ‘/usr/lib/…/bkit-ssh/bkit-shhk’ [ Not found ]
[12:00:29] Checking for file ‘/usr/lib/…/bkit-ssh/bkit-pw’ [ Not found ]
[12:00:29] Checking for file ‘/usr/lib/…/bkit-ssh/bkit-shrs’ [ Not found ]
[12:00:29] Checking for file ‘/usr/lib/…/uconf.inv’ [ Not found ]
[12:00:29] Checking for file ‘/usr/lib/…/psr’ [ Not found ]
[12:00:29] Checking for file ‘/usr/lib/…/find’ [ Not found ]
[12:00:29] Checking for file ‘/usr/lib/…/pstree’ [ Not found ]
[12:00:29] Checking for file ‘/usr/lib/…/slocate’ [ Not found ]
[12:00:29] Checking for file ‘/usr/lib/…/du’ [ Not found ]
[12:00:29] Checking for file ‘/usr/lib/…/top’ [ Not found ]
[12:00:30] Checking for directory ‘/usr/lib/…’ [ Not found ]
[12:00:30] Checking for directory ‘/usr/lib/…/bkit-ssh’ [ Not found ]
[12:00:30] Checking for directory ‘/usr/lib/.bkit-‘ [ Not found ]
[12:00:30] Checking for directory ‘/tmp/.bkp’ [ Not found ]
[12:00:30] BOBKit Rootkit [ Not found ]
[12:00:30]
[12:00:30] Checking for CiNIK Worm (Slapper.B variant)…
[12:00:30] Checking for file ‘/tmp/.cinik’ [ Not found ]
[12:00:30] Checking for directory ‘/tmp/.font-unix/.cinik’ [ Not found ]
[12:00:30] CiNIK Worm (Slapper.B variant) [ Not found ]
[12:00:30]
[12:00:30] Checking for Danny-Boy’s Abuse Kit…
[12:00:31] Checking for file ‘/dev/mdev’ [ Not found ]
[12:00:31] Checking for file ‘/usr/lib/libX.a’ [ Not found ]
[12:00:31] Danny-Boy’s Abuse Kit [ Not found ]
[12:00:31]
[12:00:31] Checking for Devil RootKit…
[12:00:31] Checking for file ‘/var/lib/games/.src’ [ Not found ]
[12:00:31] Checking for file ‘/dev/dsx’ [ Not found ]
[12:00:31] Checking for file ‘/dev/caca’ [ Not found ]
[12:00:31] Devil RootKit [ Not found ]
[12:00:31]
[12:00:31] Checking for Dica-Kit Rootkit…
[12:00:31] Checking for file ‘/lib/.sso’ [ Not found ]
[12:00:32] Checking for file ‘/lib/.so’ [ Not found ]
[12:00:32] Checking for file ‘/var/run/…dica/clean’ [ Not found ]
[12:00:32] Checking for file ‘/var/run/…dica/xl’ [ Not found ]
[12:00:32] Checking for file ‘/var/run/…dica/xdr’ [ Not found ]
[12:00:32] Checking for file ‘/var/run/…dica/psg’ [ Not found ]
[12:00:32] Checking for file ‘/var/run/…dica/secure’ [ Not found ]
[12:00:32] Checking for file ‘/var/run/…dica/rdx’ [ Not found ]
[12:00:32] Checking for file ‘/var/run/…dica/va’ [ Not found ]
[12:00:32] Checking for file ‘/var/run/…dica/cl.sh’ [ Not found ]
[12:00:32] Checking for file ‘/usr/bin/.etc’ [ Not found ]
[12:00:33] Checking for directory ‘/var/run/…dica’ [ Not found ]
[12:00:33] Checking for directory ‘/var/run/…dica/mh’ [ Not found ]
[12:00:33] Checking for directory ‘/var/run/…dica/scan’ [ Not found ]
[12:00:33] Dica-Kit Rootkit [ Not found ]
[12:00:33]
[12:00:33] Checking for Dreams Rootkit…
[12:00:33] Checking for file ‘/dev/ttyoa’ [ Not found ]
[12:00:33] Checking for file ‘/dev/ttyof’ [ Not found ]
[12:00:33] Checking for file ‘/dev/ttyop’ [ Not found ]
[12:00:33] Checking for file ‘/usr/bin/sense’ [ Not found ]
[12:00:33] Checking for file ‘/usr/bin/sl2’ [ Not found ]
[12:00:34] Checking for file ‘/usr/bin/logclear’ [ Not found ]
[12:00:34] Checking for file ‘/usr/bin/(swapd)’ [ Not found ]
[12:00:34] Checking for file ‘/usr/bin/snfs’ [ Not found ]
[12:00:34] Checking for file ‘/usr/lib/libsss’ [ Not found ]
[12:00:34] Checking for directory ‘/dev/ida/.hpd’ [ Not found ]
[12:00:34] Dreams Rootkit [ Not found ]
[12:00:34]
[12:00:34] Checking for Duarawkz Rootkit…
[12:00:34] Checking for file ‘/usr/bin/duarawkz/loginpass’ [ Not found ]
[12:00:34] Checking for directory ‘/usr/bin/duarawkz’ [ Not found ]
[12:00:34] Duarawkz Rootkit [ Not found ]
[12:00:35]
[12:00:35] Checking for Enye LKM…
[12:00:35] Checking for file ‘/etc/.enyelkmHIDE^IT.ko’ [ Not found ]
[12:00:35] Enye LKM [ Not found ]
[12:00:35]
[12:00:35] Checking for Flea Linux Rootkit…
[12:00:35] Checking for file ‘/etc/ld.so.hash’ [ Not found ]
[12:00:35] Checking for file ‘/lib/security/.config/ssh/ssh_host_key’ [ Not found ]
[12:00:35] Checking for file ‘/lib/security/.config/ssh/ssh_host_key.pub’ [ Not found ]
[12:00:35] Checking for file ‘/lib/security/.config/ssh/ssh_random_seed’ [ Not found ]
[12:00:35] Checking for file ‘/usr/bin/ssh2d’ [ Not found ]
[12:00:35] Checking for file ‘/usr/lib/ldlibns.so’ [ Not found ]
[12:00:36] Checking for file ‘/usr/lib/ldlibpst.so’ [ Not found ]
[12:00:36] Checking for file ‘/usr/lib/ldlibdu.so’ [ Not found ]
[12:00:36] Checking for file ‘/usr/lib/ldlibct.so’ [ Not found ]
[12:00:36] Checking for directory ‘/lib/security/.config/ssh’ [ Not found ]
[12:00:36] Checking for directory ‘/dev/..0’ [ Not found ]
[12:00:36] Checking for directory ‘/dev/..0/backup’ [ Not found ]
[12:00:36] Flea Linux Rootkit [ Not found ]
[12:00:36]
[12:00:36] Checking for FreeBSD Rootkit…
[12:00:36] Checking for file ‘/usr/lib/.fx/sched_host.2’ [ Not found ]
[12:00:36] Checking for file ‘/usr/lib/.fx/random_d.2’ [ Not found ]
[12:00:37] Checking for file ‘/usr/lib/.fx/set_pid.2’ [ Not found ]
[12:00:37] Checking for file ‘/usr/lib/.fx/cons.saver’ [ Not found ]
[12:00:37] Checking for file ‘/usr/lib/.fx/adore/adore/adore.ko’ [ Not found ]
[12:00:37] Checking for file ‘/bin/sysback’ [ Not found ]
[12:00:37] Checking for file ‘/usr/local/bin/sysback’ [ Not found ]
[12:00:37] Checking for directory ‘/usr/lib/.fx’ [ Not found ]
[12:00:37] Checking for directory ‘/usr/lib/.fx/adore’ [ Not found ]
[12:00:37] FreeBSD Rootkit [ Not found ]
[12:00:37]
[12:00:37] Checking for Fuck`it Rootkit…
[12:00:37] Checking for file ‘/dev/proc/fuckit/hax0r’ [ Not found ]
[12:00:38] Checking for file ‘/dev/proc/fuckit/hax0rshell’ [ Not found ]
[12:00:38] Checking for file ‘/dev/proc/fuckit/config/lports’ [ Not found ]
[12:00:38] Checking for file ‘/dev/proc/fuckit/config/rports’ [ Not found ]
[12:00:38] Checking for file ‘/dev/proc/fuckit/config/rkconf’ [ Not found ]
[12:00:38] Checking for file ‘/dev/proc/fuckit/config/password’ [ Not found ]
[12:00:38] Checking for file ‘/dev/proc/fuckit/config/progs’ [ Not found ]
[12:00:38] Checking for file ‘/dev/proc/system-bins/init’ [ Not found ]
[12:00:38] Fuck`it Rootkit [ Not found ]
[12:00:38]
[12:00:38] Checking for GasKit Rootkit…
[12:00:38] Checking for file ‘/dev/dev/gaskit/sshd/sshdd’ [ Not found ]
[12:00:39] Checking for directory ‘/dev/dev’ [ Not found ]
[12:00:39] Checking for directory ‘/dev/dev/gaskit’ [ Not found ]
[12:00:39] Checking for directory ‘/dev/dev/gaskit/sshd’ [ Not found ]
[12:00:39] GasKit Rootkit [ Not found ]
[12:00:39]
[12:00:39] Checking for Heroin LKM…
[12:00:43] Checking for kernel symbol ‘heroin’ [ Not found ]
[12:00:43] Heroin LKM [ Not found ]
[12:00:43]
[12:00:43] Checking for HjC Kit…
[12:00:43] Checking for directory ‘/dev/.hijackerz’ [ Not found ]
[12:00:43] HjC Kit [ Not found ]
[12:00:43]
[12:00:43] Checking for ignoKit Rootkit…
[12:00:43] Checking for file ‘/lib/defs/p’ [ Not found ]
[12:00:43] Checking for file ‘/lib/defs/q’ [ Not found ]
[12:00:43] Checking for file ‘/lib/defs/r’ [ Not found ]
[12:00:43] Checking for file ‘/lib/defs/s’ [ Not found ]
[12:00:43] Checking for file ‘/lib/defs/t’ [ Not found ]
[12:00:44] Checking for file ‘/usr/lib/defs/p’ [ Not found ]
[12:00:44] Checking for file ‘/usr/lib/defs/q’ [ Not found ]
[12:00:44] Checking for file ‘/usr/lib/defs/r’ [ Not found ]
[12:00:44] Checking for file ‘/usr/lib/defs/s’ [ Not found ]
[12:00:44] Checking for file ‘/usr/lib/defs/t’ [ Not found ]
[12:00:44] Checking for file ‘/usr/lib/.libigno/pkunsec’ [ Not found ]
[12:00:44] Checking for file ‘/usr/lib/.libigno/.igno/psybnc/psybnc’ [ Not found ]
[12:00:44] Checking for directory ‘/usr/lib/.libigno’ [ Not found ]
[12:00:44] Checking for directory ‘/usr/lib/.libigno/.igno’ [ Not found ]
[12:00:44] ignoKit Rootkit [ Not found ]
[12:00:45]
[12:00:45] Checking for ImperalsS-FBRK Rootkit…
[12:00:45] Checking for directory ‘/dev/fd/.88’ [ Not found ]
[12:00:45] Checking for directory ‘/dev/fd/.99’ [ Not found ]
[12:00:45] ImperalsS-FBRK Rootkit [ Not found ]
[12:00:45]
[12:00:45] Checking for Irix Rootkit…
[12:00:45] Checking for directory ‘/dev/pts/01’ [ Not found ]
[12:00:45] Checking for directory ‘/dev/pts/01/backup’ [ Not found ]
[12:00:45] Checking for directory ‘/dev/pts/01/etc’ [ Not found ]
[12:00:45] Checking for directory ‘/dev/pts/01/tmp’ [ Not found ]
[12:00:45] Irix Rootkit [ Not found ]
[12:00:46]
[12:00:46] Checking for Kitko Rootkit…
[12:00:46] Checking for directory ‘/usr/src/redhat/SRPMS/…’ [ Not found ]
[12:00:46] Kitko Rootkit [ Not found ]
[12:00:46]
[12:00:46] Checking for Knark Rootkit…
[12:00:46] Checking for file ‘/proc/knark/pids’ [ Not found ]
[12:00:46] Checking for directory ‘/proc/knark’ [ Not found ]
[12:00:46] Knark Rootkit [ Not found ]
[12:00:46]
[12:00:46] Checking for Li0n Worm…
[12:00:46] Checking for file ‘/bin/in.telnetd’ [ Not found ]
[12:00:46] Checking for file ‘/bin/mjy’ [ Not found ]
[12:00:46] Checking for file ‘/usr/man/man1/man1/lib/.lib/mjy’ [ Not found ]
[12:00:47] Checking for file ‘/usr/man/man1/man1/lib/.lib/in.telnetd’ [ Not found ]
[12:00:47] Checking for file ‘/usr/man/man1/man1/lib/.lib/.x’ [ Not found ]
[12:00:47] Checking for file ‘/dev/.lib/lib/scan/1i0n.sh’ [ Not found ]
[12:00:47] Checking for file ‘/dev/.lib/lib/scan/hack.sh’ [ Not found ]
[12:00:47] Checking for file ‘/dev/.lib/lib/scan/bind’ [ Not found ]
[12:00:47] Checking for file ‘/dev/.lib/lib/scan/randb’ [ Not found ]
[12:00:47] Checking for file ‘/dev/.lib/lib/scan/scan.sh’ [ Not found ]
[12:00:47] Checking for file ‘/dev/.lib/lib/scan/pscan’ [ Not found ]
[12:00:47] Checking for file ‘/dev/.lib/lib/scan/star.sh’ [ Not found ]
[12:00:47] Checking for file ‘/dev/.lib/lib/scan/bindx.sh’ [ Not found ]
[12:00:48] Checking for file ‘/dev/.lib/lib/scan/bindname.log’ [ Not found ]
[12:00:48] Checking for file ‘/dev/.lib/lib/1i0n.sh’ [ Not found ]
[12:00:48] Checking for file ‘/dev/.lib/lib/lib/netstat’ [ Not found ]
[12:00:48] Checking for file ‘/dev/.lib/lib/lib/dev/.1addr’ [ Not found ]
[12:00:48] Checking for file ‘/dev/.lib/lib/lib/dev/.1logz’ [ Not found ]
[12:00:48] Checking for file ‘/dev/.lib/lib/lib/dev/.1proc’ [ Not found ]
[12:00:48] Checking for file ‘/dev/.lib/lib/lib/dev/.1file’ [ Not found ]
[12:00:48] Li0n Worm [ Not found ]
[12:00:48]
[12:00:48] Checking for Lockit / LJK2 Rootkit…
[12:00:48] Checking for file ‘/usr/lib/libmen.oo/.LJK2/ssh_config’ [ Not found ]
[12:00:49] Checking for file ‘/usr/lib/libmen.oo/.LJK2/ssh_host_key’ [ Not found ]
[12:00:49] Checking for file ‘/usr/lib/libmen.oo/.LJK2/ssh_host_key.pub’ [ Not found ]
[12:00:49] Checking for file ‘/usr/lib/libmen.oo/.LJK2/ssh_random_seed*’ [ Not found ]
[12:00:49] Checking for file ‘/usr/lib/libmen.oo/.LJK2/sshd_config’ [ Not found ]
[12:00:49] Checking for file ‘/usr/lib/libmen.oo/.LJK2/backdoor/RK1bd’ [ Not found ]
[12:00:49] Checking for file ‘/usr/lib/libmen.oo/.LJK2/backup/du’ [ Not found ]
[12:00:49] Checking for file ‘/usr/lib/libmen.oo/.LJK2/backup/ifconfig’ [ Not found ]
[12:00:49] Checking for file ‘/usr/lib/libmen.oo/.LJK2/backup/inetd.conf’ [ Not found ]
[12:00:49] Checking for file ‘/usr/lib/libmen.oo/.LJK2/backup/locate’ [ Not found ]
[12:00:49] Checking for file ‘/usr/lib/libmen.oo/.LJK2/backup/login’ [ Not found ]
[12:00:50] Checking for file ‘/usr/lib/libmen.oo/.LJK2/backup/ls’ [ Not found ]
[12:00:50] Checking for file ‘/usr/lib/libmen.oo/.LJK2/backup/netstat’ [ Not found ]
[12:00:50] Checking for file ‘/usr/lib/libmen.oo/.LJK2/backup/ps’ [ Not found ]
[12:00:50] Checking for file ‘/usr/lib/libmen.oo/.LJK2/backup/pstree’ [ Not found ]
[12:00:50] Checking for file ‘/usr/lib/libmen.oo/.LJK2/backup/rc.sysinit’ [ Not found ]
[12:00:50] Checking for file ‘/usr/lib/libmen.oo/.LJK2/backup/syslogd’ [ Not found ]
[12:00:50] Checking for file ‘/usr/lib/libmen.oo/.LJK2/backup/tcpd’ [ Not found ]
[12:00:50] Checking for file ‘/usr/lib/libmen.oo/.LJK2/backup/top’ [ Not found ]
[12:00:50] Checking for file ‘/usr/lib/libmen.oo/.LJK2/clean/RK1sauber’ [ Not found ]
[12:00:50] Checking for file ‘/usr/lib/libmen.oo/.LJK2/clean/RK1wted’ [ Not found ]
[12:00:51] Checking for file ‘/usr/lib/libmen.oo/.LJK2/hack/RK1parser’ [ Not found ]
[12:00:51] Checking for file ‘/usr/lib/libmen.oo/.LJK2/hack/RK1sniff’ [ Not found ]
[12:00:51] Checking for file ‘/usr/lib/libmen.oo/.LJK2/hide/.RK1addr’ [ Not found ]
[12:00:51] Checking for file ‘/usr/lib/libmen.oo/.LJK2/hide/.RK1dir’ [ Not found ]
[12:00:51] Checking for file ‘/usr/lib/libmen.oo/.LJK2/hide/.RK1log’ [ Not found ]
[12:00:51] Checking for file ‘/usr/lib/libmen.oo/.LJK2/hide/.RK1proc’ [ Not found ]
[12:00:51] Checking for file ‘/usr/lib/libmen.oo/.LJK2/hide/RK1phidemod.c’ [ Not found ]
[12:00:51] Checking for file ‘/usr/lib/libmen.oo/.LJK2/modules/README.modules’ [ Not found ]
[12:00:51] Checking for file ‘/usr/lib/libmen.oo/.LJK2/modules/RK1hidem.c’ [ Not found ]
[12:00:52] Checking for file ‘/usr/lib/libmen.oo/.LJK2/modules/RK1phide’ [ Not found ]
[12:00:52] Checking for file ‘/usr/lib/libmen.oo/.LJK2/sshconfig/RK1ssh’ [ Not found ]
[12:00:52] Checking for directory ‘/usr/lib/libmen.oo/.LJK2’ [ Not found ]
[12:00:52] Lockit / LJK2 Rootkit [ Not found ]
[12:00:52]
[12:00:52] Checking for Mood-NT Rootkit…
[12:00:52] Checking for file ‘/sbin/init__mood-nt-_-_cthulhu’ [ Not found ]
[12:00:52] Checking for file ‘/_cthulhu/mood-nt.init’ [ Not found ]
[12:00:52] Checking for file ‘/_cthulhu/mood-nt.conf’ [ Not found ]
[12:00:52] Checking for file ‘/_cthulhu/mood-nt.sniff’ [ Not found ]
[12:00:52] Checking for directory ‘/_cthulhu’ [ Not found ]
[12:00:53] Mood-NT Rootkit [ Not found ]
[12:00:53]
[12:00:53] Checking for MRK Rootkit…
[12:00:53] Checking for file ‘/dev/ida/.inet/pid’ [ Not found ]
[12:00:53] Checking for file ‘/dev/ida/.inet/ssh_host_key’ [ Not found ]
[12:00:53] Checking for file ‘/dev/ida/.inet/ssh_random_seed’ [ Not found ]
[12:00:53] Checking for file ‘/dev/ida/.inet/tcp.log’ [ Not found ]
[12:00:53] Checking for directory ‘/dev/ida/.inet’ [ Not found ]
[12:00:53] Checking for directory ‘/var/spool/cron/.sh’ [ Not found ]
[12:00:53] MRK Rootkit [ Not found ]
[12:00:53]
[12:00:53] Checking for Ni0 Rootkit…
[12:00:54] Checking for file ‘/var/lock/subsys/…datafile…/…net…’ [ Not found ]
[12:00:54] Checking for file ‘/var/lock/subsys/…datafile…/…port…’ [ Not found ]
[12:00:54] Checking for file ‘/var/lock/subsys/…datafile…/…ps…’ [ Not found ]
[12:00:54] Checking for file ‘/var/lock/subsys/…datafile…/…file…’ [ Not found ]
[12:00:54] Checking for directory ‘/tmp/waza’ [ Not found ]
[12:00:54] Checking for directory ‘/var/lock/subsys/…datafile…’ [ Not found ]
[12:00:54] Checking for directory ‘/usr/sbin/es’ [ Not found ]
[12:00:54] Ni0 Rootkit [ Not found ]
[12:00:54]
[12:00:54] Checking for Ohhara Rootkit…
[12:00:54] Checking for file ‘/var/lock/subsys/…datafile…/…datafile…/in.smbd.log’ [ Not found ]
[12:00:55] Checking for directory ‘/var/lock/subsys/…datafile…’ [ Not found ]
[12:00:55] Checking for directory ‘/var/lock/subsys/…datafile…/…datafile…’ [ Not found ]
[12:00:55] Checking for directory ‘/var/lock/subsys/…datafile…/…datafile…/bin’ [ Not found ]
[12:00:55] Checking for directory ‘/var/lock/subsys/…datafile…/…datafile…/usr/bin’ [ Not found ]
[12:00:55] Checking for directory ‘/var/lock/subsys/…datafile…/…datafile…/usr/sbin’ [ Not found ]
[12:00:55] Checking for directory ‘/var/lock/subsys/…datafile…/…datafile…/lib/security’ [ Not found ]
[12:00:55] Ohhara Rootkit [ Not found ]
[12:00:55]
[12:00:55] Checking for Optic Kit (Tux) Worm…
[12:00:55] Checking for directory ‘/dev/tux’ [ Not found ]
[12:00:55] Checking for directory ‘/usr/bin/xchk’ [ Not found ]
[12:00:56] Checking for directory ‘/usr/bin/xsf’ [ Not found ]
[12:00:56] Checking for directory ‘/usr/bin/ssh2d’ [ Not found ]
[12:00:56] Optic Kit (Tux) Worm [ Not found ]
[12:00:56]
[12:00:56] Checking for Oz Rootkit…
[12:00:56] Checking for file ‘/dev/.oz/.nap/rkit/terror’ [ Not found ]
[12:00:56] Checking for directory ‘/dev/.oz’ [ Not found ]
[12:00:56] Oz Rootkit [ Not found ]
[12:00:56]
[12:00:56] Checking for Phalanx Rootkit…
[12:00:56] Checking for file ‘/usr/share/.home.ph1/cb’ [ Not found ]
[12:00:56] Checking for file ‘/etc/host.ph1’ [ Not found ]
[12:00:56] Checking for file ‘/bin/host.ph1’ [ Not found ]
[12:00:57] Checking for file ‘/usr/share/.home.ph1/phalanx’ [ Not found ]
[12:00:57] Checking for directory ‘/usr/share/.home.ph1’ [ Not found ]
[12:00:57] Phalanx Rootkit [ Not found ]
[12:00:57]
[12:00:57] Checking for Phalanx Rootkit (strings)…
[12:00:57] Checking for string ‘phalanx’ [ Not found ]
[12:00:57] Phalanx Rootkit (strings) [ Not found ]
[12:00:57]
[12:00:57] Checking for Portacelo Rootkit…
[12:00:57] Checking for file ‘/var/lib/…/.ak’ [ Not found ]
[12:00:57] Checking for file ‘/var/lib/…/.hk’ [ Not found ]
[12:00:57] Checking for file ‘/var/lib/…/.rs’ [ Not found ]
[12:00:58] Checking for file ‘/var/lib/…/.p’ [ Not found ]
[12:00:58] Checking for file ‘/var/lib/…/getty’ [ Not found ]
[12:00:58] Checking for file ‘/var/lib/…/lkt.o’ [ Not found ]
[12:00:58] Checking for file ‘/var/lib/…/show’ [ Not found ]
[12:00:58] Checking for file ‘/var/lib/…/nlkt.o’ [ Not found ]
[12:00:58] Checking for file ‘/var/lib/…/ssshrc’ [ Not found ]
[12:00:58] Checking for file ‘/var/lib/…/sssh_equiv’ [ Not found ]
[12:00:58] Checking for file ‘/var/lib/…/sssh_known_hosts’ [ Not found ]
[12:00:58] Checking for file ‘/var/lib/…/sssh_pid’ [ Not found ]
[12:00:58] Checking for file ‘~/.sssh/known_hosts’ [ Not found ]
[12:00:59] Portacelo Rootkit [ Not found ]
[12:00:59]
[12:00:59] Checking for R3dstorm Toolkit…
[12:00:59] Checking for file ‘/var/log/tk02/see_all’ [ Not found ]
[12:00:59] Checking for file ‘/bin/…/sshd/sbin/sshd1’ [ Not found ]
[12:00:59] Checking for file ‘/bin/…/hate/sk’ [ Not found ]
[12:00:59] Checking for file ‘/bin/…/see_all’ [ Not found ]
[12:00:59] Checking for directory ‘/var/log/tk02’ [ Not found ]
[12:00:59] Checking for directory ‘/var/log/tk02/old’ [ Not found ]
[12:00:59] Checking for directory ‘/bin/…’ [ Not found ]
[12:00:59] R3dstorm Toolkit [ Not found ]
[12:01:00]
[12:01:00] Checking for RH-Sharpe’s Rootkit…
[12:01:00] Checking for file ‘/bin/lps’ [ Not found ]
[12:01:00] Checking for file ‘/usr/bin/lpstree’ [ Not found ]
[12:01:00] Checking for file ‘/usr/bin/ltop’ [ Not found ]
[12:01:00] Checking for file ‘/usr/bin/lkillall’ [ Not found ]
[12:01:00] Checking for file ‘/usr/bin/ldu’ [ Not found ]
[12:01:00] Checking for file ‘/usr/bin/lnetstat’ [ Not found ]
[12:01:00] Checking for file ‘/usr/bin/wp’ [ Not found ]
[12:01:00] Checking for file ‘/usr/bin/shad’ [ Not found ]
[12:01:00] Checking for file ‘/usr/bin/vadim’ [ Not found ]
[12:01:01] Checking for file ‘/usr/bin/slice’ [ Not found ]
[12:01:01] Checking for file ‘/usr/bin/cleaner’ [ Not found ]
[12:01:01] Checking for file ‘/usr/include/rpcsvc/du’ [ Not found ]
[12:01:01] RH-Sharpe’s Rootkit [ Not found ]
[12:01:01]
[12:01:01] Checking for RSHA’s Rootkit…
[12:01:01] Checking for file ‘/bin/kr4p’ [ Not found ]
[12:01:01] Checking for file ‘/usr/bin/n3tstat’ [ Not found ]
[12:01:01] Checking for file ‘/usr/bin/chsh2’ [ Not found ]
[12:01:01] Checking for file ‘/usr/bin/slice2’ [ Not found ]
[12:01:02] Checking for file ‘/usr/src/linux/arch/alpha/lib/.lib/.1proc’ [ Not found ]
[12:01:02] Checking for file ‘/etc/rc.d/arch/alpha/lib/.lib/.1addr’ [ Not found ]
[12:01:02] Checking for directory ‘/etc/rc.d/rsha’ [ Not found ]
[12:01:02] Checking for directory ‘/etc/rc.d/arch/alpha/lib/.lib’ [ Not found ]
[12:01:02] RSHA’s Rootkit [ Not found ]
[12:01:02]
[12:01:02] Checking for Scalper Worm…
[12:01:02] Checking for file ‘/tmp/.a’ [ Not found ]
[12:01:02] Checking for file ‘/tmp/.uua’ [ Not found ]
[12:01:02] Scalper Worm [ Not found ]
[12:01:02]
[12:01:02] Checking for Sebek LKM…
[12:01:06] Checking for kernel symbol ‘adore or sebek’ [ Not found ]
[12:01:06] Sebek LKM [ Not found ]
[12:01:06]
[12:01:06] Checking for Shutdown Rootkit…
[12:01:06] Checking for file ‘/usr/man/man5/.. /.dir/scannah/asus’ [ Not found ]
[12:01:06] Checking for file ‘/usr/man/man5/.. /.dir/see’ [ Not found ]
[12:01:07] Checking for file ‘/usr/man/man5/.. /.dir/nscd’ [ Not found ]
[12:01:07] Checking for file ‘/usr/man/man5/.. /.dir/alpd’ [ Not found ]
[12:01:07] Checking for file ‘/etc/rc.d/rc.local ‘ [ Not found ]
[12:01:07] Checking for directory ‘/usr/man/man5/.. /.dir’ [ Not found ]
[12:01:07] Checking for directory ‘/usr/man/man5/.. /.dir/scannah’ [ Not found ]
[12:01:07] Checking for directory ‘/etc/rc.d/rc0.d/.. /.dir’ [ Not found ]
[12:01:07] Shutdown Rootkit [ Not found ]
[12:01:07]
[12:01:07] Checking for SHV4 Rootkit…
[12:01:07] Checking for file ‘/etc/ld.so.hash’ [ Not found ]
[12:01:08] Checking for file ‘/lib/libext-2.so.7’ [ Not found ]
[12:01:08] Checking for file ‘/lib/lidps1.so’ [ Not found ]
[12:01:08] Checking for file ‘/usr/sbin/xntps’ [ Not found ]
[12:01:08] Checking for directory ‘/lib/security/.config’ [ Not found ]
[12:01:08] Checking for directory ‘/lib/security/.config/ssh’ [ Not found ]
[12:01:08] SHV4 Rootkit [ Not found ]
[12:01:08]
[12:01:08] Checking for SHV5 Rootkit…
[12:01:08] Checking for file ‘/etc/sh.conf’ [ Not found ]
[12:01:08] Checking for file ‘/dev/srd0’ [ Not found ]
[12:01:08] Checking for directory ‘/usr/lib/libsh’ [ Not found ]
[12:01:09] SHV5 Rootkit [ Not found ]
[12:01:09]
[12:01:09] Checking for Sin Rootkit…
[12:01:09] Checking for file ‘/dev/.haos/haos1/.f/Denyed’ [ Not found ]
[12:01:09] Checking for file ‘/dev/ttyoa’ [ Not found ]
[12:01:09] Checking for file ‘/dev/ttyof’ [ Not found ]
[12:01:09] Checking for file ‘/dev/ttyop’ [ Not found ]
[12:01:09] Checking for file ‘/dev/ttyos’ [ Not found ]
[12:01:09] Checking for file ‘/usr/lib/.lib’ [ Not found ]
[12:01:09] Checking for file ‘/usr/lib/sn/.X’ [ Not found ]
[12:01:09] Checking for file ‘/usr/lib/sn/.sys’ [ Not found ]
[12:01:10] Checking for file ‘/usr/lib/ld/.X’ [ Not found ]
[12:01:10] Checking for file ‘/usr/man/man1/…’ [ Not found ]
[12:01:10] Checking for file ‘/usr/man/man1/…/.m’ [ Not found ]
[12:01:10] Checking for file ‘/usr/man/man1/…/.w’ [ Not found ]
[12:01:10] Checking for directory ‘/usr/lib/sn’ [ Not found ]
[12:01:10] Checking for directory ‘/usr/lib/man1/…’ [ Not found ]
[12:01:10] Checking for directory ‘/dev/.haos’ [ Not found ]
[12:01:10] Sin Rootkit [ Not found ]
[12:01:10]
[12:01:10] Checking for Slapper Worm…
[12:01:11] Checking for file ‘/tmp/.bugtraq’ [ Not found ]
[12:01:11] Checking for file ‘/tmp/.uubugtraq’ [ Not found ]
[12:01:11] Checking for file ‘/tmp/.bugtraq.c’ [ Not found ]
[12:01:11] Checking for file ‘/tmp/httpd’ [ Not found ]
[12:01:11] Checking for file ‘/tmp/.unlock’ [ Not found ]
[12:01:11] Checking for file ‘/tmp/update’ [ Not found ]
[12:01:11] Checking for file ‘/tmp/.cinik’ [ Not found ]
[12:01:11] Checking for file ‘/tmp/.b’ [ Not found ]
[12:01:11] Slapper Worm [ Not found ]
[12:01:12]
[12:01:12] Checking for Sneakin Rootkit…
[12:01:12] Checking for directory ‘/tmp/.X11-unix/…/rk’ [ Not found ]
[12:01:12] Sneakin Rootkit [ Not found ]
[12:01:12]
[12:01:12] Checking for Suckit Rootkit…
[12:01:12] Checking for file ‘/sbin/initsk12’ [ Not found ]
[12:01:12] Checking for file ‘/sbin/initxrk’ [ Not found ]
[12:01:12] Checking for file ‘/usr/bin/null’ [ Not found ]
[12:01:12] Checking for file ‘/usr/share/locale/sk/.sk12/sk’ [ Not found ]
[12:01:12] Checking for file ‘/etc/rc.d/rc0.d/S23kmdac’ [ Not found ]
[12:01:12] Checking for file ‘/etc/rc.d/rc1.d/S23kmdac’ [ Not found ]
[12:01:12] Checking for file ‘/etc/rc.d/rc2.d/S23kmdac’ [ Not found ]
[12:01:13] Checking for file ‘/etc/rc.d/rc3.d/S23kmdac’ [ Not found ]
[12:01:13] Checking for file ‘/etc/rc.d/rc4.d/S23kmdac’ [ Not found ]
[12:01:13] Checking for file ‘/etc/rc.d/rc5.d/S23kmdac’ [ Not found ]
[12:01:13] Checking for file ‘/etc/rc.d/rc6.d/S23kmdac’ [ Not found ]
[12:01:13] Checking for directory ‘/dev/sdhu0/tehdrakg’ [ Not found ]
[12:01:13] Checking for directory ‘/etc/.MG’ [ Not found ]
[12:01:13] Checking for directory ‘/usr/share/locale/sk/.sk12’ [ Not found ]
[12:01:13] Checking for directory ‘/usr/lib/perl5/site_perl/i386-linux/auto/TimeDate/.packlist’ [ Not found ]
[12:01:13] Suckit Rootkit [ Not found ]
[12:01:14]
[12:01:14] Checking for SunOS Rootkit…
[12:01:14] Checking for file ‘/etc/ld.so.hash’ [ Not found ]
[12:01:14] Checking for file ‘/lib/libext-2.so.7’ [ Not found ]
[12:01:14] Checking for file ‘/usr/bin/ssh2d’ [ Not found ]
[12:01:14] Checking for file ‘/bin/xlogin’ [ Not found ]
[12:01:14] Checking for file ‘/usr/lib/crth.o’ [ Not found ]
[12:01:14] Checking for file ‘/usr/lib/crtz.o’ [ Not found ]
[12:01:14] Checking for file ‘/sbin/login’ [ Not found ]
[12:01:14] Checking for file ‘/lib/security/.config/sn’ [ Not found ]
[12:01:14] Checking for file ‘/lib/security/.config/lpsched’ [ Not found ]
[12:01:15] Checking for file ‘/dev/kmod’ [ Not found ]
[12:01:15] Checking for file ‘/dev/dos’ [ Not found ]
[12:01:15] SunOS Rootkit [ Not found ]
[12:01:15]
[12:01:15] Checking for SunOS / NSDAP Rootkit…
[12:01:15] Checking for file ‘/usr/lib/vold/nsdap/.kit’ [ Not found ]
[12:01:15] Checking for file ‘/usr/lib/vold/nsdap/defines’ [ Not found ]
[12:01:15] Checking for file ‘/usr/lib/vold/nsdap/patcher’ [ Not found ]
[12:01:15] Checking for file ‘/usr/lib/vold/nsdap/pg’ [ Not found ]
[12:01:15] Checking for file ‘/usr/lib/vold/nsdap/cleaner’ [ Not found ]
[12:01:15] Checking for file ‘/usr/lib/vold/nsdap/utime’ [ Not found ]
[12:01:15] Checking for file ‘/usr/lib/vold/nsdap/crypt’ [ Not found ]
[12:01:16] Checking for file ‘/usr/lib/vold/nsdap/findkit’ [ Not found ]
[12:01:16] Checking for file ‘/usr/lib/vold/nsdap/sn2’ [ Not found ]
[12:01:16] Checking for file ‘/usr/lib/vold/nsdap/sniffload’ [ Not found ]
[12:01:16] Checking for file ‘/usr/lib/vold/nsdap/runsniff’ [ Not found ]
[12:01:16] Checking for file ‘/usr/lib/lpset’ [ Not found ]
[12:01:16] Checking for directory ‘/usr/lib/vold/nsdap’ [ Not found ]
[12:01:16] SunOS / NSDAP Rootkit [ Not found ]
[12:01:16]
[12:01:16] Checking for Superkit Rootkit…
[12:01:16] Checking for file ‘/usr/man/.sman/sk’ [ Not found ]
[12:01:16] Superkit Rootkit [ Not found ]
[12:01:17]
[12:01:17] Checking for TBD (Telnet BackDoor)…
[12:01:17] Checking for file ‘/usr/lib/.tbd’ [ Not found ]
[12:01:17] TBD (Telnet BackDoor) [ Not found ]
[12:01:17]
[12:01:17] Checking for TeLeKiT Rootkit…
[12:01:17] Checking for file ‘/usr/man/man3/…/TeLeKiT/bin/sniff’ [ Not found ]
[12:01:17] Checking for file ‘/usr/man/man3/…/TeLeKiT/bin/telnetd’ [ Not found ]
[12:01:17] Checking for file ‘/usr/man/man3/…/TeLeKiT/bin/teleulo’ [ Not found ]
[12:01:17] Checking for file ‘/usr/man/man3/…/cl’ [ Not found ]
[12:01:17] Checking for file ‘/dev/ptyr’ [ Not found ]
[12:01:17] Checking for file ‘/dev/ptyp’ [ Not found ]
[12:01:18] Checking for file ‘/dev/ptyq’ [ Not found ]
[12:01:18] Checking for file ‘/dev/hda06’ [ Not found ]
[12:01:18] Checking for file ‘/usr/info/libc1.so’ [ Not found ]
[12:01:18] Checking for directory ‘/usr/man/man3/…’ [ Not found ]
[12:01:18] Checking for directory ‘/usr/man/man3/…/lsniff’ [ Not found ]
[12:01:18] Checking for directory ‘/usr/man/man3/…/TeLeKiT’ [ Not found ]
[12:01:18] TeLeKiT Rootkit [ Not found ]
[12:01:18]
[12:01:18] Checking for T0rn Rootkit…
[12:01:18] Checking for file ‘/dev/.lib/lib/lib/t0rns’ [ Not found ]
[12:01:18] Checking for file ‘/dev/.lib/lib/lib/du’ [ Not found ]
[12:01:18] Checking for file ‘/dev/.lib/lib/lib/ls’ [ Not found ]
[12:01:19] Checking for file ‘/dev/.lib/lib/lib/t0rnsb’ [ Not found ]
[12:01:19] Checking for file ‘/dev/.lib/lib/lib/ps’ [ Not found ]
[12:01:19] Checking for file ‘/dev/.lib/lib/lib/t0rnp’ [ Not found ]
[12:01:19] Checking for file ‘/dev/.lib/lib/lib/find’ [ Not found ]
[12:01:19] Checking for file ‘/dev/.lib/lib/lib/ifconfig’ [ Not found ]
[12:01:19] Checking for file ‘/dev/.lib/lib/lib/pg’ [ Not found ]
[12:01:19] Checking for file ‘/dev/.lib/lib/lib/ssh.tgz’ [ Not found ]
[12:01:19] Checking for file ‘/dev/.lib/lib/lib/top’ [ Not found ]
[12:01:19] Checking for file ‘/dev/.lib/lib/lib/sz’ [ Not found ]
[12:01:20] Checking for file ‘/dev/.lib/lib/lib/login’ [ Not found ]
[12:01:20] Checking for file ‘/dev/.lib/lib/lib/in.fingerd’ [ Not found ]
[12:01:20] Checking for file ‘/dev/.lib/lib/lib/1i0n.sh’ [ Not found ]
[12:01:20] Checking for file ‘/dev/.lib/lib/lib/pstree’ [ Not found ]
[12:01:20] Checking for file ‘/dev/.lib/lib/lib/in.telnetd’ [ Not found ]
[12:01:20] Checking for file ‘/dev/.lib/lib/lib/mjy’ [ Not found ]
[12:01:20] Checking for file ‘/dev/.lib/lib/lib/sush’ [ Not found ]
[12:01:20] Checking for file ‘/dev/.lib/lib/lib/tfn’ [ Not found ]
[12:01:20] Checking for file ‘/dev/.lib/lib/lib/name’ [ Not found ]
[12:01:20] Checking for file ‘/dev/.lib/lib/lib/getip.sh’ [ Not found ]
[12:01:21] Checking for file ‘/usr/info/.torn/sh*’ [ Not found ]
[12:01:21] Checking for file ‘/usr/src/.puta/.1addr’ [ Not found ]
[12:01:21] Checking for file ‘/usr/src/.puta/.1file’ [ Not found ]
[12:01:21] Checking for file ‘/usr/src/.puta/.1proc’ [ Not found ]
[12:01:21] Checking for file ‘/usr/src/.puta/.1logz’ [ Not found ]
[12:01:21] Checking for file ‘/usr/info/.t0rn’ [ Not found ]
[12:01:21] Checking for directory ‘/dev/.lib’ [ Not found ]
[12:01:21] Checking for directory ‘/dev/.lib/lib’ [ Not found ]
[12:01:21] Checking for directory ‘/dev/.lib/lib/lib’ [ Not found ]
[12:01:21] Checking for directory ‘/dev/.lib/lib/lib/dev’ [ Not found ]
[12:01:22] Checking for directory ‘/dev/.lib/lib/scan’ [ Not found ]
[12:01:22] Checking for directory ‘/usr/src/.puta’ [ Not found ]
[12:01:22] Checking for directory ‘/usr/man/man1/man1’ [ Not found ]
[12:01:22] Checking for directory ‘/usr/man/man1/man1/lib’ [ Not found ]
[12:01:22] Checking for directory ‘/usr/man/man1/man1/lib/.lib’ [ Not found ]
[12:01:22] Checking for directory ‘/usr/man/man1/man1/lib/.lib/.backup’ [ Not found ]
[12:01:22] T0rn Rootkit [ Not found ]
[12:01:22]
[12:01:22] Checking for Trojanit Kit…
[12:01:22] Checking for file ‘/bin/.ls’ [ Not found ]
[12:01:23] Checking for file ‘/bin/.ps’ [ Not found ]
[12:01:23] Checking for file ‘/bin/.netstat’ [ Not found ]
[12:01:23] Checking for file ‘/usr/bin/.nop’ [ Not found ]
[12:01:23] Checking for file ‘/usr/bin/.who’ [ Not found ]
[12:01:23] Trojanit Kit [ Not found ]
[12:01:23]
[12:01:23] Checking for Tuxtendo Rootkit…
[12:01:23] Checking for file ‘/dev/tux/.addr’ [ Not found ]
[12:01:23] Checking for file ‘/dev/tux/.cron’ [ Not found ]
[12:01:23] Checking for file ‘/dev/tux/.file’ [ Not found ]
[12:01:23] Checking for file ‘/dev/tux/.log’ [ Not found ]
[12:01:23] Checking for file ‘/dev/tux/.proc’ [ Not found ]
[12:01:24] Checking for file ‘/dev/tux/backup/crontab’ [ Not found ]
[12:01:24] Checking for file ‘/dev/tux/backup/df’ [ Not found ]
[12:01:24] Checking for file ‘/dev/tux/backup/dir’ [ Not found ]
[12:01:24] Checking for file ‘/dev/tux/backup/find’ [ Not found ]
[12:01:24] Checking for file ‘/dev/tux/backup/ifconfig’ [ Not found ]
[12:01:24] Checking for file ‘/dev/tux/backup/locate’ [ Not found ]
[12:01:24] Checking for file ‘/dev/tux/backup/netstat’ [ Not found ]
[12:01:24] Checking for file ‘/dev/tux/backup/ps’ [ Not found ]
[12:01:24] Checking for file ‘/dev/tux/backup/pstree’ [ Not found ]
[12:01:25] Checking for file ‘/dev/tux/backup/syslogd’ [ Not found ]
[12:01:25] Checking for file ‘/dev/tux/backup/tcpd’ [ Not found ]
[12:01:25] Checking for file ‘/dev/tux/backup/top’ [ Not found ]
[12:01:25] Checking for file ‘/dev/tux/backup/updatedb’ [ Not found ]
[12:01:25] Checking for file ‘/dev/tux/backup/vdir’ [ Not found ]
[12:01:25] Checking for directory ‘/dev/tux’ [ Not found ]
[12:01:25] Checking for directory ‘/dev/tux/ssh2’ [ Not found ]
[12:01:25] Checking for directory ‘/dev/tux/backup’ [ Not found ]
[12:01:25] Tuxtendo Rootkit [ Not found ]
[12:01:25]
[12:01:25] Checking for URK Rootkit…
[12:01:26] Checking for file ‘/usr/man/man1/xxxxxxbin/find’ [ Not found ]
[12:01:26] Checking for file ‘/usr/man/man1/xxxxxxbin/du’ [ Not found ]
[12:01:26] Checking for file ‘/usr/man/man1/xxxxxxbin/ps’ [ Not found ]
[12:01:26] Checking for file ‘/tmp/conf.inf’ [ Not found ]
[12:01:26] Checking for directory ‘/usr/man/man1/xxxxxxbin’ [ Not found ]
[12:01:26] URK Rootkit [ Not found ]
[12:01:26]
[12:01:26] Checking for VcKit Rootkit…
[12:01:26] Checking for directory ‘/usr/include/linux/modules/lib.so’ [ Not found ]
[12:01:26] Checking for directory ‘/usr/include/linux/modules/lib.so/bin’ [ Not found ]
[12:01:26] VcKit Rootkit [ Not found ]
[12:01:27]
[12:01:27] Checking for Volc Rootkit…
[12:01:27] Checking for directory ‘/var/spool/.recent’ [ Not found ]
[12:01:27] Checking for directory ‘/var/spool/.recent/.files’ [ Not found ]
[12:01:27] Checking for directory ‘/usr/lib/volc’ [ Not found ]
[12:01:27] Checking for directory ‘/usr/lib/volc/backup’ [ Not found ]
[12:01:27] Volc Rootkit [ Not found ]
[12:01:27]
[12:01:27] Checking for X-Org SunOS Rootkit…
[12:01:27] Checking for file ‘/usr/lib/libX.a/bin/tmpfl’ [ Not found ]
[12:01:27] Checking for file ‘/usr/lib/libX.a/bin/rps’ [ Not found ]
[12:01:27] Checking for file ‘/usr/bin/srload’ [ Not found ]
[12:01:28] Checking for file ‘/usr/lib/libX.a/bin/sparcv7/rps’ [ Not found ]
[12:01:28] Checking for file ‘/usr/sbin/modcheck’ [ Not found ]
[12:01:28] Checking for directory ‘/usr/lib/libX.a’ [ Not found ]
[12:01:28] Checking for directory ‘/usr/lib/libX.a/bin’ [ Not found ]
[12:01:28] Checking for directory ‘/usr/lib/libX.a/bin/sparcv7’ [ Not found ]
[12:01:28] Checking for directory ‘/usr/share/man…’ [ Not found ]
[12:01:28] X-Org SunOS Rootkit [ Not found ]
[12:01:28]
[12:01:28] Checking for zaRwT.KiT Rootkit…
[12:01:28] Checking for file ‘/dev/rd/s/sendmeil’ [ Not found ]
[12:01:29] Checking for file ‘/dev/ttyf’ [ Not found ]
[12:01:29] Checking for file ‘/dev/ttyp’ [ Not found ]
[12:01:29] Checking for file ‘/dev/ttyn’ [ Not found ]
[12:01:29] Checking for file ‘/rk/tulz’ [ Not found ]
[12:01:29] Checking for directory ‘/rk’ [ Not found ]
[12:01:29] Checking for directory ‘/dev/rd/s’ [ Not found ]
[12:01:29] zaRwT.KiT Rootkit [ Not found ]
[12:01:29]
[12:01:29] Performing additional rootkit checks
[12:01:29] Info: Starting test name ‘additional_rkts’
[12:01:29]
[12:01:29] Performing Suckit Rookit additional checks
[12:01:30] Checking /sbin/init link count [ OK ]
[12:01:30] Checking for hidden file extensions [ None found ]
[12:01:30] Running skdet command [ Skipped ]
[12:01:30] Info: Unable to find the ‘skdet’ command
[12:01:30] Suckit Rookit additional checks [ OK ]
[12:01:30]
[12:01:30] Performing check of possible rootkit files and directories
[12:01:30] Info: Starting test name ‘possible_rkt_files’
[12:01:30] Checking for file ‘/dev/sdr0’ [ Not found ]
[12:01:30] Checking for file ‘/tmp/.syshackfile’ [ Not found ]
[12:01:31] Checking for file ‘/tmp/.bash_history’ [ Not found ]
[12:01:31] Checking for file ‘/usr/info/.clib’ [ Not found ]
[12:01:31] Checking for file ‘/usr/sbin/tcp.log’ [ Not found ]
[12:01:31] Checking for file ‘/usr/bin/take/pid’ [ Not found ]
[12:01:31] Checking for file ‘/sbin/create’ [ Not found ]
[12:01:31] Checking for file ‘/dev/ttypz’ [ Not found ]
[12:01:31] Checking for directory ‘/usr/bin/take’ [ Not found ]
[12:01:32] Checking for directory ‘/usr/src/.lib’ [ Not found ]
[12:01:32] Checking for directory ‘/usr/share/man/man1/.1c’ [ Not found ]
[12:01:32] Checking for directory ‘/lib/lblip.tk’ [ Not found ]
[12:01:32] Checking for directory ‘/usr/sbin/…’ [ Not found ]
[12:01:32] Checking for directory ‘/usr/share/.gun’ [ Not found ]
[12:01:32] Checking for possible rootkit files and directories [ None found ]
[12:01:32]
[12:01:32] Performing check for possible rootkit strings
[12:01:32] Info: Starting test name ‘possible_rkt_strings’
[12:01:33] Info: Found local startup file: /etc/rc.d/rc.local
[12:01:33] Info: Found local startup file: /etc/rc.d/rc.sysinit
[12:01:33] Info: Found local startup file: /etc/inittab
[12:01:33] Checking for string ‘/dev/proc/fuckit’ [ Not found ]
[12:01:33] Checking for string ‘FUCK’ [ Not found ]
[12:01:33] Checking for string ‘backdoor’ [ Not found ]
[12:01:33] Checking for string ‘vt200’ [ Not found ]
[12:01:33] Checking for string ‘/usr/bin/xstat’ [ Not found ]
[12:01:34] Checking for string ‘/bin/envpc’ [ Not found ]
[12:01:34] Checking for string ‘L4m3r0x’ [ Not found ]
[12:01:34] Checking for string ‘/usr/lib/.tbd’ [ Not found ]
[12:01:34] Checking for string ‘/dev/ptyxx/.file’ [ Not found ]
[12:01:34] Checking for string ‘/dev/sgk’ [ Not found ]
[12:01:34] Checking for string ‘/var/lock/subsys/…datafile…’ [ Not found ]
[12:01:35] Checking for string ‘/usr/lib/.tbd’ [ Not found ]
[12:01:35] Checking for string ‘/dev/proc/fuckit’ [ Not found ]
[12:01:35] Checking for string ‘/lib/.sso’ [ Not found ]
[12:01:35] Checking for string ‘/var/lock/subsys/…datafile…’ [ Not found ]
[12:01:35] Checking for string ‘/dev/caca’ [ Not found ]
[12:01:36] Checking for string ‘/dev/ttyoa’ [ Not found ]
[12:01:36] Checking for string ‘syg’ [ Not found ]
[12:01:36] Checking for string ‘sshd_config’ [ Not found ]
[12:01:36] Checking for string ‘/dev/pts/01’ [ Not found ]
[12:01:36] Checking for string ‘tw33dl3’ [ Not found ]
[12:01:36] Checking for string ‘psniff’ [ Not found ]
[12:01:37] Checking for string ‘/var/lock/subsys/…datafile…’ [ Not found ]
[12:01:37] Checking for string ‘cant open log’ [ Not found ]
[12:01:37] Checking for string ‘sniff.pid’ [ Not found ]
[12:01:37] Checking for string ‘tcp.log’ [ Not found ]
[12:01:37] Checking for string ‘/dev/ptyxx’ [ Not found ]
[12:01:38] Checking for string ‘promiscuous’ [ Not found ]
[12:01:38] Checking for string ‘/usr/lib/.tbd’ [ Not found ]
[12:01:38] Checking for string ‘/dev/xdta’ [ Not found ]
[12:01:38] Checking for string ‘/usr/lib/.tbd’ [ Not found ]
[12:01:38] Checking for string ‘in.inetd’ [ Not found ]
[12:01:39] Checking for string ‘#<HIDE_.*>’ [ Not found ]
[12:01:39] Checking for string ‘bin/xchk’ [ Not found ]
[12:01:39] Checking for string ‘bin/xsf’ [ Not found ]
[12:01:39] Checking for possible rootkit strings [ None found ]
[12:01:39]
[12:01:39] Performing malware checks
[12:01:39] Info: Starting test name ‘malware’
[12:01:39]
[12:01:39] Info: Test ‘deleted_files’ disabled at users request.
[12:01:39] Info: Starting test name ‘running_procs’
[12:01:40] Checking running processes for suspicious files [ None found ]
[12:01:40]
[12:01:40] Info: Test ‘hidden_procs’ disabled at users request.
[12:01:40]
[12:01:40] Info: Test ‘suspscan’ disabled at users request.
[12:01:40]
[12:01:40] Performing check for login backdoors
[12:01:40] Info: Starting test name ‘other_malware’
[12:01:40] Checking for ‘/bin/.login’ [ Not found ]
[12:01:40] Checking for ‘/sbin/.login’ [ Not found ]
[12:01:40] Checking for login backdoors [ None found ]
[12:01:41]
[12:01:41] Performing check for suspicious directories
[12:01:41] Checking for directory ‘/usr/X11R6/bin/.,/copy’ [ Not found ]
[12:01:41] Checking for directory ‘/dev/rd/cdb’ [ Not found ]
[12:01:41] Checking for suspicious directories [ None found ]
[12:01:41]
[12:01:41] Checking for software intrusions [ Skipped ]
[12:01:41] Info: Check skipped – tripwire not installed
[12:01:41]
[12:01:41] Performing check for sniffer log files
[12:01:41] Checking for file ‘/usr/lib/libice.log’ [ Not found ]
[12:01:41] Checking for sniffer log files [ None found ]
[12:01:41]
[12:01:41] Performing trojan specific checks
[12:01:42] Info: Starting test name ‘trojans’
[12:01:42] Checking for enabled inetd services [ Skipped ]
[12:01:42] Info: Check skipped – file ‘/etc/inetd.conf’ does not exist.
[12:01:42]
[12:01:42] Performing check for enabled xinetd services
[12:01:42] Info: Using xinetd configuration file ‘/etc/xinetd.conf’
[12:01:42] Checking ‘/etc/xinetd.conf’ for enabled services [ None found ]
[12:01:42] Found ‘includedir /etc/xinetd.d’ directive
[12:01:42] Checking ‘/etc/xinetd.d/chargen’ for enabled services [ None found ]
[12:01:42] Checking ‘/etc/xinetd.d/chargen-udp’ for enabled services [ None found ]
[12:01:43] Checking ‘/etc/xinetd.d/cups-lpd’ for enabled services [ None found ]
[12:01:43] Checking ‘/etc/xinetd.d/daytime’ for enabled services [ None found ]
[12:01:43] Checking ‘/etc/xinetd.d/daytime-udp’ for enabled services [ None found ]
[12:01:43] Checking ‘/etc/xinetd.d/echo’ for enabled services [ None found ]
[12:01:43] Checking ‘/etc/xinetd.d/echo-udp’ for enabled services [ None found ]
[12:01:43] Checking ‘/etc/xinetd.d/eklogin’ for enabled services [ None found ]
[12:01:44] Checking ‘/etc/xinetd.d/gssftp’ for enabled services [ None found ]
[12:01:44] Checking ‘/etc/xinetd.d/klogin’ for enabled services [ None found ]
[12:01:44] Checking ‘/etc/xinetd.d/krb5-telnet’ for enabled services [ None found ]
[12:01:44] Checking ‘/etc/xinetd.d/kshell’ for enabled services [ None found ]
[12:01:44] Checking ‘/etc/xinetd.d/rsync’ for enabled services [ None found ]
[12:01:44] Checking ‘/etc/xinetd.d/telnet’ for enabled services [ None found ]
[12:01:45] Checking ‘/etc/xinetd.d/time’ for enabled services [ None found ]
[12:01:45] Checking ‘/etc/xinetd.d/time-udp’ for enabled services [ None found ]
[12:01:45] Checking for enabled xinetd services [ None found ]
[12:01:45] Info: Apache backdoor check skipped: Apache modules and configuration directories not found.
[12:01:45]
[12:01:45] Performing Linux specific checks
[12:01:45] Info: Starting test name ‘os_specific’
[12:01:45] Checking kernel module commands [ OK ]
[12:01:45] Info: Using modules pathname of ‘/lib/modules/2.6.9-55.0.12.EL’
[12:01:46] Checking kernel module names [ OK ]
[12:01:48]
[12:01:48] Checking the network…
[12:01:49] Info: Starting test name ‘network’
[12:01:49] Info: Starting test name ‘ports’
[12:01:49]
[12:01:49] Performing check for backdoor ports
[12:01:49] Checking for UDP port 2001 [ Not found ]
[12:01:49] Checking for TCP port 2006 [ Not found ]
[12:01:49] Checking for TCP port 2128 [ Not found ]
[12:01:50] Checking for TCP port 14856 [ Not found ]
[12:01:50] Checking for TCP port 47107 [ Not found ]
[12:01:50] Checking for TCP port 60922 [ Not found ]
[12:01:50]
[12:01:50] Performing checks on the network interfaces
[12:01:50] Info: Starting test name ‘promisc’
[12:01:51] Checking for promiscuous interfaces [ None found ]
[12:01:51]
[12:01:51] Info: Test ‘packet_cap_apps’ disabled at users request.
[12:02:02]
[12:02:02] Checking the local host…
[12:02:02] Info: Starting test name ‘local_host’
[12:02:02]
[12:02:02] Performing system boot checks
[12:02:02] Info: Starting test name ‘startup_files’
[12:02:02] Checking for local host name [ Found ]
[12:02:02] Info: Starting test name ‘startup_malware’
[12:02:02] Info: Found local startup file: /etc/rc.d/rc.local
[12:02:03] Info: Found local startup file: /etc/rc.d/rc.sysinit
[12:02:03] Info: Found local startup file: /etc/inittab
[12:02:03] Checking for local startup files [ Found ]
[12:02:03] Checking local startup files for malware [ None found ]
[12:02:03] Info: Found system startup directory: /etc/rc.d
[12:02:07] Checking system startup files for malware [ None found ]
[12:02:07]
[12:02:07] Performing group and account checks
[12:02:07] Info: Starting test name ‘group_accounts’
[12:02:07] Checking for passwd file [ Found ]
[12:02:07] Info: Found password file: /etc/passwd
[12:02:07] Checking for root equivalent (UID 0) accounts [ None found ]
[12:02:07] Info: Found shadow file: /etc/shadow
[12:02:07] Checking for passwordless accounts [ None found ]
[12:02:08] Info: Starting test name ‘passwd_changes’
[12:02:08] Checking for passwd file changes [ None found ]
[12:02:08] Info: Starting test name ‘group_changes’
[12:02:08] Checking for group file changes [ None found ]
[12:02:08] Checking root account shell history files [ OK ]
[12:02:08]
[12:02:08] Performing system configuration file checks
[12:02:08] Info: Starting test name ‘system_configs’
[12:02:08] Checking for SSH configuration file [ Found ]
[12:02:08] Info: Found SSH configuration file: /etc/ssh/sshd_config
[12:02:08] Info: Rkhunter option ALLOW_SSH_ROOT_USER set to ‘no’.
[12:02:09] Checking if SSH root access is allowed [ Warning ]
[12:02:09] Warning: The SSH configuration option ‘PermitRootLogin’ has not been set.
The default value may be ‘yes’, to allow root access.
[12:02:09] Checking if SSH protocol v1 is allowed [ Warning ]
[12:02:09] Warning: The SSH configuration option ‘Protocol’ has not been set.
The default value may be ‘2,1’, to allow the use of protocol v1.
[12:02:09] Checking for running syslog daemon [ Found ]
[12:02:09] Checking for syslog configuration file [ Found ]
[12:02:09] Info: Found syslog configuration file: /etc/syslog.conf
[12:02:09] Checking if syslog remote logging is allowed [ Not allowed ]
[12:02:10]
[12:02:10] Performing filesystem checks
[12:02:10] Info: Starting test name ‘filesystem’
[12:02:10] Info: SCAN_MODE_DEV set to ‘THOROUGH’
[12:02:21] Checking /dev for suspicious file types [ None found ]
[12:02:22] Checking for hidden files and directories [ Warning ]
[12:02:22] Warning: Hidden file found: /usr/share/man/man1/..1.gz: gzip compressed data, from Unix, max compression
[12:02:24]
[12:02:24] Checking application versions…
[12:02:24] Info: Starting test name ‘apps’
[12:02:25] Info: Application ‘exim’ not found.
[12:02:25] Checking version of GnuPG [ Warning ]
[12:02:26] Warning: Application ‘gpg’, version ‘1.2.6’, is out of date, and possibly a security risk.
[12:02:26] Info: Application ‘httpd’ not found.
[12:02:26] Info: Application ‘named’ not found.
[12:02:26] Checking version of OpenSSL [ Warning ]
[12:02:26] Warning: Application ‘openssl’, version ‘0.9.7a’, is out of date, and possibly a security risk.
[12:02:26] Info: Application ‘php’ not found.
[12:02:26] Checking version of Procmail MTA [ OK ]
[12:02:26] Info: Application ‘procmail’ version ‘3.22’ found.
[12:02:26] Info: Application ‘proftpd’ not found.
[12:02:26] Checking version of OpenSSH [ OK ]
[12:02:27] Info: Application ‘sshd’ version ‘3.9p1’ found.
[12:02:27] Info: Applications checked: 4 out of 9
[12:02:27]
[12:02:27] System checks summary
[12:02:27] =====================
[12:02:27]
[12:02:27] File properties checks…
[12:02:27] Required commands check failed
[12:02:27] Files checked: 127
[12:02:27] Suspect files(疑わしきファイル): 6
[12:02:27]
[12:02:27] Rootkit checks…
[12:02:27] Rootkits checked : 114
[12:02:27] Possible rootkits(仕掛けられてるrootkit): 0
[12:02:27]
[12:02:27] Applications checks…
[12:02:27] Applications checked: 4
[12:02:27] Suspect applications(疑わしきアプリケーション): 2
[12:02:28]
[12:02:28] The system checks took: 2 minutes and 35 seconds
[12:02:28]
[12:02:28] Info: End date is Tue Nov 27 12:02:28 JST 2007

最終的なチェック結果は、以下のシステムサマリーでわかる。
[12:02:27] System checks summary
[12:02:27] =====================
[12:02:27]
[12:02:27] File properties checks…
[12:02:27] Required commands check failed
[12:02:27] Files checked: 127
[12:02:27] Suspect files(疑わしきファイル): 6
[12:02:27]
[12:02:27] Rootkit checks…
[12:02:27] Rootkits checked : 114
[12:02:27] Possible rootkits(仕掛けられてるrootkit): 0
[12:02:27]
[12:02:27] Applications checks…
[12:02:27] Applications checked: 4
[12:02:27] Suspect applications(疑わしきアプリケーション): 2
[12:02:28]
[12:02:28] The system checks took: 2 minutes and 35 seconds
[12:02:28]
[12:02:28] Info: End date is Tue Nov 27 12:02:28 JST 2007

このホストのチェック結果で言えることは、
■仕掛けられてるrootkitは幸い無かったが、疑わしきファイルと疑わしきアプリケーションが有った。
■疑わしきファイルとは、「ファイル自体がバイナリではなくシェルスクリプトでテキストになっていて実行可能なファイルになっているので気をつけなさい。」と言っている。
■疑わしきアプリケーションに対しては、「このアプリケーションは、バージョンが古いのでセキュリティ的にリスクを伴いますよ。」という事を言っている。

したがって、「疑わしき」と有るがそれ自体が必ず改変されている事を表しているのではない。あくまでも黒に近い白みたいなものである。
以上

コメント