LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 01-01-2014, 04:06 PM   #1
shorto
Member
 
Registered: Jul 2006
Distribution: Debian 6.0.2.1 i386
Posts: 111

Rep: Reputation: 15
Rkhunter weird log - Debian 7


Hello everybody,

My server started acting weird today so I just ran an apt-upgrade and after that rkhunter that warned me quite a few times about certain files. Could I possibly be hacked?

http://pastebin.com/5sqqvE4n

Sorry for the long log file, any advice?
 
Old 01-01-2014, 05:29 PM   #2
aus9
LQ 5k Club
 
Registered: Oct 2003
Location: Western Australia
Distribution: Icewm
Posts: 5,842

Rep: Reputation: Disabled
crudely the log says no kits detected.

2) you appear to have modified your conf file as I can see a whitelisted item but did you config for your packagemanager checks?

How about a link to your conf

3) have you considered installing and enabling extra checks such as

unhide skdet etc

http://sourceforge.net/apps/trac/rkh...MPRKH#Contents

4) you have no external mail setup or local mail

5)
Quote:
My server started acting weird today
does not help much

when did you start your first scan for RKH?

----before the upgrade?

did you keep any logs and did you read the readme? or the FAQ

When you think you have a (potential) security problem it is advised to
think and inform yourself thoroughly before you act. Please consider
checking the FAQ, the rkhunter-users mailing list archives, your
distribution documentation about security and security issues and the
CERT Intruder Detection Checklist, formerly located at
http://www.cert.org/tech_tips/intrud...checklist.html, and
archived at

http://web.archive.org/web/200801092...checklist.html


BTW you may have been better off posting in the security section as I am not an expert

Last edited by aus9; 01-01-2014 at 05:31 PM.
 
Old 01-01-2014, 06:41 PM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by shorto View Post
My server started acting weird today
Weird in what way? Please describe in detail.


Quote:
Originally Posted by shorto View Post
so I just ran an apt-upgrade
Who told you to do that? What would that fix? If you suspect a machine to be compromised then the best way to aid a perp would be to destroy evidence.


Quote:
Originally Posted by shorto View Post
and after that rkhunter that warned me quite a few times about certain files.
Well doh, the output clearly reads:
Code:
Warning: The O/S name or version has changed since the last run:
[22:52:08]          Old O/S value: Debian 7.1    New value: Debian 7.3
It continues to tell you what to expect:
Code:
[22:52:08]          Because of the change(s) the file properties checks may give some false-positive results.
...and how to fix it:
Code:
[22:52:08]          You may need to re-run rkhunter with the '--propupd' option.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Debian bind9 debug log: weird entries and how to interpret them rrije Linux - Software 1 12-21-2013 05:14 AM
Need help reading rkhunter log Spinetta Linux - Security 7 01-09-2013 08:43 AM
rkhunter scan: 1 Rootkit & 6 Possible Suspect Files /var/log/rkhunter.log included Mollusc Linux - Security 10 09-29-2011 08:43 AM
/var/log/rkhunter.log - rkhunter's (rootkit detection) logfile ahartman Linux - Security 1 07-04-2009 05:28 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 02:51 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration