LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-28-2006, 11:17 AM   #1
itaadmiraltyps
LQ Newbie
 
Registered: Apr 2006
Posts: 1

Rep: Reputation: 0
advice on chkrootkit -q output


Hi all,

need advice on this . . . should I be concerned . . . FC5 on x86 kernel-2.6.16-custom . . . thanks in advance

[root@localhost box#]chkrootkit -q

/usr/lib/perl5/5.8.8/i386-linux-thread-multi/.packlist /usr/lib/qt-3.3/etc/settings/.qt_plugins_3.3rc.lock /usr/lib/qt-3.3/etc/settings/.qtrc.lock

/proc/2664/fd: No such file or directory
eth0: PF_PACKET(/sbin/dhclient)
The tty of the following user process(es) were not found
in /var/run/utmp !
! RUID PID TTY CMD
! root 2337 tty5 /sbin/mingetty tty5
! root 2348 tty6 /sbin/mingetty tty6
! root 2433 tty7 /usr/bin/Xorg :0 -audit 0 -auth /var/gdm/:0.Xauth -nolisten tcp vt7
 
Old 05-28-2006, 11:33 AM   #2
macemoneta
Senior Member
 
Registered: Jan 2005
Location: Manalapan, NJ
Distribution: Fedora x86 and x86_64, Debian PPC and ARM, Android
Posts: 4,593
Blog Entries: 2

Rep: Reputation: 344Reputation: 344Reputation: 344Reputation: 344
No, these messages are quite normal. You will also occassionally see a false positive on an LKM trojan, also normal.

Processes start and terminate all the time, making the consolidation of information on misbehaving software a little problematic.
 
Old 05-31-2006, 11:02 PM   #3
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Manually check the .packlist and .qtrc.lock file. chkrootkit flags anything outside of standard user homedirs that has a filename prefixed with "." ,so these are normal as well. For the PF_PACKET warning, verify the integrity of the dhclient bianry with rpm -V dhclient (it will give no output if it passes). As macemoneta said, these are fairly common false positives, but it is a good idea to follow up on them anyway.
 
  


Reply

Tags
fc5



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Advice sought RE Input/output errors during backup attempt conn-fused Linux - Software 2 12-17-2005 01:25 AM
help me to understand the output of chkrootkit ddaas Linux - Security 2 04-19-2005 02:28 AM
Advice on the output of sensors??? bruno buys Linux - Software 1 08-15-2004 09:46 PM
need advice - chkrootkit estatik Linux - Security 10 03-21-2004 06:00 PM
Output of chkrootkit Toadman Linux - Security 2 08-14-2003 09:22 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:33 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration