LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-14-2004, 08:56 AM   #1
Chiel
LQ Newbie
 
Registered: Jul 2004
Location: Holland
Distribution: Mandrake
Posts: 12

Rep: Reputation: 0
Hidden files warning


> Hi i use linspire for a few days now and because i was hacked like a week or to ago (when i used mandrake OS) i scan my system more often with rkhunter and Clamav clamscan.
>
> the results at the end of both scans were 0 found, but rootkithunter gave a warning when scanning hidden files in the /etc.java directory with the message that i should check that directory.
>
> i turned on the option view hidden files and went in that Dir. i found 2 empty files
> But they where modified at the day all was installed.

System checks
* Allround tests
Checking hostname... Found. Hostname is bodhisatva
Checking for passwordless user accounts... OK
Checking for differences in user accounts... OK. No changes.
Checking for differences in user groups... OK. No changes.
Checking boot.local/rc.local file...
- /etc/rc.local [ Not found ]
- /etc/rc.d/rc.local [ Not found ]
- /usr/local/etc/rc.local [ Not found ]
- /usr/local/etc/rc.d/rc.local [ Not found ]
- /etc/conf.d/local.start [ Not found ]
- /etc/init.d/boot.local [ Not found ]
Checking rc.d files... [ Not found ]
Checking history files
Bourne Shell [ OK ]

* Filesystem checks
Checking /dev for suspicious files... [ OK ]
Scanning for hidden files... [ Warning! ]
---------------
/dev/.devfsd /etc/.java
/etc/.pwd.lock
---------------
Please inspect: /etc/.java (directory)

[Press <ENTER> to continue]


MD5
MD5 compared: 0
Incorrect MD5 checksums: 0

File scan
Scanned files: 328
Possible infected files: 0

Application scan
Vulnerable applications: 0

Scanning took 80 seconds

-----------------------------------------------------------------------

Do you have some problems, undetected rootkits, false positives, ideas
or suggestions?
Please e-mail me by filling in the contact form (@http://www.rootkit.nl)


Can there be some hidden files i realy can not see, can that be dangerous and should i be worried?

Last edited by Chiel; 11-14-2004 at 09:15 AM.
 
Old 11-14-2004, 03:09 PM   #2
XavierP
Moderator
 
Registered: Nov 2002
Location: Kent, England
Distribution: Debian Testing
Posts: 19,192
Blog Entries: 4

Rep: Reputation: 475Reputation: 475Reputation: 475Reputation: 475Reputation: 475
What happened when you checked the /etc/.java directory? Just because a directory is hidden doesn't mean that you can't see it - open your file browser (I'm guessing yours is Konqueror) and click View --> Show Hidden Files.

If I remember correctly, RootKit Hunter can sometimes bring up false positives.
 
Old 11-14-2004, 04:58 PM   #3
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
If I remember correctly, RootKit Hunter can sometimes bring up false positives.

Yep. RkHunter will normally flag anything outside of /home that's a hidden file. Check text files manually to make sure that they're not malicious.
 
Old 11-15-2004, 12:28 PM   #4
Chiel
LQ Newbie
 
Registered: Jul 2004
Location: Holland
Distribution: Mandrake
Posts: 12

Original Poster
Rep: Reputation: 0
Thnx i always hve the option show/vieuw hidden files on and when i check the files manualy it looks normal so i guess all is allright
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Hidden files? sonic04002 Linux - Newbie 2 11-09-2005 01:48 PM
Hidden Files coold8 Linux - General 5 04-27-2005 11:26 PM
hidden files Jeebizz Slackware 4 04-22-2005 07:18 PM
home directory files gone, hidden files remain Grasshopper Linux - Security 12 04-10-2005 08:23 PM
hidden files Alwyn Linux - Newbie 2 01-27-2005 12:20 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:04 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration