LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-12-2003, 09:54 PM   #1
jimrt
Member
 
Registered: Mar 2003
Posts: 32

Rep: Reputation: 15
Showtee root kit


Hi,

I recently installed the ganglia monitoring package (compiled from source) on several of my boxes. It installs the file: /usr/include/file.h . Chkrootkit is warning that I may have a Showtee root kit installed based on the existence of this file. I have listed the contents of the file below. Is this a real root-kit or is it simply a false psoitive?


#ifndef FILE_H
#define FILE_H 1

/* FreeBSD seems to gag on these.. Yet still works when not compiled in */
#if defined(BSD)
ssize_t readn (int fd, void *vptr, size_t n);
ssize_t writen (int fd, const void *vptr, size_t n);
#endif
int slurpfile ( char * filename, char *buffer, int buflen );
char *skip_whitespace ( const char *p);
char *skip_token ( const char *p);

#endif


Thanks.
 
Old 03-12-2003, 10:34 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
I'm pretty sure this is an FP: ([ -f /usr/include/file.h ]), tho that's not a fact.

If you want to be 100 percent sure you could sha1sum your file(s) and ask one of the developers to verify it. I mean, that's the proper way I guess since they don't tack sha1/md5sums or gpg sigs onto their tarballs. If you've got Aide, Samhain or Tripwire installed and maintained the database the right way, I guess you can go for 100 percent minus some calculated risks.

I find this "Showtee" stuff kinda funny, jus like the RHSharpe one. There's only one reference on the 'web and I've still gotta find sources for both "in the wild".
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
SONY BMG root kit -- do their discs play on Linux? beeblequix Linux - Software 1 12-02-2005 02:03 PM
medion kit snabgi Linux - Wireless Networking 1 01-17-2004 09:29 AM
Dos kit khopdire Linux - Software 1 06-26-2003 08:42 AM
TV Tool Kit suriyamohan Programming 2 03-21-2003 09:25 PM
Kit/aim KhzX Linux - General 6 01-05-2003 08:34 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:17 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration