LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-27-2005, 01:22 AM   #1
PennyroyalFrog
Member
 
Registered: Mar 2004
Location: Michigan
Distribution: Gentoo 2006.1
Posts: 107

Rep: Reputation: 15
chkrootkit message - good or bad?


chkrootkit outputs the following line:

Code:
Checking `sniffer'... /proc/28059/fd: No such file or directory
Is this something to be worried about? Thanks in advance.
 
Old 11-27-2005, 07:18 AM   #2
lacerto
Member
 
Registered: Oct 2003
Location: South London
Distribution: Gentoo.
Posts: 297

Rep: Reputation: 30
Nothing to worry about - the number directories are running process information by PID. Just means you don't have that particular process running
 
Old 11-27-2005, 10:42 AM   #3
PennyroyalFrog
Member
 
Registered: Mar 2004
Location: Michigan
Distribution: Gentoo 2006.1
Posts: 107

Original Poster
Rep: Reputation: 15
Thanks
 
Old 11-27-2005, 11:04 AM   #4
PennyroyalFrog
Member
 
Registered: Mar 2004
Location: Michigan
Distribution: Gentoo 2006.1
Posts: 107

Original Poster
Rep: Reputation: 15
Also, I get:

Code:
Checking `sniffer'... eth0: PF_PACKET(/sbin/dhcpcd)
I have pretty much have always had this and assumed it was a false positive. I get it everytime I run chkrootkit, and was curious if that was odd since i thought that the dhcp client doesn't always look for or check the dhcp server, or does it? Somebody enlighten me if this is also a false postive plz. Thanks
 
Old 11-27-2005, 06:38 PM   #5
PennyroyalFrog
Member
 
Registered: Mar 2004
Location: Michigan
Distribution: Gentoo 2006.1
Posts: 107

Original Poster
Rep: Reputation: 15
don't want to bump, but i'm kinda anxious about this
 
Old 11-27-2005, 07:30 PM   #6
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
It's also a common false positive that has to do with the type of socket that the DHCP client uses. You should still always verify the integrity of the dhcpd binary. On rpm-based systems you can use rpm -V binary name or compare its md5 hash to a known good version. Also I believe the other message has to do with short lived processes terminating before the check can be made. When you get a warning like that, you should re-run the scan and make sure that it comes back clean (i.e that the flagged file descriptor doesn't show up again).
 
Old 11-27-2005, 11:32 PM   #7
PennyroyalFrog
Member
 
Registered: Mar 2004
Location: Michigan
Distribution: Gentoo 2006.1
Posts: 107

Original Poster
Rep: Reputation: 15
Yea, ran chkrootkit again and it still appeared after several times (the /proc/#####/fd that is) but after i rebooted i no longer get it. I've googled it (before posting) and saw it some outputs of what people posted however nobody referred to that part as being a "true positive". I asked here cuz I can get a more targeted answer.

So you think both were false positives? I run gentoo btw, so no rpms, but i'll see if i can compare the md5 of the tarball portage used with a known one. Thanks.

Last edited by PennyroyalFrog; 11-27-2005 at 11:36 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
shell prints bad code when returning message backpacker Linux - Software 14 06-29-2005 02:53 AM
bad super-block message when udev is enabled LSA Slackware 1 11-03-2004 06:26 PM
bad interpreter error message ffenics2002 Linux - Software 2 04-15-2004 12:17 PM
Bad message with compiled kernel melinda_sayang Linux - General 2 02-18-2004 10:06 PM
Bad message from freshmeat :( LinFreak! General 7 09-24-2003 03:47 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:41 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration