LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-14-2010, 05:27 AM   #1
james_larson
Member
 
Registered: Jul 2009
Posts: 31

Rep: Reputation: 0
question on rkhunter


i was just doing my regular stuff on my laptop. then i noticed my fan was a little louder then usual. so i opened up a terminal and used to top. i noticed there was this thing was using a lot of cpu but i didnt read it fast enough cause it went away but i noticed it was update-somthing-apx. And i also noticed rkhunter was running as root. i wasnt running the command. could my laptop be compromised?

im on ubuntu 10.04
 
Old 09-14-2010, 06:31 AM   #2
salasi
Senior Member
 
Registered: Jul 2007
Location: Directly above centre of the earth, UK
Distribution: SuSE, plus some hopping
Posts: 4,070

Rep: Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897
Quote:
Originally Posted by james_larson View Post
could my laptop be compromised?
Well, it could. But, then, so could Fort Knox. I don't really have information on either at the moment, although maybe I could use this internet thingy to tell me about Fort Knox.

Quote:
Originally Posted by james_larson View Post
i was just doing my regular stuff on my laptop. then i noticed my fan was a little louder then usual.
This isn't really evidence of anything, apart from that the cpu temp is a bit high, caused by the cpu working hard 9not going to power save) or the environment being warm.

Quote:
so i opened up a terminal and used to top. i noticed there was this thing was using a lot of cpu but i didnt read it fast enough cause it went away but i noticed it was update-somthing-apx.
This choice worked out badly for you (not really your fault; you weren't to know that whatever could disappear sudenly). "ps -ef" would have captured a real snapshot, which probably would have scrolled off the screen...you may or may not have been able to scroll back, depending on what you were working in and how it was set up; if you expect this to happen again, you may want to be prepared with a little script like:
Code:
ps -ef > processes.tmp
set as executable, and in somewhere in your path - most people have a personal 'bin' directory fopr such things...or, if you are used to the top output, you could try
Code:
top -b -n 1
Quote:
And i also noticed rkhunter was running as root. i wasnt running the command. could my laptop be compromised?
From what I remember, rkhunter has to run as root (I can't confirm that immediately, due to an upgrade) and may well be run daily/weekly/some-other-periodically by your distro. This is not, by itself, a sign of a problem. In fact, its quite good.

But what did rkhunter actually say? That's the thing that would really have given a clue as to whether there is bad stuff going on (once 'false positives' have been eliminated from rkhunter.log).
 
Old 09-14-2010, 01:44 PM   #3
james_larson
Member
 
Registered: Jul 2009
Posts: 31

Original Poster
Rep: Reputation: 0
i installed rkhunter a couple days ago.
 
Old 09-14-2010, 02:04 PM   #4
John VV
LQ Muse
 
Registered: Aug 2005
Location: A2 area Mi.
Posts: 17,624

Rep: Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651
How did you "i installed rkhunter a couple days ago."

from source or from your package manager ?

have you searched the Ubuntu forums / wiki for "rkhunter"

you should only need to look through the hits for the last 2, 3 months

if there is an issue with rkhunter it will show up

Ubuntu might have set it up in a cron job ?? - i would not have
in 7+ years i have never had a hit from rkhunter , no root kits found
the same for "ckrootkit"
 
Old 09-16-2010, 08:37 PM   #5
james_larson
Member
 
Registered: Jul 2009
Posts: 31

Original Poster
Rep: Reputation: 0
i installed it from the software center
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Question about rkhunter h725 Linux - Security 3 12-06-2008 06:50 PM
RKHunter Output Question cedricd Linux - Security 4 11-25-2008 12:09 PM
RKhunter question, Getting warnings for some directories. M$ISBS Linux - Security 8 03-05-2008 01:38 AM
RKhunter Help please Golgo13 Linux - Software 3 01-16-2008 04:27 PM
rkhunter atlaika Linux - Security 7 11-29-2005 10:47 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:51 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration