LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-11-2010, 10:13 PM   #1
moxieman99
Member
 
Registered: Feb 2004
Distribution: Dabble, but latest used are Fedora 13 and Ubuntu 10.4.1
Posts: 425

Rep: Reputation: 147Reputation: 147
rkhunter hangs, "another user" logged in when I go to shut down. Please evaluate.


rkhunter hangs, "another user" logged in when I go to shut down. Please evaluate.

Running Ubuntu 10.4.1 (2.6.32.24 kernel) on an old machine (Dell Dimension 2400 -- celeron 2.4 gig chip). Set up two user accounts, me and "guest." I connect to the internet wirelessly through a router. There is one other computer, running WinVista, on the network, physically cabled into the router.

Freevo also creates a user account apparently, but I downloaded and installed Freevo, and assume that is normal behavior.

The computer is used as a normal desktop, not as a server.

Been getting a lot of income hits on my firewall, and found some outgoing connections that didn't make a lot of sense, so I downloaded and installed ClamAV and rkhunter, turned off my connection to the internet and ran both ClamAV and rkhunter.

ClamAV hung on some /sys/devices and /sys/kernel files, so I wound up excluding both /sys/devices and /sys/kernel in order to run it to completion. It came back with no detected viruses.

I set rkhunter to enable all tests and let it lose. Rkhunter gave me warnings for /usr/bin/curl and when it was checking running processes for deleted files. It hung (as in I left it running for two hours and it didn't progress) after it returned "none found" after checking running processes for suspicious files -- it did not say what test it was working on when it hung, "none found" for the suspicious files test were the last words in the verbose display it gave while running. I shut down the terminal session.

I know from Google that /usr/bin/curl is frequently a false positive.

So I go to shut down the linux computer and it tells me that I have to give the authorization password because another user is logged in. I immediately check, and the guest account is not being used, Freevo is not being used, and I had only used sudo with root.

So I think I've been compromised. Before I look at CERT guidelines, and possibly wipe and reinstall, can anyone hazard a guess based on the above facts as to anything I can check to see if my suspicions are correct about being compromised? I assume that rkhunter doesn't normally take two hours to complete one test, and the "another user logged in" bit spooked me.

Thanks,

Moxieman
 
Old 09-12-2010, 01:02 AM   #2
aus9
LQ 5k Club
 
Registered: Oct 2003
Location: Western Australia
Distribution: Icewm
Posts: 5,827

Rep: Reputation: Disabled
Hi

Until unSpawn replies....

Try uploading your /var/log/rkhunter.log to a file sharing site and posting a link here please.

2) How do you stop Freevo....ignoring the autologin feature, does it run as a daemon?

try using root powers to stop it....maybe..../etc/init.d/freevo stop

3) Ignoring that you may be compromised....what does the command ....

Code:
who
report as logged in users ....(there may be more)

4) Why have you set up a username called guest?

That name is in itself a little risky. Have you tested its password online.

5) After saving that log....re-run

rkhunter --list tests

and so one bit at time. Bear in mind that RKH will search for some extra applications that you may have installed to use in some tests

good luck
 
Old 09-12-2010, 06:49 AM   #3
moxieman99
Member
 
Registered: Feb 2004
Distribution: Dabble, but latest used are Fedora 13 and Ubuntu 10.4.1
Posts: 425

Original Poster
Rep: Reputation: 147Reputation: 147
Quote:
Originally Posted by aus9 View Post
Hi

Until unSpawn replies....

Try uploading your /var/log/rkhunter.log to a file sharing site and posting a link here please.

2) How do you stop Freevo....ignoring the autologin feature, does it run as a daemon?

try using root powers to stop it....maybe..../etc/init.d/freevo stop

3) Ignoring that you may be compromised....what does the command ....

Code:
who
report as logged in users ....(there may be more)

4) Why have you set up a username called guest?

That name is in itself a little risky. Have you tested its password online.

5) After saving that log....re-run

rkhunter --list tests

and so one bit at time. Bear in mind that RKH will search for some extra applications that you may have installed to use in some tests

good luck
"Guest" was added to the set up on the off chance that someone else would use the computer -- no one (knowingly) has, so it has not been used. When I wipe and reinstall (there is nothing on the computer that I need, since I'm just experimenting with Ubuntu, so I can readily do that) I will not add a standing guest account.

Freevo must be running as a daemon, since it never asked me if I wanted to set it up as a user. I was surprised that it set up a user account. I may just not install it next time.

I'll turn it on and run "who" and check the rkhunter log. If there's anything I don't understand, I'll post.

Thanks.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
rkhunter warnings on "possible promiscuous interface" and file properties checks vinnie_vinodh Linux - Newbie 1 04-29-2009 02:44 AM
Create a user with "shut down" privilege? John79 Linux - Server 1 02-18-2008 03:36 AM
Logged in as "root"/Fedora 8 but get "Operation not permitted" when using "chmod etc gosunlee Linux - Newbie 7 02-10-2008 05:56 AM
How do I "kick" a user who is logged in? LinuxSeeker Linux - General 11 06-03-2005 07:47 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:14 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration