LinuxQuestions.org
Help answer threads with 0 replies.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-06-2010, 03:22 AM   #1
mazinoz
Member
 
Registered: Mar 2003
Location: Mansfield Queensland Australia
Distribution: Linux Mint - Tara
Posts: 497

Rep: Reputation: 35
UNIONFS Knoppix6 and warning messages in rkhunter


I am puzzled that when I use a Knoppix 6 DVD it lists /UNIONFS/etc, var ..
in the root directory and /var/lib/rkhunter/db/rkhunter.dat lists the hosts name as 'Koffer' while /etc/hostname is 'Microknoppix. This causes multiple warnings in rkhunter about all this.

If I boot from a Ubuntu DVD /UNIONFS isn't there. Unfortunately Ubuntu doesn't appear to come with rkhunter as an installable program.

If I have dd if=/dev/urandom of=/dev/hda conv=notrunc,noerrors and remove power lead, RAM, flat pack battery, before trying this it still appears.

If I then repartition the drive (gparted) into two EQUAL partitions and install Windows XP on the first partition, it reports that the second partition is SMALLER than the first partition and not the same size. If I install Debian Lenny 5.3 after Windows the /etc/hostname is the same as that in rkhunter.dat and no /UNIONFS, and rkhunter reports no problems with hostnames.

This is starting to drive me nuts!

Anyone else encountered anything like this??
 
Old 05-06-2010, 08:39 PM   #2
Mr-Bisquit
Member
 
Registered: Feb 2009
Distribution: FreeBSD, OpenBSD, NetBSD, Debian, Fedora
Posts: 770
Blog Entries: 52

Rep: Reputation: 68
Knoppix is also built for a different purpose.
Are you using ADRIANE by any chance?
 
Old 05-09-2010, 11:22 PM   #3
mazinoz
Member
 
Registered: Mar 2003
Location: Mansfield Queensland Australia
Distribution: Linux Mint - Tara
Posts: 497

Original Poster
Rep: Reputation: 35
Thank you for the reply. No - I understand that Ariadne is the version of Knoppix 6 with the talking menu for VIP (Vision Impaired People - though they can also be Very Important!) I use a version supplied with Linux magazine for the rest of us, from memory Knoppix 6.1.

There is something going on when I either create a partition or format drives that appears to install a rootkit (I have had a SucKit infection). Once I did get it right and both /etc/hostname and /var/lib/rkhunter/db/rkhunter.dat reported the hostname as "Microknoppix"
But after I attached a USB drive it became infected. Back to the drawing board, and experimentation to try to recreate a clean system. It has occurred to me that the size discrepancy when installing Windows XP could be due to creating /dev/hda2. Bit hard to explain as I'm using a library computer and don't have laptop with me. Thanks anyway.
 
Old 05-09-2010, 11:35 PM   #4
Mr-Bisquit
Member
 
Registered: Feb 2009
Distribution: FreeBSD, OpenBSD, NetBSD, Debian, Fedora
Posts: 770
Blog Entries: 52

Rep: Reputation: 68
You're worrying too much.
Once you install debian, harden the system.
 
Old 05-13-2010, 08:37 PM   #5
mazinoz
Member
 
Registered: Mar 2003
Location: Mansfield Queensland Australia
Distribution: Linux Mint - Tara
Posts: 497

Original Poster
Rep: Reputation: 35
Dear Mr Bisquit. That thought has occurred to me, all I can say is linux rootkits and trojans can really do your head in. Still - why does Knoppix 6 have a different name for the computer in prompt - "Microknoppix" and hostname and "Koffer" in /var/lib/rkhunter/db/rkhunter.dat? How could I fix this? Do you know for sure it is just a 'bug'? Note this happens on drive that has just been 'urandomed' and had CMOS, flatpack and RAM removed. There may be a trivial explanation for this, but at the moment I just can't see it.

Cheers
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
rkhunter warning qwertyjjj Linux - Newbie 5 02-13-2010 09:00 AM
[SOLVED] rkhunter warning about 'old'versions EricTRA Linux - Security 7 12-02-2009 12:04 AM
rkhunter gives warning on LD_LIBRARY_PATH EricTRA Linux - Security 9 11-10-2009 12:56 PM
RKhunter warning about hidden files. gonus Linux - Security 3 05-03-2007 10:27 AM
Getting Warning during rkhunter? BajaNick Linux - Security 8 09-12-2004 08:34 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:42 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration