LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Ubuntu
User Name
Password
Ubuntu This forum is for the discussion of Ubuntu Linux.

Notices


Reply
  Search this Thread
Old 09-21-2015, 03:53 PM   #1
flyingpigs
LQ Newbie
 
Registered: Aug 2015
Posts: 4

Rep: Reputation: Disabled
rkhunter scan results


Hi guys,
Im new to Ubuntu and im looking for some help.
I've scanned my Ubuntu with rkhunter and I have some concerning results:
Warning: The following processes are using deleted files:
Process: /sbin/init PID: 1 File: /var/log/upstart/systemd-logind.log.1
Process: /usr/sbin/cups-browsed PID: 1168 File: /etc/passwd
Process: /sbin/init PID: 2170 File: /home/pwn20wn/.cache/upstart/indicator-bluetooth.log.1
Process: /usr/lib/x86_64-linux-gnu/bamf/bamfdaemon PID: 2400 File: /home/pwn20wn/.local/share/gvfs-metadata/root
Process: /usr/lib/firefox/firefox PID: 2703 File: /var/tmp/etilqs_F4ZmiXL3Bx5CrjT
Process: /usr/bin/unity-scope-loader PID: 2959 File: /home/pwn20wn/.cache/software-center/software-center-agent.db/record.DB
Warning: Process '/sbin/wpa_supplicant' (PID 1167) is listening on the network.
Warning: Process '/sbin/dhclient' (PID 1349) is listening on the network.
Warning: Suspicious file types found in /dev:
/dev/.udev/rules.d/root.rules: ASCII text
Warning: Hidden directory found: /etc/.java: directory
Warning: Hidden directory found: /dev/.udev: directory
Warning: Hidden file found: /dev/.initramfs: symbolic link to `/run/initramfs'
Warning: Application 'openssl', version '1.0.1f', is out of date, and possibly a security risk.
I would like to know if these are false positives or real threats and how to fix them.
Thank you very much!

Last edited by flyingpigs; 09-21-2015 at 03:59 PM.
 
Old 09-22-2015, 08:05 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
One of the first things people should do is not run the software but read the README, FAQ and other documentation. I the case of RKH it clearly states where one should look (rkhunter-users mailing list archives) and ask (rkhunter-users mailing list)...


Quote:
Originally Posted by flyingpigs View Post
Warning: The following processes are using deleted files:
Process: /sbin/init PID: 1 File: /var/log/upstart/systemd-logind.log.1
Process: /usr/sbin/cups-browsed PID: 1168 File: /etc/passwd
Common causes are log rotation, (temporary) file usage and such. From file names in /home/pwn20wn/ looks like a desktop environment session. Most importantly: any file still open on a file descriptor could be copied out and inspected if unsure (as in 'strings /path/to/file|less;' or somesuch).


Quote:
Originally Posted by flyingpigs View Post
Warning: Process '/sbin/wpa_supplicant' (PID 1167) is listening on the network.
Warning: Process '/sbin/dhclient' (PID 1349) is listening on the network.
While file names or argv[0] aren't exactly good indicators (so verify using your package management features) these are common false positives.


Quote:
Originally Posted by flyingpigs View Post
Warning: Suspicious file types found in /dev:
/dev/.udev/rules.d/root.rules: ASCII text
Its ASCII text. Read it and see.


Quote:
Originally Posted by flyingpigs View Post
Warning: Hidden directory found: /etc/.java: directory
Warning: Hidden directory found: /dev/.udev: directory
Warning: Hidden file found: /dev/.initramfs: symbolic link to `/run/initramfs'
"Hidden" here means a file name that starts with a dot. Old school. False positives most of the time.


Quote:
Originally Posted by flyingpigs View Post
Warning: Application 'openssl', version '1.0.1f', is out of date, and possibly a security risk.
Check your distros package nfo and know using the RKH application version check was discouraged long time ago. (The latter because we all like to use stuff. But help maintain it? No thanks...)
 
1 members found this post helpful.
Old 09-24-2015, 02:46 PM   #3
flyingpigs
LQ Newbie
 
Registered: Aug 2015
Posts: 4

Original Poster
Rep: Reputation: Disabled
Thank you very much for help unSpawn.
If I understand right these are false positives so nothing dangerous.
 
Old 09-25-2015, 04:40 AM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by flyingpigs View Post
If I understand right these are false positives so nothing dangerous.
If you have properly hardened your machine, didn't unduly expose it and properly maintain and audit it then chances are slim these are anything but false positives. However that is not the point. The point is in knowing how to assess things. Start with the last 2 parts of the FAQ please?
 
1 members found this post helpful.
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
rkhunter scan: 1 Rootkit & 6 Possible Suspect Files /var/log/rkhunter.log included Mollusc Linux - Security 10 09-29-2011 08:43 AM
rkhunter results mrmnemo Linux - Software 13 10-27-2010 11:40 AM
iwlist scan - no scan results compu73rg33k Linux - Wireless Networking 6 05-29-2009 02:37 AM
Help me understand rkhunter scan results d@@b Linux - Security 4 04-12-2007 03:04 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Ubuntu

All times are GMT -5. The time now is 07:16 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration