Current time: 12-29-2024, 12:55 AM Hello There, Guest! (LoginRegister)


Post Reply 
[ERLEDIGT] chkrootkit.log ist abgehackt...
Author Message
HxD Offline
Junior Member
*

Posts: 66
Joined: Jul 2009
Reputation: 2
Post: #1
[ERLEDIGT] chkrootkit.log ist abgehackt...
Folgendes,

letzte Woche Samstag wurde ein Q4 mit ispCP 1.0.3 installiert. Daraufhin habe ich nun folgendes Problem bzgl. der chkrootkit.log. Sie wird abgehakt angezeigt, siehe:

Code:
ROOTDIR is `/'
Checking `amd'... not found
Checking `basename'... not infected
Checking `biff'... not found
Checking `chfn'... not infected
Checking `chsh'... not infected
Checking `cron'... not infected
Checking `crontab'... not infected
Checking `date'... not infected
Checking `du'... not infected
Checking `dirname'... not infected
Checking `echo'... not infected
Checking `egrep'... not infected
Checking `env'... not infected
Checking `find'... not infected
Checking `fingerd'... not found
Checking `gpm'... not found
Checking `grep'... not infected
Checking `hdparm'... not found
Checking `su'... not infected
Checking `ifconfig'... not infected
Checking `inetd'... not infected
Checking `inetdconf'... not infected
Checking `identd'... not found
Checking `init'... not infected
Checking `killall'... not infected
Checking `ldsopreload'... not infected
Checking `login'... not infected
Checking `ls'... not infected
Checking `lsof'... not found
Checking `mail'... not infected
Checking `mingetty'... not found
Checking `netstat'... not infected
Checking `named'... not infected
Checking `passwd'... not infected
Checking `pidof'... not infected
Checking `pop2'... not found
Checking `pop3'... not found
Checking `ps'... not infected
Checking `pstree'... not infected
Checking `rpcinfo'... not infected
Checking `rlogind'... not found
Checking `rshd'... not found
Checking `slogin'... not infected
Checking `sendmail'... not infected
Checking `sshd'... not infected
Checking `syslogd'... not tested
Checking `tar'... not infected
Checking `tcpd'... not infected
Checking `tcpdump'... not infected
Checking `top'... not infected
Checking `telnetd'... not found
Checking `timed'... not found
Checking `traceroute'... not infected
Checking `vdir'... not infected
Checking `w'... not infected
Checking `write'... not infected
Checking `aliens'... no suspect files
Searching for sniffer's logs, it may take a while... nothing found
Searching for HiDrootkit's default dir... nothing found
Searching for t0rn's default files and dirs... nothing found
Searching for t0rn's v8 defaults... nothing found
Searching for Lion Worm default files and dirs... nothing found
Searching for RSHA's default files and dir... nothing found
Searching for RH-Sharpe's default files... nothing found
Searching for Ambient's rootkit (ark) default files and dirs... nothing found
Searching for suspicious files and dirs, it may take a while...
/lib/init/rw/.mdadm /lib/init/rw/.ramfs
/lib/init/rw/.mdadm
Searching for LPD Worm files and dirs... nothing found
Searching for Ramen Worm files and dirs... nothing found
Searching for Maniac files and dirs... nothing found
Searching for RK17 files and dirs... nothing found
Searching for Ducoci rootkit... nothing found
Searching for Adore Worm... nothing found
Searching for ShitC Worm... nothing found
Searching for Omega Worm... nothing found
Searching for Sadmind/IIS Worm... nothing found
Searching for MonKit... nothing found
Searching for Showtee... nothing found
Searching for OpticKit... nothing found
Searching for T.R.K... nothing found
Searching for Mithra... nothing found
Searching for LOC rootkit... /tmp/ispcp/var/www/ispcp/gui/tools/filemanager/plugins/tinymce/themes/advanced/images/xp
epic

Das tolle ist, die Cron ist in Ordnung aber dafür ist die auch tatsächlich angelegte log ebenfalls abgehakt! Letztes Update ist sogar von Heute 12 Uhr, sprich, die Log wird garnicht richtig mit Infos gefüttert und ich weiss mittlerweile nimmer, wo ich ansetzen soll...

Ist das bekannt?

grüße, HxD
(This post was last modified: 02-26-2010 06:00 AM by BeNe.)
02-25-2010 10:45 PM
Find all posts by this user Quote this message in a reply
BeNe Offline
Moderator
*****
Moderators

Posts: 5,899
Joined: Jan 2007
Reputation: 68
Post: #2
RE: chkrootkit.log ist abgehackt...
Würde erstmal dein /tmp Verzeichniss räumen.
Dann ist die Frage ob in der richtigen Log unter /var/log/ dazu auch alles drin steht.

Greez BeNe
02-26-2010 01:40 AM
Visit this user's website Find all posts by this user Quote this message in a reply
HxD Offline
Junior Member
*

Posts: 66
Joined: Jul 2009
Reputation: 2
Post: #3
RE: chkrootkit.log ist abgehackt...
Tatsache, nachdem ich /tmp und /var/tmp gereinigt habe, wurde nach erneutem Ausführen des Crons die log korrekt angezeigt...

Danke für den Tipp BeNe!
02-26-2010 01:49 AM
Find all posts by this user Quote this message in a reply
BeNe Offline
Moderator
*****
Moderators

Posts: 5,899
Joined: Jan 2007
Reputation: 68
Post: #4
RE: chkrootkit.log ist abgehackt...
Kein Problem! Wink
Weiterhin viel Spass mit ispCP Omega.

Greez BeNe
02-26-2010 05:30 AM
Visit this user's website Find all posts by this user Quote this message in a reply
Post Reply 


Forum Jump:


User(s) browsing this thread: 3 Guest(s)