duvidas com resultado do rkhunter

1. duvidas com resultado do rkhunter

alexandre  gomes
shurecao

(usa Fedora)

Enviado em 11/05/2017 - 23:01h

boa noite galera eu fiz um scan com o rkhunter será que algum amigo ai poderia traduzir os resultadoas encontrados desde já agradesço


[22:40:04] Running Rootkit Hunter version 1.4.2 on localhost
[22:40:04]
[22:40:04] Info: Start date is qui mai 11 22:40:04 -03 2017
[22:40:04]
[22:40:04] Checking configuration file and command-line options...
[22:40:04] Info: Detected operating system is 'Linux'
[22:40:04] Info: Uname output is 'Linux localhost.localdomain 4.10.14-200.fc25.x86_64 #1 SMP Wed May 3 22:52:30 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux'
[22:40:04] Info: Command line is /bin/rkhunter --update
[22:40:04] Info: Environment shell is /bin/bash; rkhunter is using bash
[22:40:04] Info: Using configuration file '/etc/rkhunter.conf'
[22:40:04] Info: Installation directory is '/usr'
[22:40:04] Info: Using language 'en'
[22:40:04] Info: Using '/var/lib/rkhunter/db' as the database directory
[22:40:04] Info: Using '/usr/share/rkhunter/scripts' as the support script directory
[22:40:04] Info: Using '/usr/lib64/ccache /sbin /bin /usr/sbin /usr/bin /usr/local/bin /usr/local/sbin /usr/libexec /usr/local/libexec' as the command directories
[22:40:04] Info: Using '/var/lib/rkhunter' as the temporary directory
[22:40:04] Info: X will be automatically detected
[22:40:04] Info: Using second color set
[22:40:04] Info: Found the 'basename' command: /bin/basename
[22:40:04] Info: Found the 'diff' command: /bin/diff
[22:40:04] Info: Found the 'dirname' command: /bin/dirname
[22:40:04] Info: Found the 'file' command: /bin/file
[22:40:04] Info: Found the 'find' command: /bin/find
[22:40:04] Info: Found the 'ifconfig' command: /sbin/ifconfig
[22:40:04] Info: Found the 'ip' command: /sbin/ip
[22:40:04] Info: Found the 'ipcs' command: /bin/ipcs
[22:40:04] Info: Found the 'ldd' command: /bin/ldd
[22:40:04] Info: Found the 'lsattr' command: /bin/lsattr
[22:40:04] Info: Found the 'lsmod' command: /sbin/lsmod
[22:40:04] Info: Found the 'lsof' command: /bin/lsof
[22:40:04] Info: Found the 'mktemp' command: /bin/mktemp
[22:40:04] Info: Found the 'netstat' command: /bin/netstat
[22:40:04] Info: Found the 'perl' command: /bin/perl
[22:40:04] Info: Found the 'pgrep' command: /bin/pgrep
[22:40:04] Info: Found the 'ps' command: /bin/ps
[22:40:04] Info: Found the 'pwd' command: /bin/pwd
[22:40:04] Info: Found the 'readlink' command: /bin/readlink
[22:40:04] Info: Found the 'stat' command: /bin/stat
[22:40:04] Info: Found the 'strings' command: /bin/strings
[22:40:04] Info: Found the 'wget' command: /bin/wget
[22:40:04] Info: The mirrors file will be rotated
[22:40:04] Info: Both local and remote mirrors will be used
[22:40:04] Info: The mirrors file will be updated
[22:40:04] Info: Logging to log file: /var/log/rkhunter/rkhunter.log
[22:40:04] Info: Current logging will be appended to the log file
[22:40:04] Info: Locking is not being used
[22:40:04]
[22:40:04] Checking rkhunter data files...
[22:40:04] Info: Created temporary file '/var/lib/rkhunter/rkhunter.upd.iWxjw48voj'
[22:40:04] Info: File 'mirrors.dat' is missing or empty. Downloading a new copy.
[22:40:04] Info: The mirrors file has no required mirrors in it: /var/lib/rkhunter/db/mirrors.dat
[22:40:04] Info: Using the SourceForge mirror: http://rkhunter.sourceforge.net
[22:40:04] Info: Executing download command '/bin/wget -q -O "/var/lib/rkhunter/rkhunter.upd.iWxjw48voj" http://rkhunter.sourceforge.net/1.3/mirrors.dat 2>/dev/null'
[22:40:05] Info: This version : 0
[22:40:05] Info: Latest version: 2007060601
[22:40:05] Info: Update available
[22:40:05] Checking file mirrors.dat [ Updated ]
[22:40:05] Info: File 'programs_bad.dat' is missing or empty. Downloading a new copy.
[22:40:05] Info: Executing download command '/bin/wget -q -O "/var/lib/rkhunter/rkhunter.upd.iWxjw48voj" http://rkhunter.sourceforge.net/1.3/programs_bad.dat 2>/dev/null'
[22:40:06] Info: This version : 0
[22:40:06] Info: Latest version: 2014042901
[22:40:06] Info: Update available
[22:40:06] Checking file programs_bad.dat [ Updated ]
[22:40:06] Info: Executing download command '/bin/wget -q -O "/var/lib/rkhunter/rkhunter.upd.iWxjw48voj" http://rkhunter.sourceforge.net/1.3/backdoorports.dat 2>/dev/null'
[22:40:07] Info: This version : 2010111401
[22:40:07] Info: Latest version: 2010111401
[22:40:07] Checking file backdoorports.dat [ No update ]
[22:40:07] Info: File 'suspscan.dat' is missing or empty. Downloading a new copy.
[22:40:07] Info: Executing download command '/bin/wget -q -O "/var/lib/rkhunter/rkhunter.upd.iWxjw48voj" http://rkhunter.sourceforge.net/1.3/suspscan.dat 2>/dev/null'
[22:40:08] Info: This version : 0
[22:40:08] Info: Latest version: 2009112901
[22:40:08] Info: Update available
[22:40:08] Checking file suspscan.dat [ Updated ]
[22:40:08] Info: Executing download command '/bin/wget -q -O "/var/lib/rkhunter/rkhunter.upd.iWxjw48voj" http://rkhunter.sourceforge.net/1.3/i18n/1.4.2/i18n.ver 2>/dev/null'
[22:40:08] Info: This version : 2009091601
[22:40:08] Info: Latest version: 2009091601
[22:40:08] Checking file i18n/cn [ No update ]
[22:40:09] Info: File '/var/lib/rkhunter/db/i18n/de' is missing or empty. Downloading a new copy.
[22:40:09] Info: This version : 0
[22:40:09] Info: Latest version: 2014010301
[22:40:09] Info: Executing download command '/bin/wget -q -O "/var/lib/rkhunter/rkhunter.upd.iWxjw48voj" http://rkhunter.sourceforge.net/1.3/i18n/1.4.2/de 2>/dev/null'
[22:40:09] Info: Update available
[22:40:09] Checking file i18n/de [ Updated ]
[22:40:09] Info: This version : 2013112401
[22:40:09] Info: Latest version: 2013112401
[22:40:09] Checking file i18n/en [ No update ]
[22:40:09] Info: File '/var/lib/rkhunter/db/i18n/tr' is missing or empty. Downloading a new copy.
[22:40:09] Info: This version : 0
[22:40:09] Info: Latest version: 2014030201
[22:40:09] Info: Executing download command '/bin/wget -q -O "/var/lib/rkhunter/rkhunter.upd.iWxjw48voj" http://rkhunter.sourceforge.net/1.3/i18n/1.4.2/tr 2>/dev/null'
[22:40:11] Info: Update available
[22:40:11] Checking file i18n/tr [ Updated ]
[22:40:11] Info: File '/var/lib/rkhunter/db/i18n/tr.utf8' is missing or empty. Downloading a new copy.
[22:40:11] Info: This version : 0
[22:40:11] Info: Latest version: 2014030201
[22:40:11] Info: Executing download command '/bin/wget -q -O "/var/lib/rkhunter/rkhunter.upd.iWxjw48voj" http://rkhunter.sourceforge.net/1.3/i18n/1.4.2/tr.utf8 2>/dev/null'
[22:40:12] Info: Update available
[22:40:12] Checking file i18n/tr.utf8 [ Updated ]
[22:40:12] Info: File '/var/lib/rkhunter/db/i18n/zh' is missing or empty. Downloading a new copy.
[22:40:12] Info: This version : 0
[22:40:12] Info: Latest version: 2009091601
[22:40:12] Info: Executing download command '/bin/wget -q -O "/var/lib/rkhunter/rkhunter.upd.iWxjw48voj" http://rkhunter.sourceforge.net/1.3/i18n/1.4.2/zh 2>/dev/null'
[22:40:13] Info: Update available
[22:40:13] Checking file i18n/zh [ Updated ]
[22:40:13] Info: File '/var/lib/rkhunter/db/i18n/zh.utf8' is missing or empty. Downloading a new copy.
[22:40:13] Info: This version : 0
[22:40:13] Info: Latest version: 2009091601
[22:40:13] Info: Executing download command '/bin/wget -q -O "/var/lib/rkhunter/rkhunter.upd.iWxjw48voj" http://rkhunter.sourceforge.net/1.3/i18n/1.4.2/zh.utf8 2>/dev/null'
[22:40:14] Info: Update available
[22:40:14] Checking file i18n/zh.utf8 [ Updated ]
[22:40:14]
[22:40:14] Info: End date is qui mai 11 22:40:14 -03 2017


[22:49:32] Running Rootkit Hunter version 1.4.2 on localhost
[22:49:32]
[22:49:32] Info: Start date is qui mai 11 22:49:32 -03 2017
[22:49:32]
[22:49:32] Checking configuration file and command-line options...
[22:49:32] Info: Detected operating system is 'Linux'
[22:49:32] Info: Uname output is 'Linux localhost.localdomain 4.10.14-200.fc25.x86_64 #1 SMP Wed May 3 22:52:30 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux'
[22:49:32] Info: Command line is /bin/rkhunter --check --sk
[22:49:32] Info: Environment shell is /bin/bash; rkhunter is using bash
[22:49:32] Info: Using configuration file '/etc/rkhunter.conf'
[22:49:32] Info: Installation directory is '/usr'
[22:49:32] Info: Using language 'en'
[22:49:32] Info: Using '/var/lib/rkhunter/db' as the database directory
[22:49:32] Info: Using '/usr/share/rkhunter/scripts' as the support script directory
[22:49:32] Info: Using '/usr/lib64/ccache /sbin /bin /usr/sbin /usr/bin /usr/local/bin /usr/local/sbin /usr/libexec /usr/local/libexec' as the command directories
[22:49:32] Info: Using '/var/lib/rkhunter' as the temporary directory
[22:49:32] Info: No mail-on-warning address configured
[22:49:32] Info: X will be automatically detected
[22:49:32] Info: Using second color set
[22:49:32] Info: Found the 'basename' command: /bin/basename
[22:49:32] Info: Found the 'diff' command: /bin/diff
[22:49:32] Info: Found the 'dirname' command: /bin/dirname
[22:49:32] Info: Found the 'file' command: /bin/file
[22:49:32] Info: Found the 'find' command: /bin/find
[22:49:32] Info: Found the 'ifconfig' command: /sbin/ifconfig
[22:49:32] Info: Found the 'ip' command: /sbin/ip
[22:49:32] Info: Found the 'ipcs' command: /bin/ipcs
[22:49:32] Info: Found the 'ldd' command: /bin/ldd
[22:49:32] Info: Found the 'lsattr' command: /bin/lsattr
[22:49:32] Info: Found the 'lsmod' command: /sbin/lsmod
[22:49:32] Info: Found the 'lsof' command: /bin/lsof
[22:49:32] Info: Found the 'mktemp' command: /bin/mktemp
[22:49:32] Info: Found the 'netstat' command: /bin/netstat
[22:49:32] Info: Found the 'perl' command: /bin/perl
[22:49:32] Info: Found the 'pgrep' command: /bin/pgrep
[22:49:33] Info: Found the 'ps' command: /bin/ps
[22:49:33] Info: Found the 'pwd' command: /bin/pwd
[22:49:33] Info: Found the 'readlink' command: /bin/readlink
[22:49:33] Info: Found the 'stat' command: /bin/stat
[22:49:33] Info: Found the 'strings' command: /bin/strings
[22:49:33] Info: System is not using prelinking
[22:49:33] Info: Using the '/bin/sha1sum' command for the file hash checks
[22:49:33] Info: The hash function field index is set to 1
[22:49:33] Info: Using package manager 'RPM' for file property checks
[22:49:33] Info: Found the 'rpm' command: /bin/rpm
[22:49:33] Info: Previous file attributes were stored
[22:49:33] Info: Enabled tests are: all
[22:49:33] Info: Disabled tests are: suspscan hidden_ports deleted_files packet_cap_apps apps
[22:49:33] Info: Current logging will be appended to the log file
[22:49:33] Info: Found ksym file '/proc/kallsyms'
[22:49:33] Info: Using 'date' to process epoch second times
[22:49:33] Info: Locking is not being used
[22:49:33]
[22:49:33] Starting system checks...
[22:49:33]
[22:49:33] Info: Starting test name 'system_commands'
[22:49:33] Checking system commands...
[22:49:33]
[22:49:33] Info: Starting test name 'strings'
[22:49:33] Performing 'strings' command checks
[22:49:33] Scanning for string /usr/sbin/ntpsx [ OK ]
[22:49:33] Scanning for string /usr/sbin/.../bkit-ava [ OK ]
[22:49:33] Scanning for string /usr/sbin/.../bkit-d [ OK ]
[22:49:33] Scanning for string /usr/sbin/.../bkit-shd [ OK ]
[22:49:33] Scanning for string /usr/sbin/.../bkit-f [ OK ]
[22:49:33] Scanning for string /usr/include/.../proc.h [ OK ]
[22:49:33] Scanning for string /usr/include/.../.bash_history [ OK ]
[22:49:33] Scanning for string /usr/include/.../bkit-get [ OK ]
[22:49:33] Scanning for string /usr/include/.../bkit-dl [ OK ]
[22:49:33] Scanning for string /usr/include/.../bkit-screen [ OK ]
[22:49:33] Scanning for string /usr/include/.../bkit-sleep [ OK ]
[22:49:34] Scanning for string /usr/lib/.../bkit-adore.o [ OK ]
[22:49:34] Scanning for string /usr/lib/.../ls [ OK ]
[22:49:34] Scanning for string /usr/lib/.../netstat [ OK ]
[22:49:34] Scanning for string /usr/lib/.../lsof [ OK ]
[22:49:34] Scanning for string /usr/lib/.../bkit-ssh/bkit-shdcfg [ OK ]
[22:49:34] Scanning for string /usr/lib/.../bkit-ssh/bkit-shhk [ OK ]
[22:49:34] Scanning for string /usr/lib/.../bkit-ssh/bkit-pw [ OK ]
[22:49:34] Scanning for string /usr/lib/.../bkit-ssh/bkit-shrs [ OK ]
[22:49:34] Scanning for string /usr/lib/.../bkit-ssh/bkit-mots [ OK ]
[22:49:34] Scanning for string /usr/lib/.../uconf.inv [ OK ]
[22:49:34] Scanning for string /usr/lib/.../psr [ OK ]
[22:49:34] Scanning for string /usr/lib/.../find [ OK ]
[22:49:34] Scanning for string /usr/lib/.../pstree [ OK ]
[22:49:34] Scanning for string /usr/lib/.../slocate [ OK ]
[22:49:34] Scanning for string /usr/lib/.../du [ OK ]
[22:49:34] Scanning for string /usr/lib/.../top [ OK ]
[22:49:34] Scanning for string /usr/sbin/... [ OK ]
[22:49:34] Scanning for string /usr/include/... [ OK ]
[22:49:34] Scanning for string /usr/include/.../.tmp [ OK ]
[22:49:34] Scanning for string /usr/lib/... [ OK ]
[22:49:34] Scanning for string /usr/lib/.../.ssh [ OK ]
[22:49:34] Scanning for string /usr/lib/.../bkit-ssh [ OK ]
[22:49:34] Scanning for string /usr/lib/.bkit- [ OK ]
[22:49:34] Scanning for string /tmp/.bkp [ OK ]
[22:49:34] Scanning for string /tmp/.cinik [ OK ]
[22:49:34] Scanning for string /tmp/.font-unix/.cinik [ OK ]
[22:49:34] Scanning for string /lib/.sso [ OK ]
[22:49:34] Scanning for string /lib/.so [ OK ]
[22:49:34] Scanning for string /var/run/...dica/clean [ OK ]
[22:49:34] Scanning for string /var/run/...dica/dxr [ OK ]
[22:49:34] Scanning for string /var/run/...dica/read [ OK ]
[22:49:35] Scanning for string /var/run/...dica/write [ OK ]
[22:49:35] Scanning for string /var/run/...dica/lf [ OK ]
[22:49:35] Scanning for string /var/run/...dica/xl [ OK ]
[22:49:35] Scanning for string /var/run/...dica/xdr [ OK ]
[22:49:35] Scanning for string /var/run/...dica/psg [ OK ]
[22:49:35] Scanning for string /var/run/...dica/secure [ OK ]
[22:49:35] Scanning for string /var/run/...dica/rdx [ OK ]
[22:49:35] Scanning for string /var/run/...dica/va [ OK ]
[22:49:35] Scanning for string /var/run/...dica/cl.sh [ OK ]
[22:49:35] Scanning for string /var/run/...dica/last.log [ OK ]
[22:49:35] Scanning for string /usr/bin/.etc [ OK ]
[22:49:35] Scanning for string /etc/sshd_config [ OK ]
[22:49:35] Scanning for string /etc/ssh_host_key [ OK ]
[22:49:35] Scanning for string /etc/ssh_random_seed [ OK ]
[22:49:35] Scanning for string /dev/ptyp [ OK ]
[22:49:35] Scanning for string /dev/ptyq [ OK ]
[22:49:35] Scanning for string /dev/ptyr [ OK ]
[22:49:35] Scanning for string /dev/ptys [ OK ]
[22:49:35] Scanning for string /dev/ptyt [ OK ]
[22:49:35] Scanning for string /dev/fd/.88/freshb-bsd [ OK ]
[22:49:35] Scanning for string /dev/fd/.88/fresht [ OK ]
[22:49:35] Scanning for string /dev/fd/.88/zxsniff [ OK ]
[22:49:35] Scanning for string /dev/fd/.88/zxsniff.log [ OK ]
[22:49:35] Scanning for string /dev/fd/.99/.ttyf00 [ OK ]
[22:49:35] Scanning for string /dev/fd/.99/.ttyp00 [ OK ]
[22:49:35] Scanning for string /dev/fd/.99/.ttyq00 [ OK ]
[22:49:35] Scanning for string /dev/fd/.99/.ttys00 [ OK ]
[22:49:35] Scanning for string /dev/fd/.99/.pwsx00 [ OK ]
[22:49:35] Scanning for string /etc/.acid [ OK ]
[22:49:35] Scanning for string /usr/lib/.fx/sched_host.2 [ OK ]
[22:49:35] Scanning for string /usr/lib/.fx/random_d.2 [ OK ]
[22:49:36] Scanning for string /usr/lib/.fx/set_pid.2 [ OK ]
[22:49:36] Scanning for string /usr/lib/.fx/setrgrp.2 [ OK ]
[22:49:36] Scanning for string /usr/lib/.fx/TOHIDE [ OK ]
[22:49:36] Scanning for string /usr/lib/.fx/cons.saver [ OK ]
[22:49:36] Scanning for string /usr/lib/.fx/adore/ava/ava [ OK ]
[22:49:36] Scanning for string /usr/lib/.fx/adore/adore/adore.ko [ OK ]
[22:49:36] Scanning for string /bin/sysback [ OK ]
[22:49:36] Scanning for string /usr/local/bin/sysback [ OK ]
[22:49:36] Scanning for string /usr/lib/.tbd [ OK ]
[22:49:36] Scanning for string /dev/.lib/lib/lib/t0rns [ OK ]
[22:49:36] Scanning for string /dev/.lib/lib/lib/du [ OK ]
[22:49:36] Scanning for string /dev/.lib/lib/lib/ls [ OK ]
[22:49:36] Scanning for string /dev/.lib/lib/lib/t0rnsb [ OK ]
[22:49:36] Scanning for string /dev/.lib/lib/lib/ps [ OK ]
[22:49:36] Scanning for string /dev/.lib/lib/lib/t0rnp [ OK ]
[22:49:36] Scanning for string /dev/.lib/lib/lib/find [ OK ]
[22:49:36] Scanning for string /dev/.lib/lib/lib/ifconfig [ OK ]
[22:49:36] Scanning for string /dev/.lib/lib/lib/pg [ OK ]
[22:49:36] Scanning for string /dev/.lib/lib/lib/ssh.tgz [ OK ]
[22:49:36] Scanning for string /dev/.lib/lib/lib/top [ OK ]
[22:49:36] Scanning for string /dev/.lib/lib/lib/sz [ OK ]
[22:49:36] Scanning for string /dev/.lib/lib/lib/login [ OK ]
[22:49:36] Scanning for string /dev/.lib/lib/lib/in.fingerd [ OK ]
[22:49:36] Scanning for string /dev/.lib/lib/lib/1i0n.sh [ OK ]
[22:49:36] Scanning for string /dev/.lib/lib/lib/pstree [ OK ]
[22:49:36] Scanning for string /dev/.lib/lib/lib/in.telnetd [ OK ]
[22:49:36] Scanning for string /dev/.lib/lib/lib/mjy [ OK ]
[22:49:36] Scanning for string /dev/.lib/lib/lib/sush [ OK ]
[22:49:36] Scanning for string /dev/.lib/lib/lib/tfn [ OK ]
[22:49:36] Scanning for string /dev/.lib/lib/lib/name [ OK ]
[22:49:37] Scanning for string /dev/.lib/lib/lib/getip.sh [ OK ]
[22:49:37] Scanning for string /usr/info/.torn/sh* [ OK ]
[22:49:37] Scanning for string /usr/src/.[*****]/.1addr [ OK ]
[22:49:37] Scanning for string /usr/src/.[*****]/.1file [ OK ]
[22:49:37] Scanning for string /usr/src/.[*****]/.1proc [ OK ]
[22:49:37] Scanning for string /usr/src/.[*****]/.1logz [ OK ]
[22:49:37] Scanning for string /usr/info/.t0rn [ OK ]
[22:49:37] Scanning for string /dev/.lib [ OK ]
[22:49:37] Scanning for string /dev/.lib/lib [ OK ]
[22:49:37] Scanning for string /dev/.lib/lib/lib [ OK ]
[22:49:37] Scanning for string /dev/.lib/lib/lib/dev [ OK ]
[22:49:37] Scanning for string /dev/.lib/lib/scan [ OK ]
[22:49:37] Scanning for string /usr/src/.[*****] [ OK ]
[22:49:37] Scanning for string /usr/man/man1/man1 [ OK ]
[22:49:37] Scanning for string /usr/man/man1/man1/lib [ OK ]
[22:49:37] Scanning for string /usr/man/man1/man1/lib/.lib [ OK ]
[22:49:37] Scanning for string /usr/man/man1/man1/lib/.lib/.backup [ OK ]
[22:49:37]
[22:49:37] Info: Starting test name 'shared_libs'
[22:49:37] Performing 'shared libraries' checks
[22:49:37] Checking for preloading variables [ None found ]
[22:49:37] Checking for preloaded libraries [ None found ]
[22:49:37]
[22:49:37] Info: Starting test name 'shared_libs_path'
[22:49:37] Checking LD_LIBRARY_PATH variable [ Not found ]
[22:49:37]
[22:49:37] Info: Starting test name 'properties'
[22:49:37] Performing file properties checks
[22:49:38] Warning: Checking for prerequisites [ Warning ]
[22:49:38] The file of stored file properties (rkhunter.dat) does not exist, and should be created. To do this type in 'rkhunter --propupd'.
[22:49:38] Info: The file properties check will still run as there are checks that can be performed without the 'rkhunter.dat' file.
[22:49:38]
[22:49:38] Warning: WARNING! It is the users responsibility to ensure that when the '--propupd' option
is used, all the files on their system are known to be genuine, and installed from a
reliable source. The rkhunter '--check' option will compare the current file properties
against previously stored values, and report if any values differ. However, rkhunter
cannot determine what has caused the change, that is for the user to do.
[22:49:39] /usr/sbin/adduser [ OK ]
[22:49:40] /usr/sbin/chkconfig [ OK ]
[22:49:40] /usr/sbin/chroot [ OK ]
[22:49:40] /usr/sbin/depmod [ OK ]
[22:49:40] /usr/sbin/fsck [ OK ]
[22:49:40] /usr/sbin/fuser [ OK ]
[22:49:40] /usr/sbin/groupadd [ OK ]
[22:49:40] /usr/sbin/groupdel [ OK ]
[22:49:40] /usr/sbin/groupmod [ OK ]
[22:49:40] /usr/sbin/grpck [ OK ]
[22:49:40] /usr/sbin/ifconfig [ OK ]
[22:49:40] /usr/sbin/ifdown [ Warning ]
[22:49:40] Warning: The command '/usr/sbin/ifdown' has been replaced by a script: /usr/sbin/ifdown: Bourne-Again shell script, ASCII text executable
[22:49:40] /usr/sbin/ifup [ Warning ]
[22:49:40] Warning: The command '/usr/sbin/ifup' has been replaced by a script: /usr/sbin/ifup: Bourne-Again shell script, ASCII text executable
[22:49:41] /usr/sbin/init [ OK ]
[22:49:41] /usr/sbin/insmod [ OK ]
[22:49:41] /usr/sbin/ip [ OK ]
[22:49:41] /usr/sbin/lsmod [ OK ]
[22:49:41] /usr/sbin/modinfo [ OK ]
[22:49:41] /usr/sbin/modprobe [ OK ]
[22:49:41] /usr/sbin/nologin [ OK ]
[22:49:41] /usr/sbin/ping [ OK ]
[22:49:41] /usr/sbin/pwck [ OK ]
[22:49:41] /usr/sbin/rmmod [ OK ]
[22:49:41] /usr/sbin/route [ OK ]
[22:49:41] /usr/sbin/rsyslogd [ OK ]
[22:49:42] /usr/sbin/runlevel [ OK ]
[22:49:42] /usr/sbin/sestatus [ OK ]
[22:49:42] /usr/sbin/sshd [ OK ]
[22:49:42] /usr/sbin/sulogin [ OK ]
[22:49:42] /usr/sbin/sysctl [ OK ]
[22:49:42] /usr/sbin/tcpd [ OK ]
[22:49:42] /usr/sbin/useradd [ OK ]
[22:49:42] /usr/sbin/userdel [ OK ]
[22:49:42] /usr/sbin/usermod [ OK ]
[22:49:42] /usr/sbin/vipw [ OK ]
[22:49:42] /usr/bin/awk [ OK ]
[22:49:43] /usr/bin/basename [ OK ]
[22:49:43] /usr/bin/bash [ OK ]
[22:49:43] /usr/bin/cat [ OK ]
[22:49:43] /usr/bin/chattr [ OK ]
[22:49:43] /usr/bin/chmod [ OK ]
[22:49:43] /usr/bin/chown [ OK ]
[22:49:43] /usr/bin/cp [ OK ]
[22:49:43] /usr/bin/curl [ OK ]
[22:49:43] /usr/bin/cut [ OK ]
[22:49:43] /usr/bin/date [ OK ]
[22:49:43] /usr/bin/df [ OK ]
[22:49:43] /usr/bin/diff [ OK ]
[22:49:43] /usr/bin/dirname [ OK ]
[22:49:43] /usr/bin/dmesg [ OK ]
[22:49:43] /usr/bin/du [ OK ]
[22:49:44] /usr/bin/echo [ OK ]
[22:49:44] /usr/bin/ed [ OK ]
[22:49:44] /usr/bin/egrep [ Warning ]
[22:49:44] Warning: The command '/usr/bin/egrep' has been replaced by a script: /usr/bin/egrep: POSIX shell script, ASCII text executable
[22:49:44] /usr/bin/env [ OK ]
[22:49:44] /usr/bin/fgrep [ Warning ]
[22:49:44] Warning: The command '/usr/bin/fgrep' has been replaced by a script: /usr/bin/fgrep: POSIX shell script, ASCII text executable
[22:49:44] /usr/bin/file [ OK ]
[22:49:44] /usr/bin/find [ OK ]
[22:49:44] /usr/bin/GET [ OK ]
[22:49:44] Info: Found file '/usr/bin/GET': it is whitelisted for the 'script replacement' check.
[22:49:44] /usr/bin/grep [ OK ]
[22:49:44] /usr/bin/groups [ OK ]
[22:49:44] Info: Found file '/usr/bin/groups': it is whitelisted for the 'script replacement' check.
[22:49:44] /usr/bin/head [ OK ]
[22:49:44] /usr/bin/id [ OK ]
[22:49:44] /usr/bin/kill [ OK ]
[22:49:44] /usr/bin/killall [ OK ]
[22:49:45] /usr/bin/last [ OK ]
[22:49:45] /usr/bin/lastlog [ OK ]
[22:49:45] /usr/bin/ldd [ OK ]
[22:49:45] Info: Found file '/usr/bin/ldd': it is whitelisted for the 'script replacement' check.
[22:49:45] /usr/bin/less [ OK ]
[22:49:45] /usr/bin/locate [ OK ]
[22:49:45] /usr/bin/logger [ OK ]
[22:49:45] /usr/bin/login [ OK ]
[22:49:45] /usr/bin/ls [ OK ]
[22:49:45] /usr/bin/lsattr [ OK ]
[22:49:45] /usr/bin/lsof [ OK ]
[22:49:45] /usr/bin/mail [ OK ]
[22:49:45] /usr/bin/md5sum [ OK ]
[22:49:45] /usr/bin/mktemp [ OK ]
[22:49:46] /usr/bin/more [ OK ]
[22:49:46] /usr/bin/mount [ OK ]
[22:49:46] /usr/bin/mv [ OK ]
[22:49:46] /usr/bin/netstat [ OK ]
[22:49:46] /usr/bin/newgrp [ OK ]
[22:49:46] /usr/bin/passwd [ OK ]
[22:49:46] /usr/bin/perl [ OK ]
[22:49:46] /usr/bin/pgrep [ OK ]
[22:49:46] /usr/bin/ping [ OK ]
[22:49:46] /usr/bin/pkill [ OK ]
[22:49:46] /usr/bin/ps [ OK ]
[22:49:46] /usr/bin/pstree [ OK ]
[22:49:46] /usr/bin/pwd [ OK ]
[22:49:46] /usr/bin/readlink [ OK ]
[22:49:47] /usr/bin/rkhunter [ OK ]
[22:49:47] /usr/bin/rpm [ OK ]
[22:49:47] /usr/bin/runcon [ OK ]
[22:49:47] /usr/bin/sed [ OK ]
[22:49:47] /usr/bin/sh [ OK ]
[22:49:47] /usr/bin/sha1sum [ OK ]
[22:49:47] /usr/bin/sha224sum [ OK ]
[22:49:47] /usr/bin/sha256sum [ OK ]
[22:49:47] /usr/bin/sha384sum [ OK ]
[22:49:47] /usr/bin/sha512sum [ OK ]
[22:49:47] /usr/bin/size [ OK ]
[22:49:47] /usr/bin/sort [ OK ]
[22:49:47] /usr/bin/ssh [ OK ]
[22:49:48] /usr/bin/stat [ OK ]
[22:49:48] /usr/bin/strace [ OK ]
[22:49:48] /usr/bin/strings [ OK ]
[22:49:48] /usr/bin/su [ OK ]
[22:49:48] /usr/bin/sudo [ OK ]
[22:49:48] /usr/bin/tail [ OK ]
[22:49:48] /usr/bin/telnet [ OK ]
[22:49:48] /usr/bin/test [ OK ]
[22:49:48] /usr/bin/top [ OK ]
[22:49:48] /usr/bin/touch [ OK ]
[22:49:48] /usr/bin/tr [ OK ]
[22:49:48] /usr/bin/uname [ OK ]
[22:49:48] /usr/bin/uniq [ OK ]
[22:49:49] /usr/bin/users [ OK ]
[22:49:49] /usr/bin/vmstat [ OK ]
[22:49:49] /usr/bin/w [ OK ]
[22:49:49] /usr/bin/watch [ OK ]
[22:49:49] /usr/bin/wc [ OK ]
[22:49:49] /usr/bin/wget [ OK ]
[22:49:49] /usr/bin/whatis [ OK ]
[22:49:49] Info: Found file '/usr/bin/whatis': it is whitelisted for the 'script replacement' check.
[22:49:49] /usr/bin/whereis [ OK ]
[22:49:49] /usr/bin/which [ OK ]
[22:49:49] /usr/bin/who [ OK ]
[22:49:49] /usr/bin/whoami [ OK ]
[22:49:49] /usr/bin/kmod [ OK ]
[22:49:49] /usr/bin/systemctl [ OK ]
[22:49:49] /usr/bin/gawk [ OK ]
[22:49:49] /usr/bin/mailx [ OK ]
[22:49:51] /usr/libexec/gawk [ OK ]
[22:49:52] /usr/lib/systemd/systemd [ OK ]
[22:49:52]
[22:49:52] Info: Starting test name 'rootkits'
[22:49:52] Checking for rootkits...
[22:49:52]
[22:49:52] Info: Starting test name 'known_rkts'
[22:49:52] Performing check of known rootkit files and directories
[22:49:52]
[22:49:52] Checking for 55808 Trojan - Variant A...
[22:49:52] Checking for file '/tmp/.../r' [ Not found ]
[22:49:53] Checking for file '/tmp/.../a' [ Not found ]
[22:49:53] 55808 Trojan - Variant A [ Not found ]
[22:49:53]
[22:49:53] Checking for ADM Worm...
[22:49:53] Checking for string 'w0rm' [ Not found ]
[22:49:53] ADM Worm [ Not found ]
[22:49:53]
[22:49:53] Checking for AjaKit Rootkit...
[22:49:53] Checking for file '/dev/tux/.addr' [ Not found ]
[22:49:53] Checking for file '/dev/tux/.proc' [ Not found ]
[22:49:53] Checking for file '/dev/tux/.file' [ Not found ]
[22:49:53] Checking for file '/lib/.libgh-gh/cleaner' [ Not found ]
[22:49:53] Checking for file '/lib/.libgh-gh/Patch/patch' [ Not found ]
[22:49:53] Checking for file '/lib/.libgh-gh/sb0k' [ Not found ]
[22:49:53] Checking for directory '/dev/tux' [ Not found ]
[22:49:53] Checking for directory '/lib/.libgh-gh' [ Not found ]
[22:49:53] AjaKit Rootkit [ Not found ]
[22:49:53]
[22:49:53] Checking for Adore Rootkit...
[22:49:53] Checking for file '/usr/secure' [ Not found ]
[22:49:53] Checking for file '/usr/doc/sys/qrt' [ Not found ]
[22:49:53] Checking for file '/usr/doc/sys/run' [ Not found ]
[22:49:53] Checking for file '/usr/doc/sys/crond' [ Not found ]
[22:49:53] Checking for file '/usr/sbin/kfd' [ Not found ]
[22:49:53] Checking for file '/usr/doc/kern/var' [ Not found ]
[22:49:53] Checking for file '/usr/doc/kern/string.o' [ Not found ]
[22:49:53] Checking for file '/usr/doc/kern/ava' [ Not found ]
[22:49:53] Checking for file '/usr/doc/kern/adore.o' [ Not found ]
[22:49:53] Checking for file '/var/log/ssh/old' [ Not found ]
[22:49:53] Checking for directory '/lib/security/.config/ssh' [ Not found ]
[22:49:53] Checking for directory '/usr/doc/kern' [ Not found ]
[22:49:53] Checking for directory '/usr/doc/backup' [ Not found ]
[22:49:53] Checking for directory '/usr/doc/backup/txt' [ Not found ]
[22:49:53] Checking for directory '/lib/backup' [ Not found ]
[22:49:54] Checking for directory '/lib/backup/txt' [ Not found ]
[22:49:54] Checking for directory '/usr/doc/work' [ Not found ]
[22:49:54] Checking for directory '/usr/doc/sys' [ Not found ]
[22:49:54] Checking for directory '/var/log/ssh' [ Not found ]
[22:49:54] Checking for directory '/usr/doc/.spool' [ Not found ]
[22:49:54] Checking for directory '/usr/lib/kterm' [ Not found ]
[22:49:54] Adore Rootkit [ Not found ]
[22:49:54]
[22:49:54] Checking for aPa Kit...
[22:49:54] Checking for file '/usr/share/.aPa' [ Not found ]
[22:49:54] aPa Kit [ Not found ]
[22:49:54]
[22:49:54] Checking for Apache Worm...
[22:49:54] Checking for file '/bin/.log' [ Not found ]
[22:49:54] Apache Worm [ Not found ]
[22:49:54]
[22:49:54] Checking for Ambient (ark) Rootkit...
[22:49:54] Checking for file '/usr/lib/.ark?' [ Not found ]
[22:49:54] Checking for file '/dev/ptyxx/.log' [ Not found ]
[22:49:54] Checking for file '/dev/ptyxx/.file' [ Not found ]
[22:49:54] Checking for file '/dev/ptyxx/.proc' [ Not found ]
[22:49:54] Checking for file '/dev/ptyxx/.addr' [ Not found ]
[22:49:54] Checking for directory '/dev/ptyxx' [ Not found ]
[22:49:54] Ambient (ark) Rootkit [ Not found ]
[22:49:54]
[22:49:54] Checking for Balaur Rootkit...
[22:49:54] Checking for file '/usr/lib/liblog.o' [ Not found ]
[22:49:54] Checking for directory '/usr/lib/.kinetic' [ Not found ]
[22:49:54] Checking for directory '/usr/lib/.egcs' [ Not found ]
[22:49:54] Checking for directory '/usr/lib/.wormie' [ Not found ]
[22:49:54] Balaur Rootkit [ Not found ]
[22:49:54]
[22:49:54] Checking for BeastKit Rootkit...
[22:49:54] Checking for file '/usr/sbin/arobia' [ Not found ]
[22:49:54] Checking for file '/usr/sbin/idrun' [ Not found ]
[22:49:55] Checking for file '/usr/lib/elm/arobia/elm' [ Not found ]
[22:49:55] Checking for file '/usr/lib/elm/arobia/elm/hk' [ Not found ]
[22:49:55] Checking for file '/usr/lib/elm/arobia/elm/hk.pub' [ Not found ]
[22:49:55] Checking for file '/usr/lib/elm/arobia/elm/sc' [ Not found ]
[22:49:55] Checking for file '/usr/lib/elm/arobia/elm/sd.pp' [ Not found ]
[22:49:55] Checking for file '/usr/lib/elm/arobia/elm/sdco' [ Not found ]
[22:49:55] Checking for file '/usr/lib/elm/arobia/elm/srsd' [ Not found ]
[22:49:55] Checking for directory '/lib/ldd.so/bktools' [ Not found ]
[22:49:55] BeastKit Rootkit [ Not found ]
[22:49:55]
[22:49:55] Checking for beX2 Rootkit...
[22:49:55] Checking for file '/usr/info/termcap.info-5.gz' [ Not found ]
[22:49:55] Checking for file '/usr/bin/sshd2' [ Not found ]
[22:49:55] Checking for directory '/usr/include/bex' [ Not found ]
[22:49:55] beX2 Rootkit [ Not found ]
[22:49:55]
[22:49:55] Checking for BOBKit Rootkit...
[22:49:55] Checking for file '/usr/sbin/ntpsx' [ Not found ]
[22:49:55] Checking for file '/usr/sbin/.../bkit-ava' [ Not found ]
[22:49:55] Checking for file '/usr/sbin/.../bkit-d' [ Not found ]
[22:49:55] Checking for file '/usr/sbin/.../bkit-shd' [ Not found ]
[22:49:55] Checking for file '/usr/sbin/.../bkit-f' [ Not found ]
[22:49:55] Checking for file '/usr/include/.../proc.h' [ Not found ]
[22:49:55] Checking for file '/usr/include/.../.bash_history' [ Not found ]
[22:49:55] Checking for file '/usr/include/.../bkit-get' [ Not found ]
[22:49:55] Checking for file '/usr/include/.../bkit-dl' [ Not found ]
[22:49:55] Checking for file '/usr/include/.../bkit-screen' [ Not found ]
[22:49:55] Checking for file '/usr/include/.../bkit-sleep' [ Not found ]
[22:49:55] Checking for file '/usr/lib/.../bkit-adore.o' [ Not found ]
[22:49:55] Checking for file '/usr/lib/.../ls' [ Not found ]
[22:49:55] Checking for file '/usr/lib/.../netstat' [ Not found ]
[22:49:55] Checking for file '/usr/lib/.../lsof' [ Not found ]
[22:49:55] Checking for file '/usr/lib/.../bkit-ssh/bkit-shdcfg' [ Not found ]
[22:49:55] Checking for file '/usr/lib/.../bkit-ssh/bkit-shhk' [ Not found ]
[22:49:56] Checking for file '/usr/lib/.../bkit-ssh/bkit-pw' [ Not found ]
[22:49:56] Checking for file '/usr/lib/.../bkit-ssh/bkit-shrs' [ Not found ]
[22:49:56] Checking for file '/usr/lib/.../bkit-ssh/bkit-mots' [ Not found ]
[22:49:56] Checking for file '/usr/lib/.../uconf.inv' [ Not found ]
[22:49:56] Checking for file '/usr/lib/.../psr' [ Not found ]
[22:49:56] Checking for file '/usr/lib/.../find' [ Not found ]
[22:49:56] Checking for file '/usr/lib/.../pstree' [ Not found ]
[22:49:56] Checking for file '/usr/lib/.../slocate' [ Not found ]
[22:49:56] Checking for file '/usr/lib/.../du' [ Not found ]
[22:49:56] Checking for file '/usr/lib/.../top' [ Not found ]
[22:49:56] Checking for directory '/usr/sbin/...' [ Not found ]
[22:49:56] Checking for directory '/usr/include/...' [ Not found ]
[22:49:56] Checking for directory '/usr/include/.../.tmp' [ Not found ]
[22:49:56] Checking for directory '/usr/lib/...' [ Not found ]
[22:49:56] Checking for directory '/usr/lib/.../.ssh' [ Not found ]
[22:49:56] Checking for directory '/usr/lib/.../bkit-ssh' [ Not found ]
[22:49:56] Checking for directory '/usr/lib/.bkit-' [ Not found ]
[22:49:56] Checking for directory '/tmp/.bkp' [ Not found ]
[22:49:56] BOBKit Rootkit [ Not found ]
[22:49:56]
[22:49:56] Checking for cb Rootkit...
[22:49:56] Checking for file '/dev/srd0' [ Not found ]
[22:49:56] Checking for file '/lib/libproc.so.2.0.6' [ Not found ]
[22:49:56] Checking for file '/dev/mounnt' [ Not found ]
[22:49:56] Checking for file '/etc/rc.d/init.d/init' [ Not found ]
[22:49:56] Checking for file '/usr/bin/.zeen/..<SP>/cl' [ Not found ]
[22:49:56] Checking for file '/usr/bin/.zeen/..<SP>/.x.tgz' [ Not found ]
[22:49:56] Checking for file '/usr/bin/.zeen/..<SP>/statdx' [ Not found ]
[22:49:56] Checking for file '/usr/bin/.zeen/..<SP>/wted' [ Not found ]
[22:49:56] Checking for file '/usr/bin/.zeen/..<SP>/write' [ Not found ]
[22:49:56] Checking for file '/usr/bin/.zeen/..<SP>/scan' [ Not found ]
[22:49:56] Checking for file '/usr/bin/.zeen/..<SP>/sc' [ Not found ]
[22:49:56] Checking for file '/usr/bin/.zeen/..<SP>/sl2' [ Not found ]
[22:49:57] Checking for file '/usr/bin/.zeen/..<SP>/wroot' [ Not found ]
[22:49:57] Checking for file '/usr/bin/.zeen/..<SP>/wscan' [ Not found ]
[22:49:57] Checking for file '/usr/bin/.zeen/..<SP>/wu' [ Not found ]
[22:49:57] Checking for file '/usr/bin/.zeen/..<SP>/v' [ Not found ]
[22:49:57] Checking for file '/usr/bin/.zeen/..<SP>/read' [ Not found ]
[22:49:57] Checking for file '/usr/lib/sshrc' [ Not found ]
[22:49:57] Checking for file '/usr/lib/ssh_host_key' [ Not found ]
[22:49:57] Checking for file '/usr/lib/ssh_host_key.pub' [ Not found ]
[22:49:57] Checking for file '/usr/lib/ssh_random_seed' [ Not found ]
[22:49:57] Checking for file '/usr/lib/sshd_config' [ Not found ]
[22:49:57] Checking for file '/usr/lib/shosts.equiv' [ Not found ]
[22:49:57] Checking for file '/usr/lib/ssh_known_hosts' [ Not found ]
[22:49:57] Checking for file '/u/zappa/.ssh/pid' [ Not found ]
[22:49:57] Checking for file '/usr/bin/.system/..<SP>/tcp.log' [ Not found ]
[22:49:57] Checking for file '/usr/bin/.zeen/..<SP>/curatare/attrib' [ Not found ]
[22:49:57] Checking for file '/usr/bin/.zeen/..<SP>/curatare/chattr' [ Not found ]
[22:49:57] Checking for file '/usr/bin/.zeen/..<SP>/curatare/ps' [ Not found ]
[22:49:57] Checking for file '/usr/bin/.zeen/..<SP>/curatare/pstree' [ Not found ]
[22:49:57] Checking for file '/usr/bin/.system/..<SP>/.x/xC.o' [ Not found ]
[22:49:57] Checking for directory '/usr/bin/.zeen' [ Not found ]
[22:49:57] Checking for directory '/usr/bin/.zeen/..<SP>/curatare' [ Not found ]
[22:49:57] Checking for directory '/usr/bin/.zeen/..<SP>/scan' [ Not found ]
[22:49:57] Checking for directory '/usr/bin/.system/..<SP>' [ Not found ]
[22:49:57] cb Rootkit [ Not found ]
[22:49:57]
[22:49:57] Checking for CiNIK Worm (Slapper.B variant)...
[22:49:57] Checking for file '/tmp/.cinik' [ Not found ]
[22:49:57] Checking for directory '/tmp/.font-unix/.cinik' [ Not found ]
[22:49:57] CiNIK Worm (Slapper.B variant) [ Not found ]
[22:49:57]
[22:49:57] Checking for Danny-Boy's Abuse Kit...
[22:49:57] Checking for file '/dev/mdev' [ Not found ]
[22:49:57] Checking for file '/usr/lib/libX.a' [ Not found ]
[22:49:58] Danny-Boy's Abuse Kit [ Not found ]
[22:49:58]
[22:49:58] Checking for Devil RootKit...
[22:49:58] Checking for file '/var/lib/games/.src' [ Not found ]
[22:49:58] Checking for file '/dev/dsx' [ Not found ]
[22:49:58] Checking for file '/dev/caca' [ Not found ]
[22:49:58] Checking for file '/dev/pro' [ Not found ]
[22:49:58] Checking for file '/bin/bye' [ Not found ]
[22:49:58] Checking for file '/bin/homedir' [ Not found ]
[22:49:58] Checking for file '/usr/bin/xfss' [ Not found ]
[22:49:58] Checking for file '/usr/sbin/tzava' [ Not found ]
[22:49:58] Checking for file '/usr/doc/tar/.../.dracusor/stuff/holber' [ Not found ]
[22:49:58] Checking for file '/usr/doc/tar/.../.dracusor/stuff/sense' [ Not found ]
[22:49:58] Checking for file '/usr/doc/tar/.../.dracusor/stuff/clear' [ Not found ]
[22:49:58] Checking for file '/usr/doc/tar/.../.dracusor/stuff/tzava' [ Not found ]
[22:49:58] Checking for file '/usr/doc/tar/.../.dracusor/stuff/citeste' [ Not found ]
[22:49:58] Checking for file '/usr/doc/tar/.../.dracusor/stuff/killrk' [ Not found ]
[22:49:58] Checking for file '/usr/doc/tar/.../.dracusor/stuff/searchlog' [ Not found ]
[22:49:58] Checking for file '/usr/doc/tar/.../.dracusor/stuff/gaoaza' [ Not found ]
[22:49:58] Checking for file '/usr/doc/tar/.../.dracusor/stuff/cleaner' [ Not found ]
[22:49:58] Checking for file '/usr/doc/tar/.../.dracusor/stuff/shk' [ Not found ]
[22:49:58] Checking for file '/usr/doc/tar/.../.dracusor/stuff/srs' [ Not found ]
[22:49:58] Checking for file '/usr/doc/tar/.../.dracusor/utile.tgz' [ Not found ]
[22:49:58] Checking for file '/usr/doc/tar/.../.dracusor/webpage' [ Not found ]
[22:49:58] Checking for file '/usr/doc/tar/.../.dracusor/getpsy' [ Not found ]
[22:49:58] Checking for file '/usr/doc/tar/.../.dracusor/getbnc' [ Not found ]
[22:49:58] Checking for file '/usr/doc/tar/.../.dracusor/getemech' [ Not found ]
[22:49:58] Checking for file '/usr/doc/tar/.../.dracusor/localroot.sh' [ Not found ]
[22:49:58] Checking for file '/usr/doc/tar/.../.dracusor/stuff/old/sense' [ Not found ]
[22:49:58] Checking for directory '/usr/doc/tar/.../.dracusor' [ Not found ]
[22:49:59] Devil RootKit [ Not found ]
[22:49:59]
[22:49:59] Checking for Dica-Kit Rootkit...
[22:49:59] Checking for file '/lib/.sso' [ Not found ]
[22:49:59] Checking for file '/lib/.so' [ Not found ]
[22:49:59] Checking for file '/var/run/...dica/clean' [ Not found ]
[22:49:59] Checking for file '/var/run/...dica/dxr' [ Not found ]
[22:49:59] Checking for file '/var/run/...dica/read' [ Not found ]
[22:49:59] Checking for file '/var/run/...dica/write' [ Not found ]
[22:49:59] Checking for file '/var/run/...dica/lf' [ Not found ]
[22:49:59] Checking for file '/var/run/...dica/xl' [ Not found ]
[22:49:59] Checking for file '/var/run/...dica/xdr' [ Not found ]
[22:49:59] Checking for file '/var/run/...dica/psg' [ Not found ]
[22:49:59] Checking for file '/var/run/...dica/secure' [ Not found ]
[22:49:59] Checking for file '/var/run/...dica/rdx' [ Not found ]
[22:49:59] Checking for file '/var/run/...dica/va' [ Not found ]
[22:49:59] Checking for file '/var/run/...dica/cl.sh' [ Not found ]
[22:49:59] Checking for file '/var/run/...dica/last.log' [ Not found ]
[22:49:59] Checking for file '/usr/bin/.etc' [ Not found ]
[22:49:59] Checking for file '/etc/sshd_config' [ Not found ]
[22:49:59] Checking for file '/etc/ssh_host_key' [ Not found ]
[22:49:59] Checking for file '/etc/ssh_random_seed' [ Not found ]
[22:49:59] Checking for directory '/var/run/...dica' [ Not found ]
[22:49:59] Checking for directory '/var/run/...dica/mh' [ Not found ]
[22:49:59] Checking for directory '/var/run/...dica/scan' [ Not found ]
[22:49:59] Dica-Kit Rootkit [ Not found ]
[22:49:59]
[22:49:59] Checking for Dreams Rootkit...
[22:49:59] Checking for file '/dev/ttyoa' [ Not found ]
[22:49:59] Checking for file '/dev/ttyof' [ Not found ]
[22:49:59] Checking for file '/dev/ttyop' [ Not found ]
[22:49:59] Checking for file '/usr/bin/sense' [ Not found ]
[22:50:00] Checking for file '/usr/bin/sl2' [ Not found ]
[22:50:00] Checking for file '/usr/bin/logclear' [ Not found ]
[22:50:00] Checking for file '/usr/bin/(swapd)' [ Not found ]
[22:50:00] Checking for file '/usr/bin/initrd' [ Not found ]
[22:50:00] Checking for file '/usr/bin/crontabs' [ Not found ]
[22:50:00] Checking for file '/usr/bin/snfs' [ Not found ]
[22:50:00] Checking for file '/usr/lib/libsss' [ Not found ]
[22:50:00] Checking for file '/usr/lib/libsnf.log' [ Not found ]
[22:50:00] Checking for file '/usr/lib/libshtift/top' [ Not found ]
[22:50:00] Checking for file '/usr/lib/libshtift/ps' [ Not found ]
[22:50:00] Checking for file '/usr/lib/libshtift/netstat' [ Not found ]
[22:50:00] Checking for file '/usr/lib/libshtift/ls' [ Not found ]
[22:50:00] Checking for file '/usr/lib/libshtift/ifconfig' [ Not found ]
[22:50:00] Checking for file '/usr/include/linseed.h' [ Not found ]
[22:50:00] Checking for file '/usr/include/linpid.h' [ Not found ]
[22:50:00] Checking for file '/usr/include/linkey.h' [ Not found ]
[22:50:00] Checking for file '/usr/include/linconf.h' [ Not found ]
[22:50:00] Checking for file '/usr/include/iceseed.h' [ Not found ]
[22:50:00] Checking for file '/usr/include/icepid.h' [ Not found ]
[22:50:00] Checking for file '/usr/include/icekey.h' [ Not found ]
[22:50:00] Checking for file '/usr/include/iceconf.h' [ Not found ]
[22:50:00] Checking for directory '/dev/ida/.hpd' [ Not found ]
[22:50:00] Checking for directory '/usr/lib/libshtift' [ Not found ]
[22:50:00] Dreams Rootkit [ Not found ]
[22:50:00]
[22:50:00] Checking for Duarawkz Rootkit...
[22:50:00] Checking for file '/usr/bin/duarawkz/loginpass' [ Not found ]
[22:50:00] Checking for directory '/usr/bin/duarawkz' [ Not found ]
[22:50:00] Duarawkz Rootkit [ Not found ]
[22:50:00]
[22:50:00] Checking for Enye LKM...
[22:50:00] Checking for file '/etc/.enyelkmHIDE^IT.ko' [ Not found ]
[22:50:00] Checking for file '/etc/.enyelkmOCULTAR.ko' [ Not found ]
[22:50:00] Enye LKM [ Not found ]
[22:50:00]
[22:50:00] Checking for Flea Linux Rootkit...
[22:50:00] Checking for file '/etc/ld.so.hash' [ Not found ]
[22:50:00] Checking for file '/lib/security/.config/ssh/sshd_config' [ Not found ]
[22:50:01] Checking for file '/lib/security/.config/ssh/ssh_host_key' [ Not found ]
[22:50:01] Checking for file '/lib/security/.config/ssh/ssh_host_key.pub' [ Not found ]
[22:50:01] Checking for file '/lib/security/.config/ssh/ssh_random_seed' [ Not found ]
[22:50:01] Checking for file '/usr/bin/ssh2d' [ Not found ]
[22:50:01] Checking for file '/usr/lib/ldlibns.so' [ Not found ]
[22:50:01] Checking for file '/usr/lib/ldlibps.so' [ Not found ]
[22:50:01] Checking for file '/usr/lib/ldlibpst.so' [ Not found ]
[22:50:01] Checking for file '/usr/lib/ldlibdu.so' [ Not found ]
[22:50:01] Checking for file '/usr/lib/ldlibct.so' [ Not found ]
[22:50:01] Checking for directory '/lib/security/.config/ssh' [ Not found ]
[22:50:01] Checking for directory '/dev/..0' [ Not found ]
[22:50:01] Checking for directory '/dev/..0/backup' [ Not found ]
[22:50:01] Flea Linux Rootkit [ Not found ]
[22:50:01]
[22:50:01] Checking for Fu Rootkit...
[22:50:01] Checking for file '/sbin/xc' [ Not found ]
[22:50:01] Checking for file '/usr/include/ivtype.h' [ Not found ]
[22:50:01] Checking for file '/bin/.lib' [ Not found ]
[22:50:01] Fu Rootkit [ Not found ]
[22:50:01]
[22:50:01] Checking for Fuck`it Rootkit...
[22:50:01] Checking for file '/lib/libproc.so.2.0.7' [ Not found ]
[22:50:01] Checking for file '/dev/proc/.bash_profile' [ Not found ]
[22:50:01] Checking for file '/dev/proc/.bashrc' [ Not found ]
[22:50:01] Checking for file '/dev/proc/.cshrc' [ Not found ]
[22:50:01] Checking for file '/dev/proc/fuckit/hax0r' [ Not found ]
[22:50:01] Checking for file '/dev/proc/fuckit/hax0rshell' [ Not found ]
[22:50:01] Checking for file '/dev/proc/fuckit/config/lports' [ Not found ]
[22:50:01] Checking for file '/dev/proc/fuckit/config/rports' [ Not found ]
[22:50:01] Checking for file '/dev/proc/fuckit/config/rkconf' [ Not found ]
[22:50:01] Checking for file '/dev/proc/fuckit/config/password' [ Not found ]
[22:50:02] Checking for file '/dev/proc/fuckit/config/progs' [ Not found ]
[22:50:02] Checking for file '/dev/proc/fuckit/system-bins/init' [ Not found ]
[22:50:02] Checking for file '/usr/lib/libcps.a' [ Not found ]
[22:50:02] Checking for file '/usr/lib/libtty.a' [ Not found ]
[22:50:02] Checking for directory '/dev/proc' [ Not found ]
[22:50:02] Checking for directory '/dev/proc/fuckit' [ Not found ]
[22:50:02] Checking for directory '/dev/proc/fuckit/system-bins' [ Not found ]
[22:50:02] Checking for directory '/dev/proc/toolz' [ Not found ]
[22:50:02] Fuck`it Rootkit [ Not found ]
[22:50:02]
[22:50:02] Checking for GasKit Rootkit...
[22:50:02] Checking for file '/dev/dev/gaskit/sshd/sshdd' [ Not found ]
[22:50:02] Checking for directory '/dev/dev' [ Not found ]
[22:50:02] Checking for directory '/dev/dev/gaskit' [ Not found ]
[22:50:02] Checking for directory '/dev/dev/gaskit/sshd' [ Not found ]
[22:50:02] GasKit Rootkit [ Not found ]
[22:50:02]
[22:50:02] Checking for Heroin LKM...
[22:50:02] Checking for kernel symbol 'heroin' [ Not found ]
[22:50:02] Heroin LKM [ Not found ]
[22:50:02]
[22:50:02] Checking for HjC Kit...
[22:50:02] Checking for directory '/dev/.hijackerz' [ Not found ]
[22:50:02] HjC Kit [ Not found ]
[22:50:02]
[22:50:02] Checking for ignoKit Rootkit...
[22:50:02] Checking for file '/lib/defs/p' [ Not found ]
[22:50:02] Checking for file '/lib/defs/q' [ Not found ]
[22:50:02] Checking for file '/lib/defs/r' [ Not found ]
[22:50:02] Checking for file '/lib/defs/s' [ Not found ]
[22:50:02] Checking for file '/lib/defs/t' [ Not found ]
[22:50:03] Checking for file '/usr/lib/defs/p' [ Not found ]
[22:50:03] Checking for file '/usr/lib/defs/q' [ Not found ]
[22:50:03] Checking for file '/usr/lib/defs/r' [ Not found ]
[22:50:03] Checking for file '/usr/lib/defs/s' [ Not found ]
[22:50:03] Checking for file '/usr/lib/defs/t' [ Not found ]
[22:50:03] Checking for file '/usr/lib/.libigno/pkunsec' [ Not found ]
[22:50:03] Checking for file '/usr/lib/.libigno/.igno/psybnc/psybnc' [ Not found ]
[22:50:03] Checking for directory '/usr/lib/.libigno' [ Not found ]
[22:50:03] Checking for directory '/usr/lib/.libigno/.igno' [ Not found ]
[22:50:03] ignoKit Rootkit [ Not found ]
[22:50:03]
[22:50:03] Checking for IntoXonia-NG Rootkit...
[22:50:03] Checking for kernel symbol 'funces' [ Not found ]
[22:50:03] Checking for kernel symbol 'ixinit' [ Not found ]
[22:50:03] Checking for kernel symbol 'tricks' [ Not found ]
[22:50:03] Checking for kernel symbol 'kernel_unlink' [ Not found ]
[22:50:03] Checking for kernel symbol 'rootme' [ Not found ]
[22:50:03] Checking for kernel symbol 'hide_module' [ Not found ]
[22:50:03] Checking for kernel symbol 'find_sys_call_tbl' [ Not found ]
[22:50:04] IntoXonia-NG Rootkit [ Not found ]
[22:50:04]
[22:50:04] Checking for Irix Rootkit...
[22:50:04] Checking for directory '/dev/pts/01' [ Not found ]
[22:50:04] Checking for directory '/dev/pts/01/backup' [ Not found ]
[22:50:04] Checking for directory '/dev/pts/01/etc' [ Not found ]
[22:50:04] Checking for directory '/dev/pts/01/tmp' [ Not found ]
[22:50:04] Irix Rootkit [ Not found ]
[22:50:04]
[22:50:04] Checking for Jynx Rootkit...
[22:50:04] Checking for file '/xochikit/bc' [ Not found ]
[22:50:04] Checking for file '/xochikit/ld_poison.so' [ Not found ]
[22:50:04] Checking for file '/omgxochi/bc' [ Not found ]
[22:50:04] Checking for file '/omgxochi/ld_poison.so' [ Not found ]
[22:50:04] Checking for file '/var/local/^^/bc' [ Not found ]
[22:50:04] Checking for file '/var/local/^^/ld_poison.so' [ Not found ]
[22:50:04] Checking for directory '/xochikit' [ Not found ]
[22:50:04] Checking for directory '/omgxochi' [ Not found ]
[22:50:04] Checking for directory '/var/local/^^' [ Not found ]
[22:50:04] Jynx Rootkit [ Not found ]
[22:50:04]
[22:50:04] Checking for KBeast Rootkit...
[22:50:04] Checking for file '/usr/_h4x_/ipsecs-kbeast-v1.ko' [ Not found ]
[22:50:04] Checking for file '/usr/_h4x_/_h4x_bd' [ Not found ]
[22:50:04] Checking for file '/usr/_h4x_/acctlog' [ Not found ]
[22:50:04] Checking for directory '/usr/_h4x_' [ Not found ]
[22:50:04] Checking for kernel symbol 'h4x_delete_module' [ Not found ]
[22:50:04] Checking for kernel symbol 'h4x_getdents64' [ Not found ]
[22:50:05] Checking for kernel symbol 'h4x_kill' [ Not found ]
[22:50:05] Checking for kernel symbol 'h4x_open' [ Not found ]
[22:50:05] Checking for kernel symbol 'h4x_read' [ Not found ]
[22:50:05] Checking for kernel symbol 'h4x_rename' [ Not found ]
[22:50:05] Checking for kernel symbol 'h4x_rmdir' [ Not found ]
[22:50:05] Checking for kernel symbol 'h4x_tcp4_seq_show' [ Not found ]
[22:50:05] Checking for kernel symbol 'h4x_write' [ Not found ]
[22:50:05] KBeast Rootkit [ Not found ]
[22:50:05]
[22:50:05] Checking for Kitko Rootkit...
[22:50:05] Checking for directory '/usr/src/redhat/SRPMS/...' [ Not found ]
[22:50:05] Kitko Rootkit [ Not found ]
[22:50:05]
[22:50:05] Checking for Knark Rootkit...
[22:50:05] Checking for file '/proc/knark/pids' [ Not found ]
[22:50:05] Checking for directory '/proc/knark' [ Not found ]
[22:50:05] Knark Rootkit [ Not found ]
[22:50:05]
[22:50:05] Checking for ld-linuxv.so Rootkit...
[22:50:05] Checking for file '/lib/ld-linuxv.so.1' [ Not found ]
[22:50:05] Checking for directory '/var/opt/_so_cache' [ Not found ]
[22:50:06] Checking for directory '/var/opt/_so_cache/ld' [ Not found ]
[22:50:06] Checking for directory '/var/opt/_so_cache/lc' [ Not found ]
[22:50:06] ld-linuxv.so Rootkit [ Not found ]
[22:50:06]
[22:50:06] Checking for Li0n Worm...
[22:50:06] Checking for file '/bin/in.telnetd' [ Not found ]
[22:50:06] Checking for file '/bin/mjy' [ Not found ]
[22:50:06] Checking for file '/usr/man/man1/man1/lib/.lib/mjy' [ Not found ]
[22:50:06] Checking for file '/usr/man/man1/man1/lib/.lib/in.telnetd' [ Not found ]
[22:50:06] Checking for file '/usr/man/man1/man1/lib/.lib/.x' [ Not found ]
[22:50:06] Checking for file '/dev/.lib/lib/scan/1i0n.sh' [ Not found ]
[22:50:06] Checking for file '/dev/.lib/lib/scan/hack.sh' [ Not found ]
[22:50:06] Checking for file '/dev/.lib/lib/scan/bind' [ Not found ]
[22:50:06] Checking for file '/dev/.lib/lib/scan/randb' [ Not found ]
[22:50:06] Checking for file '/dev/.lib/lib/scan/scan.sh' [ Not found ]
[22:50:06] Checking for file '/dev/.lib/lib/scan/pscan' [ Not found ]
[22:50:06] Checking for file '/dev/.lib/lib/scan/star.sh' [ Not found ]
[22:50:06] Checking for file '/dev/.lib/lib/scan/bindx.sh' [ Not found ]
[22:50:06] Checking for file '/dev/.lib/lib/scan/bindname.log' [ Not found ]
[22:50:06] Checking for file '/dev/.lib/lib/1i0n.sh' [ Not found ]
[22:50:06] Checking for file '/dev/.lib/lib/lib/netstat' [ Not found ]
[22:50:06] Checking for file '/dev/.lib/lib/lib/dev/.1addr' [ Not found ]
[22:50:06] Checking for file '/dev/.lib/lib/lib/dev/.1logz' [ Not found ]
[22:50:06] Checking for file '/dev/.lib/lib/lib/dev/.1proc' [ Not found ]
[22:50:06] Checking for file '/dev/.lib/lib/lib/dev/.1file' [ Not found ]
[22:50:06] Li0n Worm [ Not found ]
[22:50:06]
[22:50:06] Checking for Lockit / LJK2 Rootkit...
[22:50:06] Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_config' [ Not found ]
[22:50:06] Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_host_key' [ Not found ]
[22:50:06] Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_host_key.pub' [ Not found ]
[22:50:06] Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_random_seed*' [ Not found ]
[22:50:06] Checking for file '/usr/lib/libmen.oo/.LJK2/sshd_config' [ Not found ]
[22:50:06] Checking for file '/usr/lib/libmen.oo/.LJK2/backdoor/RK1bd' [ Not found ]
[22:50:07] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/du' [ Not found ]
[22:50:07] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ifconfig' [ Not found ]
[22:50:07] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/inetd.conf' [ Not found ]
[22:50:07] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/locate' [ Not found ]
[22:50:07] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/login' [ Not found ]
[22:50:07] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ls' [ Not found ]
[22:50:07] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/netstat' [ Not found ]
[22:50:07] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ps' [ Not found ]
[22:50:07] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/pstree' [ Not found ]
[22:50:07] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/rc.sysinit' [ Not found ]
[22:50:07] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/syslogd' [ Not found ]
[22:50:07] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/tcpd' [ Not found ]
[22:50:07] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/top' [ Not found ]
[22:50:07] Checking for file '/usr/lib/libmen.oo/.LJK2/clean/RK1sauber' [ Not found ]
[22:50:07] Checking for file '/usr/lib/libmen.oo/.LJK2/clean/RK1wted' [ Not found ]
[22:50:07] Checking for file '/usr/lib/libmen.oo/.LJK2/hack/RK1parse' [ Not found ]
[22:50:07] Checking for file '/usr/lib/libmen.oo/.LJK2/hack/RK1sniff' [ Not found ]
[22:50:07] Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1addr' [ Not found ]
[22:50:07] Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1dir' [ Not found ]
[22:50:07] Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1log' [ Not found ]
[22:50:07] Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1proc' [ Not found ]
[22:50:07] Checking for file '/usr/lib/libmen.oo/.LJK2/hide/RK1phidemod.c' [ Not found ]
[22:50:07] Checking for file '/usr/lib/libmen.oo/.LJK2/modules/README.modules' [ Not found ]
[22:50:07] Checking for file '/usr/lib/libmen.oo/.LJK2/modules/RK1hidem.c' [ Not found ]
[22:50:07] Checking for file '/usr/lib/libmen.oo/.LJK2/modules/RK1phide' [ Not found ]
[22:50:07] Checking for file '/usr/lib/libmen.oo/.LJK2/sshconfig/RK1ssh' [ Not found ]
[22:50:07] Checking for directory '/usr/lib/libmen.oo/.LJK2' [ Not found ]
[22:50:07] Lockit / LJK2 Rootkit [ Not found ]
[22:50:07]
[22:50:07] Checking for Mood-NT Rootkit...
[22:50:07] Checking for file '/sbin/init__mood-nt-_-_cthulhu' [ Not found ]
[22:50:08] Checking for file '/_cthulhu/mood-nt.init' [ Not found ]
[22:50:08] Checking for file '/_cthulhu/mood-nt.conf' [ Not found ]
[22:50:08] Checking for file '/_cthulhu/mood-nt.sniff' [ Not found ]
[22:50:08] Checking for directory '/_cthulhu' [ Not found ]
[22:50:08] Mood-NT Rootkit [ Not found ]
[22:50:08]
[22:50:08] Checking for MRK Rootkit...
[22:50:08] Checking for file '/dev/ida/.inet/pid' [ Not found ]
[22:50:08] Checking for file '/dev/ida/.inet/ssh_host_key' [ Not found ]
[22:50:08] Checking for file '/dev/ida/.inet/ssh_random_seed' [ Not found ]
[22:50:08] Checking for file '/dev/ida/.inet/tcp.log' [ Not found ]
[22:50:08] Checking for directory '/dev/ida/.inet' [ Not found ]
[22:50:08] Checking for directory '/var/spool/cron/.sh' [ Not found ]
[22:50:08] MRK Rootkit [ Not found ]
[22:50:08]
[22:50:08] Checking for Ni0 Rootkit...
[22:50:08] Checking for file '/var/lock/subsys/...datafile.../...net...' [ Not found ]
[22:50:08] Checking for file '/var/lock/subsys/...datafile.../...port...' [ Not found ]
[22:50:08] Checking for file '/var/lock/subsys/...datafile.../...ps...' [ Not fo


  


2. Re: duvidas com resultado do rkhunter

Alberto Federman Neto.
albfneto

(usa openSUSE)

Enviado em 13/05/2017 - 21:23h

achou só os comandos normais. nâo achou nada...
de fato rootkits linux são muito raros....
em 10 anos de linux, jamais peguei um rootkit, ou ví um!
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨
Albfneto,
Ribeirão Preto, S.P., Brasil.
Usuário Linux, Linux Counter: #479903.
Distros Favoritas: Sabayon, Gentoo, openSUSE, Mageia e OpenMandriva.


3. Re: duvidas com resultado do rkhunter

Perfil removido
removido

(usa Nenhuma)

Enviado em 13/05/2017 - 22:05h

Qual as saídas dos comandos?


rkhunter --propupd

rkhunter --update

rkhunter --check

cat /var/log/rkhunter.log



Leia:

https://www.vivaolinux.com.br/artigo/Chkrootkit-Como-determinar-se-o-sistema-esta-infectado-com-root...

man rkhunter






Patrocínio

Site hospedado pelo provedor RedeHost.
Linux banner

Destaques

Artigos

Dicas

Tópicos

Top 10 do mês

Scripts