Search Members Help

» Welcome Guest
[ Log In :: Register ]

Mini-ITX Boards Sale, Fanless BareBones Mini-ITX, Bootable 1G DSL USBs, 533MHz Fanless PC <-- SALE $200 each!
Get The Official Damn Small Linux Book. DSL Market , Great VPS hosting provided by Tektonic
 

[ Track this topic :: Email this topic :: Print this topic ]

reply to topic new topic new poll
Topic: I was rooted?!, chkrootkit saves the day, but...< Next Oldest | Next Newest >
Aether Offline





Group: Members
Posts: 5
Joined: Dec. 2005
Posted: Jan. 08 2006,18:40 QUOTE

Before I talk about the breach, I should mention that on a clean install, chkrootkit shows netstat as INFECTED.  I read a couple of poor english posts that mentioned a possiable false positive due to the addrs.h(I think) and needs to be stripped.  Anyone confirm this, I don't know how.

Also, I am curious about the /KNOPPIX/ect/dhpc/resolv.conf having a hardcoded value of 206.13.28.12... is this your nameserver?

Anyways, the first time I ran chkrootkit I found about five positive infections, ls, du, date .... normal stuff.  What has a a little concerned is, the only programs I have ever used on this distro are MyDSL, FireFox, Dillo, xMMS.   I had installed iptables and was testing rc.firewall from projectfiles.com, but I started no network daemons.  I have not been rooted since I first found them.

{edit} opps, and I enabled apt, upgraded GNU utils and installed synaptic.
Back to top
Profile PM 
0 replies since Jan. 08 2006,18:40 < Next Oldest | Next Newest >

[ Track this topic :: Email this topic :: Print this topic ]

 
reply to topic new topic new poll
Quick Reply: I was rooted?!

Do you wish to enable your signature for this post?
Do you wish to enable emoticons for this post?
Track this topic
View All Emoticons
View iB Code