Gentoo Archives: gentoo-user

From: Nilesh Govindarajan <contact@××××××××.com>
To: Gentoo User Mailing List <gentoo-user@l.g.o>
Subject: [gentoo-user] Rootkit?
Date: Thu, 06 Oct 2011 15:02:28
Message-Id: 4E8DC2B6.1000105@nileshgr.com
1 One of the servers I manage has a strange problem.
2
3 Every 24h, someone starts a process shows up as perl in the list, but
4 launching command is /usr/sbin/httpd.
5 It shows just one process, but when I run something like this:
6
7 ps -C perl -o cmd,pid
8
9 I get some 5-6 processes alternatively with cmd as /usr/sbin/httpd or
10 /usr/bin/perl.
11
12 The even more interesting thing is, /usr/sbin/httpd does not exist.
13 I suspect a rootkit, but chkrootkit & rkhunter reported nothing.
14
15 Also, I found a mysterious file: /tmp/ips.txt with following content:
16 xxx.xxx.xxx.xxx
17 127.0.0.1
18 addr:xxx.xxx.xxx.xxx
19 addr:
20 addr:127.0.0.1
21 addr:
22
23 Somebody is aware of a malware/rootkit which creates such files?
24
25 --
26 Nilesh Govindarajan
27 http://nileshgr.com

Replies

Subject Author
Re: [gentoo-user] Rootkit? Michael Mol <mikemol@×××××.com>
Re: [gentoo-user] Rootkit? Paul Hartman <paul.hartman+gentoo@×××××.com>
[gentoo-user] Re: Rootkit? Alberto Luaces <aluaces@×××.es>