Gentoo Archives: gentoo-user

From: Mark <znxster@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Hacked by association?
Date: Thu, 20 Sep 2007 07:47:58
Message-Id: 169ffc030709200034q7828ce8bla3509cb2acbb0c98@mail.gmail.com
In Reply to: Re: [gentoo-user] Hacked by association? by Grant
1 On 20/09/2007, Grant <emailgrant@×××××.com> wrote:
2 > > equery check sys-process/procps
3 > > equery check sys-apps/coreutils
4 >
5 > These check out.
6
7 Chances are you are fine then.
8
9 > chkrootkit reports no problems whatsoever which is actually kind of
10 > weird as I remember some things being reported last time I ran it, but
11 > I looked into them then and they weren't a problem.
12
13 The last time? Be careful, chkrootkit/rkhunter should always be used
14 on the fly, leaving them on a system could allow them to be
15 compromised and therefore negate the checks they run.
16
17 > rkhunter reports no problems but it says it couldn't determine the OS
18 > so MD5 checks were skipped.
19
20 Which doesn't matter as you checked out with the equery.
21
22 One other thing to check is to look for additional user (or root /
23 toor) accounts. A cracker may well have added one to allow them access
24 after the fact.
25
26 Still I would be of the opinion that you are safe.
27
28 Thanks
29 Mark
30 --
31 gentoo-user@g.o mailing list