Gentoo Archives: gentoo-user

From: walt <w41ter@×××××.com>
To: gentoo-user@l.g.o
Subject: [gentoo-user] Re: sys-forensics/chkrootkit finds INFECTED binaries on ~amd64
Date: Mon, 28 Mar 2011 23:50:40
Message-Id: imr6oh$r46$1@dough.gmane.org
In Reply to: Re: [gentoo-user] sys-forensics/chkrootkit finds INFECTED binaries on ~amd64 by Paul Hartman
1 On 03/28/2011 07:24 AM, Paul Hartman wrote:
2 > On Sun, Mar 27, 2011 at 4:09 PM, walt<w41ter@×××××.com> wrote:
3 >> I just got an email from cron on my ~amd64 machine, containing these lines:
4 >>
5 >> Checking 'find'... INFECTED
6 >> Checking 'netstat'... INFECTED
7 >>
8 >> Took me a few minutes to deduce that sys-forensics/chkrootkit was the source
9 >> of those messages. I ran chkrootkit manually and found the same messages in
10 >> the output.
11
12 >
13 > chkrootkit is old, has not been updated in years+, and those are false
14 > alarms. I got the exact same ones. Basically, chkrootkit is just
15 > grepping for a string inside those files:
16 >
17 > /usr/bin/find: sharefile.h
18 > /bin/netstat: sockaddr.h
19 >
20 > You may find that if you strip those 2 binaries of debug data, the
21 > false positives go away.
22
23 Exactly so. Thanks to you and Mick for the replies.