1 |
On 03/28/2011 07:24 AM, Paul Hartman wrote: |
2 |
> On Sun, Mar 27, 2011 at 4:09 PM, walt<w41ter@×××××.com> wrote: |
3 |
>> I just got an email from cron on my ~amd64 machine, containing these lines: |
4 |
>> |
5 |
>> Checking 'find'... INFECTED |
6 |
>> Checking 'netstat'... INFECTED |
7 |
>> |
8 |
>> Took me a few minutes to deduce that sys-forensics/chkrootkit was the source |
9 |
>> of those messages. I ran chkrootkit manually and found the same messages in |
10 |
>> the output. |
11 |
|
12 |
> |
13 |
> chkrootkit is old, has not been updated in years+, and those are false |
14 |
> alarms. I got the exact same ones. Basically, chkrootkit is just |
15 |
> grepping for a string inside those files: |
16 |
> |
17 |
> /usr/bin/find: sharefile.h |
18 |
> /bin/netstat: sockaddr.h |
19 |
> |
20 |
> You may find that if you strip those 2 binaries of debug data, the |
21 |
> false positives go away. |
22 |
|
23 |
Exactly so. Thanks to you and Mick for the replies. |