Gentoo Archives: gentoo-user

From: Peter Humphrey <peter@××××××××××××.uk>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] rkhunter reports xorddos component
Date: Wed, 27 Feb 2019 13:47:44
Message-Id: 6873069.jN6C86DfUX@peak
In Reply to: [gentoo-user] rkhunter reports xorddos component by Mick
1 On Wednesday, 27 February 2019 12:27:59 GMT Mick wrote:
2 > I noticed this beauty popping up a day ago:
3 >
4 > Rootkit checks...
5 > Rootkits checked : 498
6 > Possible rootkits: 1
7 > Rootkit names : xorddos component
8 >
9 > Fair enough the log reported a suspect file:
10 >
11 > ====================================
12 > Checking for file '/var/run/sftp.pid' [ Not found ]
13 > Checking for file '/var/run/udev.pid' [ Warning ] <==This one
14 > Checking for file '/var/run/mount.pid' [ Not found ]
15 > [snip ...]
16 >
17 > Warning: Checking for possible rootkit files and directories [ Warning ]
18 > Found file '/var/run/udev.pid'. Possible rootkit: xorddos component
19 >
20 >
21 ===================================================================
22 >
23 > I think it is a false positive, because none of the files mentioned in the
24 > interwebs[1] are seen lurking in my system, but I thought it wiser to check
25 > further.
26 >
27 > [1]
28 > http://hackermedicine.com/linux-ddos-trojan-hiding-itself-with-an-embedded-> rootkit/
29 >
30 >
31 > The rkhunter report of this xorddos component seems to have arrived with:
32 >
33 > sys-fs/udev-init-scripts-33
34 >
35 > or
36 >
37 > sys-apps/dbus-1.12.12-r1
38 >
39 >
40 > Could it be these versions are now launching /run/udev.pid? Is a file /run/
41 > udev.pid present in your system?
42
43 Yes, I have such a text file, containing just a PID.
44
45 > In any case, the file merely contains the PID number of
46 > /lib/systemd/systemd- udevd, rather than an ELF binary and /etc/init.d/
47 > does not contain anything suspicious. However, with armies generating
48 > variants of every conceivable malware I don't know if it pays to be a bit
49 > paranoid about this.
50
51 They really are out to get us...
52
53 --
54 Regards,
55 Peter.

Replies

Subject Author
Re: [gentoo-user] rkhunter reports xorddos component Rich Freeman <rich0@g.o>
Re: [gentoo-user] rkhunter reports xorddos component Mick <michaelkintzios@×××××.com>