1 |
I just got an email from cron on my ~amd64 machine, containing these lines: |
2 |
|
3 |
Checking 'find'... INFECTED |
4 |
Checking 'netstat'... INFECTED |
5 |
|
6 |
Took me a few minutes to deduce that sys-forensics/chkrootkit was the source |
7 |
of those messages. I ran chkrootkit manually and found the same messages in |
8 |
the output. |
9 |
|
10 |
I then nervously re-emerged findutils and net-tools, but chkrootkit again found |
11 |
the same binaries to be "INFECTED". |
12 |
|
13 |
Running chkrootkit on my ~x86 machine turns up no such infections even though |
14 |
the same packages are installed on both machines. |
15 |
|
16 |
Anyone have any insight into how chkrootkit works, or why the different results? |
17 |
|
18 |
Or, can anyone reproduce my problem? |
19 |
|
20 |
Thanks. |