Gentoo Archives: gentoo-user

From: walt <w41ter@×××××.com>
To: gentoo-user@l.g.o
Subject: [gentoo-user] sys-forensics/chkrootkit finds INFECTED binaries on ~amd64
Date: Sun, 27 Mar 2011 21:11:28
Message-Id: imo91k$97d$1@dough.gmane.org
1 I just got an email from cron on my ~amd64 machine, containing these lines:
2
3 Checking 'find'... INFECTED
4 Checking 'netstat'... INFECTED
5
6 Took me a few minutes to deduce that sys-forensics/chkrootkit was the source
7 of those messages. I ran chkrootkit manually and found the same messages in
8 the output.
9
10 I then nervously re-emerged findutils and net-tools, but chkrootkit again found
11 the same binaries to be "INFECTED".
12
13 Running chkrootkit on my ~x86 machine turns up no such infections even though
14 the same packages are installed on both machines.
15
16 Anyone have any insight into how chkrootkit works, or why the different results?
17
18 Or, can anyone reproduce my problem?
19
20 Thanks.

Replies

Subject Author
Re: [gentoo-user] sys-forensics/chkrootkit finds INFECTED binaries on ~amd64 Mick <michaelkintzios@×××××.com>
Re: [gentoo-user] sys-forensics/chkrootkit finds INFECTED binaries on ~amd64 Paul Hartman <paul.hartman+gentoo@×××××.com>