AmbientOcclusion
October 9th, 2008, 01:19 AM
I ran rkhunter today using this switch:
sudo rkhunter --check --pkgmgr dpkg
It did not detect any rootkits but did display these results that have me worried, I am not sure how to interpret them (I have only including the Warnings):
[22:05:45] /usr/bin/sudo [ Warning ]
[22:05:45] Warning: The file properties have changed:
[22:05:45] File: /usr/bin/sudo
[22:05:45] Current inode: 3424317 Stored inode: 2932
[22:05:45] Current file modification time: 1221075776
[22:05:45] Stored file modification time : 1210812278
[22:05:45] /usr/bin/sudo [ Warning ]
[22:05:45] Warning: The file properties have changed:
[22:05:45] File: /usr/bin/sudo
[22:05:45] Current inode: 3424317 Stored inode: 2932
[22:05:45] Current file modification time: 1221075776
[22:05:45] Stored file modification time : 1210812278
[22:05:55] /usr/sbin/unhide [ Warning ]
[22:05:55] Warning: The file '/usr/sbin/unhide' exists on the system, but it is not present in the rkhunter.dat f
ile.
[22:05:56] /usr/sbin/unhide-linux26 [ Warning ]
[22:05:56] Warning: The file '/usr/sbin/unhide-linux26' exists on the system, but it is not present in the rkhunt
er.dat file.
[22:08:19] Checking for hidden files and directories [ Warning ]
[22:08:19] Warning: Hidden directory found: /etc/.java
[22:08:19] Warning: Hidden directory found: /dev/.static
[22:08:19] Warning: Hidden directory found: /dev/.udev
[22:08:19] Warning: Hidden directory found: /dev/.initramfs
I'm somewhat of a Ubuntu security N00b, my girlfriends Vista laptop was compromised recently and she plugs it into our home lan, so this made me decide to run a scan.
Should I be worried about these warnings?
sudo rkhunter --check --pkgmgr dpkg
It did not detect any rootkits but did display these results that have me worried, I am not sure how to interpret them (I have only including the Warnings):
[22:05:45] /usr/bin/sudo [ Warning ]
[22:05:45] Warning: The file properties have changed:
[22:05:45] File: /usr/bin/sudo
[22:05:45] Current inode: 3424317 Stored inode: 2932
[22:05:45] Current file modification time: 1221075776
[22:05:45] Stored file modification time : 1210812278
[22:05:45] /usr/bin/sudo [ Warning ]
[22:05:45] Warning: The file properties have changed:
[22:05:45] File: /usr/bin/sudo
[22:05:45] Current inode: 3424317 Stored inode: 2932
[22:05:45] Current file modification time: 1221075776
[22:05:45] Stored file modification time : 1210812278
[22:05:55] /usr/sbin/unhide [ Warning ]
[22:05:55] Warning: The file '/usr/sbin/unhide' exists on the system, but it is not present in the rkhunter.dat f
ile.
[22:05:56] /usr/sbin/unhide-linux26 [ Warning ]
[22:05:56] Warning: The file '/usr/sbin/unhide-linux26' exists on the system, but it is not present in the rkhunt
er.dat file.
[22:08:19] Checking for hidden files and directories [ Warning ]
[22:08:19] Warning: Hidden directory found: /etc/.java
[22:08:19] Warning: Hidden directory found: /dev/.static
[22:08:19] Warning: Hidden directory found: /dev/.udev
[22:08:19] Warning: Hidden directory found: /dev/.initramfs
I'm somewhat of a Ubuntu security N00b, my girlfriends Vista laptop was compromised recently and she plugs it into our home lan, so this made me decide to run a scan.
Should I be worried about these warnings?