Results 1 to 5 of 5

Thread: Rootkit problem reporting

  1. #1
    Join Date
    Jan 2007
    Beans
    601
    Distro
    Ubuntu

    Rootkit problem reporting

    I just performed a fresh install of Ubuntu 9.10 from a livecd that I received from Ship It. The install went well and I ran chkrootkit and rkhunter before putting the system online. The following happened:

    1. Ran rkhunter, showed no problems

    2. Ran chkrootkit the report included this:

    Searching for Suckit rootkit... Warning: /sbin/init INFECTED

    3. Re-ran rkhunter and it reported this regarding Suckit and /sbin/init:

    /sbin/init [ OK ]
    Suckit Rootkit [ Not found ]


    the rkhunter summary included this:

    System checks summary
    =====================

    File properties checks...
    Files checked: 130
    Suspect files: 0

    Rootkit checks...
    Rootkits checked : 111
    Possible rootkits: 0


    The red text emphasis was added by me for readability. As I said, I installed from trusted media and then installed several apps from the Ubuntu software repositories, so I don't think I have a rootkit. What I think happened is chkrootkit reported a false positive but I don't remember this happening on Jaunty or previous installations of Karmic.

    Has anyone else seen this problem?

  2. #2
    Join Date
    Aug 2008
    Location
    WA
    Beans
    2,186
    Distro
    Ubuntu

    Re: Rootkit problem reporting


  3. #3
    Join Date
    Jan 2007
    Beans
    601
    Distro
    Ubuntu

    Re: Rootkit problem reporting

    Quote Originally Posted by iponeverything View Post
    Yeah, I figured it was a false positive. Thank you very much for the bug report link.

  4. #4
    Join Date
    Mar 2006
    Location
    Williams Lake
    Beans
    Hidden!
    Distro
    Ubuntu Development Release

    Re: Rootkit problem reporting

    You can also use ubuntu-bug to report bugs, Press Alt-F2 and type:

    Code:
    ubuntu-bug <packagename>
    In your case substitute rkhunter for <packagename>.

    Note: This only works for Karmic and newer.

  5. #5
    Join Date
    Jan 2007
    Beans
    601
    Distro
    Ubuntu

    Re: Rootkit problem reporting

    Quote Originally Posted by cariboo907 View Post
    You can also use ubuntu-bug to report bugs, Press Alt-F2 and type:

    Code:
    ubuntu-bug <packagename>
    In your case substitute rkhunter for <packagename>.

    Note: This only works for Karmic and newer.
    Hey, I didn't know that.. very helpful. Thank you

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •