Results 1 to 10 of 10

Thread: Oh snap chkrootkit

  1. #1
    Join Date
    May 2011
    Beans
    3

    Oh snap chkrootkit

    Hallo Forum,

    i wanted to doenload ia32libs from packaes.ubuntu.com but i was in hurry and typed packages.ubunut.com. I download and installed the package and did a chkrootkit scan.
    The page looks exactly like the original!!!!


    It sayes that i have a LKM trojan installed.

    Be carefull !!!!!!!!!!!!!!!!!!!

    with kind regards
    ubunut
    Last edited by ubunnut; May 16th, 2011 at 01:12 AM.

  2. #2
    Join Date
    Feb 2010
    Location
    In My Food Forest
    Beans
    9,318

    Re: ubunnut.com !!!!!!!! - be carefull

    There's no such site.
    Cheers & Beers, uRock
    [SIGPIC][/SIGPIC]

  3. #3
    Join Date
    Aug 2006
    Beans
    1,222

    Re: ubunnut.com !!!!!!!! - be carefull

    chrootkit occasionally comes up with false positives. It's meant for servers that are rarely updated, not regularly updated desktops.
    There's no place like ~/

  4. #4
    Join Date
    Apr 2011
    Beans
    484

    Re: ubunnut.com !!!!!!!! - be carefull

    Quote Originally Posted by Joe of loath View Post
    chrootkit occasionally comes up with false positives.
    More like always, CHrootkit is infamous for it's level of "If it moves it's hostile.".

    Quote Originally Posted by uRock View Post
    There's no such site.
    +1 I got a search results page.
    Life is an extraordinarily long concatenation of luck and coincidence.

  5. #5
    Join Date
    May 2011
    Beans
    3

    Re: ubunnut.com !!!!!!!! - be carefull

    The page name is packages.ubunut.com but it seems to be in the same subnet like packages.ubuntu.com.

    I started with the live DVD 10.10 Desktop 64 bit.

    I just downloades ia32lib packages and avira antivir and i got a lkm torjan detection. Then I did a reboot and booted into the live dvd again, installed chkrootkit and no trojan was found.

    strange thing.

  6. #6
    Join Date
    Apr 2010
    Location
    Wales, UK
    Beans
    87
    Distro
    Ubuntu 11.04 Natty Narwhal

    Re: ubunnut.com !!!!!!!! - be carefull

    Am able to reach this site here http://packages.ubunut.com/

  7. #7
    Join Date
    Nov 2006
    Location
    Oregon
    Beans
    4,434
    Distro
    Ubuntu Development Release

    Re: ubunnut.com !!!!!!!! - be carefull

    Quote Originally Posted by ubunnut View Post
    The page name is packages.ubunut.com but it seems to be in the same subnet like packages.ubuntu.com.

    I started with the live DVD 10.10 Desktop 64 bit.

    I just downloades ia32lib packages and avira antivir and i got a lkm torjan detection. Then I did a reboot and booted into the live dvd again, installed chkrootkit and no trojan was found.

    strange thing.
    So registration says it's owned by the same guy that owns Ubuntu.com. Out of curiosity, I downloaded the package that you say is malicious and checked the md5sum on it. The package is identical to the one at packages.ubuntu.com.

    I recommend changing the title of this thread, as it seems to be completely false/FUD.
    *Don't PM me directly for support, open a new thread
    *Looking for a MythTV quick start guide?

  8. #8
    Join Date
    Sep 2010
    Beans
    898

    Re: ubunnut.com !!!!!!!! - be carefull

    packages.ubunut.com seems to have the same IP address (91.189.94.219) as packages.ubuntu.com

  9. #9
    Join Date
    May 2011
    Beans
    3

    Re: ubunnut.com !!!!!!!! - be carefull

    Okay, thanks for help. Seems that i got a false positive from chkrootkit.
    I ran the live DVD ubuntu 10.10. 64 bit. I installed only the ia32lib package, avira antivir and chkrootkit. Then i got the false chkrootkit result.
    After a reboot, booting into the dvd, no trojan was there anymore.

    with kind regards
    ubunut
    Last edited by ubunnut; May 16th, 2011 at 01:21 AM.

  10. #10
    Join Date
    Feb 2010
    Location
    In My Food Forest
    Beans
    9,318

    Re: Oh snap chkrootkit

    Changed the title & marked as solved.

    This is one of the reason I gave up on using chkrootkit. It shows too many false positives.

    I am glad it is the same IP as the Ubuntu Package site and that there was no harm to your system.

    Cheers & Beers,
    uRock
    Cheers & Beers, uRock
    [SIGPIC][/SIGPIC]

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •