Re: F12 Rkhunter, Have I a rootkit? SOLVED

2010-01-06 Thread John Horne
On Tue, 2010-01-05 at 18:31 -0500, Gene Heskett wrote: On Tuesday 05 January 2010, John Horne wrote: On Tue, 2010-01-05 at 11:35 -1000, David Burns wrote: On Tue, Jan 5, 2010 at 7:46 AM, Frank Murphy (Frankly3D) frankl...@gmail.com wrote: This is a false positive. rkhunter gave me

Re: F12 Rkhunter, Have I a rootkit? SOLVED

2010-01-06 Thread Gene Heskett
On Tuesday 05 January 2010, Gene Heskett wrote: On Tuesday 05 January 2010, Kevin Fenzi wrote: On Tue, 05 Jan 2010 19:57:20 -0500 Gene Heskett gene.hesk...@verizon.net wrote: When I asked about it Kevin, F10 was under active support for another 2 or 3 months, now it is not, so why waste our

Re: F12 Rkhunter, Have I a rootkit? SOLVED

2010-01-05 Thread Frank Murphy (Frankly3D)
On 05/01/10 17:11, Kevin Fenzi wrote: On Tue, 05 Jan 2010 10:54:13 + Frank Murphy (Frankly3D) frankl...@gmail.com wrote: -- Start Rootkit Hunter Scan -- Warning: Network TCP port 47107 is being used by /usr/lib64/thunderbird-3.0/thunderbird-bin.

Re: F12 Rkhunter, Have I a rootkit? SOLVED

2010-01-05 Thread David Burns
On Tue, Jan 5, 2010 at 7:46 AM, Frank Murphy (Frankly3D) frankl...@gmail.com wrote: This is a false positive. rkhunter gave me so many false positives I stopped using it. This is probably as much (or more) a comment on my character as it is on the value of rkhunter. Dave -- fedora-list

Re: F12 Rkhunter, Have I a rootkit? SOLVED

2010-01-05 Thread John Horne
On Tue, 2010-01-05 at 11:35 -1000, David Burns wrote: On Tue, Jan 5, 2010 at 7:46 AM, Frank Murphy (Frankly3D) frankl...@gmail.com wrote: This is a false positive. rkhunter gave me so many false positives I stopped using it. This is probably as much (or more) a comment on my character as

Re: F12 Rkhunter, Have I a rootkit? SOLVED

2010-01-05 Thread Gene Heskett
On Tuesday 05 January 2010, John Horne wrote: On Tue, 2010-01-05 at 11:35 -1000, David Burns wrote: On Tue, Jan 5, 2010 at 7:46 AM, Frank Murphy (Frankly3D) frankl...@gmail.com wrote: This is a false positive. rkhunter gave me so many false positives I stopped using it. This is probably as

Re: F12 Rkhunter, Have I a rootkit? SOLVED

2010-01-05 Thread Kevin Fenzi
On Tue, 05 Jan 2010 18:31:30 -0500 Gene Heskett gene.hesk...@verizon.net wrote: _Most_ of the time. Despite some people including me, asking about /usr/sbin/unhide, one of fedora's forensic tools if I read the manpage correctly, no one has managed to come up with a way to add that file to

Re: F12 Rkhunter, Have I a rootkit? SOLVED

2010-01-05 Thread Gene Heskett
On Tuesday 05 January 2010, Kevin Fenzi wrote: On Tue, 05 Jan 2010 18:31:30 -0500 Gene Heskett gene.hesk...@verizon.net wrote: _Most_ of the time. Despite some people including me, asking about /usr/sbin/unhide, one of fedora's forensic tools if I read the manpage correctly, no one has managed

Re: F12 Rkhunter, Have I a rootkit? SOLVED

2010-01-05 Thread Kevin Fenzi
On Tue, 05 Jan 2010 19:57:20 -0500 Gene Heskett gene.hesk...@verizon.net wrote: When I asked about it Kevin, F10 was under active support for another 2 or 3 months, now it is not, so why waste our time? I built rkhunter from the latest tarball, and that still didn't fix it. Well, I am just

Re: F12 Rkhunter, Have I a rootkit? SOLVED

2010-01-05 Thread Gene Heskett
On Tuesday 05 January 2010, Kevin Fenzi wrote: On Tue, 05 Jan 2010 19:57:20 -0500 Gene Heskett gene.hesk...@verizon.net wrote: When I asked about it Kevin, F10 was under active support for another 2 or 3 months, now it is not, so why waste our time? I built rkhunter from the latest tarball,