There cannot be a "False Positives" for "Possible" and "Warning" alerts. Such
findings are routine events for RKHunter to report. They are simply alerts that
the user should investigate further to determine if the reported behavior is
malicious and if not to whitelist the finding.
-Al-
On Mon, Jan 29, 2018 at 07:35 AM, John Lorenz wrote:
> False Positive
>
> John Lorenz
> Technical Support Engineer
>
>
> Teo Technologies, Inc
> UC 425.349.1034
> WEB www.teotech.com <http://www.teotech.com/>
>
> -----Original Message-----
> From: root [mailto:r...@tc16.teocloud.com <mailto:r...@tc16.teocloud.com>]
> Sent: Sunday, January 28, 2018 4:04 AM
> To: RKresults
> Subject: [rkhunter] Warnings found for tc16.teocloud.com
> <http://tc16.teocloud.com/>
>
> Warning: Network TCP port 47107 is being used by
> /usr/java/jdk1.6.0_23/bin/java. Possible rootkit: T0rn Use the 'lsof -i' or
> 'netstat -an' command to check this.
> <rkhunter.log>
------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
Rkhunter-users mailing list
Rkhunter-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/rkhunter-users