[Bug 1508248] Re: chkrootkit gives false positive Linux/Ebury - Operation Windigo

2018-03-16 Thread Andreas Hasenack
** Changed in: chkrootkit (Ubuntu Xenial)
   Status: New => Confirmed

** Changed in: chkrootkit (Ubuntu Xenial)
   Importance: Undecided => Low

-- 
You received this bug notification because you are a member of Ubuntu
Server, which is subscribed to chkrootkit in Ubuntu.
https://bugs.launchpad.net/bugs/1508248

Title:
  chkrootkit gives false positive Linux/Ebury - Operation Windigo

To manage notifications about this bug go to:
https://bugs.launchpad.net/chkrootkit/+bug/1508248/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Bug 1508248] Re: chkrootkit gives false positive Linux/Ebury - Operation Windigo

2018-03-16 Thread Andreas Hasenack
** Changed in: chkrootkit (Ubuntu Xenial)
   Status: New => Confirmed

** Changed in: chkrootkit (Ubuntu Xenial)
   Importance: Undecided => Low

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1508248

Title:
  chkrootkit gives false positive Linux/Ebury - Operation Windigo

To manage notifications about this bug go to:
https://bugs.launchpad.net/chkrootkit/+bug/1508248/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 1508248] Re: chkrootkit gives false positive Linux/Ebury - Operation Windigo

2018-03-16 Thread Steve Beattie
** Also affects: chkrootkit (Ubuntu Xenial)
   Importance: Undecided
   Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1508248

Title:
  chkrootkit gives false positive Linux/Ebury - Operation Windigo

To manage notifications about this bug go to:
https://bugs.launchpad.net/chkrootkit/+bug/1508248/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 1508248] Re: chkrootkit gives false positive Linux/Ebury - Operation Windigo

2018-03-16 Thread Andreas Hasenack
** Changed in: chkrootkit (Ubuntu)
   Status: Triaged => Fix Released

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1508248

Title:
  chkrootkit gives false positive Linux/Ebury - Operation Windigo

To manage notifications about this bug go to:
https://bugs.launchpad.net/chkrootkit/+bug/1508248/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 1508248] Re: chkrootkit gives false positive Linux/Ebury - Operation Windigo

2018-03-16 Thread Andreas Hasenack
** Changed in: chkrootkit (Ubuntu)
   Status: Triaged => Fix Released

-- 
You received this bug notification because you are a member of Ubuntu
Server, which is subscribed to chkrootkit in Ubuntu.
https://bugs.launchpad.net/bugs/1508248

Title:
  chkrootkit gives false positive Linux/Ebury - Operation Windigo

To manage notifications about this bug go to:
https://bugs.launchpad.net/chkrootkit/+bug/1508248/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Bug 1508248] Re: chkrootkit gives false positive Linux/Ebury - Operation Windigo

2018-03-16 Thread Andreas Hasenack
Artful and Bionic are fine, since this was fixed in debian's 0.50-4:
chkrootkit (0.50-4) unstable; urgency=low

  * [132754e] Fix windigo false positive (Closes:#796599)


The patch debian is using is 
https://salsa.debian.org/pkg-security-team/chkrootkit/blob/debian/master/debian/patches/19_openssh.diff

This should be an easy SRU to xenial if someone wants to pick a low
hanging fruit:

https://wiki.ubuntu.com/StableReleaseUpdates

-- 
You received this bug notification because you are a member of Ubuntu
Server, which is subscribed to chkrootkit in Ubuntu.
https://bugs.launchpad.net/bugs/1508248

Title:
  chkrootkit gives false positive Linux/Ebury - Operation Windigo

To manage notifications about this bug go to:
https://bugs.launchpad.net/chkrootkit/+bug/1508248/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Bug 1508248] Re: chkrootkit gives false positive Linux/Ebury - Operation Windigo

2018-03-16 Thread Andreas Hasenack
Artful and Bionic are fine, since this was fixed in debian's 0.50-4:
chkrootkit (0.50-4) unstable; urgency=low

  * [132754e] Fix windigo false positive (Closes:#796599)


The patch debian is using is 
https://salsa.debian.org/pkg-security-team/chkrootkit/blob/debian/master/debian/patches/19_openssh.diff

This should be an easy SRU to xenial if someone wants to pick a low
hanging fruit:

https://wiki.ubuntu.com/StableReleaseUpdates

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1508248

Title:
  chkrootkit gives false positive Linux/Ebury - Operation Windigo

To manage notifications about this bug go to:
https://bugs.launchpad.net/chkrootkit/+bug/1508248/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 1508248] Re: chkrootkit gives false positive Linux/Ebury - Operation Windigo

2017-10-27 Thread Bug Watch Updater
Launchpad has imported 15 comments from the remote bug at
https://bugzilla.redhat.com/show_bug.cgi?id=1234436.

If you reply to an imported comment from within Launchpad, your comment
will be sent to the remote bug automatically. Read more about
Launchpad's inter-bugtracker facilities at
https://help.launchpad.net/InterBugTracking.


On 2015-06-22T14:17:58+00:00 DaveG wrote:

Description of problem:
chkrootkit always reports:

Possible Linux/Ebury - Operation Windigo installetd


Version-Release number of selected component (if applicable):
chkrootkit-0.50-4.fc22.x86_64
openssh-6.8p1-8.fc22.x86_64

How reproducible:
Always.

Steps to Reproduce:
1.
2.
3.

Actual results:


Expected results:


Additional info:
The test uses $(ssh -G) (print configuration and exit) and looks for signatures 
in the output. ssh -G now requires a host argument.

ssh -G
prints usage and exit 255, triggering report.

ssh -G localhost
prints configuration and exit 0.

I assume that openssh has changed recently.

Reply at:
https://bugs.launchpad.net/ubuntu/+source/chkrootkit/+bug/1508248/comments/0


On 2015-08-02T12:15:01+00:00 DaveG wrote:

After a little investigation

The Linux/Ebury root-kit infects ssh and can be identified by the way it
handles illegal or unknown command-line options, not printing an
information line before usage: ...

Accepted wisdom is to invoke ssh with an illegal option and check that
the expected extra line is there (clean) or missing (infected).

chkrootkit uses $(ssh -G) as it's illegal invocation but OpenSSH added
the '-G' option to print configuration back in 2014.

Long story short - chkrootkit needs to pick a different illegal option.

Currently unused options include djruzBHJUZ.

Changing the script (2 places) appears to work (I used -H, $(rpm -Vv
openssh-clients) to check).

...
Searching for Linux/Ebury - Operation Windigo ssh... nothing found
...

Reply at:
https://bugs.launchpad.net/ubuntu/+source/chkrootkit/+bug/1508248/comments/1


On 2016-06-20T14:57:59+00:00 Fedora wrote:

chkrootkit-0.50-7.fc23 has been submitted as an update to Fedora 23.
https://bodhi.fedoraproject.org/updates/FEDORA-2016-a5f68c1854

Reply at:
https://bugs.launchpad.net/ubuntu/+source/chkrootkit/+bug/1508248/comments/10


On 2016-06-20T14:58:06+00:00 Fedora wrote:

chkrootkit-0.50-7.fc24 has been submitted as an update to Fedora 24.
https://bodhi.fedoraproject.org/updates/FEDORA-2016-afc728e85d

Reply at:
https://bugs.launchpad.net/ubuntu/+source/chkrootkit/+bug/1508248/comments/11


On 2016-06-20T14:58:11+00:00 Fedora wrote:

chkrootkit-0.50-7.fc22 has been submitted as an update to Fedora 22.
https://bodhi.fedoraproject.org/updates/FEDORA-2016-37fa8f9d3a

Reply at:
https://bugs.launchpad.net/ubuntu/+source/chkrootkit/+bug/1508248/comments/12


On 2016-06-20T14:59:11+00:00 Gwyn wrote:

*** Bug 1279170 has been marked as a duplicate of this bug. ***

Reply at:
https://bugs.launchpad.net/ubuntu/+source/chkrootkit/+bug/1508248/comments/13


On 2016-06-20T20:09:45+00:00 Fedora wrote:

chkrootkit-0.50-8.fc24 has been submitted as an update to Fedora 24.
https://bodhi.fedoraproject.org/updates/FEDORA-2016-b93b991ea4

Reply at:
https://bugs.launchpad.net/ubuntu/+source/chkrootkit/+bug/1508248/comments/14


On 2016-06-20T20:09:53+00:00 Fedora wrote:

chkrootkit-0.50-8.fc23 has been submitted as an update to Fedora 23.
https://bodhi.fedoraproject.org/updates/FEDORA-2016-6c1a60982e

Reply at:
https://bugs.launchpad.net/ubuntu/+source/chkrootkit/+bug/1508248/comments/15


On 2016-06-20T20:10:00+00:00 Fedora wrote:

chkrootkit-0.50-8.fc22 has been submitted as an update to Fedora 22.
https://bodhi.fedoraproject.org/updates/FEDORA-2016-533e10ae24

Reply at:
https://bugs.launchpad.net/ubuntu/+source/chkrootkit/+bug/1508248/comments/16


On 2016-06-22T02:26:53+00:00 Fedora wrote:

chkrootkit-0.50-8.fc22 has been pushed to the Fedora 22 testing repository. If 
problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: 
https://bodhi.fedoraproject.org/updates/FEDORA-2016-533e10ae24

Reply at:
https://bugs.launchpad.net/ubuntu/+source/chkrootkit/+bug/1508248/comments/17


[Bug 1508248] Re: chkrootkit gives false positive Linux/Ebury - Operation Windigo

2017-09-28 Thread Konstantin Boyandin
Still affects Ubuntu 16.04. 'ssh -G' is a valid command; 'ssh -Z' (or
any remaining unused option) should be used.

See 
https://askubuntu.com/questions/709545/chkrootkit-says-searching-for-linux-ebury-operation-windigo-ssh-possible-l

for a script to check for 'Operation Windigo' presence.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1508248

Title:
  chkrootkit gives false positive Linux/Ebury - Operation Windigo

To manage notifications about this bug go to:
https://bugs.launchpad.net/chkrootkit/+bug/1508248/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 1508248] Re: chkrootkit gives false positive Linux/Ebury - Operation Windigo

2017-02-05 Thread NJ
This remains unfixed in Linux Mint 18.1.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1508248

Title:
  chkrootkit gives false positive Linux/Ebury - Operation Windigo

To manage notifications about this bug go to:
https://bugs.launchpad.net/chkrootkit/+bug/1508248/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1508248] Re: chkrootkit gives false positive Linux/Ebury - Operation Windigo

2016-12-27 Thread Bug Watch Updater
** Changed in: chkrootkit (Debian)
   Status: Confirmed => Fix Released

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1508248

Title:
  chkrootkit gives false positive Linux/Ebury - Operation Windigo

To manage notifications about this bug go to:
https://bugs.launchpad.net/chkrootkit/+bug/1508248/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1508248] Re: chkrootkit gives false positive Linux/Ebury - Operation Windigo

2016-09-09 Thread Chris Silva
Wish to confirm that this is still an issue.
xenial 65/bit server

ssh -G 2>&1 | grep -e illegal -e unknown > /dev/null && echo "System clean" || 
echo "System infected"
System infected

OpenSSH_7.2p2 Ubuntu-4ubuntu2.1, OpenSSL 1.0.2g-fips  1 Mar 2016
chkrootkit version 0.50

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1508248

Title:
  chkrootkit gives false positive Linux/Ebury - Operation Windigo

To manage notifications about this bug go to:
https://bugs.launchpad.net/chkrootkit/+bug/1508248/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1508248] Re: chkrootkit gives false positive Linux/Ebury - Operation Windigo

2016-07-14 Thread axel
Still valid on xenial 64-bit

Searching for Linux/Ebury - Operation Windigo ssh...Possible 
Linux/Ebury - Operation Windigo installetd
ssh -G 2>&1 | grep -e illegal -e unknown > /dev/null && echo "System clean" || 
echo "System infected"
System infected

There are topics on forum about it:
http://ubuntuforums.org/showthread.php?t=2291968
http://ubuntuforums.org/showthread.php?t=2304660

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1508248

Title:
  chkrootkit gives false positive Linux/Ebury - Operation Windigo

To manage notifications about this bug go to:
https://bugs.launchpad.net/chkrootkit/+bug/1508248/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1508248] Re: chkrootkit gives false positive Linux/Ebury - Operation Windigo

2016-06-25 Thread Bug Watch Updater
** Changed in: chkrootkit (Debian)
   Status: Unknown => Confirmed

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1508248

Title:
  chkrootkit gives false positive Linux/Ebury - Operation Windigo

To manage notifications about this bug go to:
https://bugs.launchpad.net/chkrootkit/+bug/1508248/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1508248] Re: chkrootkit gives false positive Linux/Ebury - Operation Windigo

2016-06-25 Thread Nathan Stratton Treadway
** Summary changed:

- chkrootkit gives false positive ebury
+ chkrootkit gives false positive Linux/Ebury - Operation Windigo

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1508248

Title:
  chkrootkit gives false positive Linux/Ebury - Operation Windigo

To manage notifications about this bug go to:
https://bugs.launchpad.net/chkrootkit/+bug/1508248/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs