Re: Root Kits?

2003-02-20 Thread Matthew Emmerton
> We've done a freash installation of FreeBSD 5.0 on our
> system, downloaded a root kit checker from
> www.chkrootkit.com & found that a few things were
> infected.  The files include chfn, chsh, date, ls, and
> ps.  We made sure the system was compleatly isolated by
> installing from the cd's & burning the root kit checker
> to cd & installing it from there.
>
> If you could let me know if this is an error on the root
> kit checker or something else is causing it to look
> infected, that'd be great.

It doesn't support FreeBSD 5.0 yet.

>From http://www.chkrootkit.com/:

chkrootkit has been tested on: Linux 2.0.x, 2.2.x and 2.4.x, FreeBSD 2.2.x,
3.x and 4.x, OpenBSD 2.6, 2.7, 2.8, 2.9, 3.0, 3.1 and 3.2, NetBSD 1.5.2 and
Solaris 2.5.1, 2.6 and 8.0.

--
Matt Emmerton


To Unsubscribe: send mail to [EMAIL PROTECTED]
with "unsubscribe freebsd-questions" in the body of the message



Re: Root Kits?

2003-02-20 Thread Sam Izzo
Hi,

On Thu, Feb 20, 2003 at 07:05:48PM -0800, Silent Secrets wrote:
> If you could let me know if this is an error on the root
> kit checker or something else is causing it to look
> infected, that'd be great.

According to posts on this list in previous weeks it's a false positive.

cheers
sam


To Unsubscribe: send mail to [EMAIL PROTECTED]
with "unsubscribe freebsd-questions" in the body of the message