Launchpad has imported 15 comments from the remote bug at
https://bugzilla.redhat.com/show_bug.cgi?id=1234436.

If you reply to an imported comment from within Launchpad, your comment
will be sent to the remote bug automatically. Read more about
Launchpad's inter-bugtracker facilities at
https://help.launchpad.net/InterBugTracking.

------------------------------------------------------------------------
On 2015-06-22T14:17:58+00:00 DaveG wrote:

Description of problem:
chkrootkit always reports:

Possible Linux/Ebury - Operation Windigo installetd


Version-Release number of selected component (if applicable):
chkrootkit-0.50-4.fc22.x86_64
openssh-6.8p1-8.fc22.x86_64

How reproducible:
Always.

Steps to Reproduce:
1.
2.
3.

Actual results:


Expected results:


Additional info:
The test uses $(ssh -G) (print configuration and exit) and looks for signatures 
in the output. ssh -G now requires a host argument.

ssh -G
prints usage and exit 255, triggering report.

ssh -G localhost
prints configuration and exit 0.

I assume that openssh has changed recently.

Reply at:
https://bugs.launchpad.net/ubuntu/+source/chkrootkit/+bug/1508248/comments/0

------------------------------------------------------------------------
On 2015-08-02T12:15:01+00:00 DaveG wrote:

After a little investigation....

The Linux/Ebury root-kit infects ssh and can be identified by the way it
handles illegal or unknown command-line options, not printing an
information line before usage: ...

Accepted wisdom is to invoke ssh with an illegal option and check that
the expected extra line is there (clean) or missing (infected).

chkrootkit uses $(ssh -G) as it's illegal invocation but OpenSSH added
the '-G' option to print configuration back in 2014.

Long story short - chkrootkit needs to pick a different illegal option.

Currently unused options include djruzBHJUZ.

Changing the script (2 places) appears to work (I used -H, $(rpm -Vv
openssh-clients) to check).

...
Searching for Linux/Ebury - Operation Windigo ssh... nothing found
...

Reply at:
https://bugs.launchpad.net/ubuntu/+source/chkrootkit/+bug/1508248/comments/1

------------------------------------------------------------------------
On 2016-06-20T14:57:59+00:00 Fedora wrote:

chkrootkit-0.50-7.fc23 has been submitted as an update to Fedora 23.
https://bodhi.fedoraproject.org/updates/FEDORA-2016-a5f68c1854

Reply at:
https://bugs.launchpad.net/ubuntu/+source/chkrootkit/+bug/1508248/comments/10

------------------------------------------------------------------------
On 2016-06-20T14:58:06+00:00 Fedora wrote:

chkrootkit-0.50-7.fc24 has been submitted as an update to Fedora 24.
https://bodhi.fedoraproject.org/updates/FEDORA-2016-afc728e85d

Reply at:
https://bugs.launchpad.net/ubuntu/+source/chkrootkit/+bug/1508248/comments/11

------------------------------------------------------------------------
On 2016-06-20T14:58:11+00:00 Fedora wrote:

chkrootkit-0.50-7.fc22 has been submitted as an update to Fedora 22.
https://bodhi.fedoraproject.org/updates/FEDORA-2016-37fa8f9d3a

Reply at:
https://bugs.launchpad.net/ubuntu/+source/chkrootkit/+bug/1508248/comments/12

------------------------------------------------------------------------
On 2016-06-20T14:59:11+00:00 Gwyn wrote:

*** Bug 1279170 has been marked as a duplicate of this bug. ***

Reply at:
https://bugs.launchpad.net/ubuntu/+source/chkrootkit/+bug/1508248/comments/13

------------------------------------------------------------------------
On 2016-06-20T20:09:45+00:00 Fedora wrote:

chkrootkit-0.50-8.fc24 has been submitted as an update to Fedora 24.
https://bodhi.fedoraproject.org/updates/FEDORA-2016-b93b991ea4

Reply at:
https://bugs.launchpad.net/ubuntu/+source/chkrootkit/+bug/1508248/comments/14

------------------------------------------------------------------------
On 2016-06-20T20:09:53+00:00 Fedora wrote:

chkrootkit-0.50-8.fc23 has been submitted as an update to Fedora 23.
https://bodhi.fedoraproject.org/updates/FEDORA-2016-6c1a60982e

Reply at:
https://bugs.launchpad.net/ubuntu/+source/chkrootkit/+bug/1508248/comments/15

------------------------------------------------------------------------
On 2016-06-20T20:10:00+00:00 Fedora wrote:

chkrootkit-0.50-8.fc22 has been submitted as an update to Fedora 22.
https://bodhi.fedoraproject.org/updates/FEDORA-2016-533e10ae24

Reply at:
https://bugs.launchpad.net/ubuntu/+source/chkrootkit/+bug/1508248/comments/16

------------------------------------------------------------------------
On 2016-06-22T02:26:53+00:00 Fedora wrote:

chkrootkit-0.50-8.fc22 has been pushed to the Fedora 22 testing repository. If 
problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: 
https://bodhi.fedoraproject.org/updates/FEDORA-2016-533e10ae24

Reply at:
https://bugs.launchpad.net/ubuntu/+source/chkrootkit/+bug/1508248/comments/17

------------------------------------------------------------------------
On 2016-06-22T02:27:20+00:00 Fedora wrote:

chkrootkit-0.50-8.fc24 has been pushed to the Fedora 24 testing repository. If 
problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: 
https://bodhi.fedoraproject.org/updates/FEDORA-2016-b93b991ea4

Reply at:
https://bugs.launchpad.net/ubuntu/+source/chkrootkit/+bug/1508248/comments/18

------------------------------------------------------------------------
On 2016-06-22T02:55:22+00:00 Fedora wrote:

chkrootkit-0.50-8.fc23 has been pushed to the Fedora 23 testing repository. If 
problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: 
https://bodhi.fedoraproject.org/updates/FEDORA-2016-6c1a60982e

Reply at:
https://bugs.launchpad.net/ubuntu/+source/chkrootkit/+bug/1508248/comments/19

------------------------------------------------------------------------
On 2016-06-30T14:52:33+00:00 Fedora wrote:

chkrootkit-0.50-8.fc22 has been pushed to the Fedora 22 stable
repository. If problems still persist, please make note of it in this
bug report.

Reply at:
https://bugs.launchpad.net/ubuntu/+source/chkrootkit/+bug/1508248/comments/21

------------------------------------------------------------------------
On 2016-06-30T19:53:20+00:00 Fedora wrote:

chkrootkit-0.50-8.fc23 has been pushed to the Fedora 23 stable
repository. If problems still persist, please make note of it in this
bug report.

Reply at:
https://bugs.launchpad.net/ubuntu/+source/chkrootkit/+bug/1508248/comments/22

------------------------------------------------------------------------
On 2016-06-30T21:29:13+00:00 Fedora wrote:

chkrootkit-0.50-8.fc24 has been pushed to the Fedora 24 stable
repository. If problems still persist, please make note of it in this
bug report.

Reply at:
https://bugs.launchpad.net/ubuntu/+source/chkrootkit/+bug/1508248/comments/23


** Changed in: chkrootkit (Fedora)
       Status: Unknown => Fix Released

** Changed in: chkrootkit (Fedora)
   Importance: Unknown => Undecided

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1508248

Title:
  chkrootkit gives false positive Linux/Ebury - Operation Windigo

To manage notifications about this bug go to:
https://bugs.launchpad.net/chkrootkit/+bug/1508248/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to