False positives // compromised?

arosa3000

New Member
Hallo,

heute Nach hat mir rkhunter Untenstehendes gemeldet. Chkrootkit hat nichts gemeldet. Das System ist erst 3 Tage alt, es sind nur SMTP, SSH, HTTP offen und SSH nur per Publickey. Es ist ein Ubuntu 8.04 LTS. "Last" zeigt keine User ausser mir, "Logcheck" hatte nichts gemeldet und "fail2ban" auch nicht. Ich hatte an den Paketen eigentlich nur "Dash" und "NTP" eingespielt / geändert.

Woher können diese Warning kommen???

Code:
[13:07:43] Performing file properties checks
[13:07:43] Info: Starting test name 'properties'
[13:07:43] Checking for prerequisites                        [ OK ]
[13:07:44] /bin/bash                                         [ Warning ]
[13:07:44] Warning: The file properties have changed:
[13:07:44]          File: /bin/bash
[13:07:44]          Current inode: 66104201    Stored inode: 91981237
[13:07:44] /bin/cat                                          [ Warning ]
[13:07:44] Warning: The file properties have changed:
[13:07:44]          File: /bin/cat
[13:07:44]          Current inode: 66104184    Stored inode: 91980823
[13:07:44] /bin/chmod                                        [ Warning ]
[13:07:44] Warning: The file properties have changed:
[13:07:44]          File: /bin/chmod
[13:07:44]          Current inode: 66104110    Stored inode: 91980825
[13:07:44] /bin/chown                                        [ Warning ]
[13:07:44] Warning: The file properties have changed:
[13:07:44]          File: /bin/chown
[13:07:44]          Current inode: 66104108    Stored inode: 91980826
[13:07:44] /bin/cp                                           [ Warning ]
[13:07:44] Warning: The file properties have changed:
[13:07:44]          File: /bin/cp
[13:07:44]          Current inode: 66104185    Stored inode: 91980827
[13:07:44] /bin/csh                                          [ OK ]
[13:07:45] /bin/date                                         [ Warning ]
[13:07:45] Warning: The file properties have changed:
[13:07:45]          File: /bin/date
[13:07:45]          Current inode: 66104113    Stored inode: 91980828
[13:07:45] /bin/df                                           [ Warning ]
[13:07:45] Warning: The file properties have changed:
[13:07:45]          File: /bin/df
[13:07:45]          Current inode: 66104167    Stored inode: 91980830
[13:07:45] /bin/dmesg                                        [ Warning ]
[13:07:45] Warning: The file properties have changed:
[13:07:45]          File: /bin/dmesg
[13:07:45]          Current inode: 66104189    Stored inode: 92014243
[13:07:45] /bin/echo                                         [ Warning ]
[13:07:45] Warning: The file properties have changed:
[13:07:45]          File: /bin/echo
[13:07:45]          Current inode: 66103707    Stored inode: 91980832
[13:07:45] /bin/ed                                           [ Warning ]
[13:07:45] Warning: The file properties have changed:
[13:07:45]          File: /bin/ed
[13:07:45]          Current inode: 66104174    Stored inode: 92080038
[13:07:46] /bin/egrep                                        [ Warning ]
[13:07:46] Warning: The file properties have changed:
[13:07:46]          File: /bin/egrep
[13:07:46]          Current inode: 66104198    Stored inode: 91982292
[13:07:46] Info: Found file '/bin/egrep': it is whitelisted for the 'script replacement' check.
[13:07:46] /bin/fgrep                                        [ Warning ]
[13:07:46] Warning: The file properties have changed:
[13:07:46]          File: /bin/fgrep
[13:07:46]          Current inode: 66104206    Stored inode: 91982293
[13:07:46] Info: Found file '/bin/fgrep': it is whitelisted for the 'script replacement' check.
[13:07:46] /bin/grep                                         [ Warning ]
[13:07:46] Warning: The file properties have changed:
[13:07:46]          File: /bin/grep
[13:07:46]          Current inode: 66104194    Stored inode: 91982291
[13:07:46] /bin/ip                                           [ Warning ]
[13:07:46] Warning: The file properties have changed:
[13:07:46]          File: /bin/ip
[13:07:46]          Current inode: 66103708    Stored inode: 92078775
[13:07:46] /bin/kill                                         [ Warning ]
[13:07:46] Warning: The file properties have changed:
[13:07:46]          File: /bin/kill
[13:07:46]          Current inode: 66103709    Stored inode: 92078495
[13:07:47] /bin/login                                        [ Warning ]
[13:07:47] Warning: The file properties have changed:
[13:07:47]          File: /bin/login
[13:07:47]          Current inode: 66104234    Stored inode: 91981801
[13:07:47] /bin/ls                                           [ Warning ]
[13:07:47] Warning: The file properties have changed:
[13:07:47]          File: /bin/ls
[13:07:47]          Current inode: 66104226    Stored inode: 91980835
[13:07:47] /bin/lsmod                                        [ Warning ]
[13:07:47] Warning: The file properties have changed:
[13:07:47]          File: /bin/lsmod
[13:07:47]          Current inode: 66104230    Stored inode: 92078424
[13:07:47] /bin/mktemp                                       [ Warning ]
[13:07:47] Warning: The file properties have changed:
[13:07:47]          File: /bin/mktemp
[13:07:47]          Current inode: 66104220    Stored inode: 91981144
[13:07:47] /bin/more                                         [ Warning ]
[13:07:47] Warning: The file properties have changed:
[13:07:47]          File: /bin/more
[13:07:47]          Current inode: 66104173    Stored inode: 92014244
[13:07:47] /bin/mount                                        [ Warning ]
[13:07:47] Warning: The file properties have changed:
[13:07:48]          File: /bin/mount
[13:07:48]          Current inode: 66104114    Stored inode: 92012556
[13:07:48] /bin/mv                                           [ Warning ]
[13:07:48] Warning: The file properties have changed:
[13:07:48]          File: /bin/mv
[13:07:48]          Current inode: 66104221    Stored inode: 91980838
[13:07:48] /bin/netstat                                      [ Warning ]
[13:07:48] Warning: The file properties have changed:
[13:07:48]          File: /bin/netstat
[13:07:48]          Current inode: 66104210    Stored inode: 92078313
[13:07:48] /bin/ps                                           [ Warning ]
[13:07:48] Warning: The file properties have changed:
[13:07:48]          File: /bin/ps
[13:07:48]          Current inode: 66104208    Stored inode: 92078496
[13:07:48] /bin/pwd                                          [ Warning ]
[13:07:48] Warning: The file properties have changed:
[13:07:48]          File: /bin/pwd
[13:07:48]          Current inode: 66104188    Stored inode: 91980839
[13:07:48] /bin/readlink                                     [ Warning ]
[13:07:48] Warning: The file properties have changed:
[13:07:48]          File: /bin/readlink
[13:07:48]          Current inode: 66104191    Stored inode: 91980840
[13:07:49] /bin/sed                                          [ Warning ]
[13:07:49] Warning: The file properties have changed:
[13:07:49]          File: /bin/sed
[13:07:49]          Current inode: 66104197    Stored inode: 92012638
[13:07:49] /bin/sh                                           [ Warning ]
[13:07:49] Warning: The file properties have changed:
[13:07:49]          File: /bin/sh
[13:07:49]          Current inode: 66104193    Stored inode: 91981274
[13:07:49]          Current file modification time: 1256431483
[13:07:49]          Stored file modification time : 1210617405
[13:07:49] /bin/su                                           [ Warning ]
[13:07:49] Warning: The file properties have changed:
[13:07:49]          File: /bin/su
[13:07:49]          Current inode: 66104186    Stored inode: 91981802
[13:07:49] /bin/touch                                        [ Warning ]
[13:07:49] Warning: The file properties have changed:
[13:07:49]          File: /bin/touch
[13:07:49]          Current inode: 66104111    Stored inode: 91980847
[13:07:49] /bin/uname                                        [ Warning ]
[13:07:49] Warning: The file properties have changed:
[13:07:49]          File: /bin/uname
[13:07:49]          Current inode: 66104177    Stored inode: 91980849
[13:07:50] /bin/which                                        [ Warning ]
[13:07:50] Warning: The file properties have changed:
[13:07:50]          File: /bin/which
[13:07:50]          Current inode: 66104225    Stored inode: 91981159
[13:07:50] Info: Found file '/bin/which': it is whitelisted for the 'script replacement' check.
[13:07:50] /bin/tcsh                                         [ Warning ]
[13:07:50] Warning: The file properties have changed:
[13:07:50]          File: /bin/tcsh
[13:07:50]          Current inode: 66104214    Stored inode: 92242359
 
Last edited by a moderator:
Woher können diese Warning kommen???
Hast du dir mal überlegt, was die Meldungen überhaupt bedeuten? Die Inodes der Dateien hat sich geändert. Das kann z. B. passiert sein, wenn du `aptitude upgrade` ausgeführst bzw. konkret die coreutils aktualisierst. Installiere die coreutils aus einer vertrauenswürdigen Quelle nochmal und gut ist.

Von Programmen wie rkhunter und chkrootkit ist IMHO nicht allzuviel zu halten...
 
Danke für die Antwort!

Was heisst das genau, "die Inodes der Dateien geändert"?

"apt-get upgrade" habe ich definitiv ausgeführt, ja, aber der hat mir nichts gemeldet dass "coreutils" geändert wurden! Wieso haben sich die Inodes dann trotzdem geändert?
 
Mag, sein, vielleicht habe ich es wirklich übersehen... Leider ist das eben ungewiss ;)

Würden bei Dir unter diesen Umständen nicht die Alarmglocken angehen?
 
Ok, denke ich lass das Systrem bestehen.

Was mich nur wundert: Habe in den apt-Logfiles nachgeschaut, da steht definitiv nichts von "coreutils"...

Auf der anderen Seite: Ein Eindringling würde doch eigentlich nicht alle gelisteten Dateien (mit den Inode warnings) anpacken, sondern nur einige wenige, worüber er sich den Zutriff verschafft. Oder siehst Du das anders?
 
Was mich nur wundert: Habe in den apt-Logfiles nachgeschaut, da steht definitiv nichts von "coreutils"...
Wenn es sich um einen virtuellen Server handelt, kann es auch eine Nebenwirkung der Virtualisierungstechnik sein.

Auf der anderen Seite: Ein Eindringling würde doch eigentlich nicht alle gelisteten Dateien (mit den Inode warnings) anpacken, sondern nur einige wenige, worüber er sich den Zutriff verschafft. Oder siehst Du das anders?
Das hängt von der Intention des Angreifers ab.
 
Hmm, wäre schön wenn die Virtualisierung die Ursache ist! Es ist tatsächlich ein Vserver unter Parallels...

Habe mal beim Provider angefragt, aber denke nicht dass die mir eine verwertbare Antwort geben können.
 
Hmm, wäre schön wenn die Virtualisierung die Ursache ist! Es ist tatsächlich ein Vserver unter Parallels...
Dann ist es doch eigentlich klar.

VZFS unterstützt einen COW-Mechanismus, mit dem Dateien aus einem Template in mehreren VEs geteilt werden können, solange sie nicht in einem VE überschrieben werden. Da hat der Provider eben mal die Pakete im Template aktualisiert.
 
Sorry, es lässt mir keine Ruhe ;)

Meinst Du damit, dass die das Template aktualisiert haben, die darin enthaltenen Dateien allerdings unverändert blieben (rkhunter hat ja nur die Inodes, nicht Filesize, etc. angemeckert), und lediglich durch die Änderung am Template (z.B. hinzufügen anderer Pakete) sämtliche Inodes geändert wurden?

Habe nochmal die zwei letzten Logs von rkhunter verglichen: Im ersten, vom 23.10. noch keine Warnungen, im zweiten, von heute, dann die Warnungen (siehe unten).

Dort sogar Warnung für Inodes von "/usr/bin/rkhunter"! Glaube kaum dass der Hoster dieses Paket in seinem Template hat!? Zumindest musste ich es selbst installieren...

Code:
[02:14:02] Running Rootkit Hunter version 1.3.0 on cpt
...
[02:14:48] System checks summary
[02:14:48] =====================
[02:14:48]
[02:14:48] File properties checks...
[02:14:48] Files checked: 125
[02:14:48] Suspect files: 0
[02:14:48]
[02:14:48] Rootkit checks...
[02:14:48] Rootkits checked : 110
[02:14:48] Possible rootkits: 0
[02:14:48]
[02:14:48] Applications checks...
[02:14:48] Applications checked: 4
[02:14:48] Suspect applications: 0
[02:14:48]
[02:14:48] The system checks took: 45 seconds
[02:14:48]
[02:14:48] Info: End date is Fri Oct 23 02:14:48 CEST 2009

Code:
[21:54:16] Running Rootkit Hunter version 1.3.0 on cpt
...
[21:54:19] Performing file properties checks
[21:54:19] Info: Starting test name 'properties'
[21:54:19] Checking for prerequisites                        [ OK ]
[21:54:19] /bin/bash                                         [ OK ]
[21:54:20] /bin/cat                                          [ OK ]
[21:54:20] /bin/chmod                                        [ OK ]
[21:54:20] /bin/chown                                        [ OK ]
[21:54:20] /bin/cp                                           [ OK ]
[21:54:20] /bin/csh                                          [ Warning ]
[21:54:20] Warning: The file properties have changed:
[21:54:20]          File: /bin/csh
[21:54:20]          Current inode: 73368419    Stored inode: 66098245
[21:54:20] /bin/date                                         [ OK ]
[21:54:20] /bin/df                                           [ OK ]
[21:54:20] /bin/dmesg                                        [ OK ]
[21:54:20] /bin/echo                                         [ OK ]
[21:54:20] /bin/ed                                           [ OK ]
[21:54:21] /bin/egrep                                        [ OK ]
[21:54:21] Info: Found file '/bin/egrep': it is whitelisted for the 'script replacement' check.
[21:54:21] /bin/fgrep                                        [ OK ]
[21:54:21] Info: Found file '/bin/fgrep': it is whitelisted for the 'script replacement' check.
[21:54:21] /bin/grep                                         [ OK ]
[21:54:21] /bin/ip                                           [ OK ]
[21:54:21] /bin/kill                                         [ OK ]
[21:54:21] /bin/login                                        [ OK ]
[21:54:21] /bin/ls                                           [ OK ]
[21:54:21] /bin/lsmod                                        [ OK ]
[21:54:22] /bin/mktemp                                       [ OK ]
[21:54:22] /bin/more                                         [ OK ]
[21:54:22] /bin/mount                                        [ OK ]
[21:54:22] /bin/mv                                           [ OK ]
[21:54:22] /bin/netstat                                      [ OK ]
[21:54:22] /bin/ps                                           [ OK ]
[21:54:22] /bin/pwd                                          [ OK ]
[21:54:22] /bin/readlink                                     [ OK ]
[21:54:22] /bin/sed                                          [ OK ]
[21:54:23] /bin/sh                                           [ OK ]
[21:54:23] /bin/su                                           [ OK ]
[21:54:23] /bin/touch                                        [ OK ]
[21:54:23] /bin/uname                                        [ OK ]
[21:54:23] /bin/which                                        [ OK ]
[21:54:23] Info: Found file '/bin/which': it is whitelisted for the 'script replacement' check.
[21:54:23] /bin/tcsh                                         [ OK ]
[21:54:23] /usr/bin/awk                                      [ Warning ]
[21:54:23] Warning: The file properties have changed:
[21:54:23]          File: /usr/bin/awk
[21:54:23]          Current inode: 73370147    Stored inode: 66098218
[21:54:23] /usr/bin/basename                                 [ Warning ]
[21:54:24] Warning: The file properties have changed:
[21:54:24]          File: /usr/bin/basename
[21:54:24]          Current inode: 73370149    Stored inode: 66102571
[21:54:24] /usr/bin/chattr                                   [ Warning ]
[21:54:24] Warning: The file properties have changed:
[21:54:24]          File: /usr/bin/chattr
[21:54:24]          Current inode: 73370163    Stored inode: 66102709
[21:54:24] /usr/bin/cut                                      [ Warning ]
[21:54:24] Warning: The file properties have changed:
[21:54:24]          File: /usr/bin/cut
[21:54:24]          Current inode: 73370195    Stored inode: 66102309
[21:54:24] /usr/bin/diff                                     [ Warning ]
[21:54:24] Warning: The file properties have changed:
[21:54:24]          File: /usr/bin/diff
[21:54:24]          Current inode: 73370237    Stored inode: 66102538
[21:54:24] /usr/bin/dirname                                  [ Warning ]
[21:54:24] Warning: The file properties have changed:
[21:54:24]          File: /usr/bin/dirname
[21:54:24]          Current inode: 73370241    Stored inode: 66102528
[21:54:24] /usr/bin/dpkg                                     [ Warning ]
[21:54:24] Warning: The file properties have changed:
[21:54:24]          File: /usr/bin/dpkg
[21:54:24]          Current inode: 73370245    Stored inode: 66102381
[21:54:25] /usr/bin/dpkg-query                               [ Warning ]
[21:54:25] Warning: The file properties have changed:
[21:54:25]          File: /usr/bin/dpkg-query
[21:54:25]          Current inode: 73370247    Stored inode: 66102619
[21:54:25] /usr/bin/du                                       [ Warning ]
[21:54:25] Warning: The file properties have changed:
[21:54:25]          File: /usr/bin/du
[21:54:25]          Current inode: 73370252    Stored inode: 66102547
[21:54:25] /usr/bin/env                                      [ Warning ]
[21:54:25] Warning: The file properties have changed:
[21:54:25]          File: /usr/bin/env
[21:54:25]          Current inode: 73370258    Stored inode: 66102235
[21:54:25] /usr/bin/file                                     [ Warning ]
[21:54:25] Warning: The file properties have changed:
[21:54:25]          File: /usr/bin/file
[21:54:25]          Current inode: 73370280    Stored inode: 66102252
[21:54:25] /usr/bin/find                                     [ Warning ]
[21:54:25] Warning: The file properties have changed:
[21:54:25]          File: /usr/bin/find
[21:54:25]          Current inode: 73370281    Stored inode: 66102383
[21:54:25] /usr/bin/groups                                   [ Warning ]
[21:54:25] Warning: The file properties have changed:
[21:54:25]          File: /usr/bin/groups
[21:54:25]          Current inode: 73370329    Stored inode: 66102294
[21:54:25] Info: Found file '/usr/bin/groups': it is whitelisted for the 'script replacement' check.
[21:54:26] /usr/bin/head                                     [ Warning ]
[21:54:26] Warning: The file properties have changed:
[21:54:26]          File: /usr/bin/head
[21:54:26]          Current inode: 73370334    Stored inode: 66102335
[21:54:26] /usr/bin/id                                       [ Warning ]
[21:54:26] Warning: The file properties have changed:
[21:54:26]          File: /usr/bin/id
[21:54:26]          Current inode: 73370344    Stored inode: 66102665
[21:54:26] /usr/bin/killall                                  [ Warning ]
[21:54:26] Warning: The file properties have changed:
[21:54:26]          File: /usr/bin/killall
[21:54:26]          Current inode: 73370365    Stored inode: 66102316
[21:54:26] /usr/bin/last                                     [ Warning ]
[21:54:26] Warning: The file properties have changed:
[21:54:26]          File: /usr/bin/last
[21:54:26]          Current inode: 73370366    Stored inode: 66102288
[21:54:26] /usr/bin/lastlog                                  [ Warning ]
[21:54:26] Warning: The file properties have changed:
[21:54:26]          File: /usr/bin/lastlog
[21:54:26]          Current inode: 73370368    Stored inode: 66102262
[21:54:26] /usr/bin/ldd                                      [ Warning ]
[21:54:26] Warning: The file properties have changed:
[21:54:26]          File: /usr/bin/ldd
[21:54:26]          Current inode: 73370379    Stored inode: 66102617
[21:54:26] Info: Found file '/usr/bin/ldd': it is whitelisted for the 'script replacement' check.
[21:54:27] /usr/bin/less                                     [ Warning ]
[21:54:27] Warning: The file properties have changed:
[21:54:27]          File: /usr/bin/less
[21:54:27]          Current inode: 73370380    Stored inode: 66102659
[21:54:27] /usr/bin/locate                                   [ Warning ]
[21:54:27] Warning: The file properties have changed:
[21:54:27]          File: /usr/bin/locate
[21:54:27]          Current inode: 73370396    Stored inode: 66098265
[21:54:27] /usr/bin/logger                                   [ Warning ]
[21:54:27] Warning: The file properties have changed:
[21:54:27]          File: /usr/bin/logger
[21:54:27]          Current inode: 73370399    Stored inode: 66102570
[21:54:27] /usr/bin/lsattr                                   [ Warning ]
[21:54:27] Warning: The file properties have changed:
[21:54:27]          File: /usr/bin/lsattr
[21:54:27]          Current inode: 73370403    Stored inode: 66102483
[21:54:27] /usr/bin/lsof                                     [ Warning ]
[21:54:27] Warning: The file properties have changed:
[21:54:27]          File: /usr/bin/lsof
[21:54:27]          Current inode: 73370407    Stored inode: 66102760
[21:54:27] /usr/bin/lynx                                     [ Warning ]
[21:54:27] Warning: The file properties have changed:
[21:54:27]          File: /usr/bin/lynx
[21:54:27]          Current inode: 73370410    Stored inode: 66098231
[21:54:28] /usr/bin/mail                                     [ Warning ]
[21:54:28] Warning: The file properties have changed:
[21:54:28]          File: /usr/bin/mail
[21:54:28]          Current inode: 73370417    Stored inode: 66102731
[21:54:28] /usr/bin/md5sum                                   [ Warning ]
[21:54:28] Warning: The file properties have changed:
[21:54:28]          File: /usr/bin/md5sum
[21:54:28]          Current inode: 73370437    Stored inode: 66102369
[21:54:28] /usr/bin/newgrp                                   [ Warning ]
[21:54:28] Warning: The file properties have changed:
[21:54:28]          File: /usr/bin/newgrp
[21:54:28]          Current inode: 73370550    Stored inode: 66102366
[21:54:28] /usr/bin/passwd                                   [ Warning ]
[21:54:28] Warning: The file properties have changed:
[21:54:28]          File: /usr/bin/passwd
[21:54:28]          Current inode: 73370573    Stored inode: 66102794
[21:54:28] /usr/bin/perl                                     [ Warning ]
[21:54:28] Warning: The file properties have changed:
[21:54:28]          File: /usr/bin/perl
[21:54:28]          Current inode: 73370580    Stored inode: 66102620
[21:54:28] /usr/bin/pstree                                   [ Warning ]
[21:54:28] Warning: The file properties have changed:
[21:54:28]          File: /usr/bin/pstree
[21:54:28]          Current inode: 73370627    Stored inode: 66102475
[21:54:29] /usr/bin/rkhunter                                 [ Warning ]
[21:54:29] Warning: The file properties have changed:
[21:54:29]          File: /usr/bin/rkhunter
[21:54:29]          Current inode: 73370660    Stored inode: 66103528
[21:54:29] /usr/bin/runcon                                   [ Warning ]
[21:54:29] Warning: The file properties have changed:
[21:54:29]          File: /usr/bin/runcon
[21:54:29]          Current inode: 73370670    Stored inode: 66102323
[21:54:29] /usr/bin/sha1sum                                  [ Warning ]
[21:54:29] Warning: The file properties have changed:
[21:54:29]          File: /usr/bin/sha1sum
[21:54:29]          Current inode: 73370697    Stored inode: 66102761
[21:54:29] /usr/bin/size                                     [ Warning ]
[21:54:29] Warning: The file properties have changed:
[21:54:29]          File: /usr/bin/size
[21:54:29]          Current inode: 73370708    Stored inode: 66102476
[21:54:29] /usr/bin/slocate                                  [ Warning ]
[21:54:29] Warning: The file properties have changed:
[21:54:29]          File: /usr/bin/slocate
[21:54:29]          Current inode: 73370711    Stored inode: 66098203
[21:54:29] /usr/bin/sort                                     [ Warning ]
[21:54:29] Warning: The file properties have changed:
[21:54:29]          File: /usr/bin/sort
[21:54:29]          Current inode: 73370738    Stored inode: 66102415
[21:54:30] /usr/bin/stat                                     [ Warning ]
[21:54:30] Warning: The file properties have changed:
[21:54:30]          File: /usr/bin/stat
[21:54:30]          Current inode: 73370750    Stored inode: 66102364
[21:54:30] /usr/bin/strings                                  [ Warning ]
[21:54:30] Warning: The file properties have changed:
[21:54:30]          File: /usr/bin/strings
[21:54:30]          Current inode: 73370752    Stored inode: 66102403
[21:54:30] /usr/bin/sudo                                     [ Warning ]
[21:54:30] Warning: The file properties have changed:
[21:54:30]          File: /usr/bin/sudo
[21:54:30]          Current inode: 73370754    Stored inode: 66102497
[21:54:30] /usr/bin/tail                                     [ Warning ]
[21:54:30] Warning: The file properties have changed:
[21:54:30]          File: /usr/bin/tail
[21:54:30]          Current inode: 73370760    Stored inode: 66102738
[21:54:30] /usr/bin/test                                     [ Warning ]
[21:54:30] Warning: The file properties have changed:
[21:54:30]          File: /usr/bin/test
[21:54:30]          Current inode: 73370769    Stored inode: 66102295
[21:54:30] /usr/bin/top                                      [ Warning ]
[21:54:30] Warning: The file properties have changed:
[21:54:30]          File: /usr/bin/top
[21:54:30]          Current inode: 73370776    Stored inode: 66102679
[21:54:30] /usr/bin/touch                                    [ Warning ]
[21:54:31] Warning: The file properties have changed:
[21:54:31]          File: /usr/bin/touch
[21:54:31]          Current inode: 73370777    Stored inode: 66102430
[21:54:31] /usr/bin/tr                                       [ Warning ]
[21:54:31] Warning: The file properties have changed:
[21:54:31]          File: /usr/bin/tr
[21:54:31]          Current inode: 73370779    Stored inode: 66102706
[21:54:31] /usr/bin/uniq                                     [ Warning ]
[21:54:31] Warning: The file properties have changed:
[21:54:31]          File: /usr/bin/uniq
[21:54:31]          Current inode: 73370808    Stored inode: 66102269
[21:54:31] /usr/bin/users                                    [ Warning ]
[21:54:31] Warning: The file properties have changed:
[21:54:31]          File: /usr/bin/users
[21:54:31]          Current inode: 73370817    Stored inode: 66102559
[21:54:31] /usr/bin/vmstat                                   [ Warning ]
[21:54:31] Warning: The file properties have changed:
[21:54:31]          File: /usr/bin/vmstat
[21:54:31]          Current inode: 73370828    Stored inode: 66102697
[21:54:31] /usr/bin/w                                        [ Warning ]
[21:54:31] Warning: The file properties have changed:
[21:54:31]          File: /usr/bin/w
[21:54:31]          Current inode: 73370830    Stored inode: 66098195
[21:54:31] /usr/bin/watch                                    [ Warning ]
[21:54:31] Warning: The file properties have changed:
[21:54:32]          File: /usr/bin/watch
[21:54:32]          Current inode: 73370833    Stored inode: 66102271
[21:54:32] /usr/bin/wc                                       [ Warning ]
[21:54:32] Warning: The file properties have changed:
[21:54:32]          File: /usr/bin/wc
[21:54:32]          Current inode: 73370834    Stored inode: 66102688
[21:54:32] /usr/bin/wget                                     [ Warning ]
[21:54:32] Warning: The file properties have changed:
[21:54:32]          File: /usr/bin/wget
[21:54:32]          Current inode: 73370837    Stored inode: 66102361
[21:54:32] /usr/bin/whatis                                   [ Warning ]
[21:54:32] Warning: The file properties have changed:
[21:54:32]          File: /usr/bin/whatis
[21:54:32]          Current inode: 73370838    Stored inode: 66102582
[21:54:32] /usr/bin/whereis                                  [ Warning ]
[21:54:32] Warning: The file properties have changed:
[21:54:32]          File: /usr/bin/whereis
[21:54:32]          Current inode: 73370839    Stored inode: 66102284
[21:54:32] /usr/bin/which                                    [ Warning ]
[21:54:32] Warning: The file properties have changed:
[21:54:32]          File: /usr/bin/which
[21:54:32]          Current inode: 73370840    Stored inode: 66102515
[21:54:32] /usr/bin/who                                      [ Warning ]
[21:54:32] Warning: The file properties have changed:
[21:54:32]          File: /usr/bin/who
[21:54:32]          Current inode: 73370842    Stored inode: 66102583
[21:54:33] /usr/bin/whoami                                   [ Warning ]
[21:54:33] Warning: The file properties have changed:
[21:54:33]          File: /usr/bin/whoami
[21:54:33]          Current inode: 73370843    Stored inode: 66102481
[21:54:33] /usr/bin/tcsh                                     [ Warning ]
[21:54:33] Warning: The file properties have changed:
[21:54:33]          File: /usr/bin/tcsh
[21:54:33]          Current inode: 73370765    Stored inode: 66102778
[21:54:33] /usr/bin/gawk                                     [ Warning ]
[21:54:33] Warning: The file properties have changed:
[21:54:33]          File: /usr/bin/gawk
[21:54:33]          Current inode: 73370306    Stored inode: 66102728
[21:54:33] /usr/bin/lynx.stable                              [ Warning ]
[21:54:33] Warning: The file properties have changed:
[21:54:33]          File: /usr/bin/lynx.stable
[21:54:33]          Current inode: 73370411    Stored inode: 66102431
[21:54:33] /usr/bin/w.procps                                 [ Warning ]
[21:54:33] Warning: The file properties have changed:
[21:54:33]          File: /usr/bin/w.procps
[21:54:33]          Current inode: 73370831    Stored inode: 66102328
[21:54:33] /sbin/depmod                                      [ OK ]
[21:54:34] /sbin/ifconfig                                    [ OK ]
[21:54:34] /sbin/ifdown                                      [ OK ]
[21:54:34] /sbin/ifup                                        [ OK ]
[21:54:34] /sbin/init                                        [ OK ]
[21:54:34] /sbin/insmod                                      [ OK ]
[21:54:34] /sbin/ip                                          [ OK ]
[21:54:34] /sbin/lsmod                                       [ OK ]
[21:54:35] /sbin/modinfo                                     [ OK ]
[21:54:35] /sbin/modprobe                                    [ OK ]
[21:54:35] /sbin/rmmod                                       [ OK ]
[21:54:35] /sbin/runlevel                                    [ OK ]
[21:54:35] /sbin/sulogin                                     [ OK ]
[21:54:35] /sbin/sysctl                                      [ OK ]
[21:54:35] /sbin/syslogd                                     [ OK ]
[21:54:36] /usr/sbin/adduser                                 [ Warning ]
[21:54:36] Warning: The file properties have changed:
[21:54:36]          File: /usr/sbin/adduser
[21:54:36]          Current inode: 73697543    Stored inode: 66101280
[21:54:36] Info: Found file '/usr/sbin/adduser': it is whitelisted for the 'script replacement' check.
[21:54:36] /usr/sbin/chroot                                  [ Warning ]
[21:54:36] Warning: The file properties have changed:
[21:54:36]          File: /usr/sbin/chroot
[21:54:36]          Current inode: 73697555    Stored inode: 66101272
[21:54:36] /usr/sbin/cron                                    [ Warning ]
[21:54:36] Warning: The file properties have changed:
[21:54:36]          File: /usr/sbin/cron
[21:54:36]          Current inode: 73697567    Stored inode: 66101338
[21:54:36] /usr/sbin/groupadd                                [ Warning ]
[21:54:36] Warning: The file properties have changed:
[21:54:36]          File: /usr/sbin/groupadd
[21:54:36]          Current inode: 73697579    Stored inode: 66101366
[21:54:36] /usr/sbin/groupdel                                [ Warning ]
[21:54:36] Warning: The file properties have changed:
[21:54:36]          File: /usr/sbin/groupdel
[21:54:36]          Current inode: 73697580    Stored inode: 66101363
[21:54:37] /usr/sbin/groupmod                                [ Warning ]
[21:54:37] Warning: The file properties have changed:
[21:54:37]          File: /usr/sbin/groupmod
[21:54:37]          Current inode: 73697581    Stored inode: 66101386
[21:54:37] /usr/sbin/grpck                                   [ Warning ]
[21:54:37] Warning: The file properties have changed:
[21:54:37]          File: /usr/sbin/grpck
[21:54:37]          Current inode: 73697582    Stored inode: 66101278
[21:54:37] /usr/sbin/nologin                                 [ Warning ]
[21:54:37] Warning: The file properties have changed:
[21:54:37]          File: /usr/sbin/nologin
[21:54:37]          Current inode: 73697610    Stored inode: 66101404
[21:54:37] /usr/sbin/pwck                                    [ Warning ]
[21:54:37] Warning: The file properties have changed:
[21:54:37]          File: /usr/sbin/pwck
[21:54:37]          Current inode: 73697625    Stored inode: 66101406
[21:54:38] /usr/sbin/tcpd                                    [ Warning ]
[21:54:38] Warning: The file properties have changed:
[21:54:38]          File: /usr/sbin/tcpd
[21:54:38]          Current inode: 73697664    Stored inode: 66101324
[21:54:38] /usr/sbin/useradd                                 [ Warning ]
[21:54:38] Warning: The file properties have changed:
[21:54:38]          File: /usr/sbin/useradd
[21:54:38]          Current inode: 73697684    Stored inode: 66101314
[21:54:38] /usr/sbin/userdel                                 [ Warning ]
[21:54:38] Warning: The file properties have changed:
[21:54:38]          File: /usr/sbin/userdel
[21:54:38]          Current inode: 73697685    Stored inode: 66101333
[21:54:38] /usr/sbin/usermod                                 [ Warning ]
[21:54:38] Warning: The file properties have changed:
[21:54:38]          File: /usr/sbin/usermod
[21:54:38]          Current inode: 73697686    Stored inode: 66101307
[21:54:38] /usr/sbin/vipw                                    [ Warning ]
[21:54:38] Warning: The file properties have changed:
[21:54:38]          File: /usr/sbin/vipw
[21:54:38]          Current inode: 73697692    Stored inode: 66101409
[21:54:38] /usr/sbin/xinetd                                  [ Warning ]
[21:54:38] Warning: The file properties have changed:
[21:54:38]          File: /usr/sbin/xinetd
[21:54:38]          Current inode: 73697697    Stored inode: 66101381
...
[21:55:34] System checks summary
[21:55:34] =====================
[21:55:34]
[21:55:34] File properties checks...
[21:55:34] Files checked: 125
[21:55:34] Suspect files: 77
[21:55:34]
[21:55:34] Rootkit checks...
[21:55:34] Rootkits checked : 110
[21:55:34] Possible rootkits: 0
[21:55:34]
[21:55:34] Applications checks...
[21:55:34] Applications checked: 5
[21:55:34] Suspect applications: 0
[21:55:34]
[21:55:34] The system checks took: 1 minute and 18 seconds
[21:55:34]
[21:55:34] Info: End date is Sun Oct 25 21:55:34 CET 2009
 
Back
Top