Hallo,
mein rkhunter meldet nahezu täglich in den letzten Tagen, dass eine Infizierung vorliegt (Mailtext: "Please inspect this machine, because it may be infected.").
Seht ihr in der Logdatei einen konkreten Hinweis auf das Problem? Ich kann keinen entdecken und bin dankbar für Tipps:
Gruß
prinzipal
mein rkhunter meldet nahezu täglich in den letzten Tagen, dass eine Infizierung vorliegt (Mailtext: "Please inspect this machine, because it may be infected.").
Seht ihr in der Logdatei einen konkreten Hinweis auf das Problem? Ich kann keinen entdecken und bin dankbar für Tipps:
Code:
[01:00:16] Running Rootkit Hunter version 1.3.4 on xxxxxxxx
[01:00:16]
[01:00:16] Info: Start date is Mon May 21 01:00:16 CEST 2012
[01:00:16]
[01:00:16] Checking configuration file and command-line options...
[01:00:16] Info: Detected operating system is 'Linux'
[01:00:16] Info: Found O/S name: openSUSE 10.3 (X86-64)
[01:00:16] Info: Command line is /usr/local/psa/admin/sbin/modules//watchdog/rkhunter -c --configfile /usr/local/psa/etc/modules/watchdog/rkhunter.conf --cronjob --propupd --createlogfile
[01:00:16] Info: Environment shell is /bin/sh; rkhunter is using bash
[01:00:17] Info: Using configuration file '/usr/local/psa/etc/modules/watchdog/rkhunter.conf'
[01:00:17] Info: Installation directory is '/usr/local/psa'
[01:00:17] Info: Using language 'en'
[01:00:17] Info: Using '/usr/local/psa/var/modules/watchdog/lib/rkhunter/lib/rkhunter/db' as the database directory
[01:00:17] Info: Using '/usr/local/psa/var/modules/watchdog/lib/rkhunter/rkhunter/scripts' as the support script directory
[01:00:17] Info: Using '/usr/local/psa/admin/bin/modules/watchdog /usr/local/bin /usr/local/sbin /bin /sbin /usr/bin /usr/sbin /bin /usr/bin /sbin /usr/sbin /usr/local/bin /usr/local/sbin /usr/libexec /usr/local/libexec' as the command directories
[01:00:17] Info: Using '/' as the root directory by default
[01:00:17] Info: Using '/usr/local/psa/var/modules/watchdog/lib/rkhunter/lib/rkhunter/tmp' as the temporary directory
[01:00:17] Info: Emailing warnings to '[email protected]' using command '/bin/mail -s "[rkhunter] Warnings found for ${HOST_NAME}"'
[01:00:17] Info: X will be automatically detected
[01:00:17] Info: Found the 'diff' command: /usr/bin/diff
[01:00:17] Info: Found the 'file' command: /usr/bin/file
[01:00:17] Info: Found the 'find' command: /usr/bin/find
[01:00:17] Info: Found the 'ifconfig' command: /sbin/ifconfig
[01:00:17] Info: Found the 'ip' command: /bin/ip
[01:00:17] Info: Found the 'ldd' command: /usr/bin/ldd
[01:00:18] Info: Found the 'lsattr' command: /usr/bin/lsattr
[01:00:18] Info: Found the 'lsmod' command: /bin/lsmod
[01:00:18] Info: Found the 'lsof' command: /usr/bin/lsof
[01:00:18] Info: Found the 'mktemp' command: /bin/mktemp
[01:00:18] Info: Found the 'netstat' command: /bin/netstat
[01:00:18] Info: Found the 'perl' command: /usr/bin/perl
[01:00:18] Info: Found the 'ps' command: /bin/ps
[01:00:18] Info: Found the 'pwd' command: /bin/pwd
[01:00:18] Info: Found the 'readlink' command: /usr/bin/readlink
[01:00:18] Info: Found the 'sort' command: /bin/sort
[01:00:18] Info: Found the 'stat' command: /usr/bin/stat
[01:00:18] Info: Found the 'strings' command: /usr/bin/strings
[01:00:18] Info: Found the 'uniq' command: /usr/bin/uniq
[01:00:18] Info: System is not using prelinking
[01:00:19] Info: Using the '/usr/bin/sha1sum' command for the file hash checks
[01:00:19] Info: Stored hash values used hash function '/usr/bin/sha1sum'
[01:00:19] Info: Stored hash values used package manager 'RPM' (md5 function)
[01:00:19] Info: The hash function field index is set to 1
[01:00:19] Info: Using package manager 'RPM' to update the file hash values
[01:00:19] Info: Found the 'rpm' command: /bin/rpm
[01:00:19] Info: Using package manager 'RPM' for file property checks
Gruß
prinzipal