Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Security and Privacy
FedoraForum Search

Forgot Password? Join Us!

Security and Privacy Sadly, malware, spyware, hackers and privacy threats abound in today's world. Let's be paranoid and secure our penguins, and slam the doors on privacy exploits.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 17th April 2006, 11:23 PM
jsanza@terra.es Offline
Registered User
 
Join Date: Sep 2005
Posts: 45
xchkrootkit alert ?

Hello,

If i run xchkrootkit in my system, i get :
Searching for anomalies in shell history files... nothing found
Checking `asp'... not infected
Checking `bindshell'... not infected
Checking `lkm'... chkproc: nothing detected
Checking `rexedcs'... not found
Checking `sniffer'... eth0: PF_PACKET(/sbin/dhclient)
Checking `w55808'... not infected
Checking `wted'... chkwtmp: nothing deleted
Checking `scalper'... not infected
Checking `slapper'... not infected
Checking `z2'... chklastlog: nothing deleted
Checking `chkutmp'... The tty of the following user process(es) were not found
in /var/run/utmp !
! RUID PID TTY CMD
! root 1731 tty2 /usr/bin/X -br -nolisten tcp :0 vt2 -auth /var/run/xa uth/A:0-w6a1DX
chkutmp: nothing deleted
Press ENTER to exit
[admin@darkstar tmp]$ tty
/dev/pts/2
[admin@darkstar tmp]$ ps -ef | grep "/X"
root 1718 1 0 01:39 ? 00:00:00 /bin/sh /etc/X11/prefdm -nodaemon
root 1731 1729 4 01:39 tty2 00:00:27 /usr/bin/X -br -nolisten tcp :0 vt2 -auth /var/run/xauth/A:0-w6a1DX
admin 4245 1982 0 01:50 pts/2 00:00:00 grep /X


what is this process?

what is tty2?

thank you
Reply With Quote
  #2  
Old 17th April 2006, 11:36 PM
Brian1's Avatar
Brian1 Offline
Registered User
 
Join Date: Nov 2004
Location: Seymour, Indiana
Posts: 2,511
tty is the device block for your terminal session. Normally tty is your first one and then tty2 the the one it is using for the X session. So one is in the gui you can hit Alt-Ctrl-F1 and get to the terminal of the gui. To get back to the gui hit alt_ctrl-F2. On some distros like redhat it defines 6 ttys at the bootup which means the first gui for tty1 will be tty7. tty2 will be tty8.
For more info do a ' man tty ' and also search google for tty.

Brian1
Reply With Quote
Reply

Tags
alert, xchkrootkit

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
virus alert? chatpert Security and Privacy 3 27th November 2005 05:21 AM
Chkrootkit alert ?? mtplodder Security and Privacy 5 28th December 2004 05:14 AM


Current GMT-time: 08:12 (Wednesday, 22-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat