Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Security and Privacy
FedoraForum Search

Forgot Password? Join Us!

Security and Privacy Sadly, malware, spyware, hackers and privacy threats abound in today's world. Let's be paranoid and secure our penguins, and slam the doors on privacy exploits.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 16th November 2007, 02:30 PM
paulywauly Offline
Registered User
 
Join Date: Oct 2007
Posts: 87
Check Root kit

after installing fedora 8 from the main place and running chkrootkit i get some weird lines can anyone tell me what this is all about????

Searching for suspicious files and dirs, it may take a while...
/usr/lib/gtk-2.0/immodules/.relocation-tag

checking `sniffer'... eth0: PF_PACKET(/usr/sbin/wpa_supplicant, /usr/sbin/wpa_supplicant, /sbin/dhclient)

Checking `z2'... user root deleted or never logged from lastlog!
Checking `chkutmp'... The tty of the following user process(es) were not found
in /var/run/utmp !

could i allready have a problem with this system and if i do it was just downloaded and installed within the last 2 hrs of installation this showed up
Reply With Quote
  #2  
Old 16th November 2007, 10:34 PM
universe_r9's Avatar
universe_r9 Offline
Registered User
 
Join Date: Nov 2007
Posts: 8
i don't know about it sorry!
__________________
I hope you know, I hope you know
That this has nothing to do with you

It's time to be a Big John now
And Big John don't cry
Reply With Quote
  #3  
Old 16th November 2007, 11:00 PM
jim's Avatar
jim Offline
Retired Community Manager & Avid Drinker Of Suds
 
Join Date: Feb 2005
Location: Rochester NY
Age: 38
Posts: 4,176
check for updates to the script and run again.
__________________
Registered Linux User: #376813
Western NY
My linux site
Smolt Profile

please remember to say if you problem was solved

Did you get your id10t award today?
Reply With Quote
  #4  
Old 17th November 2007, 02:38 PM
Evil_Bert's Avatar
Evil_Bert Offline
Retired Again - Administrator
 
Join Date: Nov 2007
Location: Reality
Posts: 3,034
No updates to the chrootkit package as yet.

{warning - I am not an expert}

I wouldn't worry about the wpa and dhclient stuff - all normal as these are low level routines attached to your eth0 interface in order to provide network functionality. If you used fixed LAN addresses and turned off dhcp (and its services) and similarly turned off wireless support (and its services) you could rid yourself of these lines, if it really bothered you.

In F7, I always had a 'z2' and a 'chkutmp' line (referring to the X server) but haven't yet figured out why ... they appear to be normal, however, as I've seen them discussed from time to time.

The .relocation-tag line refers to a hidden executable file in the /usr/lib/gtk-2.0/immodules/ folder that was not there in Fedora7 ... but it appears to be a bone-fide inclusion in the latest f8 gtk2 rpm:

http://rpmfind.net/linux/RPM/fedora/...c8.x86_64.html
(listed in 'files' section, near bottom of page)

... so I'd guess it's OK until demonstrated otherwise.

Last edited by Evil_Bert; 17th November 2007 at 02:54 PM.
Reply With Quote
Reply

Tags
check, kit, root

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
mount: error mounting /dev/root on /sys/root as ext3: no such file or directory nutty Hardware & Laptops 0 12th February 2009 11:00 PM
fedora 10 firewall: to check or not to check baerb8 Security and Privacy 1 25th December 2008 04:45 AM
Boot stops at eth0 check and swat doesn't accept root pwd akines Using Fedora 3 10th July 2007 11:46 PM
Can't check root email from squirrelmail kruser Using Fedora 1 30th June 2005 05:31 PM


Current GMT-time: 03:28 (Friday, 24-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat