From owner-freebsd-security@FreeBSD.ORG Thu May 12 16:38:07 2005 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 19DAF16A4D0 for ; Thu, 12 May 2005 16:38:07 +0000 (GMT) Received: from web20424.mail.yahoo.com (web20424.mail.yahoo.com [66.163.170.247]) by mx1.FreeBSD.org (Postfix) with SMTP id 88B8143D31 for ; Thu, 12 May 2005 16:38:06 +0000 (GMT) (envelope-from dhutch9999@yahoo.com) Received: (qmail 98444 invoked by uid 60001); 12 May 2005 16:38:06 -0000 Comment: DomainKeys? See http://antispam.yahoo.com/domainkeys DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s1024; d=yahoo.com; b=VrHwT40QmhgiIjUssMToQ4Da2vzD/FgghMFJetryAHP1gm4eFlBVJkjsKnPIAGgOzXoyDCW1ZFudfoRXjw5d4CHUFYZrzuMlRS+1JqEUkP2gmrmgZuEUNYjNTDimjwWG5yznfUoeWAw+PSPg2TLOXYFRkueDDG/7dfbS7EHbjgg= ; Message-ID: <20050512163806.98442.qmail@web20424.mail.yahoo.com> Received: from [12.153.72.219] by web20424.mail.yahoo.com via HTTP; Thu, 12 May 2005 09:38:06 PDT Date: Thu, 12 May 2005 09:38:06 -0700 (PDT) From: DH To: freebsd-security@freebsd.org MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="0-911594080-1115915886=:97759" X-Content-Filtered-By: Mailman/MimeDel 2.1.1 Subject: Do I have an infected init file? X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 12 May 2005 16:38:07 -0000 --0-911594080-1115915886=:97759 Content-Type: text/plain; charset=us-ascii Hello; I'm running a FreeBSD 4.10-release-p2 box and both chkrootkit 0.44 & 0.45 report that my /sbin/init file is infected. It appears as though the egrep for "UPX" in the output of "strings" triggers the infected notice. When I copy the init file from an uninfected box to this one chkrootkit continues to report it as infected. Is chkrootkit reading a copy of the /sbin/init file stored in active memory? If my machine is compromised, which rootkit is installed / how can I find out which rootkit is installed? As a side note, neither Kaspersky AV nor rkhunter report any infections. Attached is some of the debug output. Thanks in advance to any respondents. Sincerely; David Hutchens III --------------------------------- Discover Yahoo! Find restaurants, movies, travel & more fun for the weekend. Check it out! --0-911594080-1115915886=:97759--