From owner-freebsd-current@FreeBSD.ORG Sun Jun 8 06:20:40 2003 Return-Path: Delivered-To: freebsd-current@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 1C93937B401 for ; Sun, 8 Jun 2003 06:20:40 -0700 (PDT) Received: from fed1mtao04.cox.net (fed1mtao04.cox.net [68.6.19.241]) by mx1.FreeBSD.org (Postfix) with ESMTP id 97A2943FDD for ; Sun, 8 Jun 2003 06:20:39 -0700 (PDT) (envelope-from xcas@cox.net) Received: from smtp.west.cox.net ([172.18.180.52]) by fed1mtao04.cox.net (InterMail vM.5.01.04.05 201-253-122-122-105-20011231) with SMTP id <20030608132039.IAFQ27845.fed1mtao04.cox.net@smtp.west.cox.net>; Sun, 8 Jun 2003 09:20:39 -0400 From: cas To: "Perry S. Glenn" , freebsd-current@freebsd.org Date: Sun, 8 Jun 2003 9:20:32 -0400 MIME-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Message-Id: <20030608132039.IAFQ27845.fed1mtao04.cox.net@smtp.west.cox.net> Subject: Re: chkrootkit w/ current X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 08 Jun 2003 13:20:40 -0000 ============================================================ From: "Perry S. Glenn" Date: 2003/06/08 Sun AM 03:44:35 EDT To: freebsd-current@freebsd.org Subject: chkrootkit w/ current Hello, I'm running current and I had left forgot to turn the ftp knob in inetd.conf off. I came back after a drive to find my /var/ filesystem full. I did not (per sysinstall)have anon ftp on, but someone made lots of bogus directories in /var/ftp/pub anyway. I decided to install /ports/security/chkrootkit after a short google. chkrootkit says it finds 12 processes hidden from ps command and a possible LKM Trojan installed. chkroot also calls ls ps date chsh and chfn "INFECTED" Is chkrootkit giving accurate info for FreeBSD-5 ? Could someone check to see if they get false positives with this script on current. TIA --psglenn ============================================================ yes.. it does give false positives.. I asked the same question about those commands. :-)