From owner-freebsd-security@FreeBSD.ORG Tue Sep 23 09:52:01 2014 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [8.8.178.115]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 306115C6 for ; Tue, 23 Sep 2014 09:52:01 +0000 (UTC) Received: from mail-wi0-x241.google.com (mail-wi0-x241.google.com [IPv6:2a00:1450:400c:c05::241]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 6DE35D1C for ; Tue, 23 Sep 2014 09:52:00 +0000 (UTC) Received: by mail-wi0-f193.google.com with SMTP id q5so1688973wiv.0 for ; Tue, 23 Sep 2014 02:51:58 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=message-id:date:from:user-agent:mime-version:to:cc:subject :references:in-reply-to:content-type:content-transfer-encoding; bh=nCRjjguVXe0C3hhr/gjZwjipNbs7Mu+Xhsldw44k2VI=; b=TfmUl30AbfW41iTFcQFCwN/IVwSKWYPQd/s5jBGwKTveS6pVjVwWAEtcNLcgVGZGfl 5XR6v95ZRF9PJ04cakAXr7no/kRXGT1rFZSpSpIapo3up26hqImW/tfTApT/p0R4OCp0 yy7NDYKEkBjdD0aP0kSz6EA8J6KRDiCILpkwuiuAlilEUQfybA8EkCXV067osSd/qSKx AEj+CkQRazhX5m+ebcnhgt1T+8TOLWFXU8im5PO5C4+5flsnJ8QQLduzw1e3Vi3pykTz fBPhbYS9Kf/h9ovmJXlbu9GeggcWIQ+5H/r3p8r4exLFLjG6WC/7PHtrjB9J+SHz5epV r/lA== X-Received: by 10.180.92.225 with SMTP id cp1mr2005491wib.5.1411465918559; Tue, 23 Sep 2014 02:51:58 -0700 (PDT) Received: from [192.168.1.148] (78-26-20-251.network.trollfjord.no. [78.26.20.251]) by mx.google.com with ESMTPSA id bg10sm15241483wjc.47.2014.09.23.02.51.57 for (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 23 Sep 2014 02:51:58 -0700 (PDT) Message-ID: <542142BC.2000409@gmail.com> Date: Tue, 23 Sep 2014 11:51:56 +0200 From: List Monkey User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.1.1 MIME-Version: 1.0 To: Brandon Vincent Subject: Re: ossec hit: Hidden process (rootkit) References: <541FE781.2080505@gmail.com> In-Reply-To: Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit Cc: freebsd-security@freebsd.org X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.18-1 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 23 Sep 2014 09:52:01 -0000 Brandon, The ossec-rootcheck is not present on my install (has it been deprecated?) I am able to use the agent-control to force a complete run. It runs without error. Arne On 23. sep. 2014 02:29, Brandon Vincent wrote: > On Mon, Sep 22, 2014 at 2:10 AM, List Monkey wrote: >> Any other thoughts? > If you run ossec-rootcheck manually do you still get an alert? > > Brandon Vincent