• [^] # Re: ... et pour être sûr ...

    Posté par . En réponse au message Sécurité et intrusion sur ma mandrake autopsie du crime. Évalué à 1.

    rkhunter-1.1.9.tar.gz(...)
    J'ai installer ce que tu m'as conseiller un test de plus ne me déplait pas.

    L'erreur dont je parlait venait de l autre logiciel chkrookit, une simple bibliothèque static qui manquait.

    Voila la sortie par contre j'avais une version d'un logiciel décrit comme vulnérable selon sa version, je l'ai enlever des logs. Le reste n'a pas été changer.

    Est ce que ce test doit etre à partir d'un système saint ou peut etre fait sur un système compromis ?


    [root@Samaty rkhunter]# rkhunter -c


    Rootkit Hunter 1.1.9 is running

    Determining OS... Warning: this operating system is not fully supported!
    Ready
    Warning: Cannot find md5_not_known
    All MD5 checks will be skipped!


    Checking binaries
    * Selftests
    Strings (command) [ OK ]


    * System tools
    Skipped!


    Check rootkits
    * Default files and directories
    Rootkit '55808 Trojan - Variant A'... [ OK ]
    ADM Worm... [ OK ]
    Rootkit 'AjaKit'... [ OK ]
    Rootkit 'aPa Kit'... [ OK ]
    Rootkit 'Apache Worm'... [ OK ]
    Rootkit 'Ambient (ark) Rootkit'... [ OK ]
    Rootkit 'Balaur Rootkit'... [ OK ]
    Rootkit 'BeastKit'... [ OK ]
    Rootkit 'BOBKit'... [ OK ]
    Rootkit 'CiNIK Worm (Slapper.B variant)'... [ OK ]
    Rootkit 'Danny-Boy's Abuse Kit'... [ OK ]
    Rootkit 'Devil RootKit'... [ OK ]
    Rootkit 'Dica'... [ OK ]
    Rootkit 'Dreams Rootkit'... [ OK ]
    Rootkit 'Duarawkz'... [ OK ]
    Rootkit 'Flea Linux Rootkit'... [ OK ]
    Rootkit 'FreeBSD Rootkit'... [ OK ]
    Rootkit 'Fuck`it Rootkit'... [ OK ]
    Rootkit 'GasKit'... [ OK ]
    Rootkit 'Heroin LKM'... [ OK ]
    Rootkit 'HjC Kit'... [ OK ]
    Rootkit 'ignoKit'... [ OK ]
    Rootkit 'ImperalsS-FBRK'... [ OK ]
    Rootkit 'Irix Rootkit'... [ OK ]
    Rootkit 'Kitko'... [ OK ]
    Rootkit 'Knark'... [ OK ]
    Rootkit 'Li0n Worm'... [ OK ]
    Rootkit 'Lockit / LJK2'... [ OK ]
    Rootkit 'MRK'... [ OK ]
    Rootkit 'Ni0 Rootkit'... [ OK ]
    Rootkit 'RootKit for SunOS / NSDAP'... [ OK ]
    Rootkit 'Optic Kit (Tux)'... [ OK ]
    Rootkit 'Oz Rootkit'... [ OK ]
    Rootkit 'Portacelo'... [ OK ]
    Rootkit 'R3dstorm Toolkit'... [ OK ]
    Rootkit 'RH-Sharpe's rootkit'... [ OK ]
    Rootkit 'RSHA's rootkit'... [ OK ]
    Sebek LKM [ OK ]
    Rootkit 'Scalper Worm'... [ OK ]
    Rootkit 'Shutdown'... [ OK ]
    Rootkit 'SHV4'... [ OK ]
    Rootkit 'SHV5'... [ OK ]
    Rootkit 'Sin Rootkit'... [ OK ]
    Rootkit 'Slapper'... [ OK ]
    Rootkit 'Sneakin Rootkit'... [ OK ]
    Rootkit 'Suckit Rootkit'... [ OK ]
    Rootkit 'SunOS Rootkit'... [ OK ]
    Rootkit 'Superkit'... [ OK ]
    Rootkit 'TBD (Telnet BackDoor)'... [ OK ]
    Rootkit 'TeLeKiT'... [ OK ]
    Rootkit 'T0rn Rootkit'... [ OK ]
    Rootkit 'Trojanit Kit'... [ OK ]
    Rootkit 'Tuxtendo'... [ OK ]
    Rootkit 'URK'... [ OK ]
    Rootkit 'VcKit'... [ OK ]
    Rootkit 'Volc Rootkit'... [ OK ]
    Rootkit 'X-Org SunOS Rootkit'... [ OK ]
    Rootkit 'zaRwT.KiT Rootkit'... [ OK ]

    * Suspicious files and malware
    Scanning for known rootkit strings [ OK ]
    Scanning for known rootkit files [ OK ]
    Testing running processes... [ OK ]
    Miscellaneous Login backdoors [ OK ]
    Miscellaneous directories [ OK ]
    Software related files [ OK ]
    Sniffer logs [ OK ]

    [Press to continue]


    * Trojan specific characteristics
    shv4
    Checking /etc/rc.d/rc.sysinit
    Test 1 [ Clean ]
    Test 2 [ Clean ]
    Test 3 [ Clean ]
    Checking /etc/inetd.conf [ Not found ]
    Checking /etc/xinetd.conf [ Clean ]

    * Suspicious file properties
    chmod properties
    Checking /bin/ps [ Clean ]
    Checking /bin/ls [ Clean ]
    Checking /usr/bin/w [ Clean ]
    Checking /usr/bin/who [ Clean ]
    Checking /bin/netstat [ Clean ]
    Checking /bin/login [ Clean ]
    Script replacements
    Checking /bin/ps [ Clean ]
    Checking /bin/ls [ Clean ]
    Checking /usr/bin/w [ Clean ]
    Checking /usr/bin/who [ Clean ]
    Checking /bin/netstat [ Clean ]
    Checking /bin/login [ Clean ]

    * OS dependant tests

    Linux
    Checking loaded kernel modules... [ OK ]
    Checking files attributes [ OK ]
    Checking LKM module path [ OK ]


    Networking
    * Check: frequently used backdoors
    Port 2001: Scalper Rootkit [ OK ]
    Port 2006: CB Rootkit [ OK ]
    Port 2128: MRK [ OK ]
    Port 14856: Optic Kit (Tux) [ OK ]
    Port 47107: T0rn Rootkit [ OK ]
    Port 60922: zaRwT.KiT [ OK ]

    * Interfaces
    Scanning for promiscuous interfaces [ OK ]

    [Press to continue]



    System checks
    * Allround tests
    Checking hostname... Found. Hostname is Samaty
    Checking for passwordless user accounts... OK
    Checking for differences in user accounts... [ NA ]
    Checking for differences in user groups... Creating file It seems this is your first time.
    Checking boot.local/rc.local file...
    - /etc/rc.local [ OK ]
    - /etc/rc.d/rc.local [ OK ]
    - /usr/local/etc/rc.local [ Not found ]
    - /usr/local/etc/rc.d/rc.local [ Not found ]
    - /etc/conf.d/local.start [ Not found ]
    - /etc/init.d/boot.local [ Not found ]
    Checking rc.d files...
    Processing........................................
    ........................................
    ........................................
    ........................................
    ........................................
    ........................................
    ........................................
    ........................................
    ........................................
    ........................................
    ........................................

    Result rc.d files check [ OK ]
    Checking history files
    Bourne Shell [ OK ]

    * Filesystem checks
    Checking /dev for suspicious files... [ OK ]
    Scanning for hidden files... [ Warning! ]
    ---------------
    /dev/.udev.tdb /etc/.pwd.lock
    /etc/.qt_plugins_3.1rc.lock
    /etc/.java
    /etc/.qtrc.lock
    /etc/.qt_plugins_3.2rc.lock
    /etc/.qt_plugins_3.3rc.lock
    ---------------
    Please inspect: /etc/.java (directory)

    [Press to continue]



    Application advisories
    * Application scan
    Checking Apache2 modules ... [ Not found ]
    Checking Apache configuration ... [ OK ]

    * Application version scan
    - GnuPG 1.2.4 [ OK ]
    - Bind DNS [unknown] [ OK ]
    - OpenSSL 0.9.7d [ OK ]
    - Procmail MTA 3.22 [ OK ]
    - ProFTPd 1.2.10 [ OK ]
    - OpenSSH 3.9p1 [ OK ]



    Security advisories
    * Check: Groups and Accounts
    Searching for /etc/passwd... [ Found ]
    Checking users with UID '0' (root)... [ OK ]

    * Check: SSH
    Searching for sshd_config...
    Found /etc/ssh/sshd_config
    Checking for allowed root login... Watch out Root login possible. Possible risk!
    Hint: see logfile for more information
    info: PermitRootLogin yes
    Hint: See logfile for more information about this issue
    Checking for allowed protocols... [ Warning ]
    info: Users can use SSH1-protocol (see logfile for more information).

    * Check: Events and Logging
    Search for syslog configuration... [ OK ]
    Checking for running syslog slave... [ OK ]
    Checking for logging to remote system... [ OK (no remote logging) ]

    [Press to continue]



    ---------------------------- Scan results ----------------------------

    MD5
    MD5 compared: 0
    Incorrect MD5 checksums: 0

    File scan
    Scanned files: 342
    Possible infected files: 0

    Application scan
    Vulnerable applications: 1

    Scanning took 212 seconds

    -----------------------------------------------------------------------

    Do you have some problems, undetected rootkits, false positives, ideas
    or suggestions?
    Please e-mail me by filling in the contact form (@http://www.rootkit.nl(...))

    -----------------------------------------------------------------------