#1 (permalink)  
Old 12-04-2009, 06:00 AM
Registered User
 
Join Date: Jul 2002
Posts: 141
furquan
Exclamation Possible rootkit: Xzibit Rootkit ????

I installed the latest "Rkhunter 1.3.6 ", but according the Chirpy from "Configserver" he says that the "It does appear to currently throw a false-positive on CentOS v4.8 systems, but you should check this:Possible rootkit: Xzibit Rootkit"

What does this mean, Should we ignore it or do we have to do something about it, coz my server never reported any rootkit on the server prior to 1.3.6 ver.

Some one Please assist.

Thank you
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 12-09-2009, 03:59 AM
Registered User
 
Join Date: Aug 2001
Location: Wisconsin
Posts: 121
Bailey is an unknown quantity at this point
Try installing & running chkrootkit and see if that picks it up as well.

The best thing to do is to try to verify if it exists by using multiple resources to try to find it. If only rkhunter detects it, and chirpy (who is very respected in terms of server management) is advising it could be a false-positive in rkhunter, then it may be safe to ignore it.

I say "may be" because there is the remote possibility, of course, the rootkit does indeed exist. So I say "may be safe to ignore it" implying that it's ultimately 100% your decision, and you have to decide what is acceptable risk for yourself.

Sorry it's not more cut-and-dry.

Bailey
__________________
toast and jam.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 12-10-2009, 02:44 AM
Registered User
 
Join Date: Jul 2002
Posts: 141
furquan
Thank you so very much for the response

I do have chkrootkit installed on my servers and they do not report anything amiss.

All they say is "nothing infected" or "not found".

I hope things are ok.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 12-10-2009, 12:06 PM
Registered User
 
Join Date: Jul 2002
Location: Canada
Posts: 675
ramprage is on a distinguished road
You should be good to go then.
__________________
Upload Guardian 2.0 - Sign up for our early beta
ServerProgress - Server security, consulting and assistance
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 12-20-2009, 02:56 PM
Registered User
 
Join Date: Aug 2008
Posts: 9
miahac is on a distinguished road
If you look at your /var/log/rkhunter.log you will see something like this.

Found string 'hdparm' in file '/etc/rc.d/init.d/vmware-tools'. Possible rootkit: Xzibit Rootkit

which for me is a false positive ... whew
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 12-22-2009, 05:16 AM
Registered User
 
Join Date: Jul 2002
Posts: 141
furquan
Well i found this :

" Found string 'hdparm' in file '/etc/rc.d/rc.sysinit'. Possible rootkit: Xzibit Rootkit"

What does this mean ? am i clean ?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
rootkit hunter Sheldon cPanel and WHM Discussions 3 03-14-2010 10:20 AM
How to install and cofigure rootkit ? beanth cPanel Newbies 1 10-22-2008 12:03 PM
Rootkit Hunter 1.1.5 eazistore Developer Discussions 26 07-06-2005 02:33 PM
RootKit Problem Etheral cPanel and WHM Discussions 17 06-01-2005 10:39 AM
Help With Possibile Rootkit Chris2k3 cPanel and WHM Discussions 0 05-17-2004 08:19 AM


All times are GMT -5. The time now is 09:24 AM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
© cPanel Inc