Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 6 of 6
  1. #1
    Member
    Join Date
    Jul 2002
    Posts
    350

    Exclamation Possible rootkit: Xzibit Rootkit ????

    I installed the latest "Rkhunter 1.3.6 ", but according the Chirpy from "Configserver" he says that the "It does appear to currently throw a false-positive on CentOS v4.8 systems, but you should check this:Possible rootkit: Xzibit Rootkit"

    What does this mean, Should we ignore it or do we have to do something about it, coz my server never reported any rootkit on the server prior to 1.3.6 ver.

    Some one Please assist.

    Thank you

  2. #2
    Member
    Join Date
    Aug 2001
    Location
    Wisconsin
    Posts
    121

    Default

    Try installing & running chkrootkit and see if that picks it up as well.

    The best thing to do is to try to verify if it exists by using multiple resources to try to find it. If only rkhunter detects it, and chirpy (who is very respected in terms of server management) is advising it could be a false-positive in rkhunter, then it may be safe to ignore it.

    I say "may be" because there is the remote possibility, of course, the rootkit does indeed exist. So I say "may be safe to ignore it" implying that it's ultimately 100% your decision, and you have to decide what is acceptable risk for yourself.

    Sorry it's not more cut-and-dry.

    Bailey
    toast and jam.

  3. #3
    Member
    Join Date
    Jul 2002
    Posts
    350

    Default

    Thank you so very much for the response

    I do have chkrootkit installed on my servers and they do not report anything amiss.

    All they say is "nothing infected" or "not found".

    I hope things are ok.

  4. #4
    Member
    Join Date
    Jul 2002
    Location
    Canada
    Posts
    675

    Default

    You should be good to go then.
    Upload Guardian 2.0 - Sign up for our early beta
    ServerProgress - Server security, consulting and assistance

  5. #5
    Member
    Join Date
    Aug 2008
    Posts
    9

    Default

    If you look at your /var/log/rkhunter.log you will see something like this.

    Found string 'hdparm' in file '/etc/rc.d/init.d/vmware-tools'. Possible rootkit: Xzibit Rootkit

    which for me is a false positive ... whew

  6. #6
    Member
    Join Date
    Jul 2002
    Posts
    350

    Default

    Well i found this :

    " Found string 'hdparm' in file '/etc/rc.d/rc.sysinit'. Possible rootkit: Xzibit Rootkit"

    What does this mean ? am i clean ?

Similar Threads & Tags
Similar threads

  1. rootkit hunter
    By Sheldon in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 03-14-2010, 10:20 AM
  2. How to install and cofigure rootkit ?
    By beanth in forum New User Questions
    Replies: 1
    Last Post: 10-22-2008, 12:03 PM
  3. Rootkit Hunter 1.1.5
    By eazistore in forum cPanel Developers
    Replies: 26
    Last Post: 07-06-2005, 02:33 PM
  4. RootKit Problem
    By Etheral in forum cPanel and WHM Discussions
    Replies: 17
    Last Post: 06-01-2005, 10:39 AM
  5. Help With Possibile Rootkit
    By Chris2k3 in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 05-17-2004, 08:19 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube