Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Page 1 of 2 1 2 LastLast
Results 1 to 15 of 18
  1. #1
    Member Etheral's Avatar
    Join Date
    Dec 2003
    Posts
    210

    Default RootKit Problem

    i was scanning my server with RKhunter... it found this:


    /usr/sbin/prelink: /bin/egrep: at least one of file's dependencies has changed since prelinking
    /usr/sbin/prelink: /bin/egrep: at least one of file's dependencies has changed since prelinking
    /bin/egrep [ BAD ]
    /usr/sbin/prelink: /bin/fgrep: at least one of file's dependencies has changed since prelinking
    /usr/sbin/prelink: /bin/fgrep: at least one of file's dependencies has changed since prelinking
    /bin/fgrep [ BAD ]
    /usr/sbin/prelink: /bin/grep: at least one of file's dependencies has changed since prelinking
    /usr/sbin/prelink: /bin/grep: at least one of file's dependencies has changed since prelinking
    /bin/grep [ BAD ]

    How do i fix that.

  2. #2
    Member Etheral's Avatar
    Join Date
    Dec 2003
    Posts
    210

    Default

    MD5
    MD5 compared: 80
    Incorrect MD5 checksums: 3

    is the total output, i dont think checksums can be hacks tho. so are you shure about the hack?

  3. #3
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    Might not be a hacking issue - Are you running Fedora by any chance?
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  4. #4
    Member Etheral's Avatar
    Join Date
    Dec 2003
    Posts
    210

    Default

    Fedora Core 2

  5. #5
    Member Etheral's Avatar
    Join Date
    Dec 2003
    Posts
    210

    Default

    Hehe, wasnt a hacker issue, ive fixed it. wasnt a big deal.

  6. #6
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    Did you remove prelink from CRON and reboot, by any chance
    Last edited by chirpy; 01-23-2005 at 12:26 PM.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  7. #7
    Member Etheral's Avatar
    Join Date
    Dec 2003
    Posts
    210

    Default


  8. #8
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Oct 2003
    Posts
    1,914

    Default

    well what was the fix dont keep us in the dark

  9. #9
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    I already said what the fix was:
    remove prefix from CRON and reboot
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  10. #10
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Oct 2003
    Posts
    1,914

    Default

    you did not answer just smiled

    thanks but not my problem
    Last edited by dalem; 09-03-2004 at 01:50 PM.

  11. #11
    Member
    Join Date
    Apr 2003
    Posts
    55

    Default

    What prefer are you refering to?,

    I get that error when running....

    /usr/local/bin/rkhunter -c --cronjob

  12. #12
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    The information is already in my post. You need to find the prelink cron job (IIRC, it's in /etc/cron.daily) then delete it and reboot your server.
    Last edited by chirpy; 01-23-2005 at 12:26 PM.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  13. #13
    Member
    Join Date
    May 2002
    Posts
    139

    Default

    i have the same problem

    i may be thick but what do you mean by

    You need to find the prefix cron jon (IIRC, it's in /etc/cron.daily) and remove it, then reboot your server.
    i have gone to /etc/cron.daily - what am i looking for and what do i need to do ??

    there is a file called prelink do i remove this file ??

  14. #14
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    Yes, my post should have said "prelink", I'll correct it.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  15. #15
    Member
    Join Date
    Jan 2004
    Posts
    144

    Default

    You need to find the prefix cron jon (IIRC, it's in /etc/cron.daily) and remove it, then reboot your server.
    Jonathon I have done this and I still get this when I run rootkit:

    /usr/sbin/prelink: /lib/tls/libc-2.3.3.so has dependency cycle
    /usr/sbin/prelink: /bin/cat: at least one of file's dependencies has changed since prelinking
    Line:
    [ BAD ]
    /usr/sbin/prelink: /lib/tls/libc-2.3.3.so has dependency cycle
    /usr/sbin/prelink: /bin/chmod: at least one of file's dependencies has changed since prelinking
    Line: [ BAD ]
    [ BAD ]
    /usr/sbin/prelink: /lib/tls/libc-2.3.3.so has dependency cycle
    /usr/sbin/prelink: /bin/chown: at least one of file's dependencies has changed since prelinking
    Line: [ BAD ]
    [ BAD ]

    So now what?

Similar Threads & Tags
Similar threads

  1. rootkit hunter
    By Sheldon in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 03-14-2010, 11:20 AM
  2. Possible rootkit: Xzibit Rootkit ????
    By furquan in forum Security
    Replies: 5
    Last Post: 12-22-2009, 06:16 AM
  3. Rootkit Hunter 1.2.8 update Problem
    By edumadma in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 09-03-2006, 05:05 PM
  4. Rootkit Hunter 1.1.5
    By eazistore in forum cPanel Developers
    Replies: 26
    Last Post: 07-06-2005, 03:33 PM
  5. Help With Possibile Rootkit
    By Chris2k3 in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 05-17-2004, 09:19 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube