PDA

View Full Version : LiveDVD shows warnings and possible rootkits



stud_learner
07-15-2012, 05:28 AM
Hi there, I have downloaded Knoppix DVDv7.0.1 and used it to boot my laptop. I have run the rkhunter command and it shows lots of warnings and possible rootkits. Is this normal for a liveDVD or is something else? I am new to knoppix.

This is a summary of the output System checks summary

[13:39:30] ===================== [13:39:30] [13:39:30] File properties checks... [13:39:30] Required commands check failed [13:39:30] Files checked: 193 [13:39:30] Suspect files: 151 [13:39:30] [13:39:30] Rootkit checks... [13:39:30] Rootkits checked : 251 [13:39:30] Possible rootkits: 2 [13:39:30] Rootkit names : Rootkit component, Xzibit Rootkit [13:39:30] [13:39:30] Applications checks... [13:39:30] All checks skipped [13:39:30] [13:39:30] The system checks took: 3 minutes and 42 seconds [13:39:30] [13:39:30] Info: End date is Sun Jul 15 13:39:30 UTC 2012

Cheers

Werner P. Schulz
07-15-2012, 09:11 AM
Before trying a tool like rkhunter please learn how to use it and especially all about "Intrusion Procedure"

http://sourceforge.net/apps/trac/rkhunter/wiki/SPRKH

stud_learner
07-16-2012, 06:33 AM
Before trying a tool like rkhunter please learn how to use it and especially all about "Intrusion Procedure"

http://sourceforge.net/apps/trac/rkhunter/wiki/SPRKH


Thank you Werner for the link. I see that rkhunter is more than a simple scanner. The warnings were about mismatched checksums for some files and applications, but the checksum for Knoppix iso was ok. That was a bit of a puzzle for me. I have lots to learn, now that I have made the switch from "point, click and don't need to know" OS to Linux.