dalla scansione rkhunter ha rilevato 5 files sospetti:
Codice: Seleziona tutto
[15:04:09] /bin/dmesg [ Warning ]
[15:04:09] Warning: The file properties have changed:
[15:04:09] File: /bin/dmesg
[15:04:09] Current inode: 3145730 Stored inode: 3145762
[15:04:09] Current file modification time: 1296636968 (02-feb-2011 09:56:08)
[15:04:09] Stored file modification time : 1291989141 (10-dic-2010 14:52:21)
................
[15:04:10] /bin/more [ Warning ]
[15:04:10] Warning: The file properties have changed:
[15:04:10] File: /bin/more
[15:04:10] Current inode: 3145731 Stored inode: 3145777
[15:04:10] Current file modification time: 1296636968 (02-feb-2011 09:56:08)
[15:04:10] Stored file modification time : 1291989141 (10-dic-2010 14:52:21)
...................
[15:04:10] /bin/mount [ Warning ]
[15:04:10] Warning: The file properties have changed:
[15:04:10] File: /bin/mount
[15:04:10] Current inode: 3145759 Stored inode: 3145730
[15:04:10] Current file modification time: 1296636968 (02-feb-2011 09:56:08)
[15:04:10] Stored file modification time : 1291989142 (10-dic-2010 14:52:22)
................
[15:04:12] /usr/bin/logger [ Warning ]
[15:04:12] Warning: The file properties have changed:
[15:04:12] File: /usr/bin/logger
[15:04:12] Current inode: 9438805 Stored inode: 9437209
[15:04:12] Current file modification time: 1296636968 (02-feb-2011 09:56:08)
[15:04:12] Stored file modification time : 1291989142 (10-dic-2010 14:52:22)
....................
[15:04:15] /usr/bin/whereis [ Warning ]
[15:04:15] Warning: The file properties have changed:
[15:04:15] File: /usr/bin/whereis
[15:04:15] Current inode: 9448109 Stored inode: 9438812
[15:04:15] Current file modification time: 1296636968 (02-feb-2011 09:56:08)
[15:04:15] Stored file modification time : 1291989142 (10-dic-2010 14:52:22)
.............
inoltre ci sono altri warning verso la fine della scansione:
Codice: Seleziona tutto
[15:05:12] Performing filesystem checks
[15:05:12] Info: Starting test name 'filesystem'
[15:05:12] Info: SCAN_MODE_DEV set to 'THOROUGH'
[15:05:12] Checking /dev for suspicious file types [ Warning ]
[15:05:12] Warning: Suspicious file types found in /dev:
[15:05:12] /dev/shm/mono-shared-1000-shared_fileshare-francop-P31-DS3L-Linux-i686-36-12-0: data
[15:05:12] /dev/shm/mono-shared-1000-shared_data-francop-P31-DS3L-Linux-i686-312-12-0: data
[15:05:12] /dev/shm/mono.2189: data
[15:05:12] /dev/shm/pulse-shm-2978813864: data
[15:05:12] /dev/shm/pulse-shm-1542477952: data
[15:05:12] /dev/shm/pulse-shm-687299134: data
[15:05:12] /dev/shm/pulse-shm-3749256652: data
[15:05:12] /dev/shm/ecryptfs-francop-Private: ASCII text
[15:05:13] /dev/shm/pulse-shm-3177709487: data
[15:05:13] Checking for hidden files and directories [ Warning ]
[15:05:13] Warning: Hidden directory found: /etc/.java
[15:05:13] Warning: Hidden directory found: /dev/.udev
[15:05:13] Warning: Hidden directory found: /dev/.initramfs
Codice: Seleziona tutto
[15:05:16] File properties checks...
[15:05:16] Files checked: 133
[15:05:16] Suspect files: 5
[15:05:16]
[15:05:16] Rootkit checks...
[15:05:16] Rootkits checked : 245
[15:05:16] Possible rootkits: 0
[15:05:16]
[15:05:16] Applications checks...
[15:05:16] All checks skipped
[15:05:16]
[15:05:16] The system checks took: 1 minute and 10 seconds
[15:05:16]
[15:05:16] Info: End date is ven 11 feb 2011, 15.05.16, CET

