store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Tue Jun 18, 2013 11:26 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 7 posts ] 
Author Message
 Post subject: Rule 510 - Host-based anomaly detection event (rootcheck).
Unread postPosted: Fri Jul 13, 2012 4:35 am 
Offline
Forum Regular
Forum Regular

Joined: Wed Jan 02, 2008 3:21 pm
Posts: 515
Location: United Kingdom
Updated to CentOS release 6.3 yesterday evening and ran/propupd rkhunter. This morning received an ASL notification:
Code:
Trojaned version of file `/proc/1/maps` detected. Signature used: `init.` (Suckit rootkit).

First thought, this is a false positive due to CentOS update, but as file is not owned by any package wanted to check publicly before submitting. Have re-run rkhunter and it found nothing. Anyone else seen this?


Top
 Profile  
 
 Post subject: Re: Rule 510 - Host-based anomaly detection event (rootcheck
Unread postPosted: Fri Jul 13, 2012 9:31 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3264
Location: Chantilly, VA
Can you send us the file?

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Rule 510 - Host-based anomaly detection event (rootcheck
Unread postPosted: Fri Jul 13, 2012 11:00 am 
Offline
Forum Regular
Forum Regular

Joined: Wed Jan 02, 2008 3:21 pm
Posts: 515
Location: United Kingdom
mikeshinn wrote:
Can you send us the file?


As in submit it as false-positive?


Top
 Profile  
 
 Post subject: Re: Rule 510 - Host-based anomaly detection event (rootcheck
Unread postPosted: Fri Jul 13, 2012 10:08 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3264
Location: Chantilly, VA
Yes. Zip/Tar/whatever it up, and put a password on it (and of course, send us the password so we can open it). Otherwise, if it is malware, it might get stopped on the way by email scanners.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Rule 510 - Host-based anomaly detection event (rootcheck
Unread postPosted: Sat Jul 14, 2012 5:39 am 
Offline
Forum Regular
Forum Regular

Joined: Wed Jan 02, 2008 3:21 pm
Posts: 515
Location: United Kingdom
All done


Top
 Profile  
 
 Post subject: Re: Rule 510 - Host-based anomaly detection event (rootcheck
Unread postPosted: Sat Jul 14, 2012 6:25 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3264
Location: Chantilly, VA
Its a false positive alright, we'll get an update out Monday for it.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Rule 510 - Host-based anomaly detection event (rootcheck
Unread postPosted: Sun Jul 15, 2012 6:33 am 
Offline
Forum Regular
Forum Regular

Joined: Wed Jan 02, 2008 3:21 pm
Posts: 515
Location: United Kingdom
Great! Thanks for update.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 7 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: Bing [Bot] and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group