chkrootkit wted warning

This is a discussion on chkrootkit wted warning within the Linux Security forums, part of the System Security and Security Related category; Hi, I noticed in chkrootkit's output the line Checking `wted'... 8 deletion(s) between ...(shortened by me) I checked ...


Go Back   Usenet Forums > System Security and Security Related > Linux Security

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 07-01-2005
Ransom
 
Posts: n/a
Default chkrootkit wted warning

Hi,

I noticed in chkrootkit's output the line
Checking `wted'... 8 deletion(s) between ...(shortened by me)

I checked wtmp and all other logs, apparently the system has
crashed at the time in questionm so probably that's the reason
for the deletions. just to be sure I've been looking for any
suspicious activities that could indicate a compromise.

I checked for noisy network traffic.
I compared ps aux with /proc.
I booted from clean media and checked for suspicious files.
I installed check_ps and checked for hidden or fake processes.

So far, everything seems to be ok and since the system is not
connected to the LAN, I'm willing to leave it at it, but
probably somebody has additional ideas what to check.

TIA
Ransom
--
For real email get public key 0xF6BB5695 from www.keyserver.net
NO to Software Patents - http://www.ffii.org
Reply With Quote
  #2 (permalink)  
Old 07-01-2005
Eric Teuber
 
Posts: n/a
Default Re: chkrootkit wted warning

Ransom wrote:
> Hi,
>
> I noticed in chkrootkit's output the line
> Checking `wted'... 8 deletion(s) between ...(shortened by me)
>
> I checked wtmp and all other logs, apparently the system has
> crashed at the time in questionm so probably that's the reason
> for the deletions. just to be sure I've been looking for any
> suspicious activities that could indicate a compromise.
>
> I checked for noisy network traffic.
> I compared ps aux with /proc.
> I booted from clean media and checked for suspicious files.
> I installed check_ps and checked for hidden or fake processes.
>
> So far, everything seems to be ok and since the system is not
> connected to the LAN, I'm willing to leave it at it, but
> probably somebody has additional ideas what to check.
>
> TIA
> Ransom


try to compare the netstat output and a port scan from another clean system.

Eric
Reply With Quote
  #3 (permalink)  
Old 07-04-2005
Ransom
 
Posts: n/a
Default Re: chkrootkit wted warning

Eric Teuber wrote:

>
> try to compare the netstat output and a port scan from another
> clean system.
>


Thanks, will try that.

Ransom
--
For real email get public key 0xF6BB5695 from www.keyserver.net
NO to Software Patents - http://www.ffii.org
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 03:20 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0