Hi Leute!
Habe gerade mir nichts dir nichts am Server gebastelt (wurde vor ner woche gehackt und hab jetzt mal sicherhetishalber rkhunter durchlaufen lassen) - und da fällt mir folgendes auf:
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 | [ Rootkit Hunter version 1.3.8 ] Checking system commands... Performing 'strings' command checks Checking 'strings' command [ OK ] Performing 'shared libraries' checks Checking for preloading variables [ None found ] Checking for preloaded libraries [ None found ] Checking LD_LIBRARY_PATH variable [ Not found ] Performing file properties checks Checking for prerequisites [ OK ] /usr/sbin/adduser [ Warning ] /usr/sbin/chroot [ Warning ] /usr/sbin/cron [ Warning ] /usr/sbin/groupadd [ Warning ] /usr/sbin/groupdel [ Warning ] /usr/sbin/groupmod [ Warning ] /usr/sbin/grpck [ Warning ] /usr/sbin/nologin [ Warning ] /usr/sbin/pwck [ Warning ] /usr/sbin/useradd [ Warning ] /usr/sbin/userdel [ Warning ] /usr/sbin/usermod [ Warning ] /usr/sbin/vipw [ Warning ] /usr/sbin/xinetd [ Warning ] /usr/bin/awk [ Warning ] /usr/bin/basename [ Warning ] /usr/bin/chattr [ Warning ] /usr/bin/curl [ Warning ] /usr/bin/cut [ Warning ] /usr/bin/diff [ Warning ] /usr/bin/dirname [ Warning ] /usr/bin/dpkg [ Warning ] /usr/bin/dpkg-query [ Warning ] /usr/bin/du [ Warning ] /usr/bin/env [ Warning ] /usr/bin/file [ Warning ] /usr/bin/find [ Warning ] /usr/bin/GET [ Warning ] /usr/bin/groups [ Warning ] /usr/bin/head [ Warning ] /usr/bin/id [ Warning ] /usr/bin/killall [ Warning ] /usr/bin/last [ Warning ] /usr/bin/lastlog [ Warning ] /usr/bin/ldd [ Warning ] /usr/bin/less [ Warning ] /usr/bin/locate [ Warning ] /usr/bin/logger [ Warning ] /usr/bin/lsattr [ Warning ] /usr/bin/lsof [ Warning ] /usr/bin/lynx [ Warning ] /usr/bin/mail [ Warning ] /usr/bin/md5sum [ Warning ] /usr/bin/mlocate [ Warning ] /usr/bin/newgrp [ Warning ] /usr/bin/passwd [ Warning ] /usr/bin/perl [ Warning ] /usr/bin/pgrep [ Warning ] /usr/bin/pstree [ Warning ] /usr/bin/rkhunter [ Warning ] /usr/bin/runcon [ Warning ] /usr/bin/sha1sum [ Warning ] /usr/bin/sha224sum [ Warning ] /usr/bin/sha256sum [ Warning ] /usr/bin/sha384sum [ Warning ] /usr/bin/sha512sum [ Warning ] /usr/bin/size [ Warning ] /usr/bin/sort [ Warning ] /usr/bin/stat [ Warning ] /usr/bin/strings [ Warning ] /usr/bin/sudo [ Warning ] /usr/bin/tail [ Warning ] /usr/bin/test [ Warning ] /usr/bin/top [ Warning ] /usr/bin/touch [ Warning ] /usr/bin/tr [ Warning ] /usr/bin/uniq [ Warning ] /usr/bin/users [ Warning ] /usr/bin/vmstat [ Warning ] /usr/bin/w [ Warning ] /usr/bin/watch [ Warning ] /usr/bin/wc [ Warning ] /usr/bin/wget [ Warning ] /usr/bin/whatis [ Warning ] /usr/bin/whereis [ Warning ] /usr/bin/which [ Warning ] /usr/bin/who [ Warning ] /usr/bin/whoami [ Warning ] /usr/bin/unhide.rb [ Warning ] /usr/bin/gawk [ Warning ] /usr/bin/lwp-request [ Warning ] /usr/bin/bsd-mailx [ Warning ] /usr/bin/w.procps [ Warning ] /usr/bin/tcsh [ Warning ] /sbin/depmod [ Warning ] /sbin/fsck [ Warning ] /sbin/ifconfig [ Warning ] /sbin/ifdown [ Warning ] /sbin/ifup [ Warning ] /sbin/init [ Warning ] /sbin/insmod [ Warning ] /sbin/ip [ Warning ] /sbin/lsmod [ Warning ] /sbin/modinfo [ Warning ] /sbin/modprobe [ Warning ] /sbin/rmmod [ Warning ] /sbin/route [ Warning ] /sbin/runlevel [ Warning ] /sbin/sulogin [ Warning ] /sbin/sysctl [ Warning ] /sbin/syslogd [ Warning ] /bin/bash [ Warning ] /bin/cat [ Warning ] /bin/chmod [ Warning ] /bin/chown [ Warning ] /bin/cp [ Warning ] /bin/csh [ Warning ] /bin/date [ Warning ] /bin/df [ Warning ] /bin/dmesg [ Warning ] /bin/echo [ Warning ] /bin/ed [ Warning ] /bin/egrep [ Warning ] /bin/fgrep [ Warning ] /bin/fuser [ Warning ] /bin/grep [ Warning ] /bin/ip [ Warning ] /bin/kill [ Warning ] /bin/less [ Warning ] /bin/login [ Warning ] /bin/ls [ Warning ] /bin/lsmod [ Warning ] /bin/mktemp [ Warning ] /bin/more [ Warning ] /bin/mount [ Warning ] /bin/mv [ Warning ] /bin/netstat [ Warning ] /bin/ps [ Warning ] /bin/pwd [ Warning ] /bin/readlink [ Warning ] /bin/sed [ Warning ] /bin/sh [ Warning ] /bin/su [ Warning ] /bin/touch [ Warning ] /bin/uname [ Warning ] /bin/which [ Warning ] /bin/tcsh [ Warning ] /bin/dash [ Warning ] [Press <ENTER> to continue] # Checking for rootkits... Performing check of known rootkit files and directories 55808 Trojan - Variant A [ Not found ] ADM Worm [ Not found ] AjaKit Rootkit [ Not found ] Adore Rootkit [ Not found ] aPa Kit [ Not found ] Apache Worm [ Not found ] Ambient (ark) Rootkit [ Not found ] Balaur Rootkit [ Not found ] BeastKit Rootkit [ Not found ] beX2 Rootkit [ Not found ] BOBKit Rootkit [ Not found ] cb Rootkit [ Not found ] CiNIK Worm (Slapper.B variant) [ Not found ] Danny-Boy's Abuse Kit [ Not found ] Devil RootKit [ Not found ] Dica-Kit Rootkit [ Not found ] Dreams Rootkit [ Not found ] Duarawkz Rootkit [ Not found ] Enye LKM [ Not found ] Flea Linux Rootkit [ Not found ] FreeBSD Rootkit [ Not found ] Fu Rootkit [ Not found ] Fuck`it Rootkit [ Not found ] GasKit Rootkit [ Not found ] Heroin LKM [ Not found ] HjC Kit [ Not found ] ignoKit Rootkit [ Not found ] iLLogiC Rootkit [ Not found ] IntoXonia-NG Rootkit [ Not found ] Irix Rootkit [ Not found ] Kitko Rootkit [ Not found ] Knark Rootkit [ Not found ] ld-linuxv.so Rootkit [ Not found ] Li0n Worm [ Not found ] Lockit / LJK2 Rootkit [ Not found ] Mood-NT Rootkit [ Not found ] MRK Rootkit [ Not found ] Ni0 Rootkit [ Not found ] Ohhara Rootkit [ Not found ] Optic Kit (Tux) Worm [ Not found ] Oz Rootkit [ Not found ] Phalanx Rootkit [ Not found ] Phalanx2 Rootkit [ Not found ] Phalanx2 Rootkit (extended tests) [ Not found ] Portacelo Rootkit [ Not found ] R3dstorm Toolkit [ Not found ] RH-Sharpe's Rootkit [ Not found ] RSHA's Rootkit [ Not found ] Scalper Worm [ Not found ] Sebek LKM [ Not found ] Shutdown Rootkit [ Not found ] SHV4 Rootkit [ Not found ] SHV5 Rootkit [ Not found ] Sin Rootkit [ Not found ] Slapper Worm [ Not found ] Sneakin Rootkit [ Not found ] 'Spanish' Rootkit [ Not found ] Suckit Rootkit [ Not found ] SunOS Rootkit [ Not found ] SunOS / NSDAP Rootkit [ Not found ] Superkit Rootkit [ Not found ] TBD (Telnet BackDoor) [ Not found ] TeLeKiT Rootkit [ Not found ] T0rn Rootkit [ Not found ] trNkit Rootkit [ Not found ] Trojanit Kit [ Not found ] Tuxtendo Rootkit [ Not found ] URK Rootkit [ Not found ] Vampire Rootkit [ Not found ] VcKit Rootkit [ Not found ] Volc Rootkit [ Not found ] Xzibit Rootkit [ Not found ] X-Org SunOS Rootkit [ Not found ] zaRwT.KiT Rootkit [ Not found ] ZK Rootkit [ Not found ] Performing additional rootkit checks Suckit Rookit additional checks [ OK ] Checking for possible rootkit files and directories [ None found ] Checking for possible rootkit strings [ None found ] Performing malware checks Checking running processes for suspicious files [ None found ] Checking for login backdoors [ None found ] Checking for suspicious directories [ None found ] Checking for sniffer log files [ None found ] Performing trojan specific checks Checking for enabled xinetd services [ None found ] Checking for Apache backdoor [ Not found ] Performing Linux specific checks Checking loaded kernel modules [ Warning ] Checking kernel module names [ OK ] [Press <ENTER> to continue] Checking the network... Performing checks on the network ports Checking for backdoor ports [ None found ] Checking for hidden ports [ Skipped ] Performing checks on the network interfaces Checking for promiscuous interfaces [ None found ] Checking the local host... Performing system boot checks Checking for local host name [ Found ] Checking for system startup files [ Found ] Checking system startup files for malware [ None found ] Performing group and account checks Checking for passwd file [ Found ] Checking for root equivalent (UID 0) accounts [ None found ] Checking for passwordless accounts [ None found ] Checking for passwd file changes [ None found ] Checking for group file changes [ None found ] Checking root account shell history files [ OK ] Performing system configuration file checks Checking for SSH configuration file [ Found ] Checking if SSH root access is allowed [ Warning ] Checking if SSH protocol v1 is allowed [ Not allowed ] Checking for running syslog daemon [ Found ] Checking for syslog configuration file [ Found ] Checking if syslog remote logging is allowed [ Not allowed ] Performing filesystem checks Checking /dev for suspicious file types [ Warning ] Checking for hidden files and directories [ Warning ] [Press <ENTER> to continue] System checks summary ===================== File properties checks... Files checked: 138 Suspect files: 138 Rootkit checks... Rootkits checked : 246 Possible rootkits: 0 Applications checks... All checks skipped The system checks took: 1 minute and 5 seconds All results have been written to the log file (/var/log/rkhunter.log) One or more warnings have been found while checking the system. Please check the log file (/var/log/rkhunter.log) |
...hier der auszug der rkhunter.log:
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 | tail -n100 /var/log/rkhunter.log [00:56:22] Checking for TCP port 6666 [ Not found ] [00:56:22] Checking for TCP port 6667 [ Not found ] [00:56:23] Checking for TCP port 6668 [ Not found ] [00:56:23] Checking for TCP port 6669 [ Not found ] [00:56:23] Checking for TCP port 7000 [ Not found ] [00:56:23] Checking for TCP port 13000 [ Not found ] [00:56:23] Checking for TCP port 14856 [ Not found ] [00:56:23] Checking for TCP port 25000 [ Not found ] [00:56:23] Checking for TCP port 29812 [ Not found ] [00:56:23] Checking for TCP port 31337 [ Not found ] [00:56:23] Checking for TCP port 32982 [ Not found ] [00:56:23] Checking for TCP port 33369 [ Not found ] [00:56:23] Checking for TCP port 47107 [ Not found ] [00:56:23] Checking for TCP port 47018 [ Not found ] [00:56:23] Checking for TCP port 60922 [ Not found ] [00:56:23] Checking for TCP port 62883 [ Not found ] [00:56:23] Checking for TCP port 65535 [ Not found ] [00:56:24] Checking for backdoor ports [ None found ] [00:56:24] [00:56:24] Info: Starting test name 'hidden_ports' [00:56:24] Checking for hidden ports [ Skipped ] [00:56:24] Info: Unable to find the 'unhide-tcp' command [00:56:24] [00:56:24] Performing checks on the network interfaces [00:56:24] Info: Starting test name 'promisc' [00:56:24] Checking for promiscuous interfaces [ None found ] [00:56:24] [00:56:24] Info: Test 'packet_cap_apps' disabled at users request. [00:56:24] [00:56:24] Info: Starting test name 'local_host' [00:56:24] Checking the local host... [00:56:24] [00:56:24] Info: Starting test name 'startup_files' [00:56:24] Performing system boot checks [00:56:24] Checking for local host name [ Found ] [00:56:24] [00:56:24] Info: Starting test name 'startup_malware' [00:56:24] Checking for system startup files [ Found ] [00:56:24] Checking system startup files for malware [ None found ] [00:56:25] [00:56:25] Info: Starting test name 'group_accounts' [00:56:25] Performing group and account checks [00:56:25] Checking for passwd file [ Found ] [00:56:25] Info: Found password file: /etc/passwd [00:56:25] Checking for root equivalent (UID 0) accounts [ None found ] [00:56:25] Info: Found shadow file: /etc/shadow [00:56:25] Checking for passwordless accounts [ None found ] [00:56:25] [00:56:25] Info: Starting test name 'passwd_changes' [00:56:25] Checking for passwd file changes [ None found ] [00:56:25] [00:56:25] Info: Starting test name 'group_changes' [00:56:25] Checking for group file changes [ None found ] [00:56:25] Checking root account shell history files [ OK ] [00:56:25] [00:56:25] Info: Starting test name 'system_configs' [00:56:25] Performing system configuration file checks [00:56:25] Checking for SSH configuration file [ Found ] [00:56:25] Info: Found SSH configuration file: /etc/ssh/sshd_config [00:56:25] Info: Rkhunter option ALLOW_SSH_ROOT_USER set to 'no'. [00:56:25] Info: Rkhunter option ALLOW_SSH_PROT_V1 set to '0'. [00:56:25] Checking if SSH root access is allowed [ Warning ] [00:56:25] Warning: The SSH and rkhunter configuration options should be the same: [00:56:25] SSH configuration option 'PermitRootLogin': yes [00:56:25] Rkhunter configuration option 'ALLOW_SSH_ROOT_USER': no [00:56:25] Checking if SSH protocol v1 is allowed [ Not allowed ] [00:56:25] Checking for running syslog daemon [ Found ] [00:56:25] Info: Found syslog configuration file: /etc/syslog.conf [00:56:25] Checking for syslog configuration file [ Found ] [00:56:25] Checking if syslog remote logging is allowed [ Not allowed ] [00:56:25] [00:56:25] Info: Starting test name 'filesystem' [00:56:25] Performing filesystem checks [00:56:25] Info: SCAN_MODE_DEV set to 'THOROUGH' [00:56:25] Checking /dev for suspicious file types [ Warning ] [00:56:25] Warning: Suspicious file types found in /dev: [00:56:25] /dev/kmsg: ASCII text [00:56:25] Checking for hidden files and directories [ Warning ] [00:56:25] Warning: Hidden directory found: /dev/.udev [00:56:25] Warning: Hidden file found: /etc/.sysctl.conf.swp: Vim swap file, version 7.3 [00:56:29] [00:56:29] Info: Test 'apps' disabled at users request. [00:56:29] [00:56:29] System checks summary [00:56:29] ===================== [00:56:29] [00:56:29] File properties checks... [00:56:29] Files checked: 138 [00:56:29] Suspect files: 138 [00:56:29] [00:56:29] Rootkit checks... [00:56:29] Rootkits checked : 246 [00:56:29] Possible rootkits: 0 [00:56:29] [00:56:29] Applications checks... [00:56:29] All checks skipped [00:56:29] [00:56:29] The system checks took: 1 minute and 5 seconds [00:56:29] [00:56:29] Info: End date is Mon Jul 7 00:56:29 CEST 2014 |
..was meint ihr? Neuinstallation notwendig?? ☹