Package: rkhunter Version: 1.3.2-5 Filename: pool/main/r/rkhunter/rkhunter_1.3.2-5_all.deb Found error in /usr/bin/rkhunter: $ grep -A5 -B5 /tmp/ /usr/bin/rkhunter exit 0 fi fi if [ "$1" = "--debug" ]; then if [ -e "/tmp/rkhunter-debug" ]; then if [ -f "/tmp/rkhunter-debug" -a ! -h "/tmp/rkhunter-debug" ]; then rm -f /tmp/rkhunter-debug >/dev/null 2>&1 else echo "Cannot use '--debug' option. /tmp/rkhunter-debug already exists, but it is not a file." exit 1 fi fi DEBUG_OPT=1 exec 1>/tmp/rkhunter-debug 2>&1 set -x else DEBUG_OPT=0 fi -- # files and directories. # # 55808 Variant A W55808A_FILES="${RKHROOTDIR}/tmp/.../r ${RKHROOTDIR}/tmp/.../a" # AjaKit Rootkit AJAKIT_FILES="${RKHROOTDIR}/dev/tux/.addr ${RKHROOTDIR}/dev/tux/.proc -- ${RKHROOTDIR}/usr/lib/.../du ${RKHROOTDIR}/usr/lib/.../top" BOBKIT_DIRS="${RKHROOTDIR}/usr/lib/... ${RKHROOTDIR}/usr/lib/.../bkit-ssh ${RKHROOTDIR}/usr/lib/.bkit- ${RKHROOTDIR}/tmp/.bkp" # CiNIK Worm (Slapper.B variant) CINIK_FILES="${RKHROOTDIR}/tmp/.cinik" CINIK_DIRS="${RKHROOTDIR}/tmp/.font-unix/.cinik" # Danny-Boy's Abuse Kit DANNYBOYS_FILES="${RKHROOTDIR}/dev/mdev ${RKHROOTDIR}/usr/lib/libX.a" -- # Ni0 Rootkit NIO_FILES="${RKHROOTDIR}/var/lock/subsys/...datafile.../...net... ${RKHROOTDIR}/var/lock/subsys/...datafile.../...port... ${RKHROOTDIR}/var/lock/subsys/...datafile.../...ps... ${RKHROOTDIR}/var/lock/subsys/...datafile.../...file..." NIO_DIRS="${RKHROOTDIR}/tmp/waza ${RKHROOTDIR}/var/lock/subsys/...datafile... ${RKHROOTDIR}/usr/sbin/es" # Ohhara Rootkit -- ${RKHROOTDIR}/usr/man/man5/..%/.dir/scannah ${RKHROOTDIR}/etc/rc.d/rc0.d/..%/.dir" # Scalper (FreeBSD.Scalper.Worm) Worm SCALPER_FILES="${RKHROOTDIR}/tmp/.a ${RKHROOTDIR}/tmp/.uua" # SHV4 Rootkit SHV4_FILES="${RKHROOTDIR}/etc/ld.so.hash ${RKHROOTDIR}/lib/libext-2.so.7 -- ${RKHROOTDIR}/usr/lib/man1/... ${RKHROOTDIR}/dev/.haos" # Slapper Worm SLAPPER_FILES="${RKHROOTDIR}/tmp/.bugtraq ${RKHROOTDIR}/tmp/.uubugtraq ${RKHROOTDIR}/tmp/.bugtraq.c ${RKHROOTDIR}/tmp/httpd ${RKHROOTDIR}/tmp/.unlock ${RKHROOTDIR}/tmp/update ${RKHROOTDIR}/tmp/.cinik ${RKHROOTDIR}/tmp/.b" # Sneakin Rootkit SNEAKIN_DIRS="${RKHROOTDIR}/tmp/.X11-unix/.../rk" # Suckit Rootkit SUCKIT_FILES="${RKHROOTDIR}/sbin/initsk12 ${RKHROOTDIR}/sbin/initxrk -- # URK - Universal Rootkit URK_FILES="${RKHROOTDIR}/usr/man/man1/xxxxxxbin/find ${RKHROOTDIR}/usr/man/man1/xxxxxxbin/du ${RKHROOTDIR}/usr/man/man1/xxxxxxbin/ps ${RKHROOTDIR}/tmp/conf.inf" URK_DIRS="${RKHROOTDIR}/usr/man/man1/xxxxxxbin" # VcKit Rootkit VCKIT_DIRS="${RKHROOTDIR}/usr/include/linux/modules/lib.so -- rcfile:bin/xsf:Optic Kit (Tux) Worm" # Possible rootkit files and directories FILESCAN="file:${RKHROOTDIR}/dev/sdr0:Possible T0rn Rootkit MD5 hash database file:${RKHROOTDIR}/tmp/.syshackfile:Trojaned syslog daemon file:${RKHROOTDIR}/tmp/.bash_history:Possible Lite5-r Rootkit file:${RKHROOTDIR}/usr/info/.clib:Possible backdoor file:${RKHROOTDIR}/usr/sbin/tcp.log:Possible sniffer file:${RKHROOTDIR}/usr/bin/take/pid:Trojaned SSH daemon file:${RKHROOTDIR}/sbin/create:MzOzD Local backdoor file:${RKHROOTDIR}/dev/ttypz:spwn login backdoor