bonjour
rkhunter me dit que j’ai 7 fichiers suspects qui ont été modifiés, comment savoir si faux-positifs et si oui pourquoi ont ils été modifiés ? merci de m’expliquer si vous avez une idée
j’ai fais une mise à jour de 2011-11-06 08:59:36 upgrade linux-image-2.6.32-5-amd64 2.6.32-38 2.6.32-39 peut être l’explication
System checks summary
[14:40:51] =====================
[14:40:51]
[14:40:51] File properties checks...
[14:40:51] Files checked: 130
[14:40:51] Suspect files: 7
[14:40:52]
[14:40:52] Rootkit checks...
[14:40:52] Rootkits checked : 242
[14:40:52] Possible rootkits: 2
[14:40:52] Rootkit names : Xzibit Rootkit, Xzibit Rootkit
[code]
[14:38:48] /bin/lsmod [ Warning ]
[14:38:48] Warning: The file properties have changed:
[14:38:48] File: /bin/lsmod
[14:38:48] Current hash: 4e5e06443e62e2cd7d6c31728071195616d17e99
[14:38:48] Stored hash : 47309995cff1b9e2a8927ef3a174d50f02b92971
[14:38:48] Current inode: 663892 Stored inode: 654132
[14:38:48] Current file modification time: 1320008021 (30-oct.-2011 21:53:41)
[14:38:48] Stored file modification time : 1277676585 (28-juin-2010 00:09:45)
[14:38:48] /bin/mktemp [ OK ]
[14:38:58] /usr/bin/w.procps [ OK ]
[14:38:59] /sbin/depmod [ Warning ]
[14:38:59] Warning: The file properties have changed:
[14:38:59] File: /sbin/depmod
[14:38:59] Current hash: b4c91452dd43cbdf61c15594b81b55e9081b1c75
[14:38:59] Stored hash : 2a4717eba60ff98b92799da4b9190794e6ae9ed0
[14:38:59] Current inode: 130931 Stored inode: 130959
[14:38:59] Current file modification time: 1320008021 (30-oct.-2011 21:53:41)
[14:38:59] Stored file modification time : 1277676585 (28-juin-2010 00:09:45)
[14:38:59] /sbin/ifconfig [ OK ]
[14:38:59] /sbin/ifdown [ OK ]
[14:38:59] /sbin/ifup [ OK ]
[14:38:59] /sbin/init [ OK ]
[14:38:59] /sbin/insmod [ Warning ]
[14:38:59] Warning: The file properties have changed:
[14:38:59] File: /sbin/insmod
[14:38:59] Current hash: 29f705c993b0444cdfbb5b11d3750a27723fad39
[14:39:00] Stored hash : 3de1345e87c8305a6eb78e8dd3d9846a91a038e0
[14:39:00] Current inode: 142181 Stored inode: 130962
[14:39:00] Current file modification time: 1320008021 (30-oct.-2011 21:53:41)
[14:39:00] Stored file modification time : 1277676585 (28-juin-2010 00:09:45)
[14:39:00] /sbin/ip [ OK ]
[14:39:00] /sbin/lsmod [ Warning ]
[14:39:00] Warning: The file properties have changed:
[14:39:00] File: /sbin/lsmod
[14:39:00] Current hash: 4e5e06443e62e2cd7d6c31728071195616d17e99
[14:39:00] Stored hash : 47309995cff1b9e2a8927ef3a174d50f02b92971
[14:39:00] Current inode: 142183 Stored inode: 130964
[14:39:00] Current file modification time: 1320056928 (31-oct.-2011 11:28:48)
[14:39:00] Stored file modification time : 1312874561 (09-août-2011 09:22:41)
[14:39:00] /sbin/modinfo [ Warning ]
[14:39:00] Warning: The file properties have changed:
[14:39:00] File: /sbin/modinfo
[14:39:00] Current hash: aa2cf44d1af2fd1a8bd29af4d50bada18075c72f
[14:39:00] Stored hash : 9dbc8f57bfc334c485fc028ee4506b1a801d85d8
[14:39:00] Current inode: 142045 Stored inode: 130960
[14:39:00] Current file modification time: 1320008021 (30-oct.-2011 21:53:41)
[14:39:00] Stored file modification time : 1277676585 (28-juin-2010 00:09:45)
[14:39:01] /sbin/modprobe [ Warning ]
[14:39:01] Warning: The file properties have changed:
[14:39:01] File: /sbin/modprobe
[14:39:01] Current hash: 43acb30443be6280a989c07f50b59b9f74bf9b10
[14:39:01] Stored hash : 8d91c04795e930607e1c2c3f464a6a2f77ff42ad
[14:39:01] Current inode: 142055 Stored inode: 130961
[14:39:01] Current file modification time: 1320008021 (30-oct.-2011 21:53:41)
[14:39:01] Stored file modification time : 1277676585 (28-juin-2010 00:09:45)
[14:39:01] /sbin/rmmod [ Warning ]
[14:39:01] Warning: The file properties have changed:
[14:39:01] File: /sbin/rmmod
[14:39:01] Current hash: 2da3e80056e4754cb27601701d758293ee8d84a5
[14:39:01] Stored hash : dddda86f48fdcd2f983bc11bdd40c5fcf584fa23
[14:39:01] Current inode: 142182 Stored inode: 130963
[14:39:01] Current file modification time: 1320008021 (30-oct.-2011 21:53:41)
[14:39:01] Stored file modification time : 1277676585 (28-juin-2010 00:09:45)[/code]