Solved

Secuirty hack on centos

Posted on 2011-02-28
9
1,409 Views
Last Modified: 2012-05-11
Hi,

My website works perfectly fine for some time. but later it goes to read only mode which makes my website to stopped it works again as expected when restart but again after some time it goes to read only mode.
Some one told me that it has been hacked.
Please let me know how to check which script has been activated and how to rectify it and how to avoid such vulnerable attacks.

If any tool/notes available to check it would be appreciated.

Thanx
0
Comment
Question by:Insoftservice
  • 5
  • 4
9 Comments
 
LVL 15

Author Comment

by:Insoftservice
Comment Utility
Hi
Log file after using rkhunter tool.
[10:25:37] Running Rootkit Hunter version 1.3.8 on mail
[10:25:37]
[10:25:37] Info: Start date is Tue Mar  1 10:25:37 IST 2011
[10:25:37]
[10:25:37] Checking configuration file and command-line options...
[10:25:37] Info: Detected operating system is 'Linux'
[10:25:37] Info: Uname output is 'Linux abcd.in 2.6.18-194.26.1.el5 #1 SMP Tue Nov 9 12:54:40 EST 2010 i686 i686 i386 GNU/Linux'
[10:25:37] Info: Command line is /usr/local/bin/rkhunter -c
[10:25:38] Info: Environment shell is /bin/bash; rkhunter is using bash
[10:25:38] Info: Using configuration file '/usr/local/etc/rkhunter.conf'
[10:25:38] Info: Installation directory is '/usr/local'
[10:25:38] Info: Using language 'en'
[10:25:38] Info: Using '/var/lib/rkhunter/db' as the database directory
[10:25:38] Info: Using '/usr/local/lib/rkhunter/scripts' as the support script directory
[10:25:38] Info: Using '/usr/lib/qt-3.3/bin /usr/kerberos/sbin /usr/kerberos/bin /usr/local/sbin /usr/local/bin /sbin /bin /usr/sbin /usr/bin /usr/X11R6/bin /usr/libexec /usr/local/libexec' as the command directories
[10:25:38] Info: Using '/' as the root directory by default
[10:25:38] Info: Using '/var/lib/rkhunter/tmp' as the temporary directory
[10:25:38] Info: No mail-on-warning address configured
[10:25:38] Info: X will be automatically detected
[10:25:38] Info: Using second color set
[10:25:38] Info: Found the 'basename' command: /bin/basename
[10:25:38] Info: Found the 'diff' command: /usr/bin/diff
[10:25:38] Info: Found the 'dirname' command: /usr/bin/dirname
[10:25:38] Info: Found the 'file' command: /usr/bin/file
[10:25:38] Info: Found the 'find' command: /usr/bin/find
[10:25:38] Info: Found the 'ifconfig' command: /sbin/ifconfig
[10:25:38] Info: Found the 'ip' command: /sbin/ip
[10:25:38] Info: Found the 'ldd' command: /usr/bin/ldd
[10:25:38] Info: Found the 'lsattr' command: /usr/bin/lsattr
[10:25:38] Info: Found the 'lsmod' command: /sbin/lsmod
[10:25:38] Info: Found the 'lsof' command: /usr/sbin/lsof
[10:25:38] Info: Found the 'mktemp' command: /bin/mktemp
[10:25:38] Info: Found the 'netstat' command: /bin/netstat
[10:25:38] Info: Found the 'perl' command: /usr/bin/perl
[10:25:38] Info: Found the 'pgrep' command: /usr/bin/pgrep
[10:25:38] Info: Found the 'ps' command: /bin/ps
[10:25:38] Info: Found the 'pwd' command: /bin/pwd
[10:25:38] Info: Found the 'readlink' command: /usr/bin/readlink
[10:25:38] Info: Found the 'stat' command: /usr/bin/stat
[10:25:38] Info: Found the 'strings' command: /usr/bin/strings
[10:25:38] Info: System is using prelinking
[10:25:38] Info: Found the 'prelink' command: /usr/sbin/prelink
[10:25:38] Info: Found the 'sestatus' command: /usr/sbin/sestatus
[10:25:38] Info: SELinux is disabled
[10:25:38] Info: Using the prelink command (with SHA1) for the file hash checks
[10:25:38] Info: The hash function field index is set to 1
[10:25:38] Info: No package manager specified: using prelink command with 'SHA1'
[10:25:38] Info: Previous file attributes were stored
[10:25:38] Info: Enabled tests are: all
[10:25:38] Info: Disabled tests are: suspscan hidden_ports hidden_procs deleted_files packet_cap_apps
[10:25:38] Info: Including user files for file properties check:
[10:25:38]       /usr/local/etc/rkhunter.conf
[10:25:38] Info: Found ksym file '/proc/kallsyms'
[10:25:38] Info: Using 'date' to process epoch second times.
[10:25:38] Info: Locking is not being used
[10:25:38]
[10:25:38] Starting system checks...
[10:25:38]
[10:25:38] Info: Starting test name 'system_commands'
[10:25:38] Checking system commands...
[10:25:39]
[10:25:39] Info: Starting test name 'strings'
[10:25:39] Performing 'strings' command checks
[10:25:39]   Scanning for string /usr/sbin/ntpsx             [ OK ]
[10:25:39]   Scanning for string /usr/sbin/.../bkit-ava      [ OK ]
[10:25:39]   Scanning for string /usr/sbin/.../bkit-d        [ OK ]
[10:25:39]   Scanning for string /usr/sbin/.../bkit-shd      [ OK ]
[10:25:39]   Scanning for string /usr/sbin/.../bkit-f        [ OK ]
[10:25:39]   Scanning for string /usr/include/.../proc.h     [ OK ]
[10:25:39]   Scanning for string /usr/include/.../.bash_history [ OK ]
[10:25:39]   Scanning for string /usr/include/.../bkit-get   [ OK ]
[10:25:39]   Scanning for string /usr/include/.../bkit-dl    [ OK ]
[10:25:39]   Scanning for string /usr/include/.../bkit-screen [ OK ]
[10:25:39]   Scanning for string /usr/include/.../bkit-sleep [ OK ]
[10:25:39]   Scanning for string /usr/lib/.../bkit-adore.o   [ OK ]
[10:25:39]   Scanning for string /usr/lib/.../ls             [ OK ]
[10:25:39]   Scanning for string /usr/lib/.../netstat        [ OK ]
[10:25:39]   Scanning for string /usr/lib/.../lsof           [ OK ]
[10:25:40]   Scanning for string /usr/lib/.../bkit-ssh/bkit-shdcfg [ OK ]
[10:25:40]   Scanning for string /usr/lib/.../bkit-ssh/bkit-shhk [ OK ]
[10:25:40]   Scanning for string /usr/lib/.../bkit-ssh/bkit-pw [ OK ]
[10:25:40]   Scanning for string /usr/lib/.../bkit-ssh/bkit-shrs [ OK ]
[10:25:40]   Scanning for string /usr/lib/.../bkit-ssh/bkit-mots [ OK ]
[10:25:40]   Scanning for string /usr/lib/.../uconf.inv      [ OK ]
[10:25:40]   Scanning for string /usr/lib/.../psr            [ OK ]
[10:25:40]   Scanning for string /usr/lib/.../find           [ OK ]
[10:25:40]   Scanning for string /usr/lib/.../pstree         [ OK ]
[10:25:40]   Scanning for string /usr/lib/.../slocate        [ OK ]
[10:25:40]   Scanning for string /usr/lib/.../du             [ OK ]
[10:25:40]   Scanning for string /usr/lib/.../top            [ OK ]
[10:25:40]   Scanning for string /usr/sbin/...               [ OK ]
[10:25:40]   Scanning for string /usr/include/...            [ OK ]
[10:25:40]   Scanning for string /usr/include/.../.tmp       [ OK ]
[10:25:40]   Scanning for string /usr/lib/...                [ OK ]
[10:25:40]   Scanning for string /usr/lib/.../.ssh           [ OK ]
[10:25:40]   Scanning for string /usr/lib/.../bkit-ssh       [ OK ]
[10:25:40]   Scanning for string /usr/lib/.bkit-             [ OK ]
[10:25:40]   Scanning for string /tmp/.bkp                   [ OK ]
[10:25:41]   Scanning for string /tmp/.cinik                 [ OK ]
[10:25:41]   Scanning for string /tmp/.font-unix/.cinik      [ OK ]
[10:25:41]   Scanning for string /lib/.sso                   [ OK ]
[10:25:41]   Scanning for string /lib/.so                    [ OK ]
[10:25:41]   Scanning for string /var/run/...dica/clean      [ OK ]
[10:25:41]   Scanning for string /var/run/...dica/dxr        [ OK ]
[10:25:41]   Scanning for string /var/run/...dica/read       [ OK ]
[10:25:41]   Scanning for string /var/run/...dica/write      [ OK ]
[10:25:41]   Scanning for string /var/run/...dica/lf         [ OK ]
[10:25:41]   Scanning for string /var/run/...dica/xl         [ OK ]
[10:25:41]   Scanning for string /var/run/...dica/xdr        [ OK ]
[10:25:41]   Scanning for string /var/run/...dica/psg        [ OK ]
[10:25:41]   Scanning for string /var/run/...dica/secure     [ OK ]
[10:25:41]   Scanning for string /var/run/...dica/rdx        [ OK ]
[10:25:41]   Scanning for string /var/run/...dica/va         [ OK ]
[10:25:41]   Scanning for string /var/run/...dica/cl.sh      [ OK ]
[10:25:41]   Scanning for string /var/run/...dica/last.log   [ OK ]
[10:25:41]   Scanning for string /usr/bin/.etc               [ OK ]
[10:25:41]   Scanning for string /etc/sshd_config            [ OK ]
[10:25:41]   Scanning for string /etc/ssh_host_key           [ OK ]
[10:25:41]   Scanning for string /etc/ssh_random_seed        [ OK ]
[10:25:41]   Scanning for string /dev/ptyp                   [ OK ]
[10:25:41]   Scanning for string /dev/ptyq                   [ OK ]
[10:25:41]   Scanning for string /dev/ptyr                   [ OK ]
[10:25:41]   Scanning for string /dev/ptys                   [ OK ]
[10:25:41]   Scanning for string /dev/ptyt                   [ OK ]
[10:25:41]   Scanning for string /dev/fd/.88/freshb-bsd      [ OK ]
[10:25:41]   Scanning for string /dev/fd/.88/fresht          [ OK ]
[10:25:42]   Scanning for string /dev/fd/.88/zxsniff         [ OK ]
[10:25:42]   Scanning for string /dev/fd/.88/zxsniff.log     [ OK ]
[10:25:42]   Scanning for string /dev/fd/.99/.ttyf00         [ OK ]
[10:25:42]   Scanning for string /dev/fd/.99/.ttyp00         [ OK ]
[10:25:42]   Scanning for string /dev/fd/.99/.ttyq00         [ OK ]
[10:25:42]   Scanning for string /dev/fd/.99/.ttys00         [ OK ]
[10:25:42]   Scanning for string /dev/fd/.99/.pwsx00         [ OK ]
[10:25:42]   Scanning for string /etc/.acid                  [ OK ]
[10:25:42]   Scanning for string /usr/lib/.fx/sched_host.2   [ OK ]
[10:25:42]   Scanning for string /usr/lib/.fx/random_d.2     [ OK ]
[10:25:42]   Scanning for string /usr/lib/.fx/set_pid.2      [ OK ]
[10:25:42]   Scanning for string /usr/lib/.fx/setrgrp.2      [ OK ]
[10:25:42]   Scanning for string /usr/lib/.fx/TOHIDE         [ OK ]
[10:25:42]   Scanning for string /usr/lib/.fx/cons.saver     [ OK ]
[10:25:42]   Scanning for string /usr/lib/.fx/adore/ava/ava  [ OK ]
[10:25:42]   Scanning for string /usr/lib/.fx/adore/adore/adore.ko [ OK ]
[10:25:42]   Scanning for string /bin/sysback                [ OK ]
[10:25:42]   Scanning for string /usr/local/bin/sysback      [ OK ]
[10:25:42]   Scanning for string /usr/lib/.tbd               [ OK ]
[10:25:42]   Scanning for string /dev/.lib/lib/lib/t0rns     [ OK ]
[10:25:42]   Scanning for string /dev/.lib/lib/lib/du        [ OK ]
[10:25:42]   Scanning for string /dev/.lib/lib/lib/ls        [ OK ]
[10:25:42]   Scanning for string /dev/.lib/lib/lib/t0rnsb    [ OK ]
[10:25:42]   Scanning for string /dev/.lib/lib/lib/ps        [ OK ]
[10:25:42]   Scanning for string /dev/.lib/lib/lib/t0rnp     [ OK ]
[10:25:42]   Scanning for string /dev/.lib/lib/lib/find      [ OK ]
[10:25:42]   Scanning for string /dev/.lib/lib/lib/ifconfig  [ OK ]
[10:25:43]   Scanning for string /dev/.lib/lib/lib/pg        [ OK ]
[10:25:43]   Scanning for string /dev/.lib/lib/lib/ssh.tgz   [ OK ]
[10:25:43]   Scanning for string /dev/.lib/lib/lib/top       [ OK ]
[10:25:43]   Scanning for string /dev/.lib/lib/lib/sz        [ OK ]
[10:25:43]   Scanning for string /dev/.lib/lib/lib/login     [ OK ]
[10:25:43]   Scanning for string /dev/.lib/lib/lib/in.fingerd [ OK ]
[10:25:43]   Scanning for string /dev/.lib/lib/lib/1i0n.sh   [ OK ]
[10:25:43]   Scanning for string /dev/.lib/lib/lib/pstree    [ OK ]
[10:25:43]   Scanning for string /dev/.lib/lib/lib/in.telnetd [ OK ]
[10:25:43]   Scanning for string /dev/.lib/lib/lib/mjy       [ OK ]
[10:25:43]   Scanning for string /dev/.lib/lib/lib/sush      [ OK ]
[10:25:43]   Scanning for string /dev/.lib/lib/lib/tfn       [ OK ]
[10:25:43]   Scanning for string /dev/.lib/lib/lib/name      [ OK ]
[10:25:43]   Scanning for string /dev/.lib/lib/lib/getip.sh  [ OK ]
[10:25:43]   Scanning for string /usr/info/.torn/sh*         [ OK ]
[10:25:43]   Scanning for string /usr/src/.puta/.1addr       [ OK ]
[10:25:43]   Scanning for string /usr/src/.puta/.1file       [ OK ]
[10:25:43]   Scanning for string /usr/src/.puta/.1proc       [ OK ]
[10:25:43]   Scanning for string /usr/src/.puta/.1logz       [ OK ]
[10:25:43]   Scanning for string /usr/info/.t0rn             [ OK ]
[10:25:43]   Scanning for string /dev/.lib                   [ OK ]
[10:25:43]   Scanning for string /dev/.lib/lib               [ OK ]
[10:25:43]   Scanning for string /dev/.lib/lib/lib           [ OK ]
[10:25:43]   Scanning for string /dev/.lib/lib/lib/dev       [ OK ]
[10:25:43]   Scanning for string /dev/.lib/lib/scan          [ OK ]
[10:25:43]   Scanning for string /usr/src/.puta              [ OK ]
[10:25:43]   Scanning for string /usr/man/man1/man1          [ OK ]
[10:25:43]   Scanning for string /usr/man/man1/man1/lib      [ OK ]
[10:25:43]   Scanning for string /usr/man/man1/man1/lib/.lib [ OK ]
[10:25:44]   Scanning for string /usr/man/man1/man1/lib/.lib/.backup [ OK ]
[10:25:44]
[10:25:44] Info: Starting test name 'shared_libs'
[10:25:44] Performing 'shared libraries' checks
[10:25:44]   Checking for preloading variables               [ None found ]
[10:25:44]   Checking for preloaded libraries                [ None found ]
[10:25:44]
[10:25:44] Info: Starting test name 'shared_libs_path'
[10:25:44]   Checking LD_LIBRARY_PATH variable               [ Not found ]
[10:25:44]
[10:25:44] Info: Starting test name 'properties'
[10:25:44] Performing file properties checks
[10:25:44] Warning: Checking for prerequisites               [ Warning ]
[10:25:44]          The file of stored file properties (rkhunter.dat) does not exist, and should be created. To do this type in 'rkhunter --propupd'.
[10:25:44] Info: The file properties check will still run as there are checks that can be performed without the rkhunter.dat file.
[10:25:44]
[10:25:44] Warning: WARNING! It is the users responsibility to ensure that when the '--propupd' option
           is used, all the files on their system are known to be genuine, and installed from a
           reliable source. The rkhunter '--check' option will compare the current file properties
           against previously stored values, and report if any values differ. However, rkhunter
           cannot determine what has caused the change, that is for the user to do.
[10:25:44]   /usr/local/bin/rkhunter                         [ OK ]
[10:25:45]   /sbin/chkconfig                                 [ OK ]
[10:25:45]   /sbin/depmod                                    [ OK ]
[10:25:45]   /sbin/fsck                                      [ OK ]
[10:25:45]   /sbin/fuser                                     [ OK ]
[10:25:45]   /sbin/ifconfig                                  [ OK ]
[10:25:45]   /sbin/ifdown                                    [ Warning ]
[10:25:45] Warning: The command '/sbin/ifdown' has been replaced by a script: /sbin/ifdown: Bourne-Again shell script text executable
[10:25:45]   /sbin/ifup                                      [ Warning ]
[10:25:45] Warning: The command '/sbin/ifup' has been replaced by a script: /sbin/ifup: Bourne-Again shell script text executable
[10:25:45]   /sbin/init                                      [ OK ]
[10:25:45]   /sbin/insmod                                    [ OK ]
[10:25:45]   /sbin/ip                                        [ OK ]
[10:25:45]   /sbin/kudzu                                     [ OK ]
[10:25:46]   /sbin/lsmod                                     [ OK ]
[10:25:46]   /sbin/modinfo                                   [ OK ]
[10:25:46]   /sbin/modprobe                                  [ OK ]
[10:25:46]   /sbin/nologin                                   [ OK ]
[10:25:46]   /sbin/rmmod                                     [ OK ]
[10:25:46]   /sbin/route                                     [ OK ]
[10:25:46]   /sbin/runlevel                                  [ OK ]
[10:25:46]   /sbin/sulogin                                   [ OK ]
[10:25:46]   /sbin/sysctl                                    [ OK ]
[10:25:46]   /sbin/syslogd                                   [ OK ]
[10:25:46]   /bin/awk                                        [ OK ]
[10:25:47]   /bin/basename                                   [ OK ]
[10:25:47]   /bin/bash                                       [ OK ]
[10:25:47]   /bin/cat                                        [ OK ]
[10:25:47]   /bin/chmod                                      [ OK ]
[10:25:47]   /bin/chown                                      [ OK ]
[10:25:47]   /bin/cp                                         [ OK ]
[10:25:47]   /bin/csh                                        [ OK ]
[10:25:47]   /bin/cut                                        [ OK ]
[10:25:47]   /bin/date                                       [ OK ]
[10:25:47]   /bin/df                                         [ OK ]
[10:25:47]   /bin/dmesg                                      [ OK ]
[10:25:47]   /bin/echo                                       [ OK ]
[10:25:48]   /bin/ed                                         [ OK ]
[10:25:48]   /bin/egrep                                      [ OK ]
[10:25:48]   /bin/env                                        [ OK ]
[10:25:48]   /bin/fgrep                                      [ OK ]
[10:25:48]   /bin/grep                                       [ OK ]
[10:25:48]   /bin/kill                                       [ OK ]
[10:25:48]   /bin/logger                                     [ OK ]
[10:25:48]   /bin/login                                      [ OK ]
[10:25:48]   /bin/ls                                         [ OK ]
[10:25:48]   /bin/mail                                       [ OK ]
[10:25:48]   /bin/mktemp                                     [ OK ]
[10:25:48]   /bin/more                                       [ OK ]
[10:25:48]   /bin/mount                                      [ OK ]
[10:25:49]   /bin/mv                                         [ OK ]
[10:25:49]   /bin/netstat                                    [ OK ]
[10:25:49]   /bin/ps                                         [ OK ]
[10:25:49]   /bin/pwd                                        [ OK ]
[10:25:49]   /bin/rpm                                        [ OK ]
[10:25:49]   /bin/sed                                        [ OK ]
[10:25:49]   /bin/sh                                         [ OK ]
[10:25:49]   /bin/sort                                       [ OK ]
[10:25:49]   /bin/su                                         [ OK ]
[10:25:49]   /bin/touch                                      [ OK ]
[10:25:49]   /bin/uname                                      [ OK ]
[10:25:50]   /bin/gawk                                       [ OK ]
[10:25:50]   /bin/tcsh                                       [ OK ]
[10:25:50]   /usr/sbin/adduser                               [ OK ]
[10:25:50]   /usr/sbin/amd                                   [ OK ]
[10:25:50]   /usr/sbin/chroot                                [ OK ]
[10:25:50]   /usr/sbin/groupadd                              [ OK ]
[10:25:50]   /usr/sbin/groupdel                              [ OK ]
[10:25:50]   /usr/sbin/groupmod                              [ OK ]
[10:25:50]   /usr/sbin/grpck                                 [ OK ]
[10:25:50]   /usr/sbin/kudzu                                 [ OK ]
[10:25:50]   /usr/sbin/lsof                                  [ OK ]
[10:25:50]   /usr/sbin/prelink                               [ OK ]
[10:25:50]   /usr/sbin/pwck                                  [ OK ]
[10:25:50]   /usr/sbin/sestatus                              [ OK ]
[10:25:50]   /usr/sbin/tcpd                                  [ OK ]
[10:25:50]   /usr/sbin/useradd                               [ OK ]
[10:25:51]   /usr/sbin/userdel                               [ OK ]
[10:25:51]   /usr/sbin/usermod                               [ OK ]
[10:25:51]   /usr/sbin/vipw                                  [ OK ]
[10:25:51]   /usr/sbin/xinetd                                [ OK ]
[10:25:51]   /usr/bin/awk                                    [ OK ]
[10:25:51]   /usr/bin/chattr                                 [ OK ]
[10:25:51]   /usr/bin/curl                                   [ OK ]
[10:25:51]   /usr/bin/cut                                    [ OK ]
[10:25:51]   /usr/bin/diff                                   [ OK ]
[10:25:51]   /usr/bin/dirname                                [ OK ]
[10:25:51]   /usr/bin/du                                     [ OK ]
[10:25:52]   /usr/bin/elinks                                 [ OK ]
[10:25:52]   /usr/bin/env                                    [ OK ]
[10:25:52]   /usr/bin/file                                   [ OK ]
[10:25:52]   /usr/bin/find                                   [ OK ]
[10:25:52]   /usr/bin/GET                                    [ Warning ]
[10:25:52] Warning: The command '/usr/bin/GET' has been replaced by a script: /usr/bin/GET: perl script text executable
[10:25:52]   /usr/bin/groups                                 [ Warning ]
[10:25:52] Warning: The command '/usr/bin/groups' has been replaced by a script: /usr/bin/groups: Bourne shell script text executable
[10:25:52]   /usr/bin/head                                   [ OK ]
[10:25:52]   /usr/bin/id                                     [ OK ]
[10:25:52]   /usr/bin/kill                                   [ OK ]
[10:25:52]   /usr/bin/killall                                [ OK ]
[10:25:52]   /usr/bin/last                                   [ OK ]
[10:25:52]   /usr/bin/lastlog                                [ OK ]
[10:25:53]   /usr/bin/ldd                                    [ Warning ]
[10:25:53] Warning: The command '/usr/bin/ldd' has been replaced by a script: /usr/bin/ldd: Bourne shell script text executable
[10:25:53]   /usr/bin/less                                   [ OK ]
[10:25:53]   /usr/bin/links                                  [ OK ]
[10:25:53]   /usr/bin/locate                                 [ OK ]
[10:25:53]   /usr/bin/logger                                 [ OK ]
[10:25:53]   /usr/bin/lsattr                                 [ OK ]
[10:25:53]   /usr/bin/lynx                                   [ OK ]
[10:25:53]   /usr/bin/md5sum                                 [ OK ]
[10:25:53]   /usr/bin/newgrp                                 [ OK ]
[10:25:53]   /usr/bin/passwd                                 [ OK ]
[10:25:53]   /usr/bin/perl                                   [ OK ]
[10:25:53]   /usr/bin/pgrep                                  [ OK ]
[10:25:54]   /usr/bin/pstree                                 [ OK ]
[10:25:54]   /usr/bin/readlink                               [ OK ]
[10:25:54]   /usr/bin/runcon                                 [ OK ]
[10:25:54]   /usr/bin/sha1sum                                [ OK ]
[10:25:54]   /usr/bin/sha224sum                              [ OK ]
[10:25:54]   /usr/bin/sha256sum                              [ OK ]
[10:25:54]   /usr/bin/sha384sum                              [ OK ]
[10:25:54]   /usr/bin/sha512sum                              [ OK ]
[10:25:54]   /usr/bin/size                                   [ OK ]
[10:25:54]   /usr/bin/stat                                   [ OK ]
[10:25:54]   /usr/bin/strace                                 [ OK ]
[10:25:55]   /usr/bin/strings                                [ OK ]
[10:25:55]   /usr/bin/sudo                                   [ OK ]
[10:25:55]   /usr/bin/tail                                   [ OK ]
[10:25:55]   /usr/bin/test                                   [ OK ]
[10:25:55]   /usr/bin/top                                    [ OK ]
[10:25:55]   /usr/bin/tr                                     [ OK ]
[10:25:55]   /usr/bin/uniq                                   [ OK ]
[10:25:55]   /usr/bin/users                                  [ OK ]
[10:25:55]   /usr/bin/vmstat                                 [ OK ]
[10:25:55]   /usr/bin/w                                      [ OK ]
[10:25:55]   /usr/bin/watch                                  [ OK ]
[10:25:55]   /usr/bin/wc                                     [ OK ]
[10:25:56]   /usr/bin/wget                                   [ OK ]
[10:25:56]   /usr/bin/whatis                                 [ Warning ]
[10:25:56] Warning: The command '/usr/bin/whatis' has been replaced by a script: /usr/bin/whatis: Bourne shell script text executable
[10:25:56]   /usr/bin/whereis                                [ OK ]
[10:25:56]   /usr/bin/which                                  [ OK ]
[10:25:56]   /usr/bin/who                                    [ OK ]
[10:25:56]   /usr/bin/whoami                                 [ OK ]
[10:25:56]   /usr/bin/gawk                                   [ OK ]
[10:25:56]   /usr/local/etc/rkhunter.conf                    [ OK ]
[10:26:10]
[10:26:10] Info: Starting test name 'rootkits'
[10:26:10] Checking for rootkits...
[10:26:10]
[10:26:10] Info: Starting test name 'known_rkts'
[10:26:10] Performing check of known rootkit files and directories
[10:26:10]
[10:26:10] Checking for 55808 Trojan - Variant A...
[10:26:10]   Checking for file '/tmp/.../r'                  [ Not found ]
[10:26:11]   Checking for file '/tmp/.../a'                  [ Not found ]
[10:26:11] 55808 Trojan - Variant A                          [ Not found ]
[10:26:11]
[10:26:11] Checking for ADM Worm...
[10:26:11]   Checking for string 'w0rm'                      [ Not found ]
[10:26:11] ADM Worm                                          [ Not found ]
[10:26:11]
[10:26:11] Checking for AjaKit Rootkit...
[10:26:11]   Checking for file '/dev/tux/.addr'              [ Not found ]
[10:26:11]   Checking for file '/dev/tux/.proc'              [ Not found ]
[10:26:11]   Checking for file '/dev/tux/.file'              [ Not found ]
[10:26:11]   Checking for file '/lib/.libgh-gh/cleaner'      [ Not found ]
[10:26:11]   Checking for file '/lib/.libgh-gh/Patch/patch'  [ Not found ]
[10:26:11]   Checking for file '/lib/.libgh-gh/sb0k'         [ Not found ]
[10:26:11]   Checking for directory '/dev/tux'               [ Not found ]
[10:26:11]   Checking for directory '/lib/.libgh-gh'         [ Not found ]
[10:26:11] AjaKit Rootkit                                    [ Not found ]
[10:26:11]
[10:26:11] Checking for Adore Rootkit...
[10:26:11]   Checking for file '/usr/secure'                 [ Not found ]
[10:26:11]   Checking for file '/usr/doc/sys/qrt'            [ Not found ]
[10:26:11]   Checking for file '/usr/doc/sys/run'            [ Not found ]
[10:26:11]   Checking for file '/usr/doc/sys/crond'          [ Not found ]
[10:26:11]   Checking for file '/usr/sbin/kfd'               [ Not found ]
[10:26:12]   Checking for file '/usr/doc/kern/var'           [ Not found ]
[10:26:12]   Checking for file '/usr/doc/kern/string.o'      [ Not found ]
[10:26:12]   Checking for file '/usr/doc/kern/ava'           [ Not found ]
[10:26:12]   Checking for file '/usr/doc/kern/adore.o'       [ Not found ]
[10:26:12]   Checking for file '/var/log/ssh/old'            [ Not found ]
[10:26:12]   Checking for directory '/lib/security/.config/ssh' [ Not found ]
[10:26:12]   Checking for directory '/usr/doc/kern'          [ Not found ]
[10:26:12]   Checking for directory '/usr/doc/backup'        [ Not found ]
[10:26:12]   Checking for directory '/usr/doc/backup/txt'    [ Not found ]
[10:26:12]   Checking for directory '/lib/backup'            [ Not found ]
[10:26:12]   Checking for directory '/lib/backup/txt'        [ Not found ]
[10:26:12]   Checking for directory '/usr/doc/work'          [ Not found ]
[10:26:12]   Checking for directory '/usr/doc/sys'           [ Not found ]
[10:26:12]   Checking for directory '/var/log/ssh'           [ Not found ]
[10:26:12]   Checking for directory '/usr/doc/.spool'        [ Not found ]
[10:26:12]   Checking for directory '/usr/lib/kterm'         [ Not found ]
[10:26:12] Adore Rootkit                                     [ Not found ]
[10:26:12]
[10:26:12] Checking for aPa Kit...
[10:26:12]   Checking for file '/usr/share/.aPa'             [ Not found ]
[10:26:12] aPa Kit                                           [ Not found ]
[10:26:13]
[10:26:13] Checking for Apache Worm...
[10:26:13]   Checking for file '/bin/.log'                   [ Not found ]
[10:26:13] Apache Worm                                       [ Not found ]
[10:26:13]
[10:26:13] Checking for Ambient (ark) Rootkit...
[10:26:13]   Checking for file '/usr/lib/.ark?'              [ Not found ]
[10:26:13]   Checking for file '/dev/ptyxx/.log'             [ Not found ]
[10:26:13]   Checking for file '/dev/ptyxx/.file'            [ Not found ]
[10:26:13]   Checking for file '/dev/ptyxx/.proc'            [ Not found ]
[10:26:13]   Checking for file '/dev/ptyxx/.addr'            [ Not found ]
[10:26:13]   Checking for directory '/dev/ptyxx'             [ Not found ]
[10:26:13] Ambient (ark) Rootkit                             [ Not found ]
[10:26:13]
[10:26:13] Checking for Balaur Rootkit...
[10:26:13]   Checking for file '/usr/lib/liblog.o'           [ Not found ]
[10:26:13]   Checking for directory '/usr/lib/.kinetic'      [ Not found ]
[10:26:13]   Checking for directory '/usr/lib/.egcs'         [ Not found ]
[10:26:13]   Checking for directory '/usr/lib/.wormie'       [ Not found ]
[10:26:13] Balaur Rootkit                                    [ Not found ]
[10:26:13]
[10:26:13] Checking for BeastKit Rootkit...
[10:26:13]   Checking for file '/usr/sbin/arobia'            [ Not found ]
[10:26:13]   Checking for file '/usr/sbin/idrun'             [ Not found ]
[10:26:13]   Checking for file '/usr/lib/elm/arobia/elm'     [ Not found ]
[10:26:14]   Checking for file '/usr/lib/elm/arobia/elm/hk'  [ Not found ]
[10:26:14]   Checking for file '/usr/lib/elm/arobia/elm/hk.pub' [ Not found ]
[10:26:14]   Checking for file '/usr/lib/elm/arobia/elm/sc'  [ Not found ]
[10:26:14]   Checking for file '/usr/lib/elm/arobia/elm/sd.pp' [ Not found ]
[10:26:14]   Checking for file '/usr/lib/elm/arobia/elm/sdco' [ Not found ]
[10:26:14]   Checking for file '/usr/lib/elm/arobia/elm/srsd' [ Not found ]
[10:26:14]   Checking for directory '/lib/ldd.so/bktools'    [ Not found ]
[10:26:14] BeastKit Rootkit                                  [ Not found ]
[10:26:14]
[10:26:14] Checking for beX2 Rootkit...
[10:26:14]   Checking for file '/usr/info/termcap.info-5.gz' [ Not found ]
[10:26:14]   Checking for file '/usr/bin/sshd2'              [ Not found ]
[10:26:14]   Checking for directory '/usr/include/bex'       [ Not found ]
[10:26:14] beX2 Rootkit                                      [ Not found ]
[10:26:14]
[10:26:14] Checking for BOBKit Rootkit...
[10:26:14]   Checking for file '/usr/sbin/ntpsx'             [ Not found ]
[10:26:14]   Checking for file '/usr/sbin/.../bkit-ava'      [ Not found ]
[10:26:14]   Checking for file '/usr/sbin/.../bkit-d'        [ Not found ]
[10:26:14]   Checking for file '/usr/sbin/.../bkit-shd'      [ Not found ]
[10:26:14]   Checking for file '/usr/sbin/.../bkit-f'        [ Not found ]
[10:26:14]   Checking for file '/usr/include/.../proc.h'     [ Not found ]
[10:26:15]   Checking for file '/usr/include/.../.bash_history' [ Not found ]
[10:26:15]   Checking for file '/usr/include/.../bkit-get'   [ Not found ]
[10:26:15]   Checking for file '/usr/include/.../bkit-dl'    [ Not found ]
[10:26:15]   Checking for file '/usr/include/.../bkit-screen' [ Not found ]
[10:26:15]   Checking for file '/usr/include/.../bkit-sleep' [ Not found ]
[10:26:15]   Checking for file '/usr/lib/.../bkit-adore.o'   [ Not found ]
[10:26:15]   Checking for file '/usr/lib/.../ls'             [ Not found ]
[10:26:15]   Checking for file '/usr/lib/.../netstat'        [ Not found ]
[10:26:15]   Checking for file '/usr/lib/.../lsof'           [ Not found ]
[10:26:15]   Checking for file '/usr/lib/.../bkit-ssh/bkit-shdcfg' [ Not found ]
[10:26:15]   Checking for file '/usr/lib/.../bkit-ssh/bkit-shhk' [ Not found ]
[10:26:15]   Checking for file '/usr/lib/.../bkit-ssh/bkit-pw' [ Not found ]
[10:26:15]   Checking for file '/usr/lib/.../bkit-ssh/bkit-shrs' [ Not found ]
[10:26:15]   Checking for file '/usr/lib/.../bkit-ssh/bkit-mots' [ Not found ]
[10:26:15]   Checking for file '/usr/lib/.../uconf.inv'      [ Not found ]
[10:26:15]   Checking for file '/usr/lib/.../psr'            [ Not found ]
[10:26:15]   Checking for file '/usr/lib/.../find'           [ Not found ]
[10:26:15]   Checking for file '/usr/lib/.../pstree'         [ Not found ]
[10:26:15]   Checking for file '/usr/lib/.../slocate'        [ Not found ]
[10:26:15]   Checking for file '/usr/lib/.../du'             [ Not found ]
[10:26:16]   Checking for file '/usr/lib/.../top'            [ Not found ]
[10:26:16]   Checking for directory '/usr/sbin/...'          [ Not found ]
[10:26:16]   Checking for directory '/usr/include/...'       [ Not found ]
[10:26:16]   Checking for directory '/usr/include/.../.tmp'  [ Not found ]
[10:26:16]   Checking for directory '/usr/lib/...'           [ Not found ]
[10:26:16]   Checking for directory '/usr/lib/.../.ssh'      [ Not found ]
[10:26:16]   Checking for directory '/usr/lib/.../bkit-ssh'  [ Not found ]
[10:26:16]   Checking for directory '/usr/lib/.bkit-'        [ Not found ]
[10:26:16]   Checking for directory '/tmp/.bkp'              [ Not found ]
[10:26:16] BOBKit Rootkit                                    [ Not found ]
[10:26:16]
[10:26:16] Checking for cb Rootkit...
[10:26:16]   Checking for file '/dev/srd0'                   [ Not found ]
[10:26:16]   Checking for file '/lib/libproc.so.2.0.6'       [ Not found ]
[10:26:16]   Checking for file '/dev/mounnt'                 [ Not found ]
[10:26:16]   Checking for file '/etc/rc.d/init.d/init'       [ Not found ]
[10:26:16]   Checking for file '/usr/bin/.zeen/.. /cl'       [ Not found ]
[10:26:16]   Checking for file '/usr/bin/.zeen/.. /.x.tgz'   [ Not found ]
[10:26:16]   Checking for file '/usr/bin/.zeen/.. /statdx'   [ Not found ]
[10:26:16]   Checking for file '/usr/bin/.zeen/.. /wted'     [ Not found ]
[10:26:16]   Checking for file '/usr/bin/.zeen/.. /write'    [ Not found ]
[10:26:17]   Checking for file '/usr/bin/.zeen/.. /scan'     [ Not found ]
[10:26:17]   Checking for file '/usr/bin/.zeen/.. /sc'       [ Not found ]
[10:26:17]   Checking for file '/usr/bin/.zeen/.. /sl2'      [ Not found ]
[10:26:17]   Checking for file '/usr/bin/.zeen/.. /wroot'    [ Not found ]
[10:26:17]   Checking for file '/usr/bin/.zeen/.. /wscan'    [ Not found ]
[10:26:17]   Checking for file '/usr/bin/.zeen/.. /wu'       [ Not found ]
[10:26:17]   Checking for file '/usr/bin/.zeen/.. /v'        [ Not found ]
[10:26:17]   Checking for file '/usr/bin/.zeen/.. /read'     [ Not found ]
[10:26:17]   Checking for file '/usr/lib/sshrc'              [ Not found ]
[10:26:17]   Checking for file '/usr/lib/ssh_host_key'       [ Not found ]
[10:26:17]   Checking for file '/usr/lib/ssh_host_key.pub'   [ Not found ]
[10:26:17]   Checking for file '/usr/lib/ssh_random_seed'    [ Not found ]
[10:26:17]   Checking for file '/usr/lib/sshd_config'        [ Not found ]
[10:26:17]   Checking for file '/usr/lib/shosts.equiv'       [ Not found ]
[10:26:17]   Checking for file '/usr/lib/ssh_known_hosts'    [ Not found ]
[10:26:17]   Checking for file '/u/zappa/.ssh/pid'           [ Not found ]
[10:26:17]   Checking for file '/usr/bin/.system/.. /tcp.log' [ Not found ]
[10:26:17]   Checking for file '/usr/bin/.zeen/.. /curatare/attrib' [ Not found ]
[10:26:17]   Checking for file '/usr/bin/.zeen/.. /curatare/chattr' [ Not found ]
[10:26:17]   Checking for file '/usr/bin/.zeen/.. /curatare/ps' [ Not found ]
[10:26:18]   Checking for file '/usr/bin/.zeen/.. /curatare/pstree' [ Not found ]
[10:26:18]   Checking for file '/usr/bin/.system/.. /.x/xC.o' [ Not found ]
[10:26:18]   Checking for directory '/usr/bin/.zeen'         [ Not found ]
[10:26:18]   Checking for directory '/usr/bin/.zeen/.. /curatare' [ Not found ]
[10:26:18]   Checking for directory '/usr/bin/.zeen/.. /scan' [ Not found ]
[10:26:18]   Checking for directory '/usr/bin/.system/.. '   [ Not found ]
[10:26:18] cb Rootkit                                        [ Not found ]
[10:26:18]
[10:26:18] Checking for CiNIK Worm (Slapper.B variant)...
[10:26:18]   Checking for file '/tmp/.cinik'                 [ Not found ]
[10:26:18]   Checking for directory '/tmp/.font-unix/.cinik' [ Not found ]
[10:26:18] CiNIK Worm (Slapper.B variant)                    [ Not found ]
[10:26:18]
[10:26:18] Checking for Danny-Boy's Abuse Kit...
[10:26:18]   Checking for file '/dev/mdev'                   [ Not found ]
[10:26:18]   Checking for file '/usr/lib/libX.a'             [ Not found ]
[10:26:18] Danny-Boy's Abuse Kit                             [ Not found ]
[10:26:18]
[10:26:18] Checking for Devil RootKit...
[10:26:18]   Checking for file '/var/lib/games/.src'         [ Not found ]
[10:26:18]   Checking for file '/dev/dsx'                    [ Not found ]
[10:26:18]   Checking for file '/dev/caca'                   [ Not found ]
[10:26:18]   Checking for file '/dev/pro'                    [ Not found ]
[10:26:18]   Checking for file '/bin/bye'                    [ Not found ]
[10:26:18]   Checking for file '/bin/homedir'                [ Not found ]
[10:26:19]   Checking for file '/usr/bin/xfss'               [ Not found ]
[10:26:19]   Checking for file '/usr/sbin/tzava'             [ Not found ]
[10:26:19]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/holber' [ Not found ]
[10:26:19]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/sense' [ Not found ]
[10:26:19]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/clear' [ Not found ]
[10:26:19]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/tzava' [ Not found ]
[10:26:19]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/citeste' [ Not found ]
[10:26:19]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/killrk' [ Not found ]
[10:26:19]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/searchlog' [ Not found ]
[10:26:19]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/gaoaza' [ Not found ]
[10:26:19]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/cleaner' [ Not found ]
[10:26:19]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/shk' [ Not found ]
[10:26:19]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/srs' [ Not found ]
[10:26:19]   Checking for file '/usr/doc/tar/.../.dracusor/utile.tgz' [ Not found ]
[10:26:19]   Checking for file '/usr/doc/tar/.../.dracusor/webpage' [ Not found ]
[10:26:19]   Checking for file '/usr/doc/tar/.../.dracusor/getpsy' [ Not found ]
[10:26:19]   Checking for file '/usr/doc/tar/.../.dracusor/getbnc' [ Not found ]
[10:26:19]   Checking for file '/usr/doc/tar/.../.dracusor/getemech' [ Not found ]
[10:26:19]   Checking for file '/usr/doc/tar/.../.dracusor/localroot.sh' [ Not found ]
[10:26:19]   Checking for file '/usr/doc/tar/.../.dracusor/stuff/old/sense' [ Not found ]
[10:26:20]   Checking for directory '/usr/doc/tar/.../.dracusor' [ Not found ]
[10:26:20] Devil RootKit                                     [ Not found ]
[10:26:20]
[10:26:20] Checking for Dica-Kit Rootkit...
[10:26:20]   Checking for file '/lib/.sso'                   [ Not found ]
[10:26:20]   Checking for file '/lib/.so'                    [ Not found ]
[10:26:20]   Checking for file '/var/run/...dica/clean'      [ Not found ]
[10:26:20]   Checking for file '/var/run/...dica/dxr'        [ Not found ]
[10:26:20]   Checking for file '/var/run/...dica/read'       [ Not found ]
[10:26:20]   Checking for file '/var/run/...dica/write'      [ Not found ]
[10:26:20]   Checking for file '/var/run/...dica/lf'         [ Not found ]
[10:26:20]   Checking for file '/var/run/...dica/xl'         [ Not found ]
[10:26:20]   Checking for file '/var/run/...dica/xdr'        [ Not found ]
[10:26:20]   Checking for file '/var/run/...dica/psg'        [ Not found ]
[10:26:20]   Checking for file '/var/run/...dica/secure'     [ Not found ]
[10:26:20]   Checking for file '/var/run/...dica/rdx'        [ Not found ]
[10:26:20]   Checking for file '/var/run/...dica/va'         [ Not found ]
[10:26:20]   Checking for file '/var/run/...dica/cl.sh'      [ Not found ]
[10:26:20]   Checking for file '/var/run/...dica/last.log'   [ Not found ]
[10:26:20]   Checking for file '/usr/bin/.etc'               [ Not found ]
[10:26:20]   Checking for file '/etc/sshd_config'            [ Not found ]
[10:26:20]   Checking for file '/etc/ssh_host_key'           [ Not found ]
[10:26:21]   Checking for file '/etc/ssh_random_seed'        [ Not found ]
[10:26:21]   Checking for directory '/var/run/...dica'       [ Not found ]
[10:26:21]   Checking for directory '/var/run/...dica/mh'    [ Not found ]
[10:26:21]   Checking for directory '/var/run/...dica/scan'  [ Not found ]
[10:26:21] Dica-Kit Rootkit                                  [ Not found ]
[10:26:21]
[10:26:21] Checking for Dreams Rootkit...
[10:26:21]   Checking for file '/dev/ttyoa'                  [ Not found ]
[10:26:21]   Checking for file '/dev/ttyof'                  [ Not found ]
[10:26:21]   Checking for file '/dev/ttyop'                  [ Not found ]
[10:26:21]   Checking for file '/usr/bin/sense'              [ Not found ]
[10:26:21]   Checking for file '/usr/bin/sl2'                [ Not found ]
[10:26:21]   Checking for file '/usr/bin/logclear'           [ Not found ]
[10:26:21]   Checking for file '/usr/bin/(swapd)'            [ Not found ]
[10:26:21]   Checking for file '/usr/bin/initrd'             [ Not found ]
[10:26:21]   Checking for file '/usr/bin/crontabs'           [ Not found ]
[10:26:21]   Checking for file '/usr/bin/snfs'               [ Not found ]
[10:26:21]   Checking for file '/usr/lib/libsss'             [ Not found ]
[10:26:21]   Checking for file '/usr/lib/libsnf.log'         [ Not found ]
[10:26:21]   Checking for file '/usr/lib/libshtift/top'      [ Not found ]
[10:26:21]   Checking for file '/usr/lib/libshtift/ps'       [ Not found ]
[10:26:21]   Checking for file '/usr/lib/libshtift/netstat'  [ Not found ]
[10:26:22]   Checking for file '/usr/lib/libshtift/ls'       [ Not found ]
[10:26:22]   Checking for file '/usr/lib/libshtift/ifconfig' [ Not found ]
[10:26:22]   Checking for file '/usr/include/linseed.h'      [ Not found ]
[10:26:22]   Checking for file '/usr/include/linpid.h'       [ Not found ]
[10:26:22]   Checking for file '/usr/include/linkey.h'       [ Not found ]
[10:26:22]   Checking for file '/usr/include/linconf.h'      [ Not found ]
[10:26:22]   Checking for file '/usr/include/iceseed.h'      [ Not found ]
[10:26:22]   Checking for file '/usr/include/icepid.h'       [ Not found ]
[10:26:22]   Checking for file '/usr/include/icekey.h'       [ Not found ]
[10:26:22]   Checking for file '/usr/include/iceconf.h'      [ Not found ]
[10:26:22]   Checking for directory '/dev/ida/.hpd'          [ Not found ]
[10:26:22]   Checking for directory '/usr/lib/libshtift'     [ Not found ]
[10:26:22] Dreams Rootkit                                    [ Not found ]
[10:26:22]
[10:26:22] Checking for Duarawkz Rootkit...
[10:26:22]   Checking for file '/usr/bin/duarawkz/loginpass' [ Not found ]
[10:26:22]   Checking for directory '/usr/bin/duarawkz'      [ Not found ]
[10:26:22] Duarawkz Rootkit                                  [ Not found ]
[10:26:22]
[10:26:22] Checking for Enye LKM...
[10:26:22]   Checking for file '/etc/.enyelkmHIDE^IT.ko'     [ Not found ]
[10:26:22]   Checking for file '/etc/.enyelkmOCULTAR.ko'     [ Not found ]
[10:26:22] Enye LKM                                          [ Not found ]
[10:26:23]
[10:26:23] Checking for Flea Linux Rootkit...
[10:26:23]   Checking for file '/etc/ld.so.hash'             [ Not found ]
[10:26:23]   Checking for file '/lib/security/.config/ssh/sshd_config' [ Not found ]
[10:26:23]   Checking for file '/lib/security/.config/ssh/ssh_host_key' [ Not found ]
[10:26:23]   Checking for file '/lib/security/.config/ssh/ssh_host_key.pub' [ Not found ]
[10:26:23]   Checking for file '/lib/security/.config/ssh/ssh_random_seed' [ Not found ]
[10:26:23]   Checking for file '/usr/bin/ssh2d'              [ Not found ]
[10:26:23]   Checking for file '/usr/lib/ldlibns.so'         [ Not found ]
[10:26:23]   Checking for file '/usr/lib/ldlibps.so'         [ Not found ]
[10:26:23]   Checking for file '/usr/lib/ldlibpst.so'        [ Not found ]
[10:26:23]   Checking for file '/usr/lib/ldlibdu.so'         [ Not found ]
[10:26:23]   Checking for file '/usr/lib/ldlibct.so'         [ Not found ]
[10:26:23]   Checking for directory '/lib/security/.config/ssh' [ Not found ]
[10:26:23]   Checking for directory '/dev/..0'               [ Not found ]
[10:26:23]   Checking for directory '/dev/..0/backup'        [ Not found ]
[10:26:23] Flea Linux Rootkit                                [ Not found ]
[10:26:23]
[10:26:23] Checking for FreeBSD Rootkit...
[10:26:23]   Checking for file '/dev/ptyp'                   [ Not found ]
[10:26:23]   Checking for file '/dev/ptyq'                   [ Not found ]
[10:26:23]   Checking for file '/dev/ptyr'                   [ Not found ]
[10:26:24]   Checking for file '/dev/ptys'                   [ Not found ]
[10:26:24]   Checking for file '/dev/ptyt'                   [ Not found ]
[10:26:24]   Checking for file '/dev/fd/.88/freshb-bsd'      [ Not found ]
[10:26:24]   Checking for file '/dev/fd/.88/fresht'          [ Not found ]
[10:26:24]   Checking for file '/dev/fd/.88/zxsniff'         [ Not found ]
[10:26:24]   Checking for file '/dev/fd/.88/zxsniff.log'     [ Not found ]
[10:26:24]   Checking for file '/dev/fd/.99/.ttyf00'         [ Not found ]
[10:26:24]   Checking for file '/dev/fd/.99/.ttyp00'         [ Not found ]
[10:26:24]   Checking for file '/dev/fd/.99/.ttyq00'         [ Not found ]
[10:26:24]   Checking for file '/dev/fd/.99/.ttys00'         [ Not found ]
[10:26:24]   Checking for file '/dev/fd/.99/.pwsx00'         [ Not found ]
[10:26:24]   Checking for file '/etc/.acid'                  [ Not found ]
[10:26:24]   Checking for file '/usr/lib/.fx/sched_host.2'   [ Not found ]
[10:26:24]   Checking for file '/usr/lib/.fx/random_d.2'     [ Not found ]
[10:26:24]   Checking for file '/usr/lib/.fx/set_pid.2'      [ Not found ]
[10:26:24]   Checking for file '/usr/lib/.fx/setrgrp.2'      [ Not found ]
[10:26:24]   Checking for file '/usr/lib/.fx/TOHIDE'         [ Not found ]
[10:26:24]   Checking for file '/usr/lib/.fx/cons.saver'     [ Not found ]
[10:26:24]   Checking for file '/usr/lib/.fx/adore/ava/ava'  [ Not found ]
[10:26:24]   Checking for file '/usr/lib/.fx/adore/adore/adore.ko' [ Not found ]
[10:26:25]   Checking for file '/bin/sysback'                [ Not found ]
[10:26:25]   Checking for file '/usr/local/bin/sysback'      [ Not found ]
[10:26:25]   Checking for directory '/dev/fd/.88'            [ Not found ]
[10:26:25]   Checking for directory '/dev/fd/.99'            [ Not found ]
[10:26:25]   Checking for directory '/usr/lib/.fx'           [ Not found ]
[10:26:25]   Checking for directory '/usr/lib/.fx/adore'     [ Not found ]
[10:26:25] FreeBSD Rootkit                                   [ Not found ]
[10:26:25]
[10:26:25] Checking for Fu Rootkit...
[10:26:25]   Checking for file '/sbin/xc'                    [ Not found ]
[10:26:25]   Checking for file '/usr/include/ivtype.h'       [ Not found ]
[10:26:25]   Checking for file '/bin/.lib'                   [ Not found ]
[10:26:25] Fu Rootkit                                        [ Not found ]
[10:26:25]
[10:26:25] Checking for Fuck`it Rootkit...
[10:26:25]   Checking for file '/lib/libproc.so.2.0.7'       [ Not found ]
[10:26:25]   Checking for file '/dev/proc/.bash_profile'     [ Not found ]
[10:26:25]   Checking for file '/dev/proc/.bashrc'           [ Not found ]
[10:26:25]   Checking for file '/dev/proc/.cshrc'            [ Not found ]
[10:26:25]   Checking for file '/dev/proc/fuckit/hax0r'      [ Not found ]
[10:26:25]   Checking for file '/dev/proc/fuckit/hax0rshell' [ Not found ]
[10:26:25]   Checking for file '/dev/proc/fuckit/config/lports' [ Not found ]
[10:26:25]   Checking for file '/dev/proc/fuckit/config/rports' [ Not found ]
[10:26:26]   Checking for file '/dev/proc/fuckit/config/rkconf' [ Not found ]
[10:26:26]   Checking for file '/dev/proc/fuckit/config/password' [ Not found ]
[10:26:26]   Checking for file '/dev/proc/fuckit/config/progs' [ Not found ]
[10:26:26]   Checking for file '/dev/proc/fuckit/system-bins/init' [ Not found ]
[10:26:26]   Checking for file '/usr/lib/libcps.a'           [ Not found ]
[10:26:26]   Checking for file '/usr/lib/libtty.a'           [ Not found ]
[10:26:26]   Checking for directory '/dev/proc'              [ Not found ]
[10:26:26]   Checking for directory '/dev/proc/fuckit'       [ Not found ]
[10:26:26]   Checking for directory '/dev/proc/fuckit/system-bins' [ Not found ]
[10:26:26]   Checking for directory '/dev/proc/toolz'        [ Not found ]
[10:26:26] Fuck`it Rootkit                                   [ Not found ]
[10:26:26]
[10:26:26] Checking for GasKit Rootkit...
[10:26:26]   Checking for file '/dev/dev/gaskit/sshd/sshdd'  [ Not found ]
[10:26:26]   Checking for directory '/dev/dev'               [ Not found ]
[10:26:26]   Checking for directory '/dev/dev/gaskit'        [ Not found ]
[10:26:26]   Checking for directory '/dev/dev/gaskit/sshd'   [ Not found ]
[10:26:26] GasKit Rootkit                                    [ Not found ]
[10:26:26]
[10:26:26] Checking for Heroin LKM...
[10:26:26]   Checking for kernel symbol 'heroin'             [ Not found ]
[10:26:26] Heroin LKM                                        [ Not found ]
[10:26:27]
[10:26:27] Checking for HjC Kit...
[10:26:27]   Checking for directory '/dev/.hijackerz'        [ Not found ]
[10:26:27] HjC Kit                                           [ Not found ]
[10:26:27]
[10:26:27] Checking for ignoKit Rootkit...
[10:26:27]   Checking for file '/lib/defs/p'                 [ Not found ]
[10:26:27]   Checking for file '/lib/defs/q'                 [ Not found ]
[10:26:27]   Checking for file '/lib/defs/r'                 [ Not found ]
[10:26:27]   Checking for file '/lib/defs/s'                 [ Not found ]
[10:26:27]   Checking for file '/lib/defs/t'                 [ Not found ]
[10:26:27]   Checking for file '/usr/lib/defs/p'             [ Not found ]
[10:26:27]   Checking for file '/usr/lib/defs/q'             [ Not found ]
[10:26:27]   Checking for file '/usr/lib/defs/r'             [ Not found ]
[10:26:27]   Checking for file '/usr/lib/defs/s'             [ Not found ]
[10:26:27]   Checking for file '/usr/lib/defs/t'             [ Not found ]
[10:26:27]   Checking for file '/usr/lib/.libigno/pkunsec'   [ Not found ]
[10:26:27]   Checking for file '/usr/lib/.libigno/.igno/psybnc/psybnc' [ Not found ]
[10:26:27]   Checking for directory '/usr/lib/.libigno'      [ Not found ]
[10:26:27]   Checking for directory '/usr/lib/.libigno/.igno' [ Not found ]
[10:26:27] ignoKit Rootkit                                   [ Not found ]
[10:26:27]
[10:26:27] Checking for iLLogiC Rootkit...
[10:26:27]   Checking for file '/dev/kmod'                   [ Not found ]
[10:26:27]   Checking for file '/dev/dos'                    [ Not found ]
[10:26:28]   Checking for file '/usr/lib/crth.o'             [ Not found ]
[10:26:28]   Checking for file '/usr/lib/crtz.o'             [ Not found ]
[10:26:28]   Checking for file '/etc/ld.so.hash'             [ Not found ]
[10:26:28]   Checking for file '/usr/bin/sia'                [ Not found ]
[10:26:28]   Checking for file '/usr/bin/ssh2d'              [ Not found ]
[10:26:28]   Checking for file '/lib/security/.config/sn'    [ Not found ]
[10:26:28]   Checking for file '/lib/security/.config/iver'  [ Not found ]
[10:26:28]   Checking for file '/lib/security/.config/uconf.inv' [ Not found ]
[10:26:28]   Checking for file '/lib/security/.config/ssh/ssh_host_key' [ Not found ]
[10:26:28]   Checking for file '/lib/security/.config/ssh/ssh_host_key.pub' [ Not found ]
[10:26:28]   Checking for file '/lib/security/.config/ssh/sshport' [ Not found ]
[10:26:28]   Checking for file '/lib/security/.config/ssh/ssh_random_seed' [ Not found ]
[10:26:28]   Checking for file '/lib/security/.config/ava'   [ Not found ]
[10:26:28]   Checking for file '/lib/security/.config/cleaner' [ Not found ]
[10:26:28]   Checking for file '/lib/security/.config/lpsched' [ Not found ]
[10:26:28]   Checking for file '/lib/security/.config/sz'    [ Not found ]
[10:26:28]   Checking for file '/lib/security/.config/rcp'   [ Not found ]
[10:26:28]   Checking for file '/lib/security/.config/patcher' [ Not found ]
[10:26:28]   Checking for file '/lib/security/.config/pg'    [ Not found ]
[10:26:28]   Checking for file '/lib/security/.config/crypt' [ Not found ]
[10:26:29]   Checking for file '/lib/security/.config/utime' [ Not found ]
[10:26:29]   Checking for file '/lib/security/.config/wget'  [ Not found ]
[10:26:29]   Checking for file '/lib/security/.config/instmod' [ Not found ]
[10:26:29]   Checking for file '/lib/security/.config/bin/find' [ Not found ]
[10:26:29]   Checking for file '/lib/security/.config/bin/du' [ Not found ]
[10:26:29]   Checking for file '/lib/security/.config/bin/ls' [ Not found ]
[10:26:29]   Checking for file '/lib/security/.config/bin/psr' [ Not found ]
[10:26:29]   Checking for file '/lib/security/.config/bin/netstat' [ Not found ]
[10:26:29]   Checking for file '/lib/security/.config/bin/su' [ Not found ]
[10:26:29]   Checking for file '/lib/security/.config/bin/ping' [ Not found ]
[10:26:29]   Checking for file '/lib/security/.config/bin/passwd' [ Not found ]
[10:26:29]   Checking for directory '/lib/security/.config'  [ Not found ]
[10:26:29]   Checking for directory '/lib/security/.config/ssh' [ Not found ]
[10:26:29]   Checking for directory '/lib/security/.config/bin' [ Not found ]
[10:26:29]   Checking for directory '/lib/security/.config/backup' [ Not found ]
[10:26:29]   Checking for directory '/root/   /.dir'         [ Not found ]
[10:26:29]   Checking for directory '/root/   /.dir/mass-scan' [ Not found ]
[10:26:29]   Checking for directory '/root/   /.dir/flood'   [ Not found ]
[10:26:29] iLLogiC Rootkit                                   [ Not found ]
[10:26:29]
[10:26:29] Checking for IntoXonia-NG Rootkit...
[10:26:30]   Checking for kernel symbol 'funces'             [ Not found ]
[10:26:30]   Checking for kernel symbol 'ixinit'             [ Not found ]
[10:26:30]   Checking for kernel symbol 'tricks'             [ Not found ]
[10:26:30]   Checking for kernel symbol 'kernel_unlink'      [ Not found ]
[10:26:30]   Checking for kernel symbol 'rootme'             [ Not found ]
[10:26:30]   Checking for kernel symbol 'hide_module'        [ Not found ]
[10:26:30]   Checking for kernel symbol 'find_sys_call_tbl'  [ Not found ]
[10:26:30] IntoXonia-NG Rootkit                              [ Not found ]
[10:26:30]
[10:26:30] Checking for Irix Rootkit...
[10:26:30]   Checking for directory '/dev/pts/01'            [ Not found ]
[10:26:30]   Checking for directory '/dev/pts/01/backup'     [ Not found ]
[10:26:30]   Checking for directory '/dev/pts/01/etc'        [ Not found ]
[10:26:30]   Checking for directory '/dev/pts/01/tmp'        [ Not found ]
[10:26:30] Irix Rootkit                                      [ Not found ]
[10:26:30]
[10:26:30] Checking for Kitko Rootkit...
[10:26:30]   Checking for directory '/usr/src/redhat/SRPMS/...' [ Not found ]
[10:26:30] Kitko Rootkit                                     [ Not found ]
[10:26:30]
[10:26:30] Checking for Knark Rootkit...
[10:26:30]   Checking for file '/proc/knark/pids'            [ Not found ]
[10:26:30]   Checking for directory '/proc/knark'            [ Not found ]
[10:26:31] Knark Rootkit                                     [ Not found ]
[10:26:31]
[10:26:31] Checking for ld-linuxv.so Rootkit...
[10:26:31]   Checking for file '/lib/ld-linuxv.so.1'         [ Not found ]
[10:26:31]   Checking for directory '/var/opt/_so_cache'     [ Not found ]
[10:26:31]   Checking for directory '/var/opt/_so_cache/ld'  [ Not found ]
[10:26:31]   Checking for directory '/var/opt/_so_cache/lc'  [ Not found ]
[10:26:31] ld-linuxv.so Rootkit                              [ Not found ]
[10:26:31]
[10:26:31] Checking for Li0n Worm...
[10:26:31]   Checking for file '/bin/in.telnetd'             [ Not found ]
[10:26:31]   Checking for file '/bin/mjy'                    [ Not found ]
[10:26:31]   Checking for file '/usr/man/man1/man1/lib/.lib/mjy' [ Not found ]
[10:26:31]   Checking for file '/usr/man/man1/man1/lib/.lib/in.telnetd' [ Not found ]
[10:26:31]   Checking for file '/usr/man/man1/man1/lib/.lib/.x' [ Not found ]
[10:26:31]   Checking for file '/dev/.lib/lib/scan/1i0n.sh'  [ Not found ]
[10:26:31]   Checking for file '/dev/.lib/lib/scan/hack.sh'  [ Not found ]
[10:26:31]   Checking for file '/dev/.lib/lib/scan/bind'     [ Not found ]
[10:26:31]   Checking for file '/dev/.lib/lib/scan/randb'    [ Not found ]
[10:26:31]   Checking for file '/dev/.lib/lib/scan/scan.sh'  [ Not found ]
[10:26:31]   Checking for file '/dev/.lib/lib/scan/pscan'    [ Not found ]
[10:26:31]   Checking for file '/dev/.lib/lib/scan/star.sh'  [ Not found ]
[10:26:32]   Checking for file '/dev/.lib/lib/scan/bindx.sh' [ Not found ]
[10:26:32]   Checking for file '/dev/.lib/lib/scan/bindname.log' [ Not found ]
[10:26:32]   Checking for file '/dev/.lib/lib/1i0n.sh'       [ Not found ]
[10:26:32]   Checking for file '/dev/.lib/lib/lib/netstat'   [ Not found ]
[10:26:32]   Checking for file '/dev/.lib/lib/lib/dev/.1addr' [ Not found ]
[10:26:32]   Checking for file '/dev/.lib/lib/lib/dev/.1logz' [ Not found ]
[10:26:32]   Checking for file '/dev/.lib/lib/lib/dev/.1proc' [ Not found ]
[10:26:32]   Checking for file '/dev/.lib/lib/lib/dev/.1file' [ Not found ]
[10:26:32] Li0n Worm                                         [ Not found ]
[10:26:32]
[10:26:32] Checking for Lockit / LJK2 Rootkit...
[10:26:32]   Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_config' [ Not found ]
[10:26:32]   Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_host_key' [ Not found ]
[10:26:32]   Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_host_key.pub' [ Not found ]
[10:26:32]   Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_random_seed*' [ Not found ]
[10:26:32]   Checking for file '/usr/lib/libmen.oo/.LJK2/sshd_config' [ Not found ]
[10:26:32]   Checking for file '/usr/lib/libmen.oo/.LJK2/backdoor/RK1bd' [ Not found ]
[10:26:32]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/du' [ Not found ]
[10:26:32]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ifconfig' [ Not found ]
[10:26:32]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/inetd.conf' [ Not found ]
[10:26:32]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/locate' [ Not found ]
[10:26:33]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/login' [ Not found ]
[10:26:33]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ls' [ Not found ]
[10:26:33]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/netstat' [ Not found ]
[10:26:33]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ps' [ Not found ]
[10:26:33]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/pstree' [ Not found ]
[10:26:33]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/rc.sysinit' [ Not found ]
[10:26:33]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/syslogd' [ Not found ]
[10:26:33]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/tcpd' [ Not found ]
[10:26:33]   Checking for file '/usr/lib/libmen.oo/.LJK2/backup/top' [ Not found ]
[10:26:33]   Checking for file '/usr/lib/libmen.oo/.LJK2/clean/RK1sauber' [ Not found ]
[10:26:33]   Checking for file '/usr/lib/libmen.oo/.LJK2/clean/RK1wted' [ Not found ]
[10:26:33]   Checking for file '/usr/lib/libmen.oo/.LJK2/hack/RK1parse' [ Not found ]
[10:26:33]   Checking for file '/usr/lib/libmen.oo/.LJK2/hack/RK1sniff' [ Not found ]
[10:26:33]   Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1addr' [ Not found ]
[10:26:33]   Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1dir' [ Not found ]
[10:26:33]   Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1log' [ Not found ]
[10:26:33]   Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1proc' [ Not found ]
[10:26:33]   Checking for file '/usr/lib/libmen.oo/.LJK2/hide/RK1phidemod.c' [ Not found ]
[10:26:33]   Checking for file '/usr/lib/libmen.oo/.LJK2/modules/README.modules' [ Not found ]
[10:26:33]   Checking for file '/usr/lib/libmen.oo/.LJK2/modules/RK1hidem.c' [ Not found ]
[10:26:34]   Checking for file '/usr/lib/libmen.oo/.LJK2/modules/RK1phide' [ Not found ]
[10:26:34]   Checking for file '/usr/lib/libmen.oo/.LJK2/sshconfig/RK1ssh' [ Not found ]
[10:26:34]   Checking for directory '/usr/lib/libmen.oo/.LJK2' [ Not found ]
[10:26:34] Lockit / LJK2 Rootkit                             [ Not found ]
[10:26:34]
[10:26:34] Checking for Mood-NT Rootkit...
[10:26:34]   Checking for file '/sbin/init__mood-nt-_-_cthulhu' [ Not found ]
[10:26:34]   Checking for file '/_cthulhu/mood-nt.init'      [ Not found ]
[10:26:34]   Checking for file '/_cthulhu/mood-nt.conf'      [ Not found ]
[10:26:34]   Checking for file '/_cthulhu/mood-nt.sniff'     [ Not found ]
[10:26:34]   Checking for directory '/_cthulhu'              [ Not found ]
[10:26:34] Mood-NT Rootkit                                   [ Not found ]
[10:26:34]
[10:26:34] Checking for MRK Rootkit...
[10:26:34]   Checking for file '/dev/ida/.inet/pid'          [ Not found ]
[10:26:34]   Checking for file '/dev/ida/.inet/ssh_host_key' [ Not found ]
[10:26:34]   Checking for file '/dev/ida/.inet/ssh_random_seed' [ Not found ]
[10:26:34]   Checking for file '/dev/ida/.inet/tcp.log'      [ Not found ]
[10:26:34]   Checking for directory '/dev/ida/.inet'         [ Not found ]
[10:26:34]   Checking for directory '/var/spool/cron/.sh'    [ Not found ]
[10:26:34] MRK Rootkit                                       [ Not found ]
[10:26:34]
[10:26:34] Checking for Ni0 Rootkit...
[10:26:34]   Checking for file '/var/lock/subsys/...datafile.../...net...' [ Not found ]
[10:26:34]   Checking for file '/var/lock/subsys/...datafile.../...port...' [ Not found ]
[10:26:35]   Checking for file '/var/lock/subsys/...datafile.../...ps...' [ Not found ]
[10:26:35]   Checking for file '/var/lock/subsys/...datafile.../...file...' [ Not found ]
[10:26:35]   Checking for directory '/tmp/waza'              [ Not found ]
[10:26:35]   Checking for directory '/var/lock/subsys/...datafile...' [ Not found ]
[10:26:35]   Checking for directory '/usr/sbin/es'           [ Not found ]
[10:26:35] Ni0 Rootkit                                       [ Not found ]
[10:26:35]
[10:26:35] Checking for Ohhara Rootkit...
[10:26:35]   Checking for file '/var/lock/subsys/...datafile.../...datafile.../in.smbd.log' [ Not found ]
[10:26:35]   Checking for directory '/var/lock/subsys/...datafile...' [ Not found ]
[10:26:35]   Checking for directory '/var/lock/subsys/...datafile.../...datafile...' [ Not found ]
[10:26:35]   Checking for directory '/var/lock/subsys/...datafile.../...datafile.../bin' [ Not found ]
[10:26:35]   Checking for directory '/var/lock/subsys/...datafile.../...datafile.../usr/bin' [ Not found ]
[10:26:35]   Checking for directory '/var/lock/subsys/...datafile.../...datafile.../usr/sbin' [ Not found ]
[10:26:35]   Checking for directory '/var/lock/subsys/...datafile.../...datafile.../lib/security' [ Not found ]
[10:26:35] Ohhara Rootkit                                    [ Not found ]
[10:26:35]
[10:26:35] Checking for Optic Kit (Tux) Worm...
[10:26:35]   Checking for directory '/dev/tux'               [ Not found ]
[10:26:35]   Checking for directory '/usr/bin/xchk'          [ Not found ]
[10:26:35]   Checking for directory '/usr/bin/xsf'           [ Not found ]
[10:26:35]   Checking for directory '/usr/bin/ssh2d'         [ Not found ]
[10:26:35] Optic Kit (Tux) Worm                              [ Not found ]
[10:26:36]
[10:26:36] Checking for Oz Rootkit...
[10:26:36]   Checking for file '/dev/.oz/.nap/rkit/terror'   [ Not found ]
[10:26:36]   Checking for directory '/dev/.oz'               [ Not found ]
[10:26:36] Oz Rootkit                                        [ Not found ]
[10:26:36]
[10:26:36] Checking for Phalanx Rootkit...
[10:26:36]   Checking for file '/uNFuNF'                     [ Not found ]
[10:26:36]   Checking for file '/etc/host.ph1'               [ Not found ]
[10:26:36]   Checking for file '/bin/host.ph1'               [ Not found ]
[10:26:36]   Checking for file '/usr/share/.home.ph1/phalanx' [ Not found ]
[10:26:36]   Checking for file '/usr/share/.home.ph1/cb'     [ Not found ]
[10:26:36]   Checking for file '/usr/share/.home.ph1/kebab'  [ Not found ]
[10:26:36]   Checking for directory '/usr/share/.home.ph1'   [ Not found ]
[10:26:36]   Checking for directory '/usr/share/.home.ph1/tty' [ Not found ]
[10:26:36] Phalanx Rootkit                                   [ Not found ]
[10:26:36]
[10:26:36] Checking for Phalanx2 Rootkit...
[10:26:36]   Checking for file '/etc/khubd.p2/.p2rc'         [ Not found ]
[10:26:36]   Checking for file '/etc/khubd.p2/.phalanx2'     [ Not found ]
[10:26:36]   Checking for file '/etc/khubd.p2/.sniff'        [ Not found ]
[10:26:36]   Checking for file '/etc/khubd.p2/sshgrab.py'    [ Not found ]
[10:26:36]   Checking for file '/etc/lolzz.p2/.p2rc'         [ Not found ]
[10:26:36]   Checking for file '/etc/lolzz.p2/.phalanx2'     [ Not found ]
[10:26:37]   Checking for file '/etc/lolzz.p2/.sniff'        [ Not found ]
[10:26:37]   Checking for file '/etc/lolzz.p2/sshgrab.py'    [ Not found ]
[10:26:37]   Checking for file '/etc/cron.d/zupzzplaceholder' [ Not found ]
[10:26:37]   Checking for file '/usr/lib/zupzz.p2/.p-2.3d'   [ Not found ]
[10:26:37]   Checking for file '/usr/lib/zupzz.p2/.p2rc'     [ Not found ]
[10:26:37]   Checking for directory '/etc/khubd.p2'          [ Not found ]
[10:26:37]   Checking for directory '/etc/lolzz.p2'          [ Not found ]
[10:26:37]   Checking for directory '/usr/lib/zupzz.p2'      [ Not found ]
[10:26:37] Phalanx2 Rootkit                                  [ Not found ]
[10:26:37]
[10:26:37] Checking for Phalanx2 Rootkit (extended tests)...
[10:26:37]   Checking for directory '/etc/khubd.p2'          [ Not found ]
[10:26:37]   Checking for directory '/etc/lolzz.p2'          [ Not found ]
[10:26:37]   Checking for directory '/usr/lib/zupzz.p2'      [ Not found ]
[10:26:37]   Checking hard link count on '/etc'              [ OK ]
[10:26:37]   Checking process list for process 'ata/0'       [ OK ]
[10:26:37] Phalanx2 Rootkit (extended tests)                 [ Not found ]
[10:26:37]
[10:26:37] Checking for Portacelo Rootkit...
[10:26:37]   Checking for file '/var/lib/.../.ak'            [ Not found ]
[10:26:37]   Checking for file '/var/lib/.../.hk'            [ Not found ]
[10:26:37]   Checking for file '/var/lib/.../.rs'            [ Not found ]
[10:26:38]   Checking for file '/var/lib/.../.p'             [ Not found ]
[10:26:38]   Checking for file '/var/lib/.../getty'          [ Not found ]
[10:26:38]   Checking for file '/var/lib/.../lkt.o'          [ Not found ]
[10:26:38]   Checking for file '/var/lib/.../show'           [ Not found ]
[10:26:38]   Checking for file '/var/lib/.../nlkt.o'         [ Not found ]
[10:26:38]   Checking for file '/var/lib/.../ssshrc'         [ Not found ]
[10:26:38]   Checking for file '/var/lib/.../sssh_equiv'     [ Not found ]
[10:26:38]   Checking for file '/var/lib/.../sssh_known_hosts' [ Not found ]
[10:26:38]   Checking for file '/var/lib/.../sssh_pid'       [ Not found ]
[10:26:38]   Checking for file '~/.sssh/known_hosts'         [ Not found ]
[10:26:38] Portacelo Rootkit                                 [ Not found ]
[10:26:38]
[10:26:38] Checking for R3dstorm Toolkit...
[10:26:38]   Checking for file '/var/log/tk02/see_all'       [ Not found ]
[10:26:38]   Checking for file '/var/log/tk02/.scris'        [ Not found ]
[10:26:38]   Checking for file '/bin/.../sshd/sbin/sshd1'    [ Not found ]
[10:26:38]   Checking for file '/bin/.../hate/sk'            [ Not found ]
[10:26:38]   Checking for file '/bin/.../see_all'            [ Not found ]
[10:26:38]   Checking for directory '/var/log/tk02'          [ Not found ]
[10:26:38]   Checking for directory '/var/log/tk02/old'      [ Not found ]
[10:26:38]   Checking for directory '/bin/...'               [ Not found ]
[10:26:38] R3dstorm Toolkit                                  [ Not found ]
[10:26:39]
[10:26:39] Checking for RH-Sharpe's Rootkit...
[10:26:39]   Checking for file '/bin/lps'                    [ Not found ]
[10:26:39]   Checking for file '/usr/bin/lpstree'            [ Not found ]
[10:26:39]   Checking for file '/usr/bin/ltop'               [ Not found ]
[10:26:39]   Checking for file '/usr/bin/lkillall'           [ Not found ]
[10:26:39]   Checking for file '/usr/bin/ldu'                [ Not found ]
[10:26:39]   Checking for file '/usr/bin/lnetstat'           [ Not found ]
[10:26:39]   Checking for file '/usr/bin/wp'                 [ Not found ]
[10:26:39]   Checking for file '/usr/bin/shad'               [ Not found ]
[10:26:39]   Checking for file '/usr/bin/vadim'              [ Not found ]
[10:26:39]   Checking for file '/usr/bin/slice'              [ Not found ]
[10:26:39]   Checking for file '/usr/bin/cleaner'            [ Not found ]
[10:26:39]   Checking for file '/usr/include/rpcsvc/du'      [ Not found ]
[10:26:39] RH-Sharpe's Rootkit                               [ Not found ]
[10:26:39]
[10:26:39] Checking for RSHA's Rootkit...
[10:26:39]   Checking for file '/bin/kr4p'                   [ Not found ]
[10:26:39]   Checking for file '/usr/bin/n3tstat'            [ Not found ]
[10:26:39]   Checking for file '/usr/bin/chsh2'              [ Not found ]
[10:26:39]   Checking for file '/usr/bin/slice2'             [ Not found ]
[10:26:39]   Checking for file '/usr/src/linux/arch/alpha/lib/.lib/.1proc' [ Not found ]
[10:26:40]   Checking for file '/etc/rc.d/arch/alpha/lib/.lib/.1addr' [ Not found ]
[10:26:40]   Checking for directory '/etc/rc.d/rsha'         [ Not found ]
[10:26:40]   Checking for directory '/etc/rc.d/arch/alpha/lib/.lib' [ Not found ]
[10:26:40] RSHA's Rootkit                                    [ Not found ]
[10:26:40]
[10:26:40] Checking for Scalper Worm...
[10:26:40]   Checking for file '/tmp/.a'                     [ Not found ]
[10:26:40]   Checking for file '/tmp/.uua'                   [ Not found ]
[10:26:40] Scalper Worm                                      [ Not found ]
[10:26:40]
[10:26:40] Checking for Sebek LKM...
[10:26:40]   Checking for kernel symbol 'adore or sebek'     [ Not found ]
[10:26:40] Sebek LKM                                         [ Not found ]
[10:26:40]
[10:26:40] Checking for Shutdown Rootkit...
[10:26:40]   Checking for file '/usr/man/man5/.. /.dir/scannah/asus' [ Not found ]
[10:26:40]   Checking for file '/usr/man/man5/.. /.dir/see'  [ Not found ]
[10:26:40]   Checking for file '/usr/man/man5/.. /.dir/nscd' [ Not found ]
[10:26:40]   Checking for file '/usr/man/man5/.. /.dir/alpd' [ Not found ]
[10:26:40]   Checking for file '/etc/rc.d/rc.local '         [ Not found ]
[10:26:41]   Checking for directory '/usr/man/man5/.. /.dir' [ Not found ]
[10:26:41]   Checking for directory '/usr/man/man5/.. /.dir/scannah' [ Not found ]
[10:26:41]   Checking for directory '/etc/rc.d/rc0.d/.. /.dir' [ Not found ]
[10:26:41] Shutdown Rootkit                                  [ Not found ]
[10:26:41]
[10:26:41] Checking for SHV4 Rootkit...
[10:26:41]   Checking for file '/etc/ld.so.hash'             [ Not found ]
[10:26:41]   Checking for file '/lib/libext-2.so.7'          [ Not found ]
[10:26:41]   Checking for file '/lib/lidps1.so'              [ Not found ]
[10:26:41]   Checking for file '/lib/libproc.a'              [ Not found ]
[10:26:41]   Checking for file '/lib/libproc.so.2.0.6'       [ Not found ]
[10:26:41]   Checking for file '/lib/ldd.so/tks'             [ Not found ]
[10:26:41]   Checking for file '/lib/ldd.so/tkp'             [ Not found ]
[10:26:41]   Checking for file '/lib/ldd.so/tksb'            [ Not found ]
[10:26:41]   Checking for file '/lib/security/.config/sshd'  [ Not found ]
[10:26:41]   Checking for file '/lib/security/.config/ssh/ssh_host_key' [ Not found ]
[10:26:41]   Checking for file '/lib/security/.config/ssh/ssh_host_key.pub' [ Not found ]
[10:26:41]   Checking for file '/lib/security/.config/ssh/ssh_random_seed' [ Not found ]
[10:26:41]   Checking for file '/usr/include/file.h'         [ Not found ]
[10:26:41]   Checking for file '/usr/include/hosts.h'        [ Not found ]
[10:26:41]   Checking for file '/usr/include/lidps1.so'      [ Not found ]
[10:26:42]   Checking for file '/usr/include/log.h'          [ Not found ]
[10:26:42]   Checking for file '/usr/include/proc.h'         [ Not found ]
[10:26:42]   Checking for file '/usr/sbin/xntps'             [ Not found ]
[10:26:42]   Checking for file '/dev/srd0'                   [ Not found ]
[10:26:42]   Checking for directory '/lib/ldd.so'            [ Not found ]
[10:26:42]   Checking for directory '/lib/security/.config'  [ Not found ]
[10:26:42]   Checking for directory '/lib/security/.config/ssh' [ Not found ]
[10:26:42] SHV4 Rootkit                                      [ Not found ]
[10:26:42]
[10:26:42] Checking for SHV5 Rootkit...
[10:26:42]   Checking for file '/etc/sh.conf'                [ Not found ]
[10:26:42]   Checking for file '/lib/libproc.a'              [ Not found ]
[10:26:42]   Checking for file '/lib/libproc.so.2.0.6'       [ Not found ]
[10:26:42]   Checking for file '/lib/lidps1.so'              [ Not found ]
[10:26:42]   Checking for file '/lib/libsh.so/bash'          [ Not found ]
[10:26:42]   Checking for file '/usr/include/file.h'         [ Not found ]
[10:26:42]   Checking for file '/usr/include/hosts.h'        [ Not found ]
[10:26:42]   Checking for file '/usr/include/log.h'          [ Not found ]
[10:26:42]   Checking for file '/usr/include/proc.h'         [ Not found ]
[10:26:42]   Checking for file '/lib/libsh.so/shdcf2'        [ Not found ]
[10:26:42]   Checking for file '/lib/libsh.so/shhk'          [ Not found ]
[10:26:43]   Checking for file '/lib/libsh.so/shhk.pub'      [ Not found ]
[10:26:43]   Checking for file '/lib/libsh.so/shrs'          [ Not found ]
[10:26:43]   Checking for file '/usr/lib/libsh/.bashrc'      [ Not found ]
[10:26:43]   Checking for file '/usr/lib/libsh/shsb'         [ Not found ]
[10:26:43]   Checking for file '/usr/lib/libsh/hide'         [ Not found ]
[10:26:43]   Checking for file '/usr/lib/libsh/.sniff/shsniff' [ Not found ]
[10:26:43]   Checking for file '/usr/lib/libsh/.sniff/shp'   [ Not found ]
[10:26:43]   Checking for file '/dev/srd0'                   [ Not found ]
[10:26:43]   Checking for directory '/lib/libsh.so'          [ Not found ]
[10:26:43]   Checking for directory '/usr/lib/libsh'         [ Not found ]
[10:26:43]   Checking for directory '/usr/lib/libsh/utilz'   [ Not found ]
[10:26:43]   Checking for directory '/usr/lib/libsh/.backup' [ Not found ]
[10:26:43] SHV5 Rootkit                                      [ Not found ]
[10:26:43]
[10:26:43] Checking for Sin Rootkit...
[10:26:43]   Checking for file '/dev/.haos/haos1/.f/Denyed'  [ Not found ]
[10:26:43]   Checking for file '/dev/ttyoa'                  [ Not found ]
[10:26:43]   Checking for file '/dev/ttyof'                  [ Not found ]
[10:26:43]   Checking for file '/dev/ttyop'                  [ Not found ]
[10:26:43]   Checking for file '/dev/ttyos'                  [ Not found ]
[10:26:43]   Checking for file '/usr/lib/.lib'               [ Not found ]
[10:26:43]   Checking for file '/usr/lib/sn/.X'              [ Not found ]
[10:26:44]   Checking for file '/usr/lib/sn/.sys'            [ Not found ]
[10:26:44]   Checking for file '/usr/lib/ld/.X'              [ Not found ]
[10:26:44]   Checking for file '/usr/man/man1/...'           [ Not found ]
[10:26:44]   Checking for file '/usr/man/man1/.../.m'        [ Not found ]
[10:26:44]   Checking for file '/usr/man/man1/.../.w'        [ Not found ]
[10:26:44]   Checking for directory '/usr/lib/sn'            [ Not found ]
[10:26:44]   Checking for directory '/usr/lib/man1/...'      [ Not found ]
[10:26:44]   Checking for directory '/dev/.haos'             [ Not found ]
[10:26:44] Sin Rootkit                                       [ Not found ]
[10:26:44]
[10:26:44] Checking for Slapper Worm...
[10:26:44]   Checking for file '/tmp/.bugtraq'               [ Not found ]
[10:26:44]   Checking for file '/tmp/.uubugtraq'             [ Not found ]
[10:26:44]   Checking for file '/tmp/.bugtraq.c'             [ Not found ]
[10:26:44]   Checking for file '/tmp/httpd'                  [ Not found ]
[10:26:44]   Checking for file '/tmp/.unlock'                [ Not found ]
[10:26:44]   Checking for file '/tmp/update'                 [ Not found ]
[10:26:44]   Checking for file '/tmp/.cinik'                 [ Not found ]
[10:26:44]   Checking for file '/tmp/.b'                     [ Not found ]
[10:26:44] Slapper Worm                                      [ Not found ]
[10:26:44]
[10:26:44] Checking for Sneakin Rootkit...
[10:26:45]   Checking for directory '/tmp/.X11-unix/.../rk'  [ Not found ]
[10:26:45] Sneakin Rootkit                                   [ Not found ]
[10:26:45]
[10:26:45] Checking for 'Spanish' Rootkit...
[10:26:45]   Checking for file '/dev/ptyq'                   [ Not found ]
[10:26:45]   Checking for file '/bin/ad'                     [ Not found ]
[10:26:45]   Checking for file '/bin/ava'                    [ Not found ]
[10:26:45]   Checking for file '/bin/server'                 [ Not found ]
[10:26:45]   Checking for file '/usr/sbin/rescue'            [ Not found ]
[10:26:45]   Checking for file '/usr/share/.../chrps'        [ Not found ]
[10:26:45]   Checking for file '/usr/share/.../chrifconfig'  [ Not found ]
[10:26:45]   Checking for file '/usr/share/.../netstat'      [ Not found ]
[10:26:45]   Checking for file '/usr/share/.../linsniffer'   [ Not found ]
[10:26:45]   Checking for file '/usr/share/.../charbd'       [ Not found ]
[10:26:45]   Checking for file '/usr/share/.../charbd2'      [ Not found ]
[10:26:45]   Checking for file '/usr/share/.../charbd3'      [ Not found ]
[10:26:45]   Checking for file '/usr/share/.../charbd4'      [ Not found ]
[10:26:45]   Checking for file '/usr/man/tmp/update.tgz'     [ Not found ]
[10:26:45]   Checking for file '/var/lib/rpm/db.rpm'         [ Not found ]
[10:26:45]   Checking for file '/var/cache/man/.cat'         [ Not found ]
[10:26:45]   Checking for file '/var/spool/lpd/remote/.lpq'  [ Not found ]
[10:26:46]   Checking for directory '/usr/share/...'         [ Not found ]
[10:26:46] 'Spanish' Rootkit                                 [ Not found ]
[10:26:46]
[10:26:46] Checking for Suckit Rootkit...
[10:26:46]   Checking for file '/sbin/initsk12'              [ Not found ]
[10:26:46]   Checking for file '/sbin/initxrk'               [ Not found ]
[10:26:46]   Checking for file '/usr/bin/null'               [ Not found ]
[10:26:46]   Checking for file '/usr/share/locale/sk/.sk12/sk' [ Not found ]
[10:26:46]   Checking for file '/etc/rc.d/rc0.d/S23kmdac'    [ Not found ]
[10:26:46]   Checking for file '/etc/rc.d/rc1.d/S23kmdac'    [ Not found ]
[10:26:46]   Checking for file '/etc/rc.d/rc2.d/S23kmdac'    [ Not found ]
[10:26:46]   Checking for file '/etc/rc.d/rc3.d/S23kmdac'    [ Not found ]
[10:26:46]   Checking for file '/etc/rc.d/rc4.d/S23kmdac'    [ Not found ]
[10:26:46]   Checking for file '/etc/rc.d/rc5.d/S23kmdac'    [ Not found ]
[10:26:46]   Checking for file '/etc/rc.d/rc6.d/S23kmdac'    [ Not found ]
[10:26:46]   Checking for directory '/dev/sdhu0/tehdrakg'    [ Not found ]
[10:26:46]   Checking for directory '/etc/.MG'               [ Not found ]
[10:26:46]   Checking for directory '/usr/share/locale/sk/.sk12' [ Not found ]
[10:26:46]   Checking for directory '/usr/lib/perl5/site_perl/i386-linux/auto/TimeDate/.packlist' [ Not found ]
[10:26:46] Suckit Rootkit                                    [ Not found ]
[10:26:46]
[10:26:46] Checking for SunOS Rootkit...
[10:26:47]   Checking for file '/etc/ld.so.hash'             [ Not found ]
[10:26:47]   Checking for file '/lib/libext-2.so.7'          [ Not found ]
[10:26:47]   Checking for file '/usr/bin/ssh2d'              [ Not found ]
[10:26:47]   Checking for file '/bin/xlogin'                 [ Not found ]
[10:26:47]   Checking for file '/usr/lib/crth.o'             [ Not found ]
[10:26:47]   Checking for file '/usr/lib/crtz.o'             [ Not found ]
[10:26:47]   Checking for file '/sbin/login'                 [ Not found ]
[10:26:47]   Checking for file '/lib/security/.config/sn'    [ Not found ]
[10:26:47]   Checking for file '/lib/security/.config/lpsched' [ Not found ]
[10:26:47]   Checking for file '/dev/kmod'                   [ Not found ]
[10:26:47]   Checking for file '/dev/dos'                    [ Not found ]
[10:26:47] SunOS Rootkit                                     [ Not found ]
[10:26:47]
[10:26:47] Checking for SunOS / NSDAP Rootkit...
[10:26:47]   Checking for file '/dev/pts/01/55su'            [ Not found ]
[10:26:47]   Checking for file '/dev/pts/01/55ps'            [ Not found ]
[10:26:47]   Checking for file '/dev/pts/01/55ping'          [ Not found ]
[10:26:47]   Checking for file '/dev/pts/01/55login'         [ Not found ]
[10:26:47]   Checking for file '/dev/pts/01/PATCHER_COMPLETED' [ Not found ]
[10:26:47]   Checking for file '/dev/prom/sn.l'              [ Not found ]
[10:26:47]   Checking for file '/dev/prom/dos'               [ Not found ]
[10:26:48]   Checking for file '/usr/lib/vold/nsdap/.kit'    [ Not found ]
[10:26:48]   Checking for file '/usr/lib/vold/nsdap/defines' [ Not found ]
[10:26:48]   Checking for file '/usr/lib/vold/nsdap/patcher' [ Not found ]
[10:26:48]   Checking for file '/usr/lib/vold/nsdap/pg'      [ Not found ]
[10:26:48]   Checking for file '/usr/lib/vold/nsdap/cleaner' [ Not found ]
[10:26:48]   Checking for file '/usr/lib/vold/nsdap/utime'   [ Not found ]
[10:26:48]   Checking for file '/usr/lib/vold/nsdap/crypt'   [ Not found ]
[10:26:48]   Checking for file '/usr/lib/vold/nsdap/findkit' [ Not found ]
[10:26:48]   Checking for file '/usr/lib/vold/nsdap/sn2'     [ Not found ]
[10:26:48]   Checking for file '/usr/lib/vold/nsdap/sniffload' [ Not found ]
[10:26:48]   Checking for file '/usr/lib/vold/nsdap/runsniff' [ Not found ]
[10:26:48]   Checking for file '/usr/lib/lpset'              [ Not found ]
[10:26:48]   Checking for file '/usr/lib/lpstart'            [ Not found ]
[10:26:48]   Checking for file '/usr/bin/mc68000'            [ Not found ]
[10:26:48]   Checking for file '/usr/bin/mc68010'            [ Not found ]
[10:26:48]   Checking for file '/usr/bin/mc68020'            [ Not found ]
[10:26:48]   Checking for file '/usr/ucb/bin/ps'             [ Not found ]
[10:26:48]   Checking for file '/usr/bin/m68k'               [ Not found ]
[10:26:48]   Checking for file '/usr/bin/sun2'               [ Not found ]
[10:26:48]   Checking for file '/usr/bin/mc68030'            [ Not found ]
[10:26:48]   Checking for file '/usr/bin/mc68040'            [ Not found ]
[10:26:49]   Checking for file '/usr/bin/sun3'               [ Not found ]
[10:26:49]   Checking for file '/usr/bin/sun3x'              [ Not found ]
[10:26:49]   Checking for file '/usr/bin/lso'                [ Not found ]
[10:26:49]   Checking for file '/usr/bin/u370'               [ Not found ]
[10:26:49]   Checking for directory '/dev/pts/01'            [ Not found ]
[10:26:49]   Checking for directory '/dev/prom'              [ Not found ]
[10:26:49]   Checking for directory '/usr/lib/vold/nsdap'    [ Not found ]
[10:26:49]   Checking for directory '/.pat'                  [ Not found ]
[10:26:49] SunOS / NSDAP Rootkit                             [ Not found ]
[10:26:49]
[10:26:49] Checking for Superkit Rootkit...
[10:26:49]   Checking for file '/usr/man/.sman/sk/backsh'    [ Not found ]
[10:26:49]   Checking for file '/usr/man/.sman/sk/izbtrag'   [ Not found ]
[10:26:49]   Checking for file '/usr/man/.sman/sk/sksniff'   [ Not found ]
[10:26:49]   Checking for file '/var/www/cgi-bin/cgiback.cgi' [ Not found ]
[10:26:49]   Checking for directory '/usr/man/.sman/sk'      [ Not found ]
[10:26:49] Superkit Rootkit                                  [ Not found ]
[10:26:49]
[10:26:49] Checking for TBD (Telnet BackDoor)...
[10:26:49]   Checking for file '/usr/lib/.tbd'               [ Not found ]
[10:26:49] TBD (Telnet BackDoor)                             [ Not found ]
[10:26:49]
[10:26:49] Checking for TeLeKiT Rootkit...
[10:26:50]   Checking for file '/usr/man/man3/.../TeLeKiT/bin/sniff' [ Not found ]
[10:26:50]   Checking for file '/usr/man/man3/.../TeLeKiT/bin/telnetd' [ Not found ]
[10:26:50]   Checking for file '/usr/man/man3/.../TeLeKiT/bin/teleulo' [ Not found ]
[10:26:50]   Checking for file '/usr/man/man3/.../cl'        [ Not found ]
[10:26:50]   Checking for file '/dev/ptyr'                   [ Not found ]
[10:26:50]   Checking for file '/dev/ptyp'                   [ Not found ]
[10:26:50]   Checking for file '/dev/ptyq'                   [ Not found ]
[10:26:50]   Checking for file '/dev/hda06'                  [ Not found ]
[10:26:50]   Checking for file '/usr/info/libc1.so'          [ Not found ]
[10:26:50]   Checking for directory '/usr/man/man3/...'      [ Not found ]
[10:26:50]   Checking for directory '/usr/man/man3/.../lsniff' [ Not found ]
[10:26:50]   Checking for directory '/usr/man/man3/.../TeLeKiT' [ Not found ]
[10:26:50] TeLeKiT Rootkit                                   [ Not found ]
[10:26:50]
[10:26:50] Checking for T0rn Rootkit...
[10:26:50]   Checking for file '/dev/.lib/lib/lib/t0rns'     [ Not found ]
[10:26:50]   Checking for file '/dev/.lib/lib/lib/du'        [ Not found ]
[10:26:50]   Checking for file '/dev/.lib/lib/lib/ls'        [ Not found ]
[10:26:50]   Checking for file '/dev/.lib/lib/lib/t0rnsb'    [ Not found ]
[10:26:50]   Checking for file '/dev/.lib/lib/lib/ps'        [ Not found ]
[10:26:50]   Checking for file '/dev/.lib/lib/lib/t0rnp'     [ Not found ]
[10:26:50]   Checking for file '/dev/.lib/lib/lib/find'      [ Not found ]
[10:26:51]   Checking for file '/dev/.lib/lib/lib/ifconfig'  [ Not found ]
[10:26:51]   Checking for file '/dev/.lib/lib/lib/pg'        [ Not found ]
[10:26:51]   Checking for file '/dev/.lib/lib/lib/ssh.tgz'   [ Not found ]
[10:26:51]   Checking for file '/dev/.lib/lib/lib/top'       [ Not found ]
[10:26:51]   Checking for file '/dev/.lib/lib/lib/sz'        [ Not found ]
[10:26:51]   Checking for file '/dev/.lib/lib/lib/login'     [ Not found ]
[10:26:51]   Checking for file '/dev/.lib/lib/lib/in.fingerd' [ Not found ]
[10:26:51]   Checking for file '/dev/.lib/lib/lib/1i0n.sh'   [ Not found ]
[10:26:51]   Checking for file '/dev/.lib/lib/lib/pstree'    [ Not found ]
[10:26:51]   Checking for file '/dev/.lib/lib/lib/in.telnetd' [ Not found ]
[10:26:51]   Checking for file '/dev/.lib/lib/lib/mjy'       [ Not found ]
[10:26:51]   Checking for file '/dev/.lib/lib/lib/sush'      [ Not found ]
[10:26:51]   Checking for file '/dev/.lib/lib/lib/tfn'       [ Not found ]
[10:26:51]   Checking for file '/dev/.lib/lib/lib/name'      [ Not found ]
[10:26:51]   Checking for file '/dev/.lib/lib/lib/getip.sh'  [ Not found ]
[10:26:51]   Checking for file '/usr/info/.torn/sh*'         [ Not found ]
[10:26:51]   Checking for file '/usr/src/.puta/.1addr'       [ Not found ]
[10:26:51]   Checking for file '/usr/src/.puta/.1file'       [ Not found ]
[10:26:51]   Checking for file '/usr/src/.puta/.1proc'       [ Not found ]
[10:26:51]   Checking for file '/usr/src/.puta/.1logz'       [ Not found ]
[10:26:52]   Checking for file '/usr/info/.t0rn'             [ Not found ]
[10:26:52]   Checking for directory '/dev/.lib'              [ Not found ]
[10:26:52]   Checking for directory '/dev/.lib/lib'          [ Not found ]
[10:26:52]   Checking for directory '/dev/.lib/lib/lib'      [ Not found ]
[10:26:52]   Checking for directory '/dev/.lib/lib/lib/dev'  [ Not found ]
[10:26:52]   Checking for directory '/dev/.lib/lib/scan'     [ Not found ]
[10:26:52]   Checking for directory '/usr/src/.puta'         [ Not found ]
[10:26:52]   Checking for directory '/usr/man/man1/man1'     [ Not found ]
[10:26:52]   Checking for directory '/usr/man/man1/man1/lib' [ Not found ]
[10:26:52]   Checking for directory '/usr/man/man1/man1/lib/.lib' [ Not found ]
[10:26:52]   Checking for directory '/usr/man/man1/man1/lib/.lib/.backup' [ Not found ]
[10:26:52] T0rn Rootkit                                      [ Not found ]
[10:26:52]
[10:26:52] Checking for trNkit Rootkit...
[10:26:52]   Checking for file '/usr/lib/libbins.la'         [ Not found ]
[10:26:52]   Checking for file '/usr/lib/libtcs.so'          [ Not found ]
[10:26:52]   Checking for file '/dev/.ttpy/ulogin.sh'        [ Not found ]
[10:26:52]   Checking for file '/dev/.ttpy/tcpshell.sh'      [ Not found ]
[10:26:52]   Checking for file '/dev/.ttpy/bupdu'            [ Not found ]
[10:26:52]   Checking for file '/dev/.ttpy/buloc'            [ Not found ]
[10:26:52]   Checking for file '/dev/.ttpy/buloc1'           [ Not found ]
[10:26:53]   Checking for file '/dev/.ttpy/buloc2'           [ Not found ]
[10:26:53]   Checking for file '/dev/.ttpy/stat'             [ Not found ]
[10:26:53]   Checking for file '/dev/.ttpy/backps'           [ Not found ]
[10:26:53]   Checking for file '/dev/.ttpy/tree'             [ Not found ]
[10:26:53]   Checking for file '/dev/.ttpy/topk'             [ Not found ]
[10:26:53]   Checking for file '/dev/.ttpy/wold'             [ Not found ]
[10:26:53]   Checking for file '/dev/.ttpy/whoold'           [ Not found ]
[10:26:53]   Checking for file '/dev/.ttpy/backdoors'        [ Not found ]
[10:26:53] trNkit Rootkit                                    [ Not found ]
[10:26:53]
[10:26:53] Checking for Trojanit Kit...
[10:26:53]   Checking for file '/bin/.ls'                    [ Not found ]
[10:26:53]   Checking for file '/bin/.ps'                    [ Not found ]
[10:26:53]   Checking for file '/bin/.netstat'               [ Not found ]
[10:26:53]   Checking for file '/usr/bin/.nop'               [ Not found ]
[10:26:53]   Checking for file '/usr/bin/.who'               [ Not found ]
[10:26:53] Trojanit Kit                                      [ Not found ]
[10:26:53]
[10:26:53] Checking for Tuxtendo Rootkit...
[10:26:53]   Checking for file '/lib/libproc.so.2.0.7'       [ Not found ]
[10:26:53]   Checking for file '/usr/bin/xchk'               [ Not found ]
[10:26:53]   Checking for file '/usr/bin/xsf'                [ Not found ]
[10:26:53]   Checking for file '/dev/tux/suidsh'             [ Not found ]
[10:26:54]   Checking for file '/dev/tux/.addr'              [ Not found ]
[10:26:54]   Checking for file '/dev/tux/.cron'              [ Not found ]
[10:26:54]   Checking for file '/dev/tux/.file'              [ Not found ]
[10:26:54]   Checking for file '/dev/tux/.log'               [ Not found ]
[10:26:54]   Checking for file '/dev/tux/.proc'              [ Not found ]
[10:26:54]   Checking for file '/dev/tux/.iface'             [ Not found ]
[10:26:54]   Checking for file '/dev/tux/.pw'                [ Not found ]
[10:26:54]   Checking for file '/dev/tux/.df'                [ Not found ]
[10:26:54]   Checking for file '/dev/tux/.ssh'               [ Not found ]
[10:26:54]   Checking for file '/dev/tux/.tux'               [ Not found ]
[10:26:54]   Checking for file '/dev/tux/ssh2/sshd2_config'  [ Not found ]
[10:26:54]   Checking for file '/dev/tux/ssh2/hostkey'       [ Not found ]
[10:26:54]   Checking for file '/dev/tux/ssh2/hostkey.pub'   [ Not found ]
[10:26:54]   Checking for file '/dev/tux/ssh2/logo'          [ Not found ]
[10:26:54]   Checking for file '/dev/tux/ssh2/random_seed'   [ Not found ]
[10:26:54]   Checking for file '/dev/tux/backup/crontab'     [ Not found ]
[10:26:54]   Checking for file '/dev/tux/backup/df'          [ Not found ]
[10:26:54]   Checking for file '/dev/tux/backup/dir'         [ Not found ]
[10:26:54]   Checking for file '/dev/tux/backup/find'        [ Not found ]
[10:26:54]   Checking for file '/dev/tux/backup/ifconfig'    [ Not found ]
[10:26:55]   Checking for file '/dev/tux/backup/locate'      [ Not found ]
[10:26:55]   Checking for file '/dev/tux/backup/netstat'     [ Not found ]
[10:26:55]   Checking for file '/dev/tux/backup/ps'          [ Not found ]
[10:26:55]   Checking for file '/dev/tux/backup/pstree'      [ Not found ]
[10:26:55]   Checking for file '/dev/tux/backup/syslogd'     [ Not found ]
[10:26:55]   Checking for file '/dev/tux/backup/tcpd'        [ Not found ]
[10:26:55]   Checking for file '/dev/tux/backup/top'         [ Not found ]
[10:26:55]   Checking for file '/dev/tux/backup/updatedb'    [ Not found ]
[10:26:55]   Checking for file '/dev/tux/backup/vdir'        [ Not found ]
[10:26:55]   Checking for directory '/dev/tux'               [ Not found ]
[10:26:55]   Checking for directory '/dev/tux/ssh2'          [ Not found ]
[10:26:55]   Checking for directory '/dev/tux/backup'        [ Not found ]
[10:26:55] Tuxtendo Rootkit                                  [ Not found ]
[10:26:55]
[10:26:55] Checking for URK Rootkit...
[10:26:55]   Checking for file '/dev/prom/sn.l'              [ Not found ]
[10:26:55]   Checking for file '/usr/lib/ldlibps.so'         [ Not found ]
[10:26:55]   Checking for file '/usr/lib/ldlibnet.so'        [ Not found ]
[10:26:55]   Checking for file '/dev/pts/01/uconf.inv'       [ Not found ]
[10:26:55]   Checking for file '/dev/pts/01/cleaner'         [ Not found ]
[10:26:55]   Checking for file '/dev/pts/01/bin/psniff'      [ Not found ]
[10:26:56]   Checking for file '/dev/pts/01/bin/du'          [ Not found ]
[10:26:56]   Checking for file '/dev/pts/01/bin/ls'          [ Not found ]
[10:26:56]   Checking for file '/dev/pts/01/bin/passwd'      [ Not found ]
[10:26:56]   Checking for file '/dev/pts/01/bin/ps'          [ Not found ]
[10:26:56]   Checking for file '/dev/pts/01/bin/psr'         [ Not found ]
[10:26:56]   Checking for file '/dev/pts/01/bin/su'          [ Not found ]
[10:26:56]   Checking for file '/dev/pts/01/bin/find'        [ Not found ]
[10:26:56]   Checking for file '/dev/pts/01/bin/netstat'     [ Not found ]
[10:26:56]   Checking for file '/dev/pts/01/bin/ping'        [ Not found ]
[10:26:56]   Checking for file '/dev/pts/01/bin/strings'     [ Not found ]
[10:26:56]   Checking for file '/dev/pts/01/bin/bash'        [ Not found ]
[10:26:56]   Checking for file '/usr/man/man1/xxxxxxbin/du'  [ Not found ]
[10:26:56]   Checking for file '/usr/man/man1/xxxxxxbin/ls'  [ Not found ]
[10:26:56]   Checking for file '/usr/man/man1/xxxxxxbin/passwd' [ Not found ]
[10:26:56]   Checking for file '/usr/man/man1/xxxxxxbin/ps'  [ Not found ]
[10:26:56]   Checking for file '/usr/man/man1/xxxxxxbin/psr' [ Not found ]
[10:26:56]   Checking for file '/usr/man/man1/xxxxxxbin/su'  [ Not found ]
[10:26:56]   Checking for file '/usr/man/man1/xxxxxxbin/find' [ Not found ]
[10:26:56]   Checking for file '/usr/man/man1/xxxxxxbin/netstat' [ Not found ]
[10:26:56]   Checking for file '/usr/man/man1/xxxxxxbin/ping' [ Not found ]
[10:26:57]   Checking for file '/usr/man/man1/xxxxxxbin/strings' [ Not found ]
[10:26:57]   Checking for file '/usr/man/man1/xxxxxxbin/bash' [ Not found ]
[10:26:57]   Checking for file '/tmp/conf.inv'               [ Not found ]
[10:26:57]   Checking for directory '/dev/prom'              [ Not found ]
[10:26:57]   Checking for directory '/dev/pts/01'            [ Not found ]
[10:26:57]   Checking for directory '/dev/pts/01/bin'        [ Not found ]
[10:26:57]   Checking for directory '/usr/man/man1/xxxxxxbin' [ Not found ]
[10:26:57] URK Rootkit                                       [ Not found ]
[10:26:57]
[10:26:57] Checking for Vampire Rootkit...
[10:26:57]   Checking for kernel symbol 'new_getdents'       [ Not found ]
[10:26:57]   Checking for kernel symbol 'old_getdents'       [ Not found ]
[10:26:57]   Checking for kernel symbol 'should_hide_file_name' [ Not found ]
[10:26:57]   Checking for kernel symbol 'should_hide_task_name' [ Not found ]
[10:26:57] Vampire Rootkit                                   [ Not found ]
[10:26:57]
[10:26:57] Checking for VcKit Rootkit...
[10:26:57]   Checking for directory '/usr/include/linux/modules/lib.so' [ Not found ]
[10:26:57]   Checking for directory '/usr/include/linux/modules/lib.so/bin' [ Not found ]
[10:26:57] VcKit Rootkit                                     [ Not found ]
[10:26:57]
[10:26:57] Checking for Volc Rootkit...
[10:26:58]   Checking for file '/usr/bin/volc'               [ Not found ]
[10:26:58]   Checking for file '/usr/lib/volc/backdoor/divine' [ Not found ]
[10:26:58]   Checking for file '/usr/lib/volc/linsniff'      [ Not found ]
[10:26:58]   Checking for file '/etc/rc.d/rc1.d/S25sysconf'  [ Not found ]
[10:26:58]   Checking for file '/etc/rc.d/rc2.d/S25sysconf'  [ Not found ]
[10:26:58]   Checking for file '/etc/rc.d/rc3.d/S25sysconf'  [ Not found ]
[10:26:58]   Checking for file '/etc/rc.d/rc4.d/S25sysconf'  [ Not found ]
[10:26:58]   Checking for file '/etc/rc.d/rc5.d/S25sysconf'  [ Not found ]
[10:26:58]   Checking for directory '/var/spool/.recent'     [ Not found ]
[10:26:58]   Checking for directory '/var/spool/.recent/.files' [ Not found ]
[10:26:58]   Checking for directory '/usr/lib/volc'          [ Not found ]
[10:26:58]   Checking for directory '/usr/lib/volc/backup'   [ Not found ]
[10:26:58] Volc Rootkit                                      [ Not found ]
[10:26:58]
[10:26:58] Checking for Xzibit Rootkit...
[10:26:58]   Checking for file '/dev/dsx'                    [ Not found ]
[10:26:58]   Checking for file '/dev/caca'                   [ Not found ]
[10:26:58]   Checking for file '/dev/ida/.inet/linsniffer'   [ Not found ]
[10:26:58]   Checking for file '/dev/ida/.inet/logclear'     [ Not found ]
[10:26:58]   Checking for file '/dev/ida/.inet/sense'        [ Not found ]
[10:26:58]   Checking for file '/dev/ida/.inet/sl2'          [ Not found ]
[10:26:59]   Checking for file '/dev/ida/.inet/sshdu'        [ Not found ]
[10:26:59]   Checking for file '/dev/ida/.inet/s'            [ Not found ]
[10:26:59]   Checking for file '/dev/ida/.inet/ssh_host_key' [ Not found ]
[10:26:59]   Checking for file '/dev/ida/.inet/ssh_random_seed' [ Not found ]
[10:26:59]   Checking for file '/dev/ida/.inet/sl2new.c'     [ Not found ]
[10:26:59]   Checking for file '/dev/ida/.inet/tcp.log'      [ Not found ]
[10:26:59]   Checking for file '/home/httpd/cgi-bin/becys.cgi' [ Not found ]
[10:26:59]   Checking for file '/usr/local/httpd/cgi-bin/becys.cgi' [ Not found ]
[10:26:59]   Checking for file '/usr/local/apache/cgi-bin/becys.cgi' [ Not found ]
[10:26:59]   Checking for file '/www/httpd/cgi-bin/becys.cgi' [ Not found ]
[10:26:59]   Checking for file '/www/cgi-bin/becys.cgi'      [ Not found ]
[10:26:59]   Checking for directory '/dev/ida/.inet'         [ Not found ]
[10:26:59] Xzibit Rootkit                                    [ Not found ]
[10:26:59]
[10:26:59] Checking for X-Org SunOS Rootkit...
[10:26:59]   Checking for file '/usr/lib/libX.a/bin/tmpfl'   [ Not found ]
[10:26:59]   Checking for file '/usr/lib/libX.a/bin/rps'     [ Not found ]
[10:26:59]   Checking for file '/usr/bin/srload'             [ Not found ]
[10:26:59]   Checking for file '/usr/lib/libX.a/bin/sparcv7/rps' [ Not found ]
[10:26:59]   Checking for file '/usr/sbin/modcheck'          [ Not found ]
[10:26:59]   Checking for directory '/usr/lib/libX.a'        [ Not found ]
[10:27:00]   Checking for directory '/usr/lib/libX.a/bin'    [ Not found ]
[10:27:00]   Checking for directory '/usr/lib/libX.a/bin/sparcv7' [ Not found ]
[10:27:00]   Checking for directory '/usr/share/man...'      [ Not found ]
[10:27:00] X-Org SunOS Rootkit                               [ Not found ]
[10:27:00]
[10:27:00] Checking for zaRwT.KiT Rootkit...
[10:27:00]   Checking for file '/dev/rd/s/sendmeil'          [ Not found ]
[10:27:00]   Checking for file '/dev/ttyf'                   [ Not found ]
[10:27:00]   Checking for file '/dev/ttyp'                   [ Not found ]
[10:27:00]   Checking for file '/dev/ttyn'                   [ Not found ]
[10:27:00]   Checking for file '/rk/tulz'                    [ Not found ]
[10:27:00]   Checking for directory '/rk'                    [ Not found ]
[10:27:00]   Checking for directory '/dev/rd/s'              [ Not found ]
[10:27:00] zaRwT.KiT Rootkit                                 [ Not found ]
[10:27:00]
[10:27:00] Checking for ZK Rootkit...
[10:27:00]   Checking for file '/usr/share/.zk/zk'           [ Not found ]
[10:27:00]   Checking for file '/usr/X11R6/.zk/xfs'          [ Not found ]
[10:27:00]   Checking for file '/usr/X11R6/.zk/echo'         [ Not found ]
[10:27:00]   Checking for file '/etc/1ssue.net'              [ Not found ]
[10:27:00]   Checking for file '/etc/sysconfig/console/load.zk' [ Not found ]
[10:27:00]   Checking for directory '/usr/share/.zk'         [ Not found ]
[10:27:00]   Checking for directory '/usr/X11R6/.zk'         [ Not found ]
[10:27:01] ZK Rootkit                                        [ Not found ]
[10:27:01]
[10:27:01] Info: Starting test name 'additional_rkts'
[10:27:01] Performing additional rootkit checks
[10:27:01]
[10:27:01]   Performing Suckit Rookit additional checks
[10:27:01]     Checking hard link count on '/sbin/init'      [ OK ]
[10:27:01]     Checking for hidden file extensions           [ None found ]
[10:27:01]     Running skdet command                         [ Skipped ]
[10:27:01] Info: Unable to find the 'skdet' command
[10:27:01]   Suckit Rookit additional checks                 [ OK ]
[10:27:01]
[10:27:01] Info: Starting test name 'possible_rkt_files'
[10:27:01]   Performing check of possible rootkit files and directories
[10:27:01]     Checking for file '/dev/sdr0'                 [ Not found ]
[10:27:01]     Checking for file '/dev/pisu'                 [ Not found ]
[10:27:01]     Checking for file '/dev/xdta'                 [ Not found ]
[10:27:01]     Checking for file '/dev/saux'                 [ Not found ]
[10:27:01]     Checking for file '/dev/hdx'                  [ Not found ]
[10:27:01]     Checking for file '/dev/hdx1'                 [ Not found ]
[10:27:01]     Checking for file '/dev/hdx2'                 [ Not found ]
[10:27:02]     Checking for file '/dev/ptyy'                 [ Not found ]
[10:27:02]     Checking for file '/dev/ptyu'                 [ Not found ]
[10:27:02]     Checking for file '/dev/ptyv'                 [ Not found ]
[10:27:02]     Checking for file '/dev/hdbb'                 [ Not found ]
[10:27:02]     Checking for file '/tmp/.syshackfile'         [ Not found ]
[10:27:02]     Checking for file '/tmp/.bash_history'        [ Not found ]
[10:27:02]     Checking for file '/usr/info/.clib'           [ Not found ]
[10:27:02]     Checking for file '/usr/sbin/tcp.log'         [ Not found ]
[10:27:02]     Checking for file '/usr/bin/take/pid'         [ Not found ]
[10:27:02]     Checking for file '/sbin/create'              [ Not found ]
[10:27:02]     Checking for file '/dev/ttypz'                [ Not found ]
[10:27:02]     Checking for file '/var/log/tcp.log'          [ Not found ]
[10:27:02]     Checking for file '/usr/include/audit.h'      [ Not found ]
[10:27:02]     Checking for file '/usr/bin/sourcemask'       [ Not found ]
[10:27:02]     Checking for file '/usr/bin/ras2xm'           [ Not found ]
[10:27:03]     Checking for file '/dev/xmx'                  [ Not found ]
[10:27:03]     Checking for file '/usr/sbin/gpm.root'        [ Not found ]
[10:27:03]     Checking for file '/bin/vobiscum'             [ Not found ]
[10:27:03]     Checking for file '/bin/psr'                  [ Not found ]
[10:27:03]     Checking for file '/dev/kdx'                  [ Not found ]
[10:27:03]     Checking for file '/dev/dkx'                  [ Not found ]
[10:27:03]     Checking for file '/usr/sbin/sshd3'           [ Not found ]
[10:27:03]     Checking for file '/usr/sbin/jcd'             [ Not found ]
[10:27:03]     Checking for file '/etc/rc.d/init.d/jcd'      [ Not found ]
[10:27:03]     Checking for file '/usr/sbin/atd2'            [ Not found ]
[10:27:03]     Checking for file '/home/httpd/cgi-bin/linux.cgi' [ Not found ]
[10:27:03]     Checking for file '/home/httpd/cgi-bin/psid'  [ Not found ]
[10:27:03]     Checking for file '/home/httpd/cgi-bin/void.cgi' [ Not found ]
[10:27:03]     Checking for file '/etc/rc.d/init.d/system'   [ Not found ]
[10:27:04]     Checking for file '/etc/rc.d/rc3.d/S93users'  [ Not found ]
[10:27:04]     Checking for file '/tmp/.ush'                 [ Not found ]
[10:27:04]     Checking for file '/usr/lib/libhidefile.so'   [ Not found ]
[10:27:04]     Checking for file '/etc/cron.d/kmod'          [ Not found ]
[10:27:04]     Checking for file '/usr/lib/dmis/dmisd'       [ Not found ]
[10:27:04]     Checking for file '/lib/secure/libhij.so'     [ Not found ]
[10:27:04]     Checking for file '/usr/sbin/sshd3'           [ Not found ]
[10:27:04]     Checking for file '/etc/rc.d/init.d/crontab'  [ Not found ]
[10:27:04]     Checking for file '/etc/rc.d/init.d/jcd'      [ Not found ]
[10:27:04]     Checking for file '/usr/sbin/atd2'            [ Not found ]
[10:27:04]     Checking for file '/etc/rc.d/rc5.d/S93users'  [ Not found ]
[10:27:04]     Checking for directory '/dev/ptyas'           [ Not found ]
[10:27:04]     Checking for directory '/usr/bin/take'        [ Not found ]
[10:27:04]     Checking for directory '/usr/src/.lib'        [ Not found ]
[10:27:05]     Checking for directory '/usr/share/man/man1/.1c' [ Not found ]
[10:27:05]     Checking for directory '/lib/lblip.tk'        [ Not found ]
[10:27:05]     Checking for directory '/usr/sbin/...'        [ Not found ]
[10:27:05]     Checking for directory '/usr/share/.gun'      [ Not found ]
[10:27:05]     Checking for directory '/unde/vrei/tu/sa/te/ascunzi/in/server' [ Not found ]
[10:27:05]     Checking for directory '/usr/man/man1/..  /.dir' [ Not found ]
[10:27:05]     Checking for directory '/usr/X11R6/include/X11/...' [ Not found ]
[10:27:05]     Checking for directory '/usr/X11R6/lib/X11/.fonts/misc/...' [ Not found ]
[10:27:05]     Checking for directory '/tmp/.sys'            [ Not found ]
[10:27:05]     Checking for directory '/tmp/''               [ Not found ]
[10:27:05]     Checking for directory '/tmp/.,'              [ Not found ]
[10:27:05]     Checking for directory '/tmp/,.,'             [ Not found ]
[10:27:05]     Checking for directory '/dev/shm/emilien'     [ Not found ]
[10:27:05]     Checking for directory '/var/tmp/.log'        [ Not found ]
[10:27:06]     Checking for directory '/tmp/zmeu/... '       [ Not found ]
[10:27:06]     Checking for directory '/var/log/ssh'         [ Not found ]
[10:27:06]     Checking for directory '/dev/ida'             [ Not found ]
[10:27:06]     Checking for directory '/lib/java'            [ Not found ]
[10:27:06]     Checking for directory '/var/lib/games/.src/ssk/shit' [ Not found ]
[10:27:06]     Checking for directory '/usr/lib/libshtift'   [ Not found ]
[10:27:06]     Checking for directory '/usr/src/.poop'       [ Not found ]
[10:27:06]     Checking for directory '/dev/wd4'             [ Not found ]
[10:27:06]     Checking for directory '/var/run/.tmp'        [ Not found ]
[10:27:06]     Checking for directory '/usr/man/man1/lib/.lib' [ Not found ]
[10:27:06]     Checking for directory '/dev/portd'           [ Not found ]
[10:27:06]     Checking for directory '/dev/...'             [ Not found ]
[10:27:06]     Checking for directory '/usr/share/man/mansps' [ Not found ]
[10:27:06]     Checking for directory '/lib/.so'             [ Not found ]
[10:27:07]     Checking for directory '/lib/.sso'            [ Not found ]
[10:27:07]   Checking for possible rootkit files and directories [ None found ]
[10:27:07]
[10:27:07] Info: Starting test name 'possible_rkt_strings'
[10:27:07]   Performing check for possible rootkit strings
[10:27:07] Info: Using system startup paths: /etc/rc.d /etc/inittab
[10:27:07]     Checking for string 'LOGNAME=root'            [ Not found ]
[10:27:07]     Checking for string 'phalanx'                 [ Not found ]
[10:27:07]     Checking for string '/dev/proc/fuckit'        [ Not found ]
[10:27:07]     Checking for string 'FUCK'                    [ Not found ]
[10:27:07]     Checking for string 'backdoor'                [ Not found ]
[10:27:07]     Checking for string '/usr/bin/rcpc'           [ Not found ]
[10:27:07]     Checking for string '/usr/sbin/login'         [ Not found ]
[10:27:07]     Checking for string '/dev/ptyxx/.proc'        [ Not found ]
[10:27:08]     Checking for string 'vt200'                   [ Not found ]
[10:27:08]     Checking for string '/usr/bin/xstat'          [ Not found ]
[10:27:08]     Checking for string '/bin/envpc'              [ Not found ]
[10:27:08]     Checking for string 'L4m3r0x'                 [ Not found ]
[10:27:08]     Checking for string '/lib/libext'             [ Not found ]
[10:27:08]     Checking for string '/usr/sbin/login'         [ Not found ]
[10:27:08]     Checking for string '/usr/lib/.tbd'           [ Not found ]
[10:27:08]     Checking for string 'sendmail'                [ Not found ]
[10:27:08]     Checking for string 'cocacola'                [ Not found ]
[10:27:08]     Checking for string 'joao'                    [ Not found ]
[10:27:08]     Checking for string '/dev/ptyxx/.file'        [ Not found ]
[10:27:08]     Checking for string '/dev/ptyxx/.file'        [ Not found ]
[10:27:08]     Checking for string '/dev/sgk'                [ Not found ]
[10:27:09]     Checking for string '/var/lock/subsys/...datafile...' [ Not found ]
[10:27:09]     Checking for string '/usr/lib/.tbd'           [ Not found ]
[10:27:09]     Checking for string '/dev/proc/fuckit'        [ Not found ]
[10:27:09]     Checking for string '/lib/.sso'               [ Not found ]
[10:27:09]     Checking for string '/var/lock/subsys/...datafile...' [ Not found ]
[10:27:09]     Checking for string '/dev/caca'               [ Not found ]
[10:27:09]     Checking for string '/dev/ttyoa'              [ Not found ]
[10:27:09]     Checking for string '/usr/lib/ldlibns.so'     [ Not found ]
[10:27:09]     Checking for string '/dev/ptyxx/.addr'        [ Not found ]
[10:27:09]     Checking for string 'syg'                     [ Not found ]
[10:27:09]     Checking for string 'sshd_config'             [ Not found ]
[10:27:10]     Checking for string '/var/lock/subsys/...datafile...' [ Not found ]
[10:27:10]     Checking for string '/dev/pts/01'             [ Not found ]
[10:27:10]     Checking for string 'tw33dl3'                 [ Not found ]
[10:27:10]     Checking for string 'psniff'                  [ Not found ]
[10:27:10]     Checking for string 'uconf.inv'               [ Not found ]
[10:27:10]     Checking for string 'lib/ldlibps.so'          [ Not found ]
[10:27:10]     Checking for string '/usr/lib/ldlibpst.so'    [ Not found ]
[10:27:10]     Checking for string '/var/lock/subsys/...datafile...' [ Not found ]
[10:27:10]     Checking for string 'libproc.so.2.0.7'        [ Not found ]
[10:27:10]     Checking for string '/dev/ptyxx/.proc'        [ Not found ]
[10:27:10]     Checking for string '/dev/ptyxx/.proc'        [ Not found ]
[10:27:10]     Checking for string 'libproc.so.2.0.7'        [ Not found ]
[10:27:10]     Checking for string 'libproc.so.2.0.7'        [ Not found ]
[10:27:11]     Checking for string '/bin/bash'               [ Not found ]
[10:27:11]     Checking for string 'cant open log'           [ Not found ]
[10:27:11]     Checking for string 'sniff.pid'               [ Not found ]
[10:27:11]     Checking for string 'tcp.log'                 [ Not found ]
[10:27:11]     Checking for string '/dev/ptyxx'              [ Not found ]
[10:27:11]     Checking for string '/.config'                [ Not found ]
[10:27:11]     Checking for string '\$.*\$\!.*\!\!\$'        [ Not found ]
[10:27:11]     Checking for string 'promiscuous'             [ Not found ]
[10:27:11]     Checking for string '/usr/lib/.tbd'           [ Not found ]
[10:27:11]     Checking for string '/dev/ptyxx/.log'         [ Not found ]
[10:27:11]     Checking for string '/dev/xdta'               [ Not found ]
[10:27:12]     Checking for string '/usr/lib/.tbd'           [ Not found ]
[10:27:12]     Checking for string '/dev/ptyxx/.proc'        [ Not found ]
[10:27:13]     Checking for string 'in.inetd'                [ Not found ]
[10:27:13]     Checking for string '#<HIDE_.*>'              [ Not found ]
[10:27:14]     Checking for string 'bin/xchk'                [ Not found ]
[10:27:14]     Checking for string 'bin/xsf'                 [ Not found ]
[10:27:15]     Checking for string '/usr/bin/ssh2d'          [ Not found ]
[10:27:15]     Checking for string '/usr/sbin/xntps'         [ Not found ]
[10:27:16]     Checking for string 'ttyload'                 [ Not found ]
[10:27:17]     Checking for string '/etc/rc.d/init.d/init'   [ Not found ]
[10:27:17]     Checking for string 'usr/bin/xfss'            [ Not found ]
[10:27:18]     Checking for string '/usr/sbin/rpc.netinet'   [ Not found ]
[10:27:18]     Checking for string '/usr/lib/.fx/cons.saver' [ Not found ]
[10:27:19]     Checking for string '/usr/lib/.fx/xs'         [ Not found ]
[10:27:19]     Checking for string '/ssh2d'                  [ Not found ]
[10:27:20]     Checking for string '/dev/kmod'               [ Not found ]
[10:27:21]     Checking for string '/crth.o'                 [ Not found ]
[10:27:21]     Checking for string '/crtz.o'                 [ Not found ]
[10:27:22]     Checking for string '/dev/dos'                [ Not found ]
[10:27:22]     Checking for string '/lpq'                    [ Not found ]
[10:27:23]     Checking for string '/usr/sbin/rescue'        [ Not found ]
[10:27:24]     Checking for string '/usr/lib/lpstart'        [ Not found ]
[10:27:24]     Checking for string '/volc'                   [ Not found ]
[10:27:25]     Checking for string 'sourcemask'              [ Not found ]
[10:27:25]     Checking for string '/bin/vobiscum'           [ Not found ]
[10:27:26]     Checking for string '/usr/sbin/in.telnet'     [ Not found ]
[10:27:26]     Checking for string 'hdparm'                  [ Not found ]
[10:27:26]     Checking for string '/lib/ldd.so/tkps'        [ Not found ]
[10:27:27]     Checking for string 't0rnkit'                 [ Not found ]
[10:27:27]     Checking for string '/dev/proc/fuckit'        [ Not found ]
[10:27:27]     Checking for string 'libproc.so.2.0.7'        [ Not found ]
[10:27:27]     Checking for string 'libproc.so.2.0.7'        [ Not found ]
[10:27:27]     Checking for string 'libproc.so.2.0.7'        [ Not found ]
[10:27:27]     Checking for string '/usr/lib/ldlibct.so'     [ Not found ]
[10:27:27]     Checking for string '/usr/lib/ldlibdu.so'     [ Not found ]
[10:27:27]     Checking for string '/dev/ptyxx/.file'        [ Not found ]
[10:27:27]     Checking for string 'libproc.so.2.0.7'        [ Not found ]
[10:27:27]     Checking for string '/dev/ida/.inet'          [ Not found ]
[10:27:27]   Checking for possible rootkit strings           [ None found ]
[10:27:27]
[10:27:27] Info: Starting test name 'malware'
[10:27:27] Performing malware checks
[10:27:27]
[10:27:27] Info: Test 'deleted_files' disabled at users request.
[10:27:27]
[10:27:27] Info: Starting test name 'running_procs'
[10:27:28]   Checking running processes for suspicious files [ None found ]
[10:27:28]
[10:27:28] Info: Test 'hidden_procs' disabled at users request.
[10:27:28]
[10:27:28] Info: Test 'suspscan' disabled at users request.
[10:27:29]
[10:27:29] Info: Starting test name 'other_malware'
[10:27:29]   Performing check for login backdoors
[10:27:29]     Checking for '/bin/.login'                    [ Not found ]
[10:27:29]     Checking for '/sbin/.login'                   [ Not found ]
[10:27:29]   Checking for login backdoors                    [ None found ]
[10:27:29]
[10:27:29]   Performing check for suspicious directories
[10:27:29]     Checking for directory '/usr/X11R6/bin/.,/copy' [ Not found ]
[10:27:29]     Checking for directory '/dev/rd/cdb'          [ Not found ]
[10:27:29]   Checking for suspicious directories             [ None found ]
[10:27:29]
[10:27:29]   Checking for software intrusions                [ Skipped ]
[10:27:29] Info: Check skipped - tripwire not installed
[10:27:29]
[10:27:29]   Performing check for sniffer log files
[10:27:29]     Checking for file '/usr/lib/libice.log'       [ Not found ]
[10:27:29]     Checking for file '/dev/prom/sn.l'            [ Not found ]
[10:27:29]     Checking for file '/dev/fd/.88/zxsniff.log'   [ Not found ]
[10:27:29]   Checking for sniffer log files                  [ None found ]
[10:27:29]
[10:27:29] Info: Starting test name 'trojans'
[10:27:29] Performing trojan specific checks
[10:27:29]   Checking for enabled inetd services             [ Skipped ]
[10:27:29] Info: Check skipped - file '/etc/inetd.conf' does not exist.
[10:27:29]
[10:27:29]   Performing check for enabled xinetd services
[10:27:29] Info: Using xinetd configuration file '/etc/xinetd.conf'
[10:27:29]     Checking '/etc/xinetd.conf' for enabled services [ None found ]
[10:27:30]       Found 'includedir /etc/xinetd.d' directive
[10:27:30]     Checking '/etc/xinetd.d/amanda' for enabled services [ None found ]
[10:27:30]     Checking '/etc/xinetd.d/amandaidx' for enabled services [ None found ]
[10:27:30]     Checking '/etc/xinetd.d/amidxtape' for enabled services [ None found ]
[10:27:30]     Checking '/etc/xinetd.d/auth' for enabled services [ None found ]
[10:27:30]     Checking '/etc/xinetd.d/chargen-dgram' for enabled services [ None found ]
[10:27:30]     Checking '/etc/xinetd.d/chargen-stream' for enabled services [ None found ]
[10:27:30]     Checking '/etc/xinetd.d/cvs' for enabled services [ None found ]
[10:27:30]     Checking '/etc/xinetd.d/daytime-dgram' for enabled services [ None found ]
[10:27:30]     Checking '/etc/xinetd.d/daytime-stream' for enabled services [ None found ]
[10:27:30]     Checking '/etc/xinetd.d/discard-dgram' for enabled services [ None found ]
[10:27:30]     Checking '/etc/xinetd.d/discard-stream' for enabled services [ None found ]
[10:27:30]     Checking '/etc/xinetd.d/echo-dgram' for enabled services [ None found ]
[10:27:31]     Checking '/etc/xinetd.d/echo-stream' for enabled services [ None found ]
[10:27:31]     Checking '/etc/xinetd.d/eklogin' for enabled services [ None found ]
[10:27:31]     Checking '/etc/xinetd.d/ekrb5-telnet' for enabled services [ None found ]
[10:27:31]     Checking '/etc/xinetd.d/gssftp' for enabled services [ None found ]
[10:27:31]     Checking '/etc/xinetd.d/klogin' for enabled services [ None found ]
[10:27:31]     Checking '/etc/xinetd.d/krb5-telnet' for enabled services [ None found ]
[10:27:31]     Checking '/etc/xinetd.d/kshell' for enabled services [ None found ]
[10:27:31]     Checking '/etc/xinetd.d/ktalk' for enabled services [ None found ]
[10:27:31]     Checking '/etc/xinetd.d/ntalk' for enabled services [ None found ]
[10:27:31]     Checking '/etc/xinetd.d/rexec' for enabled services [ None found ]
[10:27:31]     Checking '/etc/xinetd.d/rlogin' for enabled services [ None found ]
[10:27:31]     Checking '/etc/xinetd.d/rmcp' for enabled services [ None found ]
[10:27:31]     Checking '/etc/xinetd.d/rsh' for enabled services [ None found ]
[10:27:32]     Checking '/etc/xinetd.d/rsync' for enabled services [ None found ]
[10:27:32]     Checking '/etc/xinetd.d/talk' for enabled services [ None found ]
[10:27:32]     Checking '/etc/xinetd.d/tcpmux-server' for enabled services [ None found ]
[10:27:32]     Checking '/etc/xinetd.d/telnet' for enabled services [ None found ]
[10:27:32]     Checking '/etc/xinetd.d/tftp' for enabled services [ None found ]
[10:27:32]     Checking '/etc/xinetd.d/time-dgram' for enabled services [ None found ]
[10:27:32]     Checking '/etc/xinetd.d/time-stream' for enabled services [ None found ]
[10:27:32]     Checking '/etc/xinetd.d/uucp' for enabled services [ None found ]
[10:27:32]   Checking for enabled xinetd services            [ None found ]
[10:27:32]   Checking for Apache backdoor                    [ Not found ]
[10:27:32]
[10:27:32] Info: Starting test name 'os_specific'
[10:27:32] Performing Linux specific checks
[10:27:32]   Checking loaded kernel modules                  [ OK ]
[10:27:32] Info: Using modules pathname of '/lib/modules/2.6.18-194.26.1.el5'
[10:27:33]   Checking kernel module names                    [ OK ]
[10:33:54]
[10:33:54] Info: Starting test name 'network'
[10:33:54] Checking the network...
[10:33:54]
[10:33:54] Performing checks on the network ports
[10:33:54] Info: Starting test name 'ports'
[10:33:54]   Performing check for backdoor ports
[10:33:54]     Checking for TCP port 1524                    [ Not found ]
[10:33:54]     Checking for TCP port 1984                    [ Not found ]
[10:33:54]     Checking for UDP port 2001                    [ Not found ]
[10:33:55]     Checking for TCP port 2006                    [ Not found ]
[10:33:55]     Checking for TCP port 2128                    [ Not found ]
[10:33:55]     Checking for TCP port 6666                    [ Not found ]
[10:33:55]     Checking for TCP port 6667                    [ Not found ]
[10:33:55]     Checking for TCP port 6668                    [ Not found ]
[10:33:55]     Checking for TCP port 6669                    [ Not found ]
[10:33:55]     Checking for TCP port 7000                    [ Not found ]
[10:33:55]     Checking for TCP port 13000                   [ Not found ]
[10:33:55]     Checking for TCP port 14856                   [ Not found ]
[10:33:55]     Checking for TCP port 25000                   [ Not found ]
[10:33:56]     Checking for TCP port 29812                   [ Not found ]
[10:33:56]     Checking for TCP port 31337                   [ Not found ]
[10:33:56]     Checking for TCP port 32982                   [ Not found ]
[10:33:56]     Checking for TCP port 33369                   [ Not found ]
[10:33:56]     Checking for TCP port 47107                   [ Not found ]
[10:33:56]     Checking for TCP port 47018                   [ Not found ]
[10:33:56]     Checking for TCP port 60922                   [ Not found ]
[10:33:56]     Checking for TCP port 62883                   [ Not found ]
[10:33:56]     Checking for TCP port 65535                   [ Not found ]
[10:33:56]   Checking for backdoor ports                     [ None found ]
[10:33:56]
[10:33:56] Info: Test 'hidden_ports' disabled at users request.
[10:33:56]
[10:33:56] Performing checks on the network interfaces
[10:33:57] Info: Starting test name 'promisc'
[10:33:57]   Checking for promiscuous interfaces             [ None found ]
[10:33:57]
[10:33:57] Info: Test 'packet_cap_apps' disabled at users request.
[10:33:57]
[10:33:57] Info: Starting test name 'local_host'
[10:33:57] Checking the local host...
[10:33:57]
[10:33:57] Info: Starting test name 'startup_files'
[10:33:57] Performing system boot checks
[10:33:57]   Checking for local host name                    [ Found ]
[10:33:57]
[10:33:57] Info: Starting test name 'startup_malware'
[10:33:57]   Checking for system startup files               [ Found ]
[10:34:01]   Checking system startup files for malware       [ None found ]
[10:34:02]
[10:34:02] Info: Starting test name 'group_accounts'
[10:34:02] Performing group and account checks
[10:34:02]   Checking for passwd file                        [ Found ]
[10:34:02] Info: Found password file: /etc/passwd
[10:34:02]   Checking for root equivalent (UID 0) accounts   [ None found ]
[10:34:02] Info: Found shadow file: /etc/shadow
[10:34:02]   Checking for passwordless accounts              [ None found ]
[10:34:02]
[10:34:02] Info: Starting test name 'passwd_changes'
[10:34:02]   Checking for passwd file changes                [ None found ]
[10:34:02]
[10:34:02] Info: Starting test name 'group_changes'
[10:34:02]   Checking for group file changes                 [ None found ]
[10:34:02]   Checking root account shell history files       [ OK ]
[10:34:02]
[10:34:02] Info: Starting test name 'system_configs'
[10:34:02] Performing system configuration file checks
[10:34:02]   Checking for SSH configuration file             [ Found ]
[10:34:02] Info: Found SSH configuration file: /etc/ssh/sshd_config
[10:34:02] Info: Rkhunter option ALLOW_SSH_ROOT_USER set to 'no'.
[10:34:02] Info: Rkhunter option ALLOW_SSH_PROT_V1 set to '0'.
[10:34:02]   Checking if SSH root access is allowed          [ Warning ]
[10:34:02] Warning: The SSH configuration option 'PermitRootLogin' has not been set.
           The default value may be 'yes', to allow root access.
[10:34:02]   Checking if SSH protocol v1 is allowed          [ Not allowed ]
[10:34:03]   Checking for running syslog daemon              [ Found ]
[10:34:03] Info: Found syslog configuration file: /etc/syslog.conf
[10:34:03]   Checking for syslog configuration file          [ Found ]
[10:34:03]   Checking if syslog remote logging is allowed    [ Not allowed ]
[10:34:03]
[10:34:03] Info: Starting test name 'filesystem'
[10:34:03] Performing filesystem checks
[10:34:03] Info: SCAN_MODE_DEV set to 'THOROUGH'
[10:34:03]   Checking /dev for suspicious file types         [ None found ]
[10:34:04]   Checking for hidden files and directories       [ Warning ]
[10:34:04] Warning: Hidden directory found: /dev/.udev
[10:34:04] Warning: Hidden file found: /usr/share/man/man1/..1.gz: gzip compressed data, from Unix, max compression
[10:34:04] Warning: Hidden file found: /usr/bin/.fipscheck.hmac: ASCII text
[10:34:04] Warning: Hidden file found: /usr/bin/.ssh.hmac: ASCII text
[10:34:04] Warning: Hidden file found: /usr/sbin/.sshd.hmac: ASCII text
[10:34:04] Warning: Hidden file found: /usr/sbin/.ipsec.hmac: ASCII text
[10:34:12]
[10:34:12] Info: Starting test name 'apps'
[10:34:12] Checking application versions...
[10:34:13] Info: Application 'exim' not found.
[10:34:13]   Checking version of GnuPG                       [ OK ]
[10:34:13] Info: Application 'gpg' version '1.4.5' found.
[10:34:13]   Checking version of Apache                      [ Warning ]
[10:34:13] Warning: Application 'httpd', version '2.2.8', is out of date, and possibly a security risk.
[10:34:13]   Checking version of Bind DNS                    [ OK ]
[10:34:13] Info: Application 'named' version '9.3.6-P1' found.
[10:34:13]   Checking version of OpenSSL                     [ Warning ]
[10:34:13] Warning: Application 'openssl', version '0.9.8e', is out of date, and possibly a security risk.
[10:34:14]   Checking version of PHP                         [ Warning ]
[10:34:14] Warning: Application 'php', version '5.2.10', is out of date, and possibly a security risk.
[10:34:14]   Checking version of Procmail MTA                [ OK ]
[10:34:14] Info: Application 'procmail' version '3.22' found.
[10:34:14] Info: Application 'proftpd' not found.
[10:34:14]   Checking version of OpenSSH                     [ Warning ]
[10:34:14] Warning: Application 'sshd', version '4.3p2', is out of date, and possibly a security risk.
[10:34:14] Info: Applications checked: 7 out of 9
[10:34:14]
[10:34:14] System checks summary
[10:34:14] =====================
[10:34:14]
[10:34:14] File properties checks...
[10:34:14] Required commands check failed
[10:34:14] Files checked: 141
[10:34:14] Suspect files: 6
[10:34:14]
[10:34:14] Rootkit checks...
[10:34:14] Rootkits checked : 253
[10:34:14] Possible rootkits: 0
[10:34:14]
[10:34:14] Applications checks...
[10:34:14] Applications checked: 7
[10:34:14] Suspect applications: 4
[10:34:14]
[10:34:14] The system checks took: 8 minutes and 36 seconds
[10:34:14]
[10:34:14] Info: End date is Tue Mar  1 10:34:14 IST 2011

Open in new window

0
 
LVL 12

Accepted Solution

by:
Kent W earned 500 total points
Comment Utility
Who is this "someone"?  A Linux expert, or what?
Your 6 "hits" are pretty common false positives, especially if you are using Plesk or cPanel, or some other hosting control panel.

A file system going into RO mode usually indicates corruption or block errors...have you ran an fsck, looked at other logs or dmesg?  Unless you have other evidence to support hacking, I'd really suspect an underlying hardware or file system error.
0
 
LVL 15

Author Comment

by:Insoftservice
Comment Utility
k,
Ya he is an linux expert actually i had only told him that .
It goes to read only mode after certain time.

my even newly created folder or cache folder goes to read only mode so he told me that it might be due to hack of ur system.
thx for the info.

please let me know how to secure the apache web server.
Ya, ur comments were right its ext3 error.

so, my requirement if u can pls provide.

1> tool to detect hack and its script
2>how to secure apache webserver via tool or via firewall script if u have and ready made for webhosting
3> How to repair the system (this i would try on my own but above two are necessary . pls try to give if u have)

Thnx for ur suggestion
0
 
LVL 12

Assisted Solution

by:Kent W
Kent W earned 500 total points
Comment Utility
Securing Apache is pretty straight forward, but it's not usually Apache itself that causes hacks, it's bad practices with file permissions.
For instance, on CMS upload / posting directories, you never want to use 777 perms, always use the least required to get the job done.  You can use things like suPHP

You do want an "intelligent" install and config of apache, and make sure it doesn't have "serving 101" no-nos.  This will help for the most part -
http://httpd.apache.org/docs/2.0/misc/security_tips.html

Of course, on your firewall, just open what you need.  If you are not serving anything over SSL/HTTPS, then just close port 443 altogether.  

Running your sshd server on a port other than 22 is a good idea, also, as it will cut down on the brute force / dictionary attacks.  You can also use tolls like Denyhost or Fail2ban to automatically block IPs that are hammering your ssh or other services.

The goo thing - Linux itself is usually pretty safe and hard to hack, and most of the successful hacks are because of unintelligent installs of CMS and other web scripts, most often by leaving certain public areas wide open with RWX perms.  Very easy to upload a script and execute.  All the common CMS's have security issues from time to time...so just keep up with the latest and make sure you are patched with the latest, exercise good web permissions practices, and only allow traffic on ports you really, really need open.  That should go a long way toward making you safe.
0
How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

 
LVL 15

Author Comment

by:Insoftservice
Comment Utility
Hi mugojava,
Thx for ur comments.
Ya i would keep drop policy and only open port 80 and telnet port as its only needed for use.
as on my server i am just enabling webhosting .
And i will keep all my files in 760 mode. i hope its secured.please suggest.

Please even let me know the cmd to repair my file system as i am worried that some thing might get wrong as i am unable to up my other server with mysql-client.

Thnx again for ur valuable comments  
0
 
LVL 12

Assisted Solution

by:Kent W
Kent W earned 500 total points
Comment Utility
To repair the file system, you will want to start up in single user mode, or just do an
init 1
(same thing, different approach)

Then, unmount the affected filesystem...if its "/" then
umount /
If it's "sda1", then
umount /dev/sda1

then run fsck
fsck -t ext3 -y / (or /dev/sda1, whichever fits your fs)
(-t is for type of file system type, good to include to prevent possible corruption, -y is so you don't have to type "y" at every "repair?" prompt.

Then, just reboot, or, if you want to do this manually...
mount / (or the same path you have with umount)
init 3 (takes you back to regular multi-user environment...I prefer to reboot, though...feels more "thorough")
0
 
LVL 15

Author Comment

by:Insoftservice
Comment Utility
hi,
i did that part and thx for ur help.
one more thng if u can do.
Please let me know i want to do os hardening for LAMP hosting, and there is one more thing in apache ie httpd- t
i dont know what its is actually but i am doing research on it.
0
 
LVL 12

Assisted Solution

by:Kent W
Kent W earned 500 total points
Comment Utility
The "-t" just checks the config file for errors.

Usually it's not so much hardening Apache as it is the app you are hosting under it, such as Wordpress, Joomla, Drupal, etc.....
Many of the issue come from setting bad directory perms and allowing upload and execute to the same directory, for instance.  Hardening is mostly about what it's serving, along with regular server hardening...firewall, cut unneeded inet services, etc.
There are things you can do such as suPHP and other directives, but, until it's know what you are serving and how, it's really just a guess on what works for your instance.  Some things don't work well with suPHP, and the directives you add / change / remove also depend on the real-world needs of your web apps.
0
 
LVL 15

Author Closing Comment

by:Insoftservice
Comment Utility
thx for the help it worked .
basically what rights has to be given to the root folder and files of an dynamic website
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Join & Write a Comment

This subject  of securing wireless devices conjures up visions of your PC or mobile phone connecting to the Internet through some hotspot at Starbucks. But it is so much more than that. Let’s look at the facts: devices#sthash.eoFY7dic.
Our Group Policy work started with Small Business Server in 2000. Microsoft gave us an excellent OU and GPO model in subsequent SBS editions that utilized WMI filters, OU linking, and VBS scripts. These are some of experiences plus our spending a lo…
Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now