Page 1 of 1

Rudy edition and Chkrootkit, weird results

Posted: Tue 06 Mar 2007, 12:06
by polux
Hi Debernardis, I'm using from cd the latest 070227 Ruddy edition. I did a scan with chkrootkit and the results came with some infected files. I booted and rebooted several times and got the same results. :shock:

Checking `basename'... INFECTED
Checking `cron'... INFECTED
Checking `dirname'... INFECTED
Checking `echo'... INFECTED
Checking `env'... INFECTED
Checking `login'... INFECTED
Checking `passwd'... INFECTED
Checking `traceroute'... INFECTED
Searching for Suckit rootkit... Warning: /sbin/init INFECTED

Im running it in a normal cd (not a multi session) so I haven't modified or changed anything in it.
Can they be false positives or something to worry about?

Posted: Tue 06 Mar 2007, 12:15
by debernardis
This is a known issue: chkrootkit finds as anormal the busybox equivalents to standard gnu utilities.
See http://www.murga-linux.com/puppy/viewtopic.php?t=8395
So no worry 8)

Posted: Tue 06 Mar 2007, 12:21
by polux
Thank you for your fast reply :)

And by the way, congratulations for such a great derivative you made.