LINUX LITE 7.2 FINAL RELEASED - SEE RELEASE ANNOUNCEMENTS SECTION FOR DETAILS


Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Are they false ?
#27
Still on the first of security links.

I have solved the above one, in that it is something internal in distro, and it is not trying access externally. Its common behaviour in many Linux distros.

ufw logs clear.

netstat

Code:
sudo watch netstat -anlp

shows no foreign connection or any to /bin/sh or /bin/su

trace backs running clear currently. ( I was allowed to connect LL, for this and can show them montoring and ufw results)

rkhunter, I have discovered it is false positive, something to do with package manager, Debian say its been fixed.

rkhunter wiki has this for updates which I had done before using it and since then.

Code:
sudo rkhunter --propupd

On ubuntu forums notice the help

Code:
sudo rkhunter - h

from this I found a way to update the database

Code:
sudo rkhunter --update

Neither are on the rkhunter wiki it is a different method and commands.

This found and updated the list of false positives in rkhunter that propupd didn't find.

I then edited the rkhunter.conf file as admin saved and used

Code:
sudo rkhunter -C

As per the conf to update rkhunter with these changes.

It now runs with no results detected, only everything Okay, not found, or clear.

I have updated LL and notice that both Perl and Pulse have many updates it may help in chkrootkit which I'll start on tomorrow.

Update -
.bash_profile, .bash_rc, .profile, /etc/profile - all clear of other uses

Update 2 -
samba activity noted above, this is a cron job to back up samba password each day.
no cron jobs set at root
cron.d empty/no issues found
cron.daily / all clean no issues found
cron.hourly, cron.monthly empty/no issues found
cron.weekly all clean no issues found
All checking manually.

Code:
printenv
no backdoors, hooks escalated priviledges found , all clean.

/etc/ld.so.conf.d
no malicious linkages found

/etc/rc.local clean
/etc/rc0 thru 6 all files checked all clean
/etc/init.d clean
/etc/network all files clean
/etc/NetworkManager all files clean  Smile
Reply


Messages In This Thread
Are they false ? - by bitsnpcs - 11-09-2017, 03:30 PM
Re: Are they false ? - by rokytnji - 11-09-2017, 05:46 PM
Re: Are they false ? - by bitsnpcs - 11-09-2017, 08:08 PM
Re: Are they false ? - by newtusmaximus - 11-11-2017, 02:09 PM
Re: Are they false ? - by trinidad - 11-11-2017, 02:17 PM
Re: Are they false ? - by bitsnpcs - 11-11-2017, 03:19 PM
Re: Are they false ? - by newtusmaximus - 11-11-2017, 03:29 PM
Re: Are they false ? - by newtusmaximus - 11-11-2017, 03:54 PM
Re: Are they false ? - by trinidad - 11-11-2017, 04:14 PM
Re: Are they false ? - by newtusmaximus - 11-11-2017, 04:35 PM
Re: Are they false ? - by bitsnpcs - 11-11-2017, 06:34 PM
Re: Are they false ? - by trinidad - 11-11-2017, 08:00 PM
Re: Are they false ? - by trinidad - 11-11-2017, 08:38 PM
Re: Are they false ? - by Vera - 11-11-2017, 09:00 PM
Re: Are they false ? - by trinidad - 11-11-2017, 09:26 PM
Re: Are they false ? - by bitsnpcs - 11-11-2017, 11:47 PM
Re: Are they false ? - by rokytnji - 11-12-2017, 04:44 AM
Re: Are they false ? - by ian_r_h - 11-12-2017, 09:21 AM
Re: Are they false ? - by trinidad - 11-12-2017, 03:24 PM
Re: Are they false ? - by newtusmaximus - 11-12-2017, 11:43 PM
Re: Are they false ? - by bitsnpcs - 11-14-2017, 08:54 PM
Re: Are they false ? - by Valtam - 11-15-2017, 02:41 AM
Re: Are they false ? - by bitsnpcs - 11-15-2017, 04:52 AM
Re: Are they false ? - by trinidad - 11-15-2017, 12:47 PM
Re: Are they false ? - by bitsnpcs - 11-15-2017, 02:12 PM
Re: Are they false ? - by bitsnpcs - 11-15-2017, 10:20 PM
Re: Are they false ? - by bitsnpcs - 11-16-2017, 12:23 AM
Re: Are they false ? - by JmaCWQ - 11-16-2017, 04:23 AM
Re: Are they false ? - by bitsnpcs - 11-16-2017, 07:32 PM
Re: Are they false ? - by bitsnpcs - 11-16-2017, 08:35 PM
Re: Are they false ? - by trinidad - 11-16-2017, 09:16 PM
Re: Are they false ? - by TheDead - 11-16-2017, 09:53 PM
Re: Are they false ? - by bitsnpcs - 11-16-2017, 10:22 PM
Re: Are they false ? - by JmaCWQ - 11-17-2017, 06:26 AM

Forum Jump:


Users browsing this thread: 14 Guest(s)