Re: [arch-general] rkhunter found possible rootkit

2019-08-20 Thread brent s.
On 8/20/19 5:58 AM, Oliver Jaksch via arch-general wrote: > On Tuesday, 20 August 2019, 10:15:58 CEST you wrote: >> Am 20.08.19 um 10:00 schrieb Filipe Laíns via arch-general: >>> On Tue, 2019-08-20 at 08:33 +0200, Oliver Jaksch via arch-general wrote: I let rkhunter running around once a week

Re: [arch-general] rkhunter found possible rootkit

2019-08-20 Thread Oliver Jaksch via arch-general
On Tuesday, 20 August 2019, 10:15:58 CEST you wrote: > Am 20.08.19 um 10:00 schrieb Filipe Laíns via arch-general: > > On Tue, 2019-08-20 at 08:33 +0200, Oliver Jaksch via arch-general wrote: > >> I let rkhunter running around once a week. There were nothing since many > >> months. But today it's r

Re: [arch-general] rkhunter found possible rootkit

2019-08-20 Thread Filipe Laíns via arch-general
On Tue, 2019-08-20 at 09:31 +0100, Filipe Laíns via arch-general wrote: > so I can give any guarantees *I can't Filipe Laíns 3DCE 51D6 0930 EBA4 7858 BA41 46F6 33CB B0EB 4BF2 signature.asc Description: This is a digitally signed message part

Re: [arch-general] rkhunter found possible rootkit

2019-08-20 Thread Filipe Laíns via arch-general
On Tue, 2019-08-20 at 10:15 +0200, ProgAndy wrote: > Am 20.08.19 um 10:00 schrieb Filipe Laíns via arch-general: > > On Tue, 2019-08-20 at 08:33 +0200, Oliver Jaksch via arch-general > > wrote: > > > I let rkhunter running around once a week. There were nothing > > > since many > > > months. But t

Re: [arch-general] rkhunter found possible rootkit

2019-08-20 Thread Ralf Mardorf via arch-general
On Tue, 20 Aug 2019 10:15:58 +0200, ProgAndy wrote: >Am 20.08.19 um 10:00 schrieb Filipe Laíns via arch-general: >> On Tue, 2019-08-20 at 08:33 +0200, Oliver Jaksch wrote: >> No, those libraries are used for key manipulation, that's why >> rkhunter thinks that they might be sniffer. >> >In thi

Re: [arch-general] rkhunter found possible rootkit

2019-08-20 Thread ProgAndy
Am 20.08.19 um 10:00 schrieb Filipe Laíns via arch-general: > On Tue, 2019-08-20 at 08:33 +0200, Oliver Jaksch via arch-general wrote: >> I let rkhunter running around once a week. There were nothing since many >> months. But today it's report complains about */lib64/libkeyutils.so.1.9* >> and >

Re: [arch-general] rkhunter found possible rootkit

2019-08-20 Thread Ralf Mardorf via arch-general
On Tue, 2019-08-20 at 08:33 +0200, Oliver Jaksch via arch-general wrote: > Should I/we be worried? Hi Oliver, if something conceivably harmful is found you should take care. If you wouldn't, then why are you using it at all? If proprietary software would detect something you suspect to be a false

Re: [arch-general] rkhunter found possible rootkit

2019-08-20 Thread Filipe Laíns via arch-general
On Tue, 2019-08-20 at 08:33 +0200, Oliver Jaksch via arch-general wrote: > I let rkhunter running around once a week. There were nothing since many > months. But today it's report complains about */lib64/libkeyutils.so.1.9* and > therefore other tools they're (seems to be) using this SO. > > The

[arch-general] rkhunter found possible rootkit

2019-08-19 Thread Oliver Jaksch via arch-general
I let rkhunter running around once a week. There were nothing since many months. But today it's report complains about */lib64/libkeyutils.so.1.9* and therefore other tools they're (seems to be) using this SO. The SO matches the one from 'core/keyutils 1.6.1-1' in size and hash. I've uploaded th