F21: infection reported by "chkrootkit".

2015-07-23 Thread William
Hi all, While doing my routine patches and scans, "chkrootkit reported the following: (*** snip ***) Checking `asp'... not infected Checking `bindshell'... warning, got bogus l2cap line. warning, got bogus l2cap line. warning, got bogus l2cap line. warning, got bogus l2cap line. warning, got b

Re: F21: infection reported by "chkrootkit".

2015-07-23 Thread Michael Schwendt
On Thu, 23 Jul 2015 14:56:00 -0400, William wrote: > Hi all, > > While doing my routine patches and scans, "chkrootkit reported the > following: > > (*** snip ***) > Checking `asp'... not infected > Checking `bindshell'... warning, got bogus l2cap line. > warning, got bogus l2cap line. > warnin

Re: F21: infection reported by "chkrootkit".

2015-07-28 Thread William
Good afternoon, On 07/23/2015 02:56 PM, William wrote: Hi all, While doing my routine patches and scans, "chkrootkit reported the following: (*** snip ***) Checking `asp'... not infected Checking `bindshell'... warning, got bogus l2cap line. warning, got bogus l2cap line. (*** snip ***) warn

Re: F21: infection reported by "chkrootkit".

2015-07-28 Thread Joe Zeff
On 07/28/2015 10:55 AM, William wrote: I realized a lot later that I also should have mentioned that the "chkrootkit" run was shortly after doing "yum update", "prelink -a", and rebooting. I don't know if that's significant. I'm not sure why you're using prelink, but if you're worried about s

Re: F21: infection reported by "chkrootkit".

2015-07-28 Thread Michael Schwendt
On Tue, 28 Jul 2015 13:55:47 -0400, William wrote: > > By examining the chkrootkit program -- it's a large shell script with > > a few helper tools -- to understand what it does to perform a check. > > ??? I looked at that long sh script. It didn't help. I don't see how > knowing that chkro

Re: F21: infection reported by "chkrootkit".

2015-07-28 Thread William
On 07/28/2015 01:55 PM, William wrote: Good afternoon, On 07/23/2015 02:56 PM, William wrote: Hi all, While doing my routine patches and scans, "chkrootkit reported the following: (*** snip ***) Checking `asp'... not infected Checking `bindshell'... warning, got bogus l2cap line. warning,

Re: F21: infection reported by "chkrootkit".

2015-07-28 Thread Joe Zeff
On 07/28/2015 02:37 PM, William wrote: The "-r" option requires an address. What address should I provide? Did you mean "-R" or "-r"? Sorry; that should have been -R. The idea is to randomize where the various libraries are located, making it harder for malware (if any) to hook into them.

Re: F21: infection reported by "chkrootkit".

2015-07-29 Thread William
(replying to two posts) On 07/28/2015 05:37 PM, William wrote: On 07/28/2015 01:55 PM, William wrote: Good afternoon, On 07/23/2015 02:56 PM, William wrote: Hi all, While doing my routine patches and scans, "chkrootkit reported the following: (*** snip ***) Checking `asp'... not infected

Re: F21: infection reported by "chkrootkit".

2015-07-29 Thread Michael Schwendt
On Wed, 29 Jul 2015 14:49:54 -0400, William wrote: > I already realized that "chkrootkit" is not bullet-proof. I understand > that *no* security tool or method is bullet-proof. Malicious people are > always brewing new evil things, and security tools and methods are > almost always stuck tryin

Re: F21: infection reported by "chkrootkit".

2015-07-30 Thread Butrus Damaskus
On Tue, Jul 28, 2015 at 11:18 PM, Michael Schwendt wrote: > ... > it. For a very long time, it considered the main systemd executable as > infected, and nobody did anything about that. Everywhere you could > Obviously, given what a mess systemd is. I wouldn't blame chkrootkit for it! -- users m

Re: F21: infection reported by "chkrootkit".

2015-07-30 Thread Olivia
Hello Butrus, Yes I'm Real. To prove I'm real first off.. You are Community support for Fedora users and your mail Id users@lists.fedoraproject.org I was just taking a quick shower and I heard my phone vibrate, my hair isnt even close to being dry yet but I wanted to quickly check my email to

Re: F21: infection reported by "chkrootkit".

2015-07-30 Thread Joe Zeff
On 07/30/2015 11:33 AM, Olivia wrote: Hello Butrus, Yes I'm Real. No you're not. This is the third copy of the exact same message I've received from you today, except for the name at the top. *plonk!* -- users mailing list users@lists.fedoraproject.org To unsubscribe or change subscription

Re: F21: infection reported by "chkrootkit".

2015-07-30 Thread Matthew Miller
On Thu, Jul 30, 2015 at 11:38:01AM -0700, Joe Zeff wrote: > On 07/30/2015 11:33 AM, Olivia wrote: > >Hello Butrus, > >Yes I'm Real. > No you're not. This is the third copy of the exact same message > I've received from you today, except for the name at the top. List admins are on this. No need to

Re: F21: infection reported by "chkrootkit".

2015-07-30 Thread Olivia
Hello Matthew, Yes I'm Real. To prove I'm real first off.. You are Community support for Fedora users and your mail Id users@lists.fedoraproject.org I was just taking a quick shower and I heard my phone vibrate, my hair isnt even close to being dry yet but I wanted to quickly check my email to

Re: F21: infection reported by "chkrootkit".

2015-07-30 Thread Joe Zeff
On 07/30/2015 11:39 AM, Matthew Miller wrote: List admins are on this. No need to spread this further by replying more. Thanks. You should have paid more attention to the final *plonk!* That was the sound of "her" email address dropping to the bottom of my killfile. -- users mailing list use

Re: F21: infection reported by "chkrootkit".

2015-07-31 Thread Michael Schwendt
On Thu, 30 Jul 2015 20:28:03 +0200, Butrus Damaskus wrote: > > ... > > it. For a very long time, it considered the main systemd executable as > > infected, and nobody did anything about that. Everywhere you could > > > > Obviously, given what a mess systemd is. I wouldn't blame chkrootkit for it!