Wiki-en veut du vieux:)?
Bienvenu dans le Forum (et for Femmes:)!) des 'wikinenveut'Smile!
On y discute de tout les sujets, concernant l'exclusion, le droit des pères, l'écriture et l'art en général, mais surtout et sinon de Linux et des Logiciels Libres et des NTIC, par et pour les gens de R.2000:)!
Everybody welcomes at Home:)!
Rechercher
 
 

Résultats par :
 


Rechercher Recherche avancée

Shopactif


Navigation
 Portail
 Index
 Membres
 Profil
 FAQ
 Rechercher
Partenaires
Forum gratuit


Tchat Blablaland



Sniffer logs and security : chkrootkit:)!

Voir le sujet précédent Voir le sujet suivant Aller en bas

Sniffer logs and security : chkrootkit:)!

Message  Milux le Sam 25 Déc - 10:02

Needed under Linux as we drive some 'bloody' Windows computer with us... Sad, 2 use a sniffer log as chkrootkit in cron and or rkhunter, for specifics use or directories!

See the documentation 4 much precisions : man chkrootkit is your friend:)!

Or at least :
http://www.chkrootkit.org/README

of :
http://www.chkrootkit.org/

--


Dernière édition par Milux le Ven 7 Jan - 15:59, édité 1 fois

Milux

Messages : 2794
Date d'inscription : 30/08/2010

Revenir en haut Aller en bas

Re: Sniffer logs and security : chkrootkit:)!

Message  Milux le Sam 25 Déc - 10:18

It may take a while, so i made it on my 'little' computer to show it partialy:)!

--

Needs to install it... (some commands under Debian ar : apt-get install/update/upgrade... aso:)!

-
mezig@mezig-desktop:~$ sudo apt-get install chkrootkit
mezig@mezig-desktop:~$ chkrootkit
..

mezig@mezig-desktop:~$ sudo chkrootkit
ROOTDIR is `/'
Checking `amd'... not found
Checking `basename'... not infected
Checking `biff'... not found
Checking `chfn'... not infected
Checking `chsh'... not infected
Checking `cron'... not infected
Checking `crontab'... not infected
Checking `date'... not infected
Checking `du'... not infected
Checking `dirname'... not infected
Checking `echo'... not infected
Checking `egrep'... not infected
Checking `env'... not infected
Checking `find'... not infected
Checking `fingerd'... not found
Checking `gpm'... not found
Checking `grep'... not infected
Checking `hdparm'... not infected
Checking `su'... not infected
Checking `ifconfig'... not infected
Checking `inetd'... not infected
Checking `inetdconf'... not infected
Checking `identd'... not found
Checking `init'... not infected
Checking `killall'... not infected
Checking `ldsopreload'... not infected
Checking `login'... not infected
Checking `ls'... not infected
Checking `lsof'... not infected
Checking `mail'... not infected
Checking `mingetty'... not found
Checking `netstat'... not infected
Checking `named'... not found
Checking `passwd'... not infected
Checking `pidof'... not infected
Checking `pop2'... not found
Checking `pop3'... not found
Checking `ps'... not infected
Checking `pstree'... not infected
Checking `rpcinfo'... not infected
Checking `rlogind'... not found
Checking `rshd'... not found
Checking `slogin'... not infected
Checking `sendmail'... not infected
Checking `sshd'... not found
Checking `syslogd'... not tested
Checking `tar'... not infected
Checking `tcpd'... not infected
Checking `tcpdump'... not infected
Checking `top'... not infected
Checking `telnetd'... not found
Checking `timed'... not found
Checking `traceroute'... not found
Checking `vdir'... not infected
Checking `w'... not infected
Checking `write'... not infected
Checking `aliens'... no suspect files
Searching for sniffer's logs, it may take a while... nothing found
Searching for rootkit HiDrootkit's default files... nothing found
Searching for rootkit t0rn's default files... nothing found
Searching for t0rn's v8 defaults... nothing found
Searching for rootkit Lion's default files... nothing found
Searching for rootkit RSHA's default files... nothing found
Searching for rootkit RH-Sharpe's default files... nothing found
Searching for Ambient's rootkit (ark) default files and dirs... nothing found
Searching for suspicious files and dirs, it may take a while... The following suspicious files and directories were found:
/usr/lib/firefox-3.6.13/.autoreg /usr/lib/xulrunner-1.9.2.13/.autoreg /usr/lib/thunderbird-3.1.7/.autoreg /usr/lib/jvm/.java-6-openjdk.jinfo /usr/lib/pymodules/python2.6/.path

<<<<< that's normal, as Firefox use many interpretor as Java and python and, thy have their own library path(config files:)... sawn suspicious.. on a general scan!
It's a general scan, on a personal computer 4 example...Smile! >>>>>>>>>>>>>

Searching for LPD Worm files and dirs... nothing found
Searching for Ramen Worm files and dirs... nothing found
Searching for Maniac files and dirs... nothing found
Searching for RK17 files and dirs... nothing found
Searching for Ducoci rootkit... nothing found
Searching for Adore Worm... nothing found
Searching for ShitC Worm... nothing found
Searching for Omega Worm... nothing found
Searching for Sadmind/IIS Worm... nothing found
Searching for MonKit... nothing found
Searching for Showtee... nothing found
Searching for OpticKit... nothing found
Searching for T.R.K... nothing found
Searching for Mithra... nothing found
Searching for LOC rootkit... nothing found
Searching for Romanian rootkit... nothing found
Searching for Suckit rootkit... nothing found
Searching for Volc rootkit... nothing found
Searching for Gold2 rootkit... nothing found
Searching for TC2 Worm default files and dirs... nothing found
Searching for Anonoying rootkit default files and dirs... nothing found
Searching for ZK rootkit default files and dirs... nothing found
Searching for ShKit rootkit default files and dirs... nothing found
Searching for AjaKit rootkit default files and dirs... nothing found
Searching for zaRwT rootkit default files and dirs... nothing found
Searching for Madalin rootkit default files... nothing found
Searching for Fu rootkit default files... nothing found
Searching for ESRK rootkit default files... nothing found
Searching for rootedoor... nothing found
Searching for ENYELKM rootkit default files... nothing found
Searching for common ssh-scanners default files... nothing found
Searching for suspect PHP files... nothing found
Searching for anomalies in shell history files... nothing found
Checking `asp'... not infected
Checking `bindshell'... not infected
Checking `lkm'... chkproc: nothing detected
chkdirs: nothing detected
Checking `rexedcs'... not found
Checking `sniffer'... lo: not promisc and no packet sniffer sockets
eth0: not promisc and no packet sniffer sockets
Checking `w55808'... not infected
Checking `wted'... chkwtmp: nothing deleted
Checking `scalper'... not infected
Checking `slapper'... not infected
Checking `z2'... user mezig deleted or never logged from lastlog!
<<<<<< i'm on admin 'securized' profile.. (sudo) , so he can't see me anymore>>>>>>>>>>
Checking `chkutmp'... chkutmp: nothing deleted
Checking `OSX_RSPLUG'... not infected
mezig@mezig-desktop:~$

--


Dernière édition par Milux le Ven 7 Jan - 16:03, édité 1 fois

Milux

Messages : 2794
Date d'inscription : 30/08/2010

Revenir en haut Aller en bas

Re: Sniffer logs and security : chkrootkit:)!

Message  Milux le Sam 25 Déc - 10:25

During that time.. in 'backpart' usual process :
tail -f /var/log/syslog fives us some of the systems activities (partial too... 4 example:)! -

-

'Dec 25 07:09:01 mezig-desktop CRON[32199]: (root) CMD ( [ -x /usr/lib/php5/maxlifetime ] && [ -d /var/lib/php5 ] && find /var/lib/php5/ -type f -cmin +$(/usr/lib/php5/maxlifetime) -print0 | xargs -n 200 -r -0 rm)
Dec 25 07:17:01 mezig-desktop CRON[32369]: (root) CMD ( cd / && run-parts --report /etc/cron.hourly)
Dec 25 07:30:01 mezig-desktop CRON[32496]: (root) CMD (start -q anacron || Smile
Dec 25 07:30:01 mezig-desktop anacron[32499]: Anacron 2.3 started on 2010-12-25
Dec 25 07:30:01 mezig-desktop anacron[32499]: Will run job `cron.daily' in 5 min.
Dec 25 07:30:01 mezig-desktop anacron[32499]: Jobs will be executed sequentially
Dec 25 07:35:01 mezig-desktop anacron[32499]: Job `cron.daily' started
Dec 25 07:35:01 mezig-desktop anacron[32688]: Updated timestamp for job `cron.daily' to 2010-12-25
Dec 25 07:39:01 mezig-desktop CRON[381]: (root) CMD ( [ -x /usr/lib/php5/maxlifetime ] && [ -d /var/lib/php5 ] && find /var/lib/php5/ -type f -cmin +$(/usr/lib/php5/maxlifetime) -print0 | xargs -n 200 -r -0 rm)
Dec 25 07:54:05 mezig-desktop /usr/bin/crontab[2753]: (root) LIST (nobody)
Dec 25 07:56:53 mezig-desktop kernel: [239622.744759] lo: Disabled Privacy Extensions
Dec 25 08:00:01 mezig-desktop CRON[3735]: (www-data) CMD ( if test -x /usr/share/drupal6/scripts/cron.sh ; then /usr/share/drupal6/scripts/cron.sh ; fi)
.....

Ther si many others administratives commands, i can use.. it's just an initiation to who may be interrested:)!

That's make me think i have to do some duties, so later on:)!

xx Mi

<(")

--

Milux

Messages : 2794
Date d'inscription : 30/08/2010

Revenir en haut Aller en bas

Re: Sniffer logs and security : chkrootkit:)!

Message  Milux le Ven 7 Jan - 11:38

Realy many things too at :

http://linux.byexamples.com/archives/category/text-manipulation/tail/

on every important security commands explained and with many examples Smile!

4 else see syslog and syslog page at :

http://datatracker.ietf.org/wg/syslog/charter/

--


Dernière édition par Milux le Ven 7 Jan - 16:10, édité 1 fois

Milux

Messages : 2794
Date d'inscription : 30/08/2010

Revenir en haut Aller en bas

Re: Sniffer logs and security : chkrootkit:)!

Message  Milux le Ven 7 Jan - 11:45

Another rootkit U can use under Linux : rkhunter (part of:)!)!

[Press <ENTER> to continue]


Checking for rootkits...

Performing check of known rootkit files and directories
55808 Trojan - Variant A [ Not found ]
ADM Worm [ Not found ]
AjaKit Rootkit [ Not found ]
Adore Rootkit [ Not found ]
aPa Kit [ Not found ]
Apache Worm [ Not found ]
Ambient (ark) Rootkit [ Not found ]
Balaur Rootkit [ Not found ]
BeastKit Rootkit [ Not found ]
beX2 Rootkit [ Not found ]
BOBKit Rootkit [ Not found ]
cb Rootkit [ Not found ]
CiNIK Worm (Slapper.B variant) [ Not found ]
Danny-Boy's Abuse Kit [ Not found ]
Devil RootKit [ Not found ]
Dica-Kit Rootkit [ Not found ]
Dreams Rootkit [ Not found ]
Duarawkz Rootkit [ Not found ]
Enye LKM [ Not found ]
Flea Linux Rootkit [ Not found ]
FreeBSD Rootkit [ Not found ]
Fu Rootkit [ Not found ]
Fuck`it Rootkit [ Not found ]
GasKit Rootkit [ Not found ]
Heroin LKM [ Not found ]
HjC Kit [ Not found ]
ignoKit Rootkit [ Not found ]
iLLogiC Rootkit [ Not found ]
IntoXonia-NG Rootkit [ Not found ]
Irix Rootkit [ Not found ]
Kitko Rootkit [ Not found ]
Knark Rootkit [ Not found ]
ld-linuxv.so Rootkit [ Not found ]
Li0n Worm [ Not found ]
Lockit / LJK2 Rootkit [ Not found ]
Mood-NT Rootkit [ Not found ]
MRK Rootkit [ Not found ]
Ni0 Rootkit [ Not found ]
Ohhara Rootkit [ Not found ]
Optic Kit (Tux) Worm [ Not found ]
Oz Rootkit [ Not found ]
Phalanx Rootkit [ Not found ]
Phalanx2 Rootkit [ Not found ]
Phalanx2 Rootkit (extended tests) [ Not found ]
Portacelo Rootkit [ Not found ]
R3dstorm Toolkit [ Not found ]
RH-Sharpe's Rootkit [ Not found ]
RSHA's Rootkit [ Not found ]
Scalper Worm [ Not found ]
Sebek LKM [ Not found ]
Shutdown Rootkit [ Not found ]
SHV4 Rootkit [ Not found ]
SHV5 Rootkit [ Not found ]
Sin Rootkit [ Not found ]
Slapper Worm [ Not found ]
Sneakin Rootkit [ Not found ]
'Spanish' Rootkit [ Not found ]
Suckit Rootkit [ Not found ]
SunOS Rootkit [ Not found ]
SunOS / NSDAP Rootkit [ Not found ]
Superkit Rootkit [ Not found ]
TBD (Telnet BackDoor) [ Not found ]
TeLeKiT Rootkit [ Not found ]
T0rn Rootkit [ Not found ]
trNkit Rootkit [ Not found ]
Trojanit Kit [ Not found ]
Tuxtendo Rootkit [ Not found ]
URK Rootkit [ Not found ]
Vampire Rootkit [ Not found ]
VcKit Rootkit [ Not found ]
Volc Rootkit [ Not found ]
Xzibit Rootkit [ Not found ]
X-Org SunOS Rootkit [ Not found ]
zaRwT.KiT Rootkit [ Not found ]
ZK Rootkit [ Not found ]

Performing additional rootkit checks
Suckit Rookit additional checks [ OK ]
Checking for possible rootkit files and directories [ None found ]
Checking for possible rootkit strings [ None found ]

Performing malware checks
Checking running processes for suspicious files [ None found ]
Checking for login backdoors [ None found ]
Checking for suspicious directories [ None found ]
Checking for sniffer log files [ None found ]

Performing trojan specific checks
Checking for enabled inetd services [ OK ]
Checking for Apache backdoor [ Not found ]

Performing Linux specific checks
Checking loaded kernel modules [ OK ]
Checking kernel module names [ OK ]

[Press <ENTER> to continue]


Checking the network...

Performing check for backdoor ports
Checking for TCP port 1524 [ Not found ]
Checking for TCP port 1984 [ Not found ]
Checking for UDP port 2001 [ Not found ]
Checking for TCP port 2006 [ Not found ]
Checking for TCP port 2128 [ Not found ]
Checking for TCP port 6666 [ Not found ]
Checking for TCP port 6667 [ Not found ]
Checking for TCP port 6668 [ Not found ]
Checking for TCP port 6669 [ Not found ]
Checking for TCP port 7000 [ Not found ]
Checking for TCP port 13000 [ Not found ]
Checking for TCP port 14856 [ Not found ]
Checking for TCP port 25000 [ Not found ]
Checking for TCP port 29812 [ Not found ]
Checking for TCP port 31337 [ Not found ]
Checking for TCP port 33369 [ Not found ]
Checking for TCP port 47107 [ Not found ]
Checking for TCP port 47018 [ Not found ]
Checking for TCP port 60922 [ Not found ]
Checking for TCP port 62883 [ Not found ]
Checking for TCP port 65535 [ Not found ]

Performing checks on the network interfaces
Checking for promiscuous interfaces [ None found ]

[Press <ENTER> to continue]


Checking the local host...

Performing system boot checks
Checking for local host name [ Found ]
Checking for system startup files [ Found ]
Checking system startup files for malware [ None found ]

Performing group and account checks
Checking for passwd file [ Found ]
Checking for root equivalent (UID 0) accounts [ None found ]
Checking for passwordless accounts [ None found ]
Checking for passwd file changes [ None found ]
Checking for group file changes [ None found ]
Checking root account shell history files [ None found ]


(..)

nothing found... but i'll give him some work on specifics ans sensibles targets:)!

--

Milux

Messages : 2794
Date d'inscription : 30/08/2010

Revenir en haut Aller en bas

Re: Sniffer logs and security : chkrootkit:)!

Message  Milux le Ven 7 Jan - 12:13

Read.. 4 Ubuntu-fr all that is write here:)!

http://forum.ubuntu-fr.org/viewtopic.php?id=90395

--

Milux

Messages : 2794
Date d'inscription : 30/08/2010

Revenir en haut Aller en bas

Re: Sniffer logs and security : chkrootkit:)!

Message  Milux le Ven 7 Jan - 12:15

4 chkrootkit.. the beter is the .org at :
http://www.chkrootkit.org/

Smile!

--

Milux

Messages : 2794
Date d'inscription : 30/08/2010

Revenir en haut Aller en bas

Re: Sniffer logs and security : chkrootkit:)!

Message  Milux le Ven 7 Jan - 12:50

Supposed to be interresting 2 :

vmstat ...Smile?

mezig@mezig-desktop:~$ sudo vmstat
[sudo] password for mezig:
procs -----------memory---------- ---swap-- -----io---- -system-- ----cpu----
r b swpd free buff cache si so bi bo in cs us sy id wa
1 0 160272 134572 271048 1992252 0 0 17 29 27 23 50 4 46 0
mezig@mezig-desktop:~$

Sad!

--

Milux

Messages : 2794
Date d'inscription : 30/08/2010

Revenir en haut Aller en bas

Re: Sniffer logs and security : chkrootkit:)!

Message  Milux le Ven 7 Jan - 12:54

Troll, Crack Info/Intox...Smile?

http://forum.ubuntu-fr.org/viewtopic.php?pid=3904394#p3904394


Exim pas patché depuis 2 ans:(!

--

Milux

Messages : 2794
Date d'inscription : 30/08/2010

Revenir en haut Aller en bas

Re: Sniffer logs and security : chkrootkit:)!

Message  Milux le Ven 7 Jan - 12:55

The all new news... at there Smile!

http://blog.iweb.com/fr/2010/12/faille-de-securite-identifiee-sur-exim/7178.html

--

Milux

Messages : 2794
Date d'inscription : 30/08/2010

Revenir en haut Aller en bas

Re: Sniffer logs and security : chkrootkit:)!

Message  Milux le Sam 26 Mar - 18:32

If interrested, another one:)?

https://docs.google.com/document/d/1pVEzdxwQBG1leBjmdOtS2yMAdzN4TOKGQz7Af2bUluI/edit?hl=fr&authkey=CODQz8sO

--

Milux

Messages : 2794
Date d'inscription : 30/08/2010

Revenir en haut Aller en bas

Re: Sniffer logs and security : chkrootkit:)!

Message  Contenu sponsorisé


Contenu sponsorisé


Revenir en haut Aller en bas

Voir le sujet précédent Voir le sujet suivant Revenir en haut

- Sujets similaires

 
Permission de ce forum:
Vous ne pouvez pas répondre aux sujets dans ce forum