Bonjour,
Since the last update of f32, rkhunter send a lot of warning (in spite of the --propupd I run after each update...):
Warning: Checking for possible rootkit files and directories [ Warning ] Found file '/lib/libkeyutils.so.1.9'. Possible rootkit: Sniffer component Found file '/lib64/libkeyutils.so.1.9'. Possible rootkit: Sniffer component Found file '/usr/lib/libkeyutils.so.1.9'. Possible rootkit: Sniffer component Found file '/usr/lib64/libkeyutils.so.1.9'. Possible rootkit: Sniffer component Warning: The following processes are using suspicious files: Command: abrt-applet UID: 2995 PID: 2663 Pathname: 24376 Possible Rootkit: Spam tool component Command: abrtd UID: 0 PID: 1580 Pathname: /usr/lib64/libkeyutils.so.1.9 Possible Rootkit: Spam tool component Command: abrt-dbus UID: 0 PID: 3087 Pathname: /usr/lib64/libkeyutils.so.1.9 Possible Rootkit: Spam tool component Command: abrt-dump-journ UID: 0 PID: 1629 Pathname: /usr/lib64/libkeyutils.so.1.9 Possible Rootkit: Spam tool component Command: auditd UID: 0 PID: 1386 Pathname: /usr/lib64/libkeyutils.so.1.9 Possible Rootkit: Spam tool component Command: chrome<-----------------this one repeated several times---------> UID: 11750 PID: 11749 Pathname: 24376 Possible Rootkit: Spam tool component Command: cleanupd UID: 0 PID: 2062 Pathname: /usr/lib64/libkeyutils.so.1.9 Possible Rootkit: Spam tool component Command: cupsd UID: 0 PID: 1525 Pathname: /usr/lib64/libkeyutils.so.1.9 Possible Rootkit: Spam tool component Command: dnfdragora-upda UID: 3025 PID: 2621 Pathname: /usr/lib64/libkeyutils.so.1.9 Possible Rootkit: Spam tool component Command: evolution-addre UID: 3025 PID: 3168 Pathname: /usr/lib64/libkeyutils.so.1.9 Possible Rootkit: Spam tool component Command: evolution-alarm UID: 3007 PID: 2571 Pathname: 24376 Possible Rootkit: Spam tool component etc. etc.
chkrootkit does not teturn any problem...
What is the problem?
Thank you.
El 28/1/21 a las 11:44, François Patte escribió:
Bonjour,
Since the last update of f32, rkhunter send a lot of warning (in spite of the --propupd I run after each update...):
Warning: Checking for possible rootkit files and directories [ Warning ] Found file '/lib/libkeyutils.so.1.9'. Possible rootkit: Sniffer component Found file '/lib64/libkeyutils.so.1.9'. Possible rootkit: Sniffer component Found file '/usr/lib/libkeyutils.so.1.9'. Possible rootkit: Sniffer component Found file '/usr/lib64/libkeyutils.so.1.9'. Possible rootkit: Sniffer component Warning: The following processes are using suspicious files: Command: abrt-applet UID: 2995 PID: 2663 Pathname: 24376 Possible Rootkit: Spam tool component Command: abrtd UID: 0 PID: 1580 Pathname: /usr/lib64/libkeyutils.so.1.9 Possible Rootkit: Spam tool component
---- TRIMMED
A simple google search shows:
https://bbs.archlinux.org/viewtopic.php?id=248420
and
https://bugs.archlinux.org/task/63369
It seems a problem against the name of libkeyutils.so.1.9. Perhaps must report to rkhunter / fedora developers team.
On Thursday, 28 January 2021 10:44:09 GMT François Patte wrote:
Bonjour,
Since the last update of f32, rkhunter send a lot of warning (in spite of the --propupd I run after each update...):
Warning: Checking for possible rootkit files and directories [ Warning ] Found file '/lib/libkeyutils.so.1.9'. Possible rootkit:
<snip>
https://bugzilla.redhat.com/show_bug.cgi?id=1914662
rkhunter-1.4.6-10 fixes this and according to bodhi it should be in the stable repo now for F32
Colin
On Thursday, 28 January 2021 10:44:09 GMT François Patte wrote:
<snip>
https://bugzilla.redhat.com/show_bug.cgi?id=1914662
rkhunter-1.4.6-10 fixes this and according to bodhi it should be in the stable repo now for F32
I confirm this.
I patched my F32 work station several minutes ago. The patching included rkhunter. After the patching, the warnings about "libkeyutils.so.1.9" no longer occur.
Bill.
On Thu, 28 Jan 2021 at 06:44, François Patte < francois.patte@mi.parisdescartes.fr> wrote:
Bonjour,
Since the last update of f32, rkhunter send a lot of warning (in spite of the --propupd I run after each update...):
Warning: Checking for possible rootkit files and directories [ Warning ] Found file '/lib/libkeyutils.so.1.9'. Possible rootkit: Sniffer component Found file '/lib64/libkeyutils.so.1.9'. Possible rootkit:
[...] There is a recent thread in this forum on similar reports. The issue affects other distros: FS#63369 : [keyutils] RKhunter reports a possible rootkit (archlinux.org) https://bugs.archlinux.org/task/63369