F17 - false positive? -> Fwd: rkhunter Daily Run on testserver

Reindl Harald h.reindl at thelounge.net
Thu Jun 14 08:16:48 UTC 2012


after upgrade a test-VM to F17 i get this rkhunter warnings
i can not really believe that there is a rootkit not existing
on the F16 setup and think this is a false positive

can anybody confirm this or should i make a bugreport now?

-------- Original-Nachricht --------
Betreff: rkhunter Daily Run on testserver
Datum: Thu, 14 Jun 2012 03:49:14 +0200
Von: root
An: rhsoft at test.rh

--------------------- Start Rootkit Hunter Update ---------------------
[ Rootkit Hunter version 1.4.0 ]

Checking rkhunter data files...
  Checking file mirrors.dat                                  [ No update ]
  Checking file programs_bad.dat                             [ No update ]
  Checking file backdoorports.dat                            [ No update ]
  Checking file suspscan.dat                                 [ No update ]
  Checking file i18n/cn                                      [ No update ]
  Checking file i18n/de                                      [ No update ]
  Checking file i18n/en                                      [ No update ]
  Checking file i18n/zh                                      [ No update ]
  Checking file i18n/zh.utf8                                 [ No update ]

---------------------- Start Rootkit Hunter Scan ----------------------
Warning: 'Spanish' Rootkit                        [ Warning ]
         File '/bin/ad' found
Warning: Hidden file found: /usr/share/man/man5/.k5identity.5.gz: gzip compressed data, from Unix, max compression

----------------------- End Rootkit Hunter Scan -----------------------


-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 262 bytes
Desc: OpenPGP digital signature
URL: <http://lists.fedoraproject.org/pipermail/users/attachments/20120614/4545fb28/attachment.sig>


More information about the users mailing list