possível rootkit (false possitive ???)

1

bom dia:

quando eu faço um rkhunter - check me mostra que eu possuo rootkits:

/usr/bin/rkhunter: 14795: [: /usr/lib/firefox/firefox: unexpected operator
/usr/bin/rkhunter: 14795: [: /usr/lib/firefox/firefox: unexpected operator
/usr/bin/rkhunter: 14795: [: /usr/bin/konsole: unexpected operator
    Checking for suspicious (large) shared memory segments   [ Warning ]

Em /var/log/rkhunter.log mostre-me isto:

Warning: The following suspicious (large) shared memory segments have been found:
[21:17:06]          Process: /usr/lib/firefox/firefox (deleted)    PID: 9750    Owner: louie    Size: 4,0MB (configured size allowed: 1,0MB)
[21:17:07]          Process: /usr/lib/firefox/firefox (deleted)    PID: 9750    Owner: louie    Size: 4,0MB (configured size allowed: 1,0MB)
[21:17:07]          Process: /usr/bin/konsole (deleted)    PID: 11415    Owner: louie    Size: 1,7MB (configured size allowed: 1,0MB)

Whit Chkrootkit olny me mostra uma infecção: "tcpd" Eu li em vários lugares que é um falso positivo.

Rkhunter também pode ser falsos positivos? Obrigado.

    
por louiesanchezdj 05.06.2018 / 21:35

0 respostas