Bonjour à tous,
à la suite de la discussion suivante, comportement aléatoire du scanner (réparation efficace hier soir, puis nouvelle panne ce matin, puis de nouveau, ce soir, le scanner est trouvé par xsane) ,
j’ai lancé rkhunter, et récolté les «Warning» suivants:
# rkhunter --check --skip-keypress | grep Warning
/usr/bin/rkhunter [ Warning ]
/usr/bin/lwp-request [ Warning ]
Checking for enabled inetd services [ Warning ]
Checking for backdoor ports [ Warning ]
Checking for hidden files and directories [ Warning ]
# rkhunter --check --rwo
Warning: The file properties have changed:
File: /usr/bin/rkhunter
Current inode: 454958 Stored inode: 422636
Warning: The command '/usr/bin/lwp-request' has been replaced by a script: /usr/bin/lwp-request: Perl script text executable
Warning: Found enabled inetd service: sane-port
Warning: Network TCP port 6666 is being used by /usr/sbin/crtmpserver. Possible rootkit: Possible rogue IRC bot
Use the 'lsof -i' or 'netstat -an' command to check this.
Warning: Hidden directory found: /etc/.git
Warning: Hidden directory found: /etc/.java
Warning: Hidden file found: /etc/.rsyncd.conf.swp: Vim swap file, version 8.1, pid 23783, user root, host pclf-w970suw, file /etc/rsyncd.conf, modified
dont je ne sais pas quoi faire. (y compris avec les commandes lsof -i et netstat -an)
et un possible rootkit:
File properties checks...
Files checked: 150
Suspect files: 2
Rootkit checks...
Rootkits checked : 480
Possible rootkits: 1
Applications checks...
All checks skipped
The system checks took: 2 minutes and 55 seconds
All results have been written to the log file: /var/log/rkhunter.log
One or more warnings have been found while checking the system.
Please check the log file (/var/log/rkhunter.log)