- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Should init contain string HOME in HPUX 11.0?
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-15-2003 05:53 AM
07-15-2003 05:53 AM
This is a scary thing for me. Still we looked a bit harder and the reason it thinks we've got suckit is that the string HOME appears in /sbin/init.
Please advise me what you find, I'd love to know whether I'm getting excited over nothing or not.
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-15-2003 05:56 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-15-2003 05:58 AM
07-15-2003 05:58 AM
Re: Should init contain string HOME in HPUX 11.0?
Like does login contain 7 ^root$ entries?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-15-2003 06:08 AM
07-15-2003 06:08 AM
Re: Should init contain string HOME in HPUX 11.0?
root
root
root
root
root
root
root
That's 7 by my count.
Pete
Pete
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-15-2003 06:15 AM
07-15-2003 06:15 AM
Re: Should init contain string HOME in HPUX 11.0?
How about mail, is it setuid?
Here's an ll (not that I trust it).
-r-sr-sr-x 2 root mail 45056 Nov 7 1997 /usr/bin/mail
Perhaps a better question would be where on the various disks I've got can I find a trustworthy version of ll?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-15-2003 06:18 AM
07-15-2003 06:18 AM
Re: Should init contain string HOME in HPUX 11.0?
-r-sr-sr-x 2 root mail 45056 Nov 14 2000 /usr/bin/mail
I'm not sure where you might locate a trusty version.
Pete
Pete
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-15-2003 06:27 AM
07-15-2003 06:27 AM
Re: Should init contain string HOME in HPUX 11.0?
So in summary:
I ran chkrootkit.041 which www.chkrootkit.org said had been tested on HPUX 11.0.
It then came back with results:
/sbin/ifconfig: No such file or directory
/sbin/ifconfig: No such file or directory
Checking `ifconfig'... INFECTED
Checking `login'... INFECTED
Checking `mail'... INFECTED
Checking `passwd'... INFECTED
/usr/lib/.unix95
/usr/lib/.unix95
/usr/lib/security
/usr/lib/security/libpam_unix.1
/usr/lib/security/libpam_updbe.1
Warning: /sbin/init INFECTED
ifconfig is obviously not quite right since it's looking in the wrong place.
login, mail and init we've just covered.
So I guess the logical conclusion is that chkrootkit isn't quite working for HPUX 11.0.
Or the cracker has very cleverly covered their tracks.
Or I'm missing something.
Thanks for all the help so far, how many points do you want for the rest of the answers, they're all good?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-15-2003 06:33 AM
07-15-2003 06:33 AM
Re: Should init contain string HOME in HPUX 11.0?
A nice offer, but it's up to you! Glad to be of help.
Pete
Pete
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-15-2003 06:37 AM
07-15-2003 06:37 AM
Re: Should init contain string HOME in HPUX 11.0?
I feel somewhat less like the world is out to get me, which is good.
You'll just have to put up with the indistinguishable 9 points for each answer then. Thanks for your lightning fast response.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-15-2003 06:40 AM
07-15-2003 06:40 AM
Re: Should init contain string HOME in HPUX 11.0?
Pete
Pete
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-15-2003 06:46 AM
07-15-2003 06:46 AM
Re: Should init contain string HOME in HPUX 11.0?
I can put your mind to rest on the date issue - I was on the wrong system. Here's my 11.0 version:
# ll /usr/bin/mail
-r-sr-sr-x 2 root mail 45056 Nov 7 1997 /usr/bin/mail
Pete
Pete
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-15-2003 06:56 AM
07-15-2003 06:56 AM
Re: Should init contain string HOME in HPUX 11.0?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-15-2003 06:58 AM
07-15-2003 06:58 AM
Re: Should init contain string HOME in HPUX 11.0?
;^)
Pete
Pete
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-15-2003 07:32 AM
07-15-2003 07:32 AM
Re: Should init contain string HOME in HPUX 11.0?
Now all I've got to worry about is an absence of any hard evidence that anything's wrong.
There's always the, "Maybe there's a monster living under my bed?" to go back to I suppose.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-19-2003 04:04 PM
07-19-2003 04:04 PM
Re: Should init contain string HOME in HPUX 11.0?
I am indeed surprised that chkrootkit isn't truly ported over to HP-UX. I have tested chkrootkit on Linux and Solaris, and I have found it to be rather reliable so far.
I suggest that you feedback to chkrootkit's development team on the large number of false positives. A concerned person running chkrootkit might just reformat his entire system to be on the safe side!
Hope this helps. Regards.
Steven Sim Kok Leong
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-20-2003 11:51 PM
07-20-2003 11:51 PM
Re: Should init contain string HOME in HPUX 11.0?
I haven't installed gcc so the make sense, didn't run. Since there was a script there I ran it anyway, perhaps the make changes the script to take out these bits.
It did flip me out a bit so I went off in headless chicken mode for a while.
I shall see what chkrootkit have to say on the matter.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-13-2004 04:38 AM
08-13-2004 04:38 AM
Re: Should init contain string HOME in HPUX 11.0?
on 2 old HP-UX 11 boxes.
Also tested chkrootkit 0.43
We also saw the ifconfig not found / ifconfig infected confusion after noting there was an ifconfig in /usr/sbin.
So we hacked the chkrootkit script to find the real ifconfig and 'hey presto' no more 'infected' flag on ifconfig!
# diff chkrootkit chkrootkit.original
2083c2083
< CMD="/usr/sbin/ifconfig"
---
> CMD="${ROOTDIR}sbin/ifconfig"
#
Now to explore the other 'infected' flags and see if they are more 'false positives'.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-14-2004 01:15 PM
08-14-2004 01:15 PM
Re: Should init contain string HOME in HPUX 11.0?
Bill Hassell, sysadmin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-15-2004 10:00 PM
08-15-2004 10:00 PM
Re: Should init contain string HOME in HPUX 11.0?
I had a fast response from the
chkrootkit maintainers who promise a fix to the ifconfig test miss-reporting 'infected' in chkrootkit 0.44
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-26-2004 10:42 PM
08-26-2004 10:42 PM
Re: Should init contain string HOME in HPUX 11.0?
It's amazing to think that people will actually provide tools like this for free.
There is no substitute for a really in depth knowledge of the OS. Hopefully one day I'll get there.
Thanks to all who replied.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-14-2004 01:24 AM
12-14-2004 01:24 AM
Re: Should init contain string HOME in HPUX 11.0?
http://forums.itrc.hp.com/service/forums/questionanswer.do?threadId=249747
I now get no false 'infected' results and am satisfied that chkrootkit 0.44 is useful to see if any obvious rootkit tell-tales have been left behind.