Rootkit found on my Centos server
Posted: 19 Aug 2016, 14:33
I did a scan with Rkunter on my Centos server and it came up with a possible rootkit find:
So I checked the logs:
And it came up with
I cannot find that this is a false positive on the net.
The file /tmp/.bash_history contains :
Help!
Code: Select all
Rootkit checks...
Rootkits checked : 368
Possible rootkits: 1
Rootkit names : Lite5-r Rootkit
So I checked the logs:
Code: Select all
cat /var/log/rkhunter/rkhunter.log |grep 'Lite5-r Rootkit'
And it came up with
Code: Select all
Found file '/tmp/.bash_history'. Possible rootkit: Lite5-r Rootkit
I cannot find that this is a false positive on the net.
The file /tmp/.bash_history contains :
Code: Select all
passwd
exit
Help!