View previous topic :: View next topic |
Author |
Message |
Napalm Llama Guru
Joined: 04 Jun 2005 Posts: 533 Location: Cardiff, UK
|
Posted: Mon Jun 28, 2010 1:08 am Post subject: Dodgy system behaviour - possible rootkit? |
|
|
My system's been acting up for the last couple of months, with various, seemingly unrelated things going wrong. I ran rkhunter recently, and it threw up warnings for the majority of system commands. I know the files could have just changed because of updates, but it's still worrying.
The extra-weird thing though is the behaviour of libnss3.so. My system has two libraries with this name:
/usr/lib/libnss3.so
/usr/lib/mozilla/libnss3.so
Chrome depends on the Mozilla one, even though equery says it isn't claimed by any packages. Trouble is, Chrome won't start unless I replace the Mozilla library with a symlink to the main one. So I move /usr/lib/mozilla/libnss3.so to eg. /usr/lib/mozilla/libnss3.so.old, or /usr/lib/mozilla/libnss3.soveryold, or /usr/lib/mozilla/libnss3backup, and replace it with a symlink to /usr/lib/libnss3.so. And a few days later, without fail, the symlink has changed. Instead of pointing to the correct library, it now points right back to the mozilla one, no matter what name I changed it to. I don't see how an automated script could do that.
Does this sound like rootkit behaviour - eg. replacing the libnss libray so that an attacker can listen in on SSL traffic? Or am I just being paranoid? _________________ Ryzen 5600x; Asus TUF Gaming B550-Plus; Geforce 1660 Super
Registered Linux User #381314
# killall humans |
|
Back to top |
|
|
Ant P. Watchman
Joined: 18 Apr 2009 Posts: 6920
|
Posted: Mon Jun 28, 2010 7:26 am Post subject: |
|
|
That definitely isn't right. I've got half a dozen browsers installed and there's no /usr/lib/mozilla/libnss.so on my system. |
|
Back to top |
|
|
Hu Administrator
Joined: 06 Mar 2007 Posts: 23093
|
Posted: Tue Jun 29, 2010 2:06 am Post subject: Re: Dodgy system behaviour - possible rootkit? |
|
|
Napalm Llama wrote: | I ran rkhunter recently, and it threw up warnings for the majority of system commands. | Although false positives can occur in some cases, they are usually not particularly numerous. Please share the warnings so we can analyze them. |
|
Back to top |
|
|
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|