Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Dodgy system behaviour - possible rootkit?
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
Napalm Llama
Guru
Guru


Joined: 04 Jun 2005
Posts: 533
Location: Cardiff, UK

PostPosted: Mon Jun 28, 2010 1:08 am    Post subject: Dodgy system behaviour - possible rootkit? Reply with quote

My system's been acting up for the last couple of months, with various, seemingly unrelated things going wrong. I ran rkhunter recently, and it threw up warnings for the majority of system commands. I know the files could have just changed because of updates, but it's still worrying.
The extra-weird thing though is the behaviour of libnss3.so. My system has two libraries with this name:
/usr/lib/libnss3.so
/usr/lib/mozilla/libnss3.so

Chrome depends on the Mozilla one, even though equery says it isn't claimed by any packages. Trouble is, Chrome won't start unless I replace the Mozilla library with a symlink to the main one. So I move /usr/lib/mozilla/libnss3.so to eg. /usr/lib/mozilla/libnss3.so.old, or /usr/lib/mozilla/libnss3.soveryold, or /usr/lib/mozilla/libnss3backup, and replace it with a symlink to /usr/lib/libnss3.so. And a few days later, without fail, the symlink has changed. Instead of pointing to the correct library, it now points right back to the mozilla one, no matter what name I changed it to. I don't see how an automated script could do that.

Does this sound like rootkit behaviour - eg. replacing the libnss libray so that an attacker can listen in on SSL traffic? Or am I just being paranoid?
_________________
Ryzen 5600x; Asus TUF Gaming B550-Plus; Geforce 1660 Super
Registered Linux User #381314
# killall humans
Back to top
View user's profile Send private message
Ant P.
Watchman
Watchman


Joined: 18 Apr 2009
Posts: 6920

PostPosted: Mon Jun 28, 2010 7:26 am    Post subject: Reply with quote

That definitely isn't right. I've got half a dozen browsers installed and there's no /usr/lib/mozilla/libnss.so on my system.
Back to top
View user's profile Send private message
Hu
Administrator
Administrator


Joined: 06 Mar 2007
Posts: 23093

PostPosted: Tue Jun 29, 2010 2:06 am    Post subject: Re: Dodgy system behaviour - possible rootkit? Reply with quote

Napalm Llama wrote:
I ran rkhunter recently, and it threw up warnings for the majority of system commands.
Although false positives can occur in some cases, they are usually not particularly numerous. Please share the warnings so we can analyze them.
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum