Last login: Wed Apr 15 22:19:53 on ttyp3
Welcome to Darwin!
rootkit hunter needs to be started with administrator privileges, please authenticate first.
Rootkit Hunter 1.2.8 is running
Determining OS… Darwin
Warning: Mac OS X is not fully supported!
Checking binaries
Selftests
Strings (command) [ OK ]
System tools
Skipped!
Check rootkits
Default files and directories
Rootkit ‘55808 Trojan - Variant A’… [ OK ]
ADM Worm… [ OK ]
Rootkit ‘AjaKit’… [ OK ]
Rootkit ‘aPa Kit’… [ OK ]
Rootkit ‘Apache Worm’… [ OK ]
Rootkit ‘Ambient (ark) Rootkit’… [ OK ]
Rootkit ‘Balaur Rootkit’… [ OK ]
Rootkit ‘BeastKit’… [ OK ]
Rootkit ‘beX2’… [ OK ]
Rootkit ‘BOBKit’… [ OK ]
Rootkit ‘CiNIK Worm (Slapper.B variant)’… [ OK ]
Rootkit ‘Danny-Boy’s Abuse Kit’… [ OK ]
Rootkit ‘Devil RootKit’… [ OK ]
Rootkit ‘Dica’… [ OK ]
Rootkit ‘Dreams Rootkit’… [ OK ]
Rootkit ‘Duarawkz’… [ OK ]
Rootkit ‘Flea Linux Rootkit’… [ OK ]
Rootkit ‘FreeBSD Rootkit’… [ OK ]
Rootkit ‘Fuck`it Rootkit’… [ OK ]
Rootkit ‘GasKit’… [ OK ]
Rootkit ‘Heroin LKM’… [ OK ]
Rootkit ‘HjC Kit’… [ OK ]
Rootkit ‘ignoKit’… [ OK ]
Rootkit ‘ImperalsS-FBRK’… [ OK ]
Rootkit ‘Irix Rootkit’… [ OK ]
Rootkit ‘Kitko’… [ OK ]
Rootkit ‘Knark’… [ OK ]
Rootkit ‘Li0n Worm’… [ OK ]
Rootkit ‘Lockit / LJK2’… [ OK ]
Rootkit ‘MRK’… [ OK ]
Rootkit ‘Ni0 Rootkit’… [ OK ]
Rootkit ‘RootKit for SunOS / NSDAP’… [ OK ]
Rootkit ‘Optic Kit (Tux)’… [ OK ]
Rootkit ‘Oz Rootkit’… [ OK ]
Rootkit ‘Portacelo’… [ OK ]
Rootkit ‘R3dstorm Toolkit’… [ OK ]
Rootkit ‘RH-Sharpe’s rootkit’… [ OK ]
Rootkit ‘RSHA’s rootkit’… [ OK ]
Sebek LKM [ OK ]
Rootkit ‘Scalper Worm’… [ OK ]
Rootkit ‘Shutdown’… [ OK ]
Rootkit ‘SHV4’… [ OK ]
Rootkit ‘SHV5’… [ OK ]
Rootkit ‘Sin Rootkit’… [ OK ]
Rootkit ‘Slapper’… [ OK ]
Rootkit ‘Sneakin Rootkit’… [ OK ]
Rootkit ‘Suckit Rootkit’… [ OK ]
Rootkit ‘SunOS Rootkit’… [ OK ]
Rootkit ‘Superkit’… [ OK ]
Rootkit ‘TBD (Telnet BackDoor)’… [ OK ]
Rootkit ‘TeLeKiT’… [ OK ]
Rootkit ‘T0rn Rootkit’… [ OK ]
Rootkit ‘Trojanit Kit’… [ OK ]
Rootkit ‘Tuxtendo’… [ OK ]
Rootkit ‘URK’… [ OK ]
Rootkit ‘VcKit’… [ OK ]
Rootkit ‘Volc Rootkit’… [ OK ]
Rootkit ‘X-Org SunOS Rootkit’… [ OK ]
Rootkit ‘zaRwT.KiT Rootkit’… [ OK ]
Suspicious files and malware
Scanning for known rootkit strings [ OK ]
Scanning for known rootkit files [ OK ]
Testing running processes… [ OK ]
Miscellaneous Login backdoors [ OK ]
Miscellaneous directories [ OK ]
Software related files [ OK ]
Sniffer logs [ OK ]
Trojan specific characteristics
shv4
Checking /etc/rc.d/rc.sysinit [ Not found ]
Checking /etc/inetd.conf [ Clean ]
Checking /etc/xinetd.conf [ Skipped ]
Interfaces
Scanning for promiscuous interfaces [ OK ]
System checks
Allround tests
Checking hostname… Found. Hostname is poweribook.local
Checking for passwordless user accounts… Skipped
Checking for differences in user accounts… OK. No changes.
Checking for differences in user groups… OK. No changes.
Checking boot.local/rc.local file…
/etc/rc.local [ Not found ]
/etc/rc.d/rc.local [ Not found ]
/usr/local/etc/rc.local [ Not found ]
/usr/local/etc/rc.d/rc.local [ Not found ]
/etc/conf.d/local.start [ Not found ]
/etc/init.d/boot.local [ Not found ]
Checking rc.d files… [ Not found ]
Checking history files
Bourne Shell [ Not Found ]
Filesystem checks
Checking /dev for suspicious files… [ OK ]
Scanning for hidden files… [ OK ]
Application advisories
Application scan
Checking Apache2 modules … [ Not found ]
Checking Apache configuration … [ OK ]
Application version scan
GnuPG 2.0.10 [ Unknown ]
Apache 1.3.41 [ Unknown ]
Bind DNS 9.3.5-P2 [ Unknown ]
OpenSSL 0.9.7l [ Unknown ]
PHP 4.4.9 [ Unknown ]
Procmail MTA 3.22 [ OK ]
OpenSSH 5.1p1 [ Unknown ]
Your system contains some unknown version numbers. Please run Rootkit Hunter
with the --update parameter or fill in the contact form (www.rootkit.nl)
Security advisories
Check: Groups and Accounts
Searching for /etc/passwd… [ Found ]
Checking users with UID ‘0’ (root)… [ OK ]
Check: SSH
Searching for sshd_config…
Found /etc/sshd_config
Checking for allowed root login… Watch out Root login possible. Possible risk! ma samo mi kazi
info:
Hint: See logfile for more information about this issue
Checking for allowed protocols… [ Warning (SSH v1 allowed) ]
Check: Events and Logging
Search for syslog configuration… [ OK ]
Checking for running syslog slave… [ OK ]
Checking for logging to remote system… [ OK (remote logging) ]
info: install.* @127.0.0.1:32376
File scan
Scanned files: 342
Possible infected files: 0
Application scan
Vulnerable applications: 0
Scanning took 83 seconds
Do you have some problems, undetected rootkits, false positives, ideas
or suggestions?
Please e-mail me by filling in the contact form (@http://www.rootkit.nl)