Security Basics mailing list archives

RE: HP UX 10.20


From: "John C. Dack" <John.Dack () herald-group com>
Date: Fri, 5 Sep 2003 07:17:49 +0100

Hi,

I have ran the chkrootkit program on a HPUX box that has had a new install of 10:20 and has never been connected to the 
internet and have had the same results, I'm not sure but this may be a misinterpretation by the chkrootkit program.

I'm sure someone will tell me if I'm wrong :-)

John

-----Original Message-----
From: Alvin Wong [mailto:alvin.wong () b2b com my]
Sent: 04 September 2003 09:41
To: security-basics () securityfocus com
Subject: HP UX 10.20


Hi, 

I would like to request for help on HP UX 10.20. I have recently ran
chkrootkit on it and found that there was an alert for Suckit rootkit
where /sbin/init has been infected. What is the recommended plan of
action here? Do i replace it with a new init? and where do i get the new
init from?
Anyone has recommendations or links to information where i can clean the
system of the rootkit?
Thanks in advance.




---------------------------------------------------------------------------
Attend Black Hat Briefings & Training Federal, September 29-30 (Training), 
October 1-2 (Briefings) in Tysons Corner, VA; the world's premier 
technical IT security event.  Modeled after the famous Black Hat event in 
Las Vegas! 6 tracks, 12 training sessions, top speakers and sponsors.  
Symantec is the Diamond sponsor.  Early-bird registration ends September 6.Visit us: www.blackhat.com
---------------------------------------------------------------------------- 
--------------------------------------------------------
 
  
The Herald Group accepts no liability for the content of this email, or for the consequences of any actions taken on 
the basis of the information provided, unless that information is subsequently confirmed in writing. Any views or 
opinions presented in this email are solely those of the author and do not necessarily represent those of the company.  
  
WARNING: Computer viruses can be transmitted via email. The recipient should check this email and any attachments for 
the presence of viruses. The company accepts no liability for any damage caused by any virus transmitted by this email. 
 
  
http://www.herald-group.com 
  

Current thread: