LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-21-2005, 06:37 AM   #1
Ovalteen
Member
 
Registered: Jun 2004
Location: Australia
Distribution: Ubuntu 5.04
Posts: 55

Rep: Reputation: 15
Rkhunter finds "suspicious" files in /dev


Hello all,

I've just run rkhunter and it came up with the following message:
Code:
* Filesystem checks
   Checking /dev for suspicious files...                      [ Warning! (unusual files found) ]
---------------------------------------------
Unusual files:
/dev/pst0:        ASCII text
/dev/pts0:        ASCII text
---------------------------------------------
I had this message come up previously but I thought it may have been a false positive, so I let it slide. Is it anything to be concerned about? All other tests are OK.

Cheers

Ovalteen
 
Old 03-21-2005, 07:55 PM   #2
Ovalteen
Member
 
Registered: Jun 2004
Location: Australia
Distribution: Ubuntu 5.04
Posts: 55

Original Poster
Rep: Reputation: 15
OK, I chipped away at it a bit more.

I was under the impression that pts was some kind of terminal or something. Is this the case? I wasn't sure what I should do with it but eventually just opened it in VI. I should have done that earlier, but I didn't think it would work, as it doesn't for other items in that folder.

The files (both pts0 and pst0) both had some "Hello" type of message in them (just 2 or 3 words). I was pretty sure I didn't put this there myself, so I greped the bash history for each user, but I didn't find any matches. Is it possible though, that maybe the command wasn't recorded because more than one session of that user was open at once?

Anyway, I deleted the text, ran rkhunter again and it's all fine. I figure it was probably just me being a stupid or testing out something, as none of my logs seem to indicate trouble. I can't imagine someone hacked in just to write "Hello".

Cheers

Ovalteen
 
Old 03-22-2005, 04:50 AM   #3
ilikejam
Senior Member
 
Registered: Aug 2003
Location: Glasgow
Distribution: Fedora / Solaris
Posts: 3,109

Rep: Reputation: 97
Hi.

It's probably a script trying to redirect some output to a virtual terminal which wasn't open, so a new file was made with the contents of the message.

Dave
 
Old 03-22-2005, 06:28 AM   #4
Ovalteen
Member
 
Registered: Jun 2004
Location: Australia
Distribution: Ubuntu 5.04
Posts: 55

Original Poster
Rep: Reputation: 15
Thanks for the tip Dave. I'll have a look and see what I may have run.

Cheers

Ovalteen
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
lilo says, "L 01 01 01" and fdisk says, "Unable to seek on /dev/hda1" clausawits Linux - General 3 12-31-2007 09:33 PM
"No PCMCIA Controller Detected" but Suse 10 finds the Wireless Card aj87uk SUSE / openSUSE 3 11-06-2005 03:59 PM
add "Artist" and "Album Title" to mp3 files powah Linux - Software 2 04-05-2005 03:04 AM
Writing to "/dev/usb/hiddev*" and to "/proc/bus/usb/00B/00S" throw an arror EI stpg Programming 0 07-14-2004 05:44 AM
"X-MS" cant open because "x-Multimedia System" cant access files at "smb&qu ponchy5 Linux - Networking 0 03-29-2004 11:18 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:30 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration