Re: [gentoo-user] rkhunter reports xorddos component

2019-02-27 Thread Philip Webb
190227 Neil Bothwick wrote: > On Wed, 27 Feb 2019 15:07:35 +, Mick wrote: >> I checked on a non-gentoo systemd based distro and this file is not there. >> It seems it is related to sys-fs/udev-init-scripts. > Indeed, I am getting this warning on one openrc machine > and none of the systemd ones

Re: [gentoo-user] rkhunter reports xorddos component

2019-02-27 Thread Neil Bothwick
On Wed, 27 Feb 2019 15:07:35 +, Mick wrote: > > Little info here. I don't run systemd here but I also have that > > file. > > I checked on a non-gentoo systemd based distro and this file is not > there. It seems it is related to sys-fs/udev-init-scripts. > Indeed, I am getting this war

Re: [gentoo-user] rkhunter reports xorddos component

2019-02-27 Thread Dale
Mick wrote: > On Wednesday, 27 February 2019 13:50:58 GMT Dale wrote: > >> Little info here. I don't run systemd here but I also have that file. > I checked on a non-gentoo systemd based distro and this file is not there. > It > seems it is related to sys-fs/udev-init-scripts. I mentioned tha

Re: [gentoo-user] rkhunter reports xorddos component

2019-02-27 Thread Mick
On Wednesday, 27 February 2019 14:29:40 GMT Rich Freeman wrote: > On Wed, Feb 27, 2019 at 8:47 AM Peter Humphrey wrote: > > On Wednesday, 27 February 2019 12:27:59 GMT Mick wrote: > > > Could it be these versions are now launching /run/udev.pid? Is a file > > > /run/ udev.pid present in your sys

Re: [gentoo-user] rkhunter reports xorddos component

2019-02-27 Thread Mick
On Wednesday, 27 February 2019 13:50:58 GMT Dale wrote: > Little info here. I don't run systemd here but I also have that file. I checked on a non-gentoo systemd based distro and this file is not there. It seems it is related to sys-fs/udev-init-scripts. > I checked with equery b but obviou

Re: [gentoo-user] rkhunter reports xorddos component

2019-02-27 Thread Mick
On Wednesday, 27 February 2019 13:47:31 GMT Peter Humphrey wrote: > On Wednesday, 27 February 2019 12:27:59 GMT Mick wrote: > > I noticed this beauty popping up a day ago: > > > > Rootkit checks... > > > > Rootkits checked : 498 > > Possible rootkits: 1 > > Rootkit names: xorddos

Re: [gentoo-user] rkhunter reports xorddos component

2019-02-27 Thread Rich Freeman
On Wed, Feb 27, 2019 at 8:47 AM Peter Humphrey wrote: > > On Wednesday, 27 February 2019 12:27:59 GMT Mick wrote: > > > > Could it be these versions are now launching /run/udev.pid? Is a file /run/ > > udev.pid present in your system? > > Yes, I have such a text file, containing just a PID. > > >

Re: [gentoo-user] rkhunter reports xorddos component

2019-02-27 Thread Dale
Mick wrote: > I noticed this beauty popping up a day ago: > > Rootkit checks... > Rootkits checked : 498 > Possible rootkits: 1 > Rootkit names: xorddos component > > Fair enough the log reported a suspect file: > > > Checking for file '/var/run/

Re: [gentoo-user] rkhunter reports xorddos component

2019-02-27 Thread Peter Humphrey
On Wednesday, 27 February 2019 12:27:59 GMT Mick wrote: > I noticed this beauty popping up a day ago: > > Rootkit checks... > Rootkits checked : 498 > Possible rootkits: 1 > Rootkit names: xorddos component > > Fair enough the log reported a suspect file: > >

[gentoo-user] rkhunter reports xorddos component

2019-02-27 Thread Mick
I noticed this beauty popping up a day ago: Rootkit checks... Rootkits checked : 498 Possible rootkits: 1 Rootkit names: xorddos component Fair enough the log reported a suspect file: Checking for file '/var/run/sftp.pid' [ Not found ]