Scan by chkrootkit shows "tcpd" as being INFECTED.
Although a scan by rkhunter shows ok,(except for regular false positives)
Shall I be worried?
(I'm on Ubuntu 16.10 with 4.8.0-37-generic)
chkrootkitmalwarerootkitSecuritytcpdump
Scan by chkrootkit shows "tcpd" as being INFECTED.
Although a scan by rkhunter shows ok,(except for regular false positives)
Shall I be worried?
(I'm on Ubuntu 16.10 with 4.8.0-37-generic)
Best Answer
In this Ubuntu Forums post, user kpatz tested this in a fresh 16.10 VM and chkrootkit still complained, making this a false positive. You can always check if a file has been tampered by comparing the md5sum from the package:
Of course, the md5sums file itself maybe tampered, (and so could
md5sum
itself and so on...).