Debian Debian-France Debian-Facile Debian-fr.org Forum-Debian.fr Debian ? Communautés

Debian-facile

Bienvenue sur Debian-Facile, site d'aide pour les nouveaux utilisateurs de Debian.

Vous n'êtes pas identifié(e).

#1 29-07-2021 18:56:33

DoggySmile78
Membre
Inscription : 11-03-2021

attaque bootkit uefi ACPI ?

Bonjour à tous,
je suis nouveau sur Debian mais je crois avoir été infecté par un bootkit uefi. J'ai de nombreuses connexions ssh entrantes et sortantes non désirées et meme en root, je me retrouve avec des 'permission non accordée' pour certaines operations. Je ne peux pas desactiver CUPS ou utiliser gparted meme en root. J'ai parfois des problemes d'ecran 'Out of range' alors qu'avant je n'avais rien de tout ca. Au demarrage, j'ai des lignes en plus concernant des tables ACPI erronées.
Etant en dual boot avec Windows, j'avais le secure boot de disabled.
Depuis, mes 3 pcs sur le reseau ont les memes problemes.
J'ai clear le CMOS, flashé le BIOS avec Freedos mais rien n'y fait. Voici le rapport rkhunter. Pouvez-vous me dire si vous voyez quelque chose de louche ?
Si vous pouvez me dire quoi vous fournir comme commande en plus. Encore une fois, je suis novice.
Je n'ai mis que le debut.


[21:41:51] Running Rootkit Hunter version 1.4.6 on debian
[21:41:51]
[21:41:51] Info: Start date is dim. 11 juil. 2021 21:41:51 CEST
[21:41:51]
[21:41:51] Checking configuration file and command-line options...
[21:41:51] Info: Detected operating system is 'Linux'
[21:41:51] Info: Found O/S name: Debian GNU/Linux 11 (bullseye)
[21:41:51] Info: Command line is /usr/bin/rkhunter --check
[21:41:51] Info: Environment shell is /bin/bash; rkhunter is using dash
[21:41:51] Info: Using configuration file '/etc/rkhunter.conf'
[21:41:51] Info: Installation directory is '/usr'
[21:41:51] Info: Using language 'en'
[21:41:51] Info: Using '/var/lib/rkhunter/db' as the database directory
[21:41:51] Info: Using '/usr/share/rkhunter/scripts' as the support script directory
[21:41:51] Info: Using '/usr/local/sbin /usr/local/bin /usr/sbin /usr/bin /sbin /bin /usr/libexec' as the command directories
[21:41:51] Info: Using '/var/lib/rkhunter/tmp' as the temporary directory
[21:41:51] Info: No mail-on-warning address configured
[21:41:51] Info: X will be automatically detected
[21:41:51] Info: Using second color set
[21:41:51] Info: Found the 'basename' command: /usr/bin/basename
[21:41:51] Info: Found the 'diff' command: /usr/bin/diff
[21:41:51] Info: Found the 'dirname' command: /usr/bin/dirname
[21:41:51] Info: Found the 'file' command: /usr/bin/file
[21:41:51] Info: Found the 'find' command: /usr/bin/find
[21:41:51] Info: Found the 'ifconfig' command: /usr/sbin/ifconfig
[21:41:51] Info: Found the 'ip' command: /usr/sbin/ip
[21:41:51] Info: Found the 'ipcs' command: /usr/bin/ipcs
[21:41:51] Info: Found the 'ldd' command: /usr/bin/ldd
[21:41:51] Info: Found the 'lsattr' command: /usr/bin/lsattr
[21:41:51] Info: Found the 'lsmod' command: /usr/sbin/lsmod
[21:41:51] Info: Found the 'lsof' command: /usr/bin/lsof
[21:41:51] Info: Found the 'mktemp' command: /usr/bin/mktemp
[21:41:51] Info: Found the 'netstat' command: /usr/bin/netstat
[21:41:52] Info: Found the 'numfmt' command: /usr/bin/numfmt
[21:41:52] Info: Found the 'perl' command: /usr/bin/perl
[21:41:52] Info: Found the 'pgrep' command: /usr/bin/pgrep
[21:41:52] Info: Found the 'ps' command: /usr/bin/ps
[21:41:52] Info: Found the 'pwd' command: /usr/bin/pwd
[21:41:52] Info: Found the 'readlink' command: /usr/bin/readlink
[21:41:52] Info: Found the 'stat' command: /usr/bin/stat
[21:41:52] Info: Found the 'strings' command: /usr/bin/strings
[21:41:52] Info: System is not using prelinking
[21:41:52] Info: Using the '/usr/bin/sha256sum' command for the file hash checks
[21:41:52] Info: Stored hash values used hash function '/usr/bin/sha256sum'
[21:41:52] Info: Stored hash values did not use a package manager
[21:41:52] Info: The hash function field index is set to 1
[21:41:52] Info: No package manager specified: using hash function '/usr/bin/sha256sum'
[21:41:52] Info: Previous file attributes were stored
[21:41:52] Info: Enabled tests are: all
[21:41:52] Info: Disabled tests are: suspscan hidden_ports hidden_procs deleted_files packet_cap_apps apps
[21:41:52] Info: Found kernel symbols file '/proc/kallsyms'
[21:41:52] Info: Using syslog for some logging - facility/priority level is 'authpriv.warning'.
[21:41:52] Info: Found the 'logger' command: /usr/bin/logger
[21:41:52] Info: Using 'date' to process epoch second times
[21:41:52]
[21:41:52] Checking if the O/S has changed since last time...
[21:41:52] Info: Nothing seems to have changed.
[21:41:52] Info: Locking is not being used
[21:41:52]
[21:41:52] Starting system checks...
[21:41:52]
[21:41:52] Info: Starting test name 'system_commands'
[21:41:52] Checking system commands...
[21:41:52]
[21:41:52] Info: Starting test name 'strings'
[21:41:52] Performing 'strings' command checks
[21:41:52]   Scanning for string /usr/sbin/ntpsx             [ OK ]
[21:41:52]   Scanning for string /usr/sbin/.../bkit-ava      [ OK ]
[21:41:52]   Scanning for string /usr/sbin/.../bkit-d        [ OK ]
[21:41:52]   Scanning for string /usr/sbin/.../bkit-shd      [ OK ]
[21:41:52]   Scanning for string /usr/sbin/.../bkit-f        [ OK ]
[21:41:52]   Scanning for string /usr/include/.../proc.h     [ OK ]
[21:41:52]   Scanning for string /usr/include/.../.bash_history [ OK ]
[21:41:53]   Scanning for string /usr/include/.../bkit-get   [ OK ]
[21:41:53]   Scanning for string /usr/include/.../bkit-dl    [ OK ]
[21:41:53]   Scanning for string /usr/include/.../bkit-screen [ OK ]
[21:41:53]   Scanning for string /usr/include/.../bkit-sleep [ OK ]
[21:41:53]   Scanning for string /usr/lib/.../bkit-adore.o   [ OK ]
[21:41:53]   Scanning for string /usr/lib/.../ls             [ OK ]
[21:41:53]   Scanning for string /usr/lib/.../netstat        [ OK ]
[21:41:53]   Scanning for string /usr/lib/.../lsof           [ OK ]
[21:41:53]   Scanning for string /usr/lib/.../bkit-ssh/bkit-shdcfg [ OK ]
[21:41:53]   Scanning for string /usr/lib/.../bkit-ssh/bkit-shhk [ OK ]
[21:41:53]   Scanning for string /usr/lib/.../bkit-ssh/bkit-pw [ OK ]
[21:41:53]   Scanning for string /usr/lib/.../bkit-ssh/bkit-shrs [ OK ]
[21:41:53]   Scanning for string /usr/lib/.../bkit-ssh/bkit-mots [ OK ]
[21:41:53]   Scanning for string /usr/lib/.../uconf.inv      [ OK ]
[21:41:53]   Scanning for string /usr/lib/.../psr            [ OK ]
[21:41:53]   Scanning for string /usr/lib/.../find           [ OK ]
[21:41:53]   Scanning for string /usr/lib/.../pstree         [ OK ]
[21:41:53]   Scanning for string /usr/lib/.../slocate        [ OK ]
[21:41:53]   Scanning for string /usr/lib/.../du             [ OK ]
[21:41:53]   Scanning for string /usr/lib/.../top            [ OK ]
[21:41:53]   Scanning for string /usr/sbin/...               [ OK ]
[21:41:53]   Scanning for string /usr/include/...            [ OK ]
[21:41:53]   Scanning for string /usr/include/.../.tmp       [ OK ]
[21:41:53]   Scanning for string /usr/lib/...                [ OK ]
[21:41:53]   Scanning for string /usr/lib/.../.ssh           [ OK ]
[21:41:53]   Scanning for string /usr/lib/.../bkit-ssh       [ OK ]
[21:41:53]   Scanning for string /usr/lib/.bkit-             [ OK ]
[21:41:53]   Scanning for string /tmp/.bkp                   [ OK ]
[21:41:53]   Scanning for string /tmp/.cinik                 [ OK ]
[21:41:53]   Scanning for string /tmp/.font-unix/.cinik      [ OK ]
[21:41:53]   Scanning for string /lib/.sso                   [ OK ]
[21:41:53]   Scanning for string /lib/.so                    [ OK ]
[21:41:53]   Scanning for string /var/run/...dica/clean      [ OK ]
[21:41:53]   Scanning for string /var/run/...dica/dxr        [ OK ]
[21:41:53]   Scanning for string /var/run/...dica/read       [ OK ]
[21:41:53]   Scanning for string /var/run/...dica/write      [ OK ]
[21:41:53]   Scanning for string /var/run/...dica/lf         [ OK ]
[21:41:53]   Scanning for string /var/run/...dica/xl         [ OK ]
[21:41:53]   Scanning for string /var/run/...dica/xdr        [ OK ]
[21:41:53]   Scanning for string /var/run/...dica/psg        [ OK ]
[21:41:53]   Scanning for string /var/run/...dica/secure     [ OK ]
[21:41:54]   Scanning for string /var/run/...dica/rdx        [ OK ]
[21:41:54]   Scanning for string /var/run/...dica/va         [ OK ]
[21:41:54]   Scanning for string /var/run/...dica/cl.sh      [ OK ]
[21:41:54]   Scanning for string /var/run/...dica/last.log   [ OK ]
[21:41:54]   Scanning for string /usr/bin/.etc               [ OK ]
[21:41:54]   Scanning for string /etc/sshd_config            [ OK ]
[21:41:54]   Scanning for string /etc/ssh_host_key           [ OK ]
[21:41:54]   Scanning for string /etc/ssh_random_seed        [ OK ]
[21:41:54]   Scanning for string /dev/ptyp                   [ OK ]
[21:41:54]   Scanning for string /dev/ptyq                   [ OK ]
[21:41:54]   Scanning for string /dev/ptyr                   [ OK ]
[21:41:54]   Scanning for string /dev/ptys                   [ OK ]
[21:41:54]   Scanning for string /dev/ptyt                   [ OK ]
[21:41:54]   Scanning for string /dev/fd/.88/freshb-bsd      [ OK ]
[21:41:54]   Scanning for string /dev/fd/.88/fresht          [ OK ]
[21:41:54]   Scanning for string /dev/fd/.88/zxsniff         [ OK ]
[21:41:54]   Scanning for string /dev/fd/.88/zxsniff.log     [ OK ]
[21:41:54]   Scanning for string /dev/fd/.99/.ttyf00         [ OK ]
[21:41:54]   Scanning for string /dev/fd/.99/.ttyp00         [ OK ]
[21:41:54]   Scanning for string /dev/fd/.99/.ttyq00         [ OK ]
[21:41:54]   Scanning for string /dev/fd/.99/.ttys00         [ OK ]
[21:41:54]   Scanning for string /dev/fd/.99/.pwsx00         [ OK ]
[21:41:54]   Scanning for string /etc/.acid                  [ OK ]
[21:41:54]   Scanning for string /usr/lib/.fx/sched_host.2   [ OK ]
[21:41:55]   Scanning for string /usr/lib/.fx/random_d.2     [ OK ]
[21:41:55]   Scanning for string /usr/lib/.fx/set_pid.2      [ OK ]
[21:41:55]   Scanning for string /usr/lib/.fx/setrgrp.2      [ OK ]
[21:41:55]   Scanning for string /usr/lib/.fx/TOHIDE         [ OK ]
[21:41:55]   Scanning for string /usr/lib/.fx/cons.saver     [ OK ]
[21:41:55]   Scanning for string /usr/lib/.fx/adore/ava/ava  [ OK ]
[21:41:55]   Scanning for string /usr/lib/.fx/adore/adore/adore.ko [ OK ]
[21:41:55]   Scanning for string /bin/sysback                [ OK ]
[21:41:55]   Scanning for string /usr/local/bin/sysback      [ OK ]
[21:41:55]   Scanning for string /usr/lib/.tbd               [ OK ]
[21:41:55]   Scanning for string /dev/.lib/lib/lib/t0rns     [ OK ]
[21:41:55]   Scanning for string /dev/.lib/lib/lib/du        [ OK ]
[21:41:55]   Scanning for string /dev/.lib/lib/lib/ls        [ OK ]
[21:41:55]   Scanning for string /dev/.lib/lib/lib/t0rnsb    [ OK ]
[21:41:55]   Scanning for string /dev/.lib/lib/lib/ps        [ OK ]
[21:41:55]   Scanning for string /dev/.lib/lib/lib/t0rnp     [ OK ]
[21:41:55]   Scanning for string /dev/.lib/lib/lib/find      [ OK ]
[21:41:55]   Scanning for string /dev/.lib/lib/lib/ifconfig  [ OK ]
[21:41:55]   Scanning for string /dev/.lib/lib/lib/pg        [ OK ]
[21:41:55]   Scanning for string /dev/.lib/lib/lib/ssh.tgz   [ OK ]
[21:41:55]   Scanning for string /dev/.lib/lib/lib/top       [ OK ]
[21:41:55]   Scanning for string /dev/.lib/lib/lib/sz        [ OK ]
[21:41:55]   Scanning for string /dev/.lib/lib/lib/login     [ OK ]
[21:41:55]   Scanning for string /dev/.lib/lib/lib/in.fingerd [ OK ]
[21:41:56]   Scanning for string /dev/.lib/lib/lib/1i0n.sh   [ OK ]
[21:41:56]   Scanning for string /dev/.lib/lib/lib/pstree    [ OK ]
[21:41:56]   Scanning for string /dev/.lib/lib/lib/in.telnetd [ OK ]
[21:41:56]   Scanning for string /dev/.lib/lib/lib/mjy       [ OK ]
[21:41:56]   Scanning for string /dev/.lib/lib/lib/sush      [ OK ]
[21:41:56]   Scanning for string /dev/.lib/lib/lib/tfn       [ OK ]
[21:41:56]   Scanning for string /dev/.lib/lib/lib/name      [ OK ]
[21:41:56]   Scanning for string /dev/.lib/lib/lib/getip.sh  [ OK ]
[21:41:56]   Scanning for string /usr/info/.torn/sh*         [ OK ]
[21:41:56]   Scanning for string /usr/src/.puta/.1addr       [ OK ]
[21:41:56]   Scanning for string /usr/src/.puta/.1file       [ OK ]
[21:41:56]   Scanning for string /usr/src/.puta/.1proc       [ OK ]
[21:41:56]   Scanning for string /usr/src/.puta/.1logz       [ OK ]
[21:41:56]   Scanning for string /usr/info/.t0rn             [ OK ]
[21:41:56]   Scanning for string /dev/.lib                   [ OK ]
[21:41:56]   Scanning for string /dev/.lib/lib               [ OK ]
[21:41:56]   Scanning for string /dev/.lib/lib/lib           [ OK ]
[21:41:56]   Scanning for string /dev/.lib/lib/lib/dev       [ OK ]
[21:41:56]   Scanning for string /dev/.lib/lib/scan          [ OK ]
[21:41:56]   Scanning for string /usr/src/.puta              [ OK ]
[21:41:56]   Scanning for string /usr/man/man1/man1          [ OK ]
[21:41:56]   Scanning for string /usr/man/man1/man1/lib      [ OK ]
[21:41:56]   Scanning for string /usr/man/man1/man1/lib/.lib [ OK ]
[21:41:56]   Scanning for string /usr/man/man1/man1/lib/.lib/.backup [ OK ]
[21:41:57]
[21:41:57] Info: Starting test name 'shared_libs'
[21:41:57] Performing 'shared libraries' checks
[21:41:57]   Checking for preloading variables               [ None found ]
[21:41:57]   Checking for preloaded libraries                [ None found ]
[21:41:57]
[21:41:57] Info: Starting test name 'shared_libs_path'
[21:41:57]   Checking LD_LIBRARY_PATH variable               [ Not found ]
[21:41:57]
[21:41:57] Info: Starting test name 'properties'
[21:41:57] Performing file properties checks
[21:41:57]   Checking for prerequisites                      [ OK ]
[21:42:04]   /usr/sbin/adduser                               [ OK ]
[21:42:04] Info: Found file '/usr/sbin/adduser': it is whitelisted for the 'script replacement' check.
[21:42:04]   /usr/sbin/chroot                                [ OK ]
[21:42:04]   /usr/sbin/cron                                  [ OK ]
[21:42:04]   /usr/sbin/depmod                                [ OK ]
[21:42:05]   /usr/sbin/fsck                                  [ OK ]
[21:42:05]   /usr/sbin/groupadd                              [ OK ]
[21:42:05]   /usr/sbin/groupdel                              [ OK ]
[21:42:05]   /usr/sbin/groupmod                              [ OK ]
[21:42:06]   /usr/sbin/grpck                                 [ OK ]
[21:42:06]   /usr/sbin/ifconfig                              [ OK ]
[21:42:06]   /usr/sbin/ifdown                                [ OK ]
[21:42:06]   /usr/sbin/ifup                                  [ OK ]
[21:42:06]   /usr/sbin/init                                  [ OK ]
[21:42:07]   /usr/sbin/insmod                                [ OK ]
[21:42:07]   /usr/sbin/ip                                    [ OK ]
[21:42:07]   /usr/sbin/lsmod                                 [ OK ]
[21:42:07]   /usr/sbin/modinfo                               [ OK ]
[21:42:08]   /usr/sbin/modprobe                              [ OK ]
[21:42:08]   /usr/sbin/nologin                               [ OK ]
[21:42:08]   /usr/sbin/pwck                                  [ OK ]
[21:42:09]   /usr/sbin/rmmod                                 [ OK ]
[21:42:09]   /usr/sbin/route                                 [ OK ]
[21:42:09]   /usr/sbin/rsyslogd                              [ OK ]
[21:42:09]   /usr/sbin/runlevel                              [ OK ]
[21:42:10]   /usr/sbin/sulogin                               [ OK ]
[21:42:10]   /usr/sbin/sysctl                                [ OK ]
[21:42:10]   /usr/sbin/useradd                               [ OK ]
[21:42:10]   /usr/sbin/userdel                               [ OK ]
[21:42:11]   /usr/sbin/usermod                               [ OK ]
[21:42:11]   /usr/sbin/vipw                                  [ OK ]
[21:42:11]   /usr/sbin/unhide                                [ OK ]
[21:42:11]   /usr/sbin/unhide-linux                          [ OK ]
[21:42:12]   /usr/sbin/unhide-posix                          [ OK ]
[21:42:12]   /usr/sbin/unhide-tcp                            [ OK ]
[21:42:12]   /usr/bin/awk                                    [ OK ]
[21:42:12]   /usr/bin/basename                               [ OK ]
[21:42:12]   /usr/bin/bash                                   [ OK ]
[21:42:13]   /usr/bin/cat                                    [ OK ]
[21:42:13]   /usr/bin/chattr                                 [ OK ]
[21:42:13]   /usr/bin/chmod                                  [ OK ]
[21:42:13]   /usr/bin/chown                                  [ OK ]
[21:42:13]   /usr/bin/cp                                     [ OK ]
[21:42:14]   /usr/bin/cut                                    [ OK ]
[21:42:14]   /usr/bin/date                                   [ OK ]
[21:42:14]   /usr/bin/df                                     [ OK ]
[21:42:14]   /usr/bin/diff                                   [ OK ]
[21:42:14]   /usr/bin/dirname                                [ OK ]
[21:42:14]   /usr/bin/dmesg                                  [ OK ]
[21:42:15]   /usr/bin/dpkg                                   [ OK ]
[21:42:15]   /usr/bin/dpkg-query                             [ OK ]
[21:42:15]   /usr/bin/du                                     [ OK ]
[21:42:15]   /usr/bin/echo                                   [ OK ]
[21:42:15]   /usr/bin/egrep                                  [ OK ]
[21:42:15] Info: Found file '/usr/bin/egrep': it is whitelisted for the 'script replacement' check.
[21:42:16]   /usr/bin/env                                    [ OK ]
[21:42:16]   /usr/bin/fgrep                                  [ OK ]
[21:42:16] Info: Found file '/usr/bin/fgrep': it is whitelisted for the 'script replacement' check.
[21:42:16]   /usr/bin/file                                   [ OK ]
[21:42:16]   /usr/bin/find                                   [ OK ]
[21:42:16]   /usr/bin/fuser                                  [ OK ]
[21:42:16]   /usr/bin/GET                                    [ OK ]
[21:42:17]   /usr/bin/grep                                   [ OK ]
[21:42:17]   /usr/bin/groups                                 [ OK ]
[21:42:17]   /usr/bin/head                                   [ OK ]
[21:42:17]   /usr/bin/id                                     [ OK ]
[21:42:18]   /usr/bin/ip                                     [ OK ]
[21:42:18]   /usr/bin/ipcs                                   [ OK ]
[21:42:18]   /usr/bin/kill                                   [ OK ]
[21:42:18]   /usr/bin/killall                                [ OK ]
[21:42:18]   /usr/bin/last                                   [ OK ]
[21:42:18]   /usr/bin/lastlog                                [ OK ]
[21:42:19]   /usr/bin/ldd                                    [ OK ]
[21:42:19] Info: Found file '/usr/bin/ldd': it is whitelisted for the 'script replacement' check.
[21:42:19]   /usr/bin/less                                   [ OK ]
[21:42:19]   /usr/bin/locate                                 [ OK ]
[21:42:19]   /usr/bin/logger                                 [ OK ]
[21:42:19]   /usr/bin/login                                  [ OK ]
[21:42:20]   /usr/bin/ls                                     [ OK ]
[21:42:20]   /usr/bin/lsattr                                 [ OK ]
[21:42:20]   /usr/bin/lsmod                                  [ OK ]
[21:42:20]   /usr/bin/lsof                                   [ OK ]
[21:42:20]   /usr/bin/mail                                   [ Warning ]
[21:42:20] Warning: The file '/usr/bin/mail' exists on the system, but it is not present in the 'rkhunter.dat' file.
[21:42:20]   /usr/bin/md5sum                                 [ OK ]
[21:42:21]   /usr/bin/mktemp                                 [ OK ]
[21:42:21]   /usr/bin/more                                   [ OK ]
[21:42:21]   /usr/bin/mount                                  [ OK ]
[21:42:21]   /usr/bin/mv                                     [ OK ]
[21:42:21]   /usr/bin/netstat                                [ OK ]
[21:42:22]   /usr/bin/newgrp                                 [ OK ]
[21:42:22]   /usr/bin/passwd                                 [ OK ]
[21:42:22]   /usr/bin/perl                                   [ OK ]
[21:42:22]   /usr/bin/pgrep                                  [ OK ]
[21:42:22]   /usr/bin/ping                                   [ OK ]
[21:42:22]   /usr/bin/pkill                                  [ OK ]
[21:42:23]   /usr/bin/ps                                     [ OK ]
[21:42:23]   /usr/bin/pstree                                 [ OK ]
[21:42:23]   /usr/bin/pwd                                    [ OK ]
[21:42:23]   /usr/bin/readlink                               [ OK ]
[21:42:23]   /usr/bin/rkhunter                               [ OK ]
[21:42:23]   /usr/bin/runcon                                 [ OK ]
[21:42:24]   /usr/bin/sed                                    [ OK ]
[21:42:24]   /usr/bin/sh                                     [ OK ]
[21:42:24]   /usr/bin/sha1sum                                [ OK ]
[21:42:24]   /usr/bin/sha224sum                              [ OK ]
[21:42:24]   /usr/bin/sha256sum                              [ OK ]
[21:42:25]   /usr/bin/sha384sum                              [ OK ]
[21:42:25]   /usr/bin/sha512sum                              [ OK ]
[21:42:25]   /usr/bin/size                                   [ OK ]
[21:42:25]   /usr/bin/sort                                   [ OK ]
[21:42:25]   /usr/bin/ssh                                    [ OK ]
[21:42:26]   /usr/bin/stat                                   [ OK ]
[21:42:26]   /usr/bin/strings                                [ OK ]
[21:42:26]   /usr/bin/su                                     [ OK ]
[21:42:26]   /usr/bin/sudo                                   [ OK ]
[21:42:26]   /usr/bin/tail                                   [ OK ]
[21:42:27]   /usr/bin/telnet                                 [ OK ]
[21:42:27]   /usr/bin/test                                   [ OK ]
[21:42:27]   /usr/bin/top                                    [ OK ]
[21:42:27]   /usr/bin/touch                                  [ OK ]
[21:42:27]   /usr/bin/tr                                     [ OK ]
[21:42:27]   /usr/bin/uname                                  [ OK ]
[21:42:28]   /usr/bin/uniq                                   [ OK ]
[21:42:28]   /usr/bin/users                                  [ OK ]
[21:42:28]   /usr/bin/vmstat                                 [ OK ]
[21:42:28]   /usr/bin/w                                      [ OK ]
[21:42:28]   /usr/bin/watch                                  [ OK ]
[21:42:28]   /usr/bin/wc                                     [ OK ]
[21:42:29]   /usr/bin/wget                                   [ OK ]
[21:42:29]   /usr/bin/whatis                                 [ OK ]
[21:42:29]   /usr/bin/whereis                                [ OK ]
[21:42:29]   /usr/bin/which                                  [ OK ]
[21:42:29] Info: Found file '/usr/bin/which': it is whitelisted for the 'script replacement' check.
[21:42:29]   /usr/bin/who                                    [ OK ]
[21:42:30]   /usr/bin/whoami                                 [ OK ]
[21:42:30]   /usr/bin/numfmt                                 [ OK ]
[21:42:30]   /usr/bin/kmod                                   [ OK ]
[21:42:30]   /usr/bin/systemd                                [ OK ]
[21:42:30]   /usr/bin/systemctl                              [ OK ]
[21:42:30]   /usr/bin/gawk                                   [ OK ]
[21:42:31]   /usr/bin/lwp-request                            [ Warning ]
[21:42:31] Warning: The command '/usr/bin/lwp-request' has been replaced by a script: /usr/bin/lwp-request: Perl script text executable
[21:42:31]   /usr/bin/locate.findutils                       [ OK ]
[21:42:31]   /usr/bin/bsd-mailx                              [ Warning ]
[21:42:31] Warning: The file '/usr/bin/bsd-mailx' exists on the system, but it is not present in the 'rkhunter.dat' file.
[21:42:31]   /usr/bin/dash                                   [ OK ]
[21:42:31]   /usr/bin/x86_64-linux-gnu-size                  [ OK ]
[21:42:31]   /usr/bin/x86_64-linux-gnu-strings               [ OK ]
[21:42:32]   /usr/bin/telnet.netkit                          [ OK ]
[21:42:38]   /usr/lib/systemd/systemd                        [ OK ]
[21:42:42]
 

Hors ligne

#2 30-07-2021 13:19:31

Debian Alain
Membre
Lieu : Bretagne
Distrib. : unstable sid / bullseye (stable)
Noyau : Linux sid 5.18.0-3-amd64
(G)UI : Gnome X.org (X11) / GDM3
Inscription : 11-03-2017
Site Web

Re : attaque bootkit uefi ACPI ?

tu as quoi comme distribution ? stretch ? buster ? bulseye ?

et comme bureau ? gnome ? kde ? xfce ? lxde ? lxqt ?

quel kernel ? 5.10.0-8 amd64 ?

Hors ligne

#3 30-07-2021 18:21:24

rodrigue7973
Membre
Lieu : beloeil
Distrib. : windows 11 pro
(G)UI : gnome
Inscription : 19-11-2017
Site Web

Re : attaque bootkit uefi ACPI ?

tu ne vas pas lire une ligne message : [21:41:51] Info: Found O/S name: Debian GNU/Linux 11 (bullseye)

Etant dyslexique, j'ai des problèmes quant à la rédaction de messages en français courant. Je vous prie dès lors d'accepter toutes mes excuses si mes interventions peuvent vous paraître étranges et je vous remercie d'avance pour votre compréhension.

Hors ligne

Pied de page des forums