C. L. Martinez
unread,Jul 28, 2018, 8:05:38 AM7/28/18Sign in to reply to author
Sign in to forward
You do not have permission to delete messages in this group
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to wa...@googlegroups.com
Hi all,
I am seeing a high increment of alerts about trojanized binaries in FreeBSD platforms, like for example:
Trojaned version of file '/bin/kill' detected. Signature used: '/dev/[ab,d-k,m-z]|/dev/[F-Z]|/dev/[A-D]|/dev/[0-9]|proc\.h|bash|tmp' (Generic).
It is a false positive, because this server was updated yesterday from official updates ... It is strange, because this only happens with FreeBSD servers and not with my OpenBSD servers ... Any to tip to debug this?
Thanks
--
Greetings,
C. L. Martinez