-
Notifications
You must be signed in to change notification settings - Fork 1.1k
Closed
Description
Hi,
I have been receiving the following alert:
Host-based anomaly detection event (rootcheck).
Trojaned version of file '/bin/grep' detected. Signature used: 'bash|givemer|/dev/' (Generic).
I have tested in the server the following command:
strings /bin/grep | grep -E 'bash|givemer|/dev/'
With the result:
/dev/null
I have been looking around worried that may be a hack but so far chkrootkit and other tests doesn't show this positive.
I was wondering if this may be a false positive from ossec side.
Thanks in advance!
Metadata
Metadata
Assignees
Labels
No labels