Replies: 3 comments 2 replies
-
|
Hi, thank you very much for pointing this out and for taking the time to investigate what was happening. |
Beta Was this translation helpful? Give feedback.
-
|
just wanted to note this is still happening |
Beta Was this translation helpful? Give feedback.
-
|
I just released the new Beta 1.2.1.1 version, which changes the way the service is mounted and deployed. The /tmp/... is no longer there. This way, it will no longer be detected as a false positive. |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Hi @MacRimi,
First — thank you for the tool! The terminal menu is excellent.
The web monitor part however triggers high-severity rootkit alerts on my security scanner (Wazuh rule 521, rkhunter, chkrootkit, etc.) because it extracts the AppImage into a hidden
/tmp/.mount_XXXXXXXXdirectory that is intentionally concealed fromlstat()and normal readdir scans — the exact same behavior that real kernel-level rootkits use.I had a scare this morning from this alert and grok made things worse. Lol
I came to the conclusion after a lot of scans and AI help it was false positive so I disabled it for now until I find a way to suppress the wazuh alerts.
This is the alert I got.
Beta Was this translation helpful? Give feedback.
All reactions