On Wed, 29 Jun 2005, Andrew Ruef wrote:
Took the system down to init 1 and checked it out for any signs of foul play, found none. No anomalous behavior in the logs, nothing weird that grsec reported. Nothing in the NIDS logs of the attached system..
Did you do an MD5 comparison between the 'ps' command on your box and a known good binary? That sounds like a trojaned ps binary or something amiss in the kernel.
But still... anyone else seen this behavior?
-- [email protected] mailing list
