Re: Chkrootkit - true/false ?

2004-05-22 Thread Donovan Baarda
On Sat, May 22, 2004 at 10:03:37AM +0800, Jason Lim wrote:
   Checking `lkm'... You have 3 process hidden for readdir command
   You have 3 process hidden for ps command
   Warning: Possible LKM Trojan installed
  
   Sometimes chkrootkit returns nothing detected and every time rkhunter
   tells me nothing is wrong. Is this a false positive with chkrootkit
 and
   debian woody?

chkrootkit on nearly anything occasionally gives this false positive.
I believe it is something to do with normal processes terminating or
spawning at the time chkrootkit is looking for hidden processes. Hence
the word Possible in its report.

If you run chkrootkit again, you will probably not see the message
again. If you repeatedly see that message every time you run
chkrootkit, then you can start panicing.


Donovan Baardahttp://minkirri.apana.org.au/~abo/



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Re: Chkrootkit - true/false ?

2004-05-22 Thread Andreas John
Donovan Baarda wrote:
On Sat, May 22, 2004 at 10:03:37AM +0800, Jason Lim wrote:
Checking `lkm'... You have 3 process hidden for readdir command
You have 3 process hidden for ps command
Warning: Possible LKM Trojan installed
If you run chkrootkit again, you will probably not see the message
again. If you repeatedly see that message every time you run
chkrootkit, then you can start panicing.
This is a known bug in ps command of debian. I don't know if the sid 
version is updated by now, but this particular lkm - 3 process problem 
*will* occur again.
chkrootkit gives often false positives, but this is no reason not look 
for a trojan. read the perl code to see what it checks. it's quite 
simple, it checks the existence of certain hidden directories, files or 
processes. try to invstigate, why they exist on your machine.

rgds,
j.

--
Andreas John
net-lab GmbH
Luisenstrasse 30b
63067 Offenbach
Tel: +49 69 85700331
http://www.net-lab.net
--
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]


Re: Chkrootkit - true/false ?

2004-05-22 Thread Donovan Baarda
On Sat, May 22, 2004 at 10:03:37AM +0800, Jason Lim wrote:
   Checking `lkm'... You have 3 process hidden for readdir command
   You have 3 process hidden for ps command
   Warning: Possible LKM Trojan installed
  
   Sometimes chkrootkit returns nothing detected and every time rkhunter
   tells me nothing is wrong. Is this a false positive with chkrootkit
 and
   debian woody?

chkrootkit on nearly anything occasionally gives this false positive.
I believe it is something to do with normal processes terminating or
spawning at the time chkrootkit is looking for hidden processes. Hence
the word Possible in its report.

If you run chkrootkit again, you will probably not see the message
again. If you repeatedly see that message every time you run
chkrootkit, then you can start panicing.


Donovan Baardahttp://minkirri.apana.org.au/~abo/





Re: Chkrootkit - true/false ?

2004-05-22 Thread Andreas John
Donovan Baarda wrote:
On Sat, May 22, 2004 at 10:03:37AM +0800, Jason Lim wrote:
Checking `lkm'... You have 3 process hidden for readdir command
You have 3 process hidden for ps command
Warning: Possible LKM Trojan installed
If you run chkrootkit again, you will probably not see the message
again. If you repeatedly see that message every time you run
chkrootkit, then you can start panicing.
This is a known bug in ps command of debian. I don't know if the sid 
version is updated by now, but this particular lkm - 3 process problem 
*will* occur again.
chkrootkit gives often false positives, but this is no reason not look 
for a trojan. read the perl code to see what it checks. it's quite 
simple, it checks the existence of certain hidden directories, files or 
processes. try to invstigate, why they exist on your machine.

rgds,
j.

--
Andreas John
net-lab GmbH
Luisenstrasse 30b
63067 Offenbach
Tel: +49 69 85700331
http://www.net-lab.net