Re: Chkrootkit - true/false ?
On Sat, May 22, 2004 at 10:03:37AM +0800, Jason Lim wrote: Checking `lkm'... You have 3 process hidden for readdir command You have 3 process hidden for ps command Warning: Possible LKM Trojan installed Sometimes chkrootkit returns nothing detected and every time rkhunter tells me nothing is wrong. Is this a false positive with chkrootkit and debian woody? chkrootkit on nearly anything occasionally gives this false positive. I believe it is something to do with normal processes terminating or spawning at the time chkrootkit is looking for hidden processes. Hence the word Possible in its report. If you run chkrootkit again, you will probably not see the message again. If you repeatedly see that message every time you run chkrootkit, then you can start panicing. Donovan Baardahttp://minkirri.apana.org.au/~abo/ -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]
Re: Chkrootkit - true/false ?
Donovan Baarda wrote: On Sat, May 22, 2004 at 10:03:37AM +0800, Jason Lim wrote: Checking `lkm'... You have 3 process hidden for readdir command You have 3 process hidden for ps command Warning: Possible LKM Trojan installed If you run chkrootkit again, you will probably not see the message again. If you repeatedly see that message every time you run chkrootkit, then you can start panicing. This is a known bug in ps command of debian. I don't know if the sid version is updated by now, but this particular lkm - 3 process problem *will* occur again. chkrootkit gives often false positives, but this is no reason not look for a trojan. read the perl code to see what it checks. it's quite simple, it checks the existence of certain hidden directories, files or processes. try to invstigate, why they exist on your machine. rgds, j. -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]
Re: Chkrootkit - true/false ?
On Sat, May 22, 2004 at 10:03:37AM +0800, Jason Lim wrote: Checking `lkm'... You have 3 process hidden for readdir command You have 3 process hidden for ps command Warning: Possible LKM Trojan installed Sometimes chkrootkit returns nothing detected and every time rkhunter tells me nothing is wrong. Is this a false positive with chkrootkit and debian woody? chkrootkit on nearly anything occasionally gives this false positive. I believe it is something to do with normal processes terminating or spawning at the time chkrootkit is looking for hidden processes. Hence the word Possible in its report. If you run chkrootkit again, you will probably not see the message again. If you repeatedly see that message every time you run chkrootkit, then you can start panicing. Donovan Baardahttp://minkirri.apana.org.au/~abo/
Re: Chkrootkit - true/false ?
Donovan Baarda wrote: On Sat, May 22, 2004 at 10:03:37AM +0800, Jason Lim wrote: Checking `lkm'... You have 3 process hidden for readdir command You have 3 process hidden for ps command Warning: Possible LKM Trojan installed If you run chkrootkit again, you will probably not see the message again. If you repeatedly see that message every time you run chkrootkit, then you can start panicing. This is a known bug in ps command of debian. I don't know if the sid version is updated by now, but this particular lkm - 3 process problem *will* occur again. chkrootkit gives often false positives, but this is no reason not look for a trojan. read the perl code to see what it checks. it's quite simple, it checks the existence of certain hidden directories, files or processes. try to invstigate, why they exist on your machine. rgds, j. -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net