Re: chkrootkit V. 0.47
- From: Robert Watson <rwatson@xxxxxxxxxxx>
- Date: Wed, 28 Nov 2007 11:45:28 +0000 (GMT)
On Tue, 20 Nov 2007, JP wrote:
--and--
Checking `lkm'... You have 131 process hidden for readdir command
chkproc: Warning: Possible LKM Trojan installed
I wonder if it's trying to use procfs, which isn't mounted by default in FreeBSD, and as a result reporting that /proc is empty (which is expected). You could try mounting procfs and see if the message goes away, which would answer the question -- however, we don't generaly advise mounting procfs unless it is required, as it is a deprecated feature.
Robert N M Watson
Computer Laboratory
University of Cambridge
_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"
- Follow-Ups:
- Re: chkrootkit V. 0.47
- From: Luiz Eduardo Roncato Cordeiro
- Re: chkrootkit V. 0.47
- References:
- chkrootkit V. 0.47
- From: JP
- chkrootkit V. 0.47
- Prev by Date: Re: IPSEC help
- Next by Date: Re: chkrootkit V. 0.47
- Previous by thread: Re: chkrootkit V. 0.47
- Next by thread: Re: chkrootkit V. 0.47
- Index(es):
Relevant Pages
|
|