Re: chkrootkit-0.34 report

From: Seth Arnold (sarnold@wirex.com)
Date: 10/30/01


Date: Tue, 30 Oct 2001 14:33:53 -0800
From: Seth Arnold <sarnold@wirex.com>
To: focus-linux@securityfocus.com
Subject: Re: chkrootkit-0.34 report
Message-ID: <20011030143353.A994@wirex.com>

On Mon, Oct 29, 2001 at 07:46:33PM -0800, Herbert Kwong wrote:
> I just used chkrootkit 0.34 to check my system. It
> reports the following message:
> Checking 'lkm'... You have 2 process hidden for ps
> command
> Warning: Possible LKM Trojan installed

Well, I've never used chkrootkit, but it has to get this information
somehow. If the rootkit author wasn't very bright, you will see the
extra processes in your /proc/ tree. (You could also try 'pstree',
'top', etc, if the rootkit author didn't change all process reporting
tools.)

If the rootkit author was smarter than the average bear, the only way I
can think of finding out is loading your own kernel module, designed to
print out all process information. Of course, a rootkit author could
prevent this from working too, though probably only in a fashion that
would prevent your module from loading at all..

Cheers!

-- 
The Bill of Rights: 7 out of 10 rights haven't been sold yet! Contact
your congressman for details how *you* can buy one today!



Relevant Pages

  • Re: process identification
    ... (found it with the chkrootkit, but the other one didn't saw it, thanks go ... > Your machines is probably compromised by script kiddies, who have installed a rootkit. ... to facilitate one-on-one interaction with one of our expert instructors. ... Attend a course taught by an expert instructor with years of in-the-field ...
    (Security-Basics)
  • Re: zkmem virus
    ... While it may remove the standard rootkit, it will not cope with the other ... backdoors left by an attacker who already got access to your system. ... I just ran chkrootkit and it found zk rootkit. ...
    (alt.linux)
  • Re: Can rootkits be installed without root permissions?
    ... I was reading some articles about Sony's XCP copy protection ... A rootkit is usually installed after gaining root, ... The README of chkrootkit, ...
    (comp.os.linux.misc)
  • RE: chkrootkit and 4.10-prerelease issues?
    ... whether chfn & chsh are infected against 4.9 MD5 Sums, ... and my nightly chkrootkit reports this on run. ... report as infected. ...
    (FreeBSD-Security)
  • Re: My machine compromised?
    ... > After reading on report of servers compromised. ... Just for curiorsity I ... > run chkrootkit on my own machine and come up with this result: ...
    (Debian-User)