Re: LKM Trojan installed

From: Dragos Ruiu (dr@kyx.net)
Date: 02/08/03

  • Next message: Richard Dicaire: "Re: IPTables stops logging after long uptime"
    From: Dragos Ruiu <dr@kyx.net>
    To: Cal Peake <bugtraq@absolutedigital.net>, "Rivanor P. Soares" <rivanor@bol.com.br>
    Date: Sat, 8 Feb 2003 11:33:36 +0000
    
    

    On February 8, 2003 12:27 am, Cal Peake wrote:
    > > While running 'chkrootkit' at my box (RH 7.3) I saw the following:
    > >
    > > Checking `lkm'... You have 69 process hidden for ps command
    > > Warning: Possible LKM Trojan installed
    > >
    > > Could this be *true* ? How can I discover it?
    >
    > Rivanor,
    >
    > I know that RH patches their ps command to hide threads. If you're running
    > a multi-threaded process (such as coldfusion) it very well could be why
    > you're getting this warning.

    _process_ threads

    -- 
    dr@kyx.net   pgp: http://dragos.com/ kyxpgp
    http://cansecwest.com
    


    Relevant Pages

    • Re: [PATCH] Remove pointless <0 comparison for unsigned variable in fs/fcntl.c
      ... The warning is sometimes useful, but when it comes to a construct like ... that the range of a type is smaller on one architecture than another. ... IOW, a lot of the gcc warnings are just not valid, and trying to shut gcc ... It's not even that I will drop the patches, ...
      (Linux-Kernel)
    • Re: [patch] 0/4 Support for Toshiba TMIO multifunction devices
      ... About patches their self... ... WARNING: line over 80 characters ... Russell King will probably point to linux-arm-kernel etiquette article ...
      (Linux-Kernel)
    • Re: LKM Trojan installed
      ... On Fri, 07 Feb 2003, Rivanor P. Soares wrote: ... You have 69 process hidden for ps command ... Warning: Possible LKM Trojan installed ...
      (Focus-Linux)
    • Re: lsass.exe
      ... a firewall would prevent either worm. ... > keep up to date with the patches? ... >>warning and than restarted. ... >>researching it online from my other computer, ...
      (microsoft.public.scripting.virus.discussion)
    • Re: Help needed to fix section mismatch warnings
      ... the whitelisted names in modpost. ... I have patches for the ones ... This has a build warning with my toolchain: ... but otherwise no section mismatch warning. ...
      (Linux-Kernel)