Re: chkrootkit and LKM?

From: Ali-Reza Anghaie (ali_at_packetknife.com)
Date: 06/17/03

  • Next message: L Whiteside: "Wierd Profile in Document Settings"
    To: incidents@securityfocus.com
    Date: Mon, 16 Jun 2003 21:26:42 -0400
    
    
    

    On Monday 16 June 2003 10:59, Janus N. wrote:
    > I using a RHL9 as my workstation. A few days ago I downloaded chkrootkit
    > and it consistently gives the same output (>20 hidden processes) when
    > checking for LKM rootkit:
    >
    > Checking `lkm'... You have 38 process hidden for readdir command
    > Warning: Possible LKM Trojan installed
    >
    > This is even after reboots. How can I check if this is actually the work
    > of the LKM? Or any other rootkit for that matter?

    What does "chkrootkit -x lkm" return? If anything...

    If it shows PIDs you'll want to hunt through /proc manually for those
    processes.

    Cheers, -Ali

    -- 
    OpenPGP Key: 030E44E6
    --
    Was I helpful?:  http://svcs.affero.net/rm.php?r=packetknife
    --
    War is evil, but it is often the lesser evil. -- George Orwell
    
    



  • Next message: L Whiteside: "Wierd Profile in Document Settings"

    Relevant Pages

    • chkrootkit and LKM?
      ... and it consistently gives the same output (>20 hidden processes) when ... checking for LKM rootkit: ... Warning: Possible LKM Trojan installed ... world's premier technical IT security event! ...
      (Incidents)
    • Re: Help, my machine has been hacked
      ... >>> Yes, it protects you only from changed ps binary, but OP said, that ... >>> anything was not detected by chkrootkit (so any hidden processes ... > I thought about following situation: chkrootkit isn't complaining about ... Not if the LKM is filtering what ...
      (comp.os.linux.security)