[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: have I been rooted?

On Sat, 2003-03-15 at 06:04, David H. Clymer wrote:
> I just ran chkrootkit,and it at one point, indicates that I may have an
> LKM rootkit installed on my box (see output below). I then downloaded
> and installed sash, and when I run chkrootkit as sashroot, It doesnt
> detect anything (also see output below). Which should I believe? Is
> there any way to determine if there is indeed a LKM rootkit installed
> without downtime (or at least a minimum). This box serves as mailserver
> for approximatly 600 users, has no backup or secondary server (all very
> bad things, i know, but cash is very, very short) and is administered
> remotely, so and taking it down, wiping/reinstalling, is not an option
> at this point. 

I had a similar scare with chkrootkit when I first started using it. It
turns out that it can occasionally give "false positives". Something to
do with processes completing and vanishing in the middle of checking if
processes are trying to hide themselves.

This is documented somewhere... I did a google search and found
something which explained this behaviour.

ABO: finger abo@minkirri.apana.org.au for more info, including pgp key

Reply to: