[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Chkrootkit - true/false ?



yeah. i think there are some bug reports on chkrootkit / woody. if you run it again right after, you shouldn't get the message again. (i personally prefer rkhunter) :)

http://tinyurl.com/3fddn

~august

David Ross wrote:
Hi
I have rkhunter and chkrootkit running in a cron job every morning and
every now and again I get chkrootkit results like this:

Checking `lkm'... You have     3 process hidden for ps command
Warning: Possible LKM Trojan installed

And sometimes this:

Checking `lkm'... You have     3 process hidden for readdir command
You have     3 process hidden for ps command
Warning: Possible LKM Trojan installed

Sometimes chkrootkit returns nothing detected and every time rkhunter
tells me nothing is wrong. Is this a false positive with chkrootkit and
debian woody?

Dave




Reply to: