[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: chkrootkit and lkm



On Tue, Nov 25, 2003 at 12:18:35PM -0800, Johannes Graumann wrote:
> Hello,
> 
> This is a testing/unstable system.
> 
> I was just running 'chkrootkit' and came across this warning:
> 
> > Checking `lkm'... You have     4 process hidden for ps command
> > Warning: Possible LKM Trojan installed
> 
(...)
> 
> Any comment is highly appreciated.

This is known bug in chkrootkit, it does not understand processes with pid 
'0' (kernel threads) which are not listed under /proc and emits this 
"alert".

As a matter of fact it was reported previous to the compromise. Please
check the following bugs for more information:

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=217278
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=217278

HTH

Javi

Attachment: signature.asc
Description: Digital signature


Reply to: