[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: chkrootkit has me worried!



and..

:/usr/local/sbin# /usr/lib/chkrootkit/chkproc -v
PID     4: not in ps output
PID  1769: not in ps output
PID 15688: not in ps output
PID 15690: not in ps output
PID 17760: not in ps output
PID 17762: not in ps output
PID 21583: not in ps output
PID 21585: not in ps output
PID 21919: not in ps output
PID 21921: not in ps output
PID 23002: not in readdir output
PID 23002: not in ps output
PID 23085: not in readdir output
PID 23085: not in ps output
PID 23105: not in readdir output
PID 23105: not in ps output
You have     3 process hidden for readdir command
You have    13 process hidden for ps command



and....

freeway:~# cd /proc/1769/fd
freeway:/proc/1769/fd# ls -l
total 0
lrwx------   1 root     root           64 Nov 29 05:11 0 -> /dev/null
lrwx------   1 root     root           64 Nov 29 05:11 1 -> /dev/null
lrwx------   1 root     root           64 Nov 29 05:11 2 -> /dev/null
lrwx------   1 root     root           64 Nov 29 05:11 3 -> socket:[300]
freeway:/proc/1769/fd# grep 300 /proc/net/udp
freeway:/proc/1769/fd# grep 300 /proc/net/tcp
  26: 00000000:0016 00000000:0000 0A 00000000:00000000 00:00000000 00000000    
0        0 300
freeway:/proc/1769/fd


:/



Reply to: