[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: chkrootkit detects hidden processes in mozilla-firefox and xmms

   > I'm not entirely sure whether this is normal behavior, a
   > symptom of possible badness, or simple user error.  I'm a bit
   > worried it might mean my  system has been compromised.  Any help
   > or explanation would be greatly appreciated.

     You might be interested in http://bugs.debian.org/222179. I
   wonder if there is a process with a pid of {4125,4126,4127} that
   have tasks with a pid of 4128 and 4129.

Thanks, that turns out to be the case.  Checking now I see all of the
"hidden" processes under /proc/N/task of the related process.

I had known about the [now-fixed, I think] bug in chkrootkit where it
thought ksoftirqd and a few other kernel things were suspicious, but
I didn't know about it getting confused by user things.

My blood pressure is down a lot now, thanks again!

Reply to: