[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Possible LKM Trojan installed



On Fri, Aug 24, 2007 at 11:24:35AM -0400, John wrote:
> Today's run of chkrootkit produced the following ominous message:

[elided]

> Am I right in thinking the only thing to do is wipe the machine down
> to bare metal and reinstall?  I'm not sufficiently knowledgeable to do
> much forensic checking.

Chkrootkit has been un-updated (by the original maintainer, not by Debian)
for something like a year, and that's a well-known false positive.
-- 
Carl Fink                                   nitpicking@nitpicking.com 

Read my blog at nitpickingblog.blogspot.com.  Reviews!  Observations!
Stupid mistakes you can correct!



Reply to: