Gentoo Archives: gentoo-user

From: "Hemmann
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] chkrootkit LKM trojan ?
Date: Sun, 16 Jul 2006 19:17:20
Message-Id: 200607162054.22874.volker.armin.hemmann@tu-clausthal.de
In Reply to: [gentoo-user] chkrootkit LKM trojan ? by Dave S
1 On Sunday 16 July 2006 20:25, Dave S wrote:
2 > HI, I have a potential security problem ...
3 >
4 > and err its not on gentoo, its on ubuntu but I am not getting any response
5 > there & you guys are the most tech bunch I know - Thought I would lay it
6 > on the table :)
7 >
8 > I just had an email from chkrootkit last night -
9 >
10 > ---
11 >
12 > The following suspicious files and directories were found:
13 >
14 > You have 3 process hidden for readdir command
15 > You have 3 process hidden for ps command
16 > chkproc: Warning: Possible LKM Trojan installed
17 >
18 > ---
19 >
20 > Running chkrootkit now and all is OK
21 >
22 > root@dave-comp:~#
23 > root@dave-comp:~# chkrootkit | grep chkproc
24 > Checking `lkm'... chkproc: nothing detected
25 > root@dave-comp:~#
26 >
27 > I have even 'sudo install --reinstall chkrootkit' in case its binarys have
28 > been modified (paranoid)
29
30 if you installed using the tools of the system, it could be worthless, because
31 compromised. Boot from a cd and check from the cd.
32 --
33 gentoo-user@g.o mailing list

Replies

Subject Author
Re: [gentoo-user] chkrootkit LKM trojan ? Dave S <gentoo@××××××××.net>