Gentoo Archives: gentoo-user

From: Dave S <gentoo@××××××××.net>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] chkrootkit LKM trojan ?
Date: Sun, 16 Jul 2006 20:04:05
Message-Id: 200607162054.18404.gentoo@pusspaws.net
In Reply to: Re: [gentoo-user] chkrootkit LKM trojan ? by "Hemmann
1 On Sunday 16 July 2006 19:54, Hemmann, Volker Armin wrote:
2 > On Sunday 16 July 2006 20:25, Dave S wrote:
3 > > HI, I have a potential security problem ...
4 > >
5 > > and err its not on gentoo, its on ubuntu but I am not getting any
6 > > response there & you guys are the most tech bunch I know - Thought I
7 > > would lay it on the table :)
8 > >
9 > > I just had an email from chkrootkit last night -
10 > >
11 > > ---
12 > >
13 > > The following suspicious files and directories were found:
14 > >
15 > > You have 3 process hidden for readdir command
16 > > You have 3 process hidden for ps command
17 > > chkproc: Warning: Possible LKM Trojan installed
18 > >
19 > > ---
20 > >
21 > > Running chkrootkit now and all is OK
22 > >
23 > > root@dave-comp:~#
24 > > root@dave-comp:~# chkrootkit | grep chkproc
25 > > Checking `lkm'... chkproc: nothing detected
26 > > root@dave-comp:~#
27 > >
28 > > I have even 'sudo install --reinstall chkrootkit' in case its binarys
29 > > have been modified (paranoid)
30 >
31 > if you installed using the tools of the system, it could be worthless,
32 > because compromised. Boot from a cd and check from the cd.
33
34 I understand. Booted from knoppix 5.0.1, executed a
35
36 'chroot /mnt/hda1 chkrootkit' and a
37 'chroot /mnt/hda1 rkhunter -c'
38
39 - both scans brought back nothing. From what I have read the chkrootkit &
40 rkhunter binarys would have been from the CD and therefore untainted ? Am I
41 correct ?
42
43 Are there any other checks I can do - re-installing the system is not my
44 preferred option :)
45
46 Dave
47
48
49
50
51 --
52 gentoo-user@g.o mailing list

Replies

Subject Author
Re: [gentoo-user] chkrootkit LKM trojan ? "Hemmann
Re: [gentoo-user] chkrootkit LKM trojan ? "Hemmann
[gentoo-user] Re: chkrootkit LKM trojan ? dnlt0hn5ntzhbqkv51 <dnlt0hn5ntzhbqkv51@×××××××××.net>
Re: [gentoo-user] chkrootkit LKM trojan ? Jerry McBride <mcbrides9@×××××××.net>