Gentoo Archives: gentoo-user

From: "Hemmann
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] chkrootkit LKM trojan ?
Date: Sun, 16 Jul 2006 20:42:15
Message-Id: 200607162233.06617.volker.armin.hemmann@tu-clausthal.de
In Reply to: Re: [gentoo-user] chkrootkit LKM trojan ? by Dave S
1 On Sunday 16 July 2006 21:54, Dave S wrote:
2 > On Sunday 16 July 2006 19:54, Hemmann, Volker Armin wrote:
3 > > On Sunday 16 July 2006 20:25, Dave S wrote:
4 > > > HI, I have a potential security problem ...
5 > > >
6 > > > and err its not on gentoo, its on ubuntu but I am not getting any
7 > > > response there & you guys are the most tech bunch I know - Thought I
8 > > > would lay it on the table :)
9 > > >
10 > > > I just had an email from chkrootkit last night -
11 > > >
12 > > > ---
13 > > >
14 > > > The following suspicious files and directories were found:
15 > > >
16 > > > You have 3 process hidden for readdir command
17 > > > You have 3 process hidden for ps command
18 > > > chkproc: Warning: Possible LKM Trojan installed
19 > > >
20 > > > ---
21 > > >
22 > > > Running chkrootkit now and all is OK
23 > > >
24 > > > root@dave-comp:~#
25 > > > root@dave-comp:~# chkrootkit | grep chkproc
26 > > > Checking `lkm'... chkproc: nothing detected
27 > > > root@dave-comp:~#
28 > > >
29 > > > I have even 'sudo install --reinstall chkrootkit' in case its binarys
30 > > > have been modified (paranoid)
31 > >
32 > > if you installed using the tools of the system, it could be worthless,
33 > > because compromised. Boot from a cd and check from the cd.
34 >
35 > I understand. Booted from knoppix 5.0.1, executed a
36 >
37 > 'chroot /mnt/hda1 chkrootkit' and a
38 > 'chroot /mnt/hda1 rkhunter -c'
39 >
40 > - both scans brought back nothing. From what I have read the chkrootkit &
41 > rkhunter binarys would have been from the CD and therefore untainted ? Am I
42 > correct ?
43 >
44
45 no, if you chroot, the binaries from the chroot are used.
46
47 use chkrootkit without chrooting - best with full path (/usr/sbin/chkrootkit)
48 --
49 gentoo-user@g.o mailing list