D&C Lug - Home Page
Devon & Cornwall Linux Users' Group

[ Date Index ][ Thread Index ]
[ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] What Next?



On Mon, 26 May 2003, Michael Chidley wrote:
> I`ve been playing with `chkrootkit` on one on the LinuxFormat DVDs, i ran it
> and got the following output.....
>
> Checking `lkm'... You have     4 process hidden for ps command
> Warning: Possible LKM Trojan installed

How often have you run chkrootkit?
It checks the difference in the output of ps and the contents of somthing
under /proc . If a process has died in the interim, then the count will be
wrong.

I've had chkrootkit return a false positive to me on a few occasions,
mainly cause of a "suspicious" open port, when a quick netstat showed me
exactly what the program was on that port, and it was supposed to be
there.

HTH,
Mark.



--
The Mailing List for the Devon & Cornwall LUG
Mail majordomo@xxxxxxxxxxxx with "unsubscribe list" in the
message body to unsubscribe.


Lynx friendly