Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 26 Dec 2006 22:44:51 -0500
From:      Kris Kennaway <kris@obsecurity.org>
To:        Matthew Herzog <matthew.herzog@gmail.com>
Cc:        freebsd-stable@freebsd.org
Subject:   Re: chkrootkit finds 94 process hidden for readdir
Message-ID:  <20061227034451.GA9859@xor.obsecurity.org>
In-Reply-To: <7cf39bb60612231257p1a8a62c3g43a9da939306a59e@mail.gmail.com>
References:  <7cf39bb60612231257p1a8a62c3g43a9da939306a59e@mail.gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help

--envbJBWh7q8WU6mo
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Sat, Dec 23, 2006 at 03:57:35PM -0500, Matthew Herzog wrote:
> Hello.
>=20
> I run FreeBSD 6.1-RELEASE-p7 on an UltraSparc 5 machine.
>=20
> I ran chkrootkit yesterday and saw this:
>=20
> Checking `lkm'... You have    94 process hidden for readdir command
> chkproc: Warning: Possible LKM Trojan installed
>=20
> Everything else was deemed clean by chkrootkit.
>=20
> When I booted into single user mode and ran chkrootkit it said there were
> "33 process hidden for readdir command"
>=20
> The sha256 checksum is slightly different for the /usr/bin/su binary
> on the install
> media compared to the /usr/bin/su on the running install.
>=20
> I could find nothing definitive on this subject posted online so . . . .

Most likely this is just another false positive with this inherently
unreliable problem.

Kris

--envbJBWh7q8WU6mo
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (FreeBSD)

iD8DBQFFkewzWry0BWjoQKURAqe7AJ9C7iaDBT3o0iY8T6kiRg8rwJ3gwACcDIP4
b5ogf7Kzu7Sp8/B5wWaqk8w=
=2UZg
-----END PGP SIGNATURE-----

--envbJBWh7q8WU6mo--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20061227034451.GA9859>