jayjwa |
07-16-2006 09:14 AM |
/proc after 2.6.17.5
Umm...looks like they tightened up security a bit in /proc in 2.6.17.5 after the root race local exploit issue in <= 2.6.17.4 (this was actually 4 screens long, results of running "chkrootkit". As root.)
Code:
...
/proc/3/fd/.: Permission denied
/proc/3/fd/..: Permission denied
/proc/4/fd/.: Permission denied
/proc/4/fd/..: Permission denied
/proc/5/fd/.: Permission denied
/proc/5/fd/..: Permission denied
/proc/6/fd/.: Permission denied
/proc/6/fd/..: Permission denied
/proc/8/fd/.: Permission denied
/proc/8/fd/..: Permission denied
/proc/11/fd/.: Permission denied
/proc/11/fd/..: Permission denied
/proc/13/fd/.: Permission denied
/proc/13/fd/..: Permission denied
/proc/68/fd/.: Permission denied
/proc/68/fd/..: Permission denied
/proc/69/fd/.: Permission denied
/proc/69/fd/..: Permission denied
/proc/70/fd/.: Permission denied
/proc/70/fd/..: Permission denied
/proc/718/fd/.: Permission denied
/proc/718/fd/..: Permission denied
/proc/911/fd/.: Permission denied
/proc/911/fd/..: Permission denied
/proc/911/fd/0: Permission denied
/proc/911/fd/1: Permission denied
/proc/911/fd/2: Permission denied
/proc/911/fd/3: Permission denied
/proc/911/fd/4: Permission denied
/proc/915/fd/.: Permission denied
/proc/915/fd/..: Permission denied
/proc/915/fd/0: Permission denied
/proc/915/fd/1: Permission denied
/proc/915/fd/2: Permission denied
/proc/915/fd/3: Permission denied
/proc/915/fd/4: Permission denied
/proc/915/fd/5: Permission denied
/proc/915/fd/6: Permission denied
/proc/915/fd/7: Permission denied
/proc/915/fd/8: Permission denied
/proc/915/fd/9: Permission denied
/proc/915/fd/10: Permission denied
/proc/915/fd/11: Permission denied
/proc/924/fd/.: Permission denied
/proc/924/fd/..: Permission denied
/proc/924/fd/0: Permission denied
/proc/924/fd/1: Permission denied
/proc/924/fd/2: Permission denied
/proc/924/fd/3: Permission denied
/proc/926/fd/.: Permission denied
/proc/926/fd/..: Permission denied
/proc/926/fd/0: Permission denied
/proc/926/fd/1: Permission denied
/proc/926/fd/2: Permission denied
/proc/926/fd/3: Permission denied
/proc/926/fd/4: Permission denied
/proc/935/fd/.: Permission denied
/proc/935/fd/..: Permission denied
/proc/935/fd/0: Permission denied
/proc/935/fd/1: Permission denied
/proc/935/fd/2: Permission denied
/proc/935/fd/3: Permission denied
/proc/935/fd/4: Permission denied
/proc/949/fd/.: Permission denied
/proc/949/fd/..: Permission denied
/proc/949/fd/0: Permission denied
/proc/949/fd/1: Permission denied
/proc/949/fd/2: Permission denied
/proc/949/fd/3: Permission denied
/proc/949/fd/4: Permission denied
/proc/949/fd/6: Permission denied
/proc/1019/fd/.: Permission denied
/proc/1019/fd/..: Permission denied
/proc/1019/fd/0: Permission denied
/proc/1019/fd/1: Permission denied
/proc/1019/fd/2: Permission denied
...
other results:
Checking LKM... You have 15 process hidden for readdir command
You have 18 process hidden for ps command
chkproc: Warning: Possible LKM Trojan installed
I can see the forum subject lines now: "procs hidden, am I hacked? plz help!" ;)
I have a feeling this will break stuff...
|