LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   Linux - Newbie (https://www.linuxquestions.org/questions/linux-newbie-8/)
-   -   chkrootkit warning (https://www.linuxquestions.org/questions/linux-newbie-8/chkrootkit-warning-756529/)

qwertyjjj 09-20-2009 04:40 AM

chkrootkit warning
 
I had the following come up in my daily chkrootkit.
Is this a problem or a false positive?

Code:

Checking `lkm'... You have    2 process hidden for readdir command
You have    2 process hidden for ps command
chkproc: Warning: Possible LKM Trojan installed
Checking `rexedcs'... not found
Checking `sniffer'... eth0: not promisc and no PF_PACKET sockets
eth0:0: not promisc and no PF_PACKET sockets


unSpawn 09-20-2009 09:51 AM

Go to LQ search (http://www.linuxquestions.org/questions/search.php), then
make Keywords read "Warning*Possible*LKM*Trojan*installed" (w/o quotes),
select Forum: Linux - Security,
Find Threads with Prefix: any,
Find Threads with Replies: at least 1,
Find Posts from: any date,
Show Results as: Posts
... and you'll find results back to as far as http://www.linuxquestions.org/questi...001#post662001, or http://www.linuxquestions.org/questi...39#post1941339 which also mentions reading the Chkrootkit FAQ regarding this issue. Sure you deserve a personal answer, sure it's easier to blindly ask again instead of having to search LQ for yourself but this question was asked many times before. Searching isn't that hard and makes things more efficient for all of us.

* IMHO there really shouldn't be any reason anymore for you to hang in /Newbie. You have over 300 posts by now.


All times are GMT -5. The time now is 08:43 PM.