LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-13-2004, 05:18 PM   #1
provkitir
Member
 
Registered: Jul 2004
Location: Mass
Distribution: Freebsd 5.3, Debian sid 2.6.7
Posts: 101

Rep: Reputation: 15
chkrootkit warning of lkm trojan


hi

i run a debian sarge with kernel 2.6.7, tightly firewalled with firestarter, softwares mostly apt-got except for a maybe-questionable maple 9 for linux , and recently installed chkrootkit to check the integrity of my box. everything was fine except a warning that read:

Checking `lkm'... You have 7 process hidden for readdir command
You have 7 process hidden for ps command
Warning: Possible LKM Trojan installed

okay, first of all, could someone enlighten me with how to see what hidden processes are goin on and how to get rid of them? i checked 'memstat' and nothing out of the ordinary was there. second of all, how bad are lkm trojans if one do have them? third and last, is it possible to get rid of lkm trojans, if so, how?

thanks. the whole reason i threw my m$ out the window was because of viruses, i don't want to deal with any kind of unclean box. ps, i'm also somewhat pushed for space.. so i'd really prefer to not install anything [runnin out of harddrive]

thanks a bunch!
 
Old 10-13-2004, 06:00 PM   #2
jschiwal
LQ Guru
 
Registered: Aug 2001
Location: Fargo, ND
Distribution: SuSE AMD64
Posts: 15,733

Rep: Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682
Here is a message from someone with the same surprise.
http://www.webservertalk.com/archive...-9-390056.html

A couple of the responces:

ROOTDIR is `/'
Checking `lkm'... You have 4 process hidden for ps command
Warning: Possible LKM Trojan installed
[root@spare chkrootkit-0.44]# ./chkproc -v
PID 1250: not in ps output
PID 1251: not in ps output
PID 1252: not in ps output
PID 1253: not in ps output
You have 4 process hidden for ps command

and then given the PID numbers
cd /proc/1250/ && cat cmdline
And get an idea of at least what the program says it is.

Another poster suggested that the 'clamav' program will cause this false
alarm.
Perhaps you could (after disconnected from the netork) stop the clamav program ( disable service? ) and reboot and then run the chkrootkit again.

Also, google for information on the LKM Trojan to find out how to detect it manually.

Does debian have the equivalent of rpm --verify --package <PACKAGE_FILE> command to verify whether or not files have been changed?
your files against the source packages. Verifying the coreutills

--

p.s. Here is a webpage article on checking for root kits by scanning ports and using chkrootkit.
http://www.start-linux.com/articles/article_91.php

Last edited by jschiwal; 10-13-2004 at 06:08 PM.
 
Old 10-13-2004, 06:03 PM   #3
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Run the chkrootkit helper app: chkproc -v

That should give you a list of the hidden processes ID numbers. You can then look them up in /proc by their PID number.

False positives are not uncommon in chkrootkit. If a short-lived process terminates between the output of ps can be compared to /proc then it will report a hidden process.

That being said, if you actually do have an lkm rootkit installed, then you'll have to wipe the system, do a full reformat and reinstall from trusted media. You should also consider any other OS's on that system to be compromised as well. Once your system's security has been compromised, it can be extremely difficult to identify any other changes to the system (ie hidden backdoors, added users, secondary rootkits etc), so re-installing is the only real option.
 
Old 10-13-2004, 06:39 PM   #4
provkitir
Member
 
Registered: Jul 2004
Location: Mass
Distribution: Freebsd 5.3, Debian sid 2.6.7
Posts: 101

Original Poster
Rep: Reputation: 15
thank you very much!

i found out that those were just firefox locales. so there's no worries
thanks again!
 
Old 10-14-2004, 02:38 AM   #5
dimgr
Member
 
Registered: Jun 2004
Posts: 92

Rep: Reputation: 15
it is a bug
use rkhunter instead
 
Old 10-20-2004, 06:17 AM   #6
grey_moon
LQ Newbie
 
Registered: Oct 2004
Posts: 1

Rep: Reputation: 0
Make sure you have the latest version of chkrootkit or it will spit out false positives...
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Possible LKM Trojan installed gnjohn Linux - Security 1 03-14-2005 10:37 PM
possible LKM trojan installed? PennyroyalFrog Linux - Security 15 01-07-2005 01:28 AM
LKM trojan? help! synaptical Linux - Security 3 03-07-2004 07:16 AM
lkm trojan nullpt Linux - Security 3 12-26-2003 06:42 PM
lkm trojan nullpt *BSD 3 12-25-2003 12:09 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:39 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration