Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
possible lkm trojan only while doing emerge
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
PennyroyalFrog
Apprentice
Apprentice


Joined: 07 Oct 2004
Posts: 194

PostPosted: Tue Jan 04, 2005 11:59 pm    Post subject: possible lkm trojan only while doing emerge Reply with quote

If i run chkrootkit while doing an emerge i get the following:

Code:
Checking `lkm'... You have     3 process hidden for ps command
Warning: Possible LKM Trojan installed


If i run chkrootkit while not doing an emerge then i don't get any warning. even stranger is that sometimes the amount of hidden processes varies. but it's always/onlly at 0 when i'm NOT doing an emerge... could someone shed some light on this? thanks.
Back to top
View user's profile Send private message
ToeiRei
Veteran
Veteran


Joined: 03 Jan 2005
Posts: 1191
Location: Austria

PostPosted: Wed Jan 05, 2005 12:16 am    Post subject: Reply with quote

I do not know chkrootkit... I use rkhunter but maybe it complains about child processes?

Rei
_________________
Please stand by - The mailer daemon is busy burning your messages in hell...
Back to top
View user's profile Send private message
Mythos
l33t
l33t


Joined: 02 May 2004
Posts: 953
Location: Portugal

PostPosted: Wed Jan 05, 2005 12:24 am    Post subject: Reply with quote

rkhunter excelent tool :)
_________________
Best Regards,
Sérgio Henrique
Linux dune 3.0.6-gentoo #1 SMP Thu Oct 27 16:47:29 WEST 2011 x86_64 Intel(R) Core(TM)2 Duo CPU T7500 @ 2.20GHz GenuineIntel GNU/Linux
Back to top
View user's profile Send private message
ToeiRei
Veteran
Veteran


Joined: 03 Jan 2005
Posts: 1191
Location: Austria

PostPosted: Wed Jan 05, 2005 12:29 am    Post subject: Reply with quote

yeah- but the update mirrors are not the best

for being really sure to have a clean system I would checksum the whole system (tripwire / aide ....) </paranoia>

Rei
_________________
Please stand by - The mailer daemon is busy burning your messages in hell...
Back to top
View user's profile Send private message
speed_bump
Tux's lil' helper
Tux's lil' helper


Joined: 10 Jan 2004
Posts: 92
Location: Wisconsin, USA

PostPosted: Wed Jan 05, 2005 12:52 am    Post subject: Reply with quote

There's most likely no LKM. Basically, to detect this scenario chkrootkit gathers ps output and then traverses the /proc directory looking for discrepancies. This means that you have two static pictures of the system taken at two different points in time. In many cases, this will be just fine. However, if you have a system where lots of processes are being created and destroyed very quickly (eg you're compiling lots of packages) those two snapshots may well disagree.

Unless you have other evidence to suggest a compromise, I'd leave it at that.
Back to top
View user's profile Send private message
PennyroyalFrog
Apprentice
Apprentice


Joined: 07 Oct 2004
Posts: 194

PostPosted: Wed Jan 05, 2005 12:54 am    Post subject: Reply with quote

thanks for the replies, i also tried rkhunter with no 'positives'. everything returned back normal.
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum