Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 24 Dec 2006 12:45:23 +1100
From:      Edwin Groothuis <edwin@mavetju.org>
To:        Matthew Herzog <matthew.herzog@gmail.com>
Cc:        freebsd-stable@freebsd.org
Subject:   Re: chkrootkit finds 94 process hidden for readdir
Message-ID:  <20061224014523.GB90165@k7.mavetju>
In-Reply-To: <7cf39bb60612231257p1a8a62c3g43a9da939306a59e@mail.gmail.com>
References:  <7cf39bb60612231257p1a8a62c3g43a9da939306a59e@mail.gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On Sat, Dec 23, 2006 at 03:57:35PM -0500, Matthew Herzog wrote:
> I run FreeBSD 6.1-RELEASE-p7 on an UltraSparc 5 machine.
> I ran chkrootkit yesterday and saw this:
> Checking `lkm'... You have    94 process hidden for readdir command
> chkproc: Warning: Possible LKM Trojan installed

I thought this was related to the time difference in "ps" and the
processing of the /proc directory.

Edwin

-- 
Edwin Groothuis      |            Personal website: http://www.mavetju.org
edwin@mavetju.org    |          Weblog: http://weblog.barnet.com.au/edwin/



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20061224014523.GB90165>