Re: My machine compromised?

From: Joerg Johannes (liste_joerg_at_gmx.de)
Date: 12/03/03

  • Next message: Tom: "Re: [OT] Slashdot and media accuracy (was Re: Improved Debian Project Emergency Communications)"
    To: debian-user@lists.debian.org
    Date: Wed, 03 Dec 2003 10:32:31 +0100
    
    
    

    Am Mi, den 03.12.2003 schrieb Vanh Phom um 10:03:
    > Hi folk,
    > After reading on report of servers compromised. Just for curiorsity I
    > run chkrootkit on my own machine and come up with this result:
    >
    > Searching for anomalies in shell history files... nothing found
    > Checking `asp'... not infected
    > Checking `bindshell'... not infected
    > Checking `lkm'... You have 12 process hidden for readdir command
    > You have 12 process hidden for ps command
    > Warning: Possible LKM Trojan installed
    > Checking `rexedcs'... not found
    > Checking `sniffer'...
    > eth0: PROMISC
    >
    > Is my machine compromised? How to fix this?

    Did you read /usr/share/doc/chkrootkit/README.Debian ? No you didn't.

    noflushd: A running noflushd and a 2.2 kernel may cause chkrootkit to
    warn
      about the presence of lkm.
      On 2.4.20: noflushd may trigger lkm warnings as well. --paolo

    lkm: In general, any process starting at around same time as lkm test
    may
      trigger a warning. Just try
      while true;do chkrootkit lkm;sleep 1;done
      during normal system use. See also FAQ 6 on www.chkrootkit.org r--
    paolo

    > Vanh

    joerg

    -- 
    Gib GATES keine Chance!
    
    

    -- 
    To UNSUBSCRIBE, email to debian-user-request@lists.debian.org 
    with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
    


  • Next message: Tom: "Re: [OT] Slashdot and media accuracy (was Re: Improved Debian Project Emergency Communications)"

    Relevant Pages

    • Re: Is this LKM Trojan?
      ... > chkproc: Warning: Possible LKM Trojan installed ... when I looked at my router's security log half an hour ... If I run chkrootkit -x lkm I get: ...
      (uk.comp.os.linux)
    • Mdk10 Official false chkrootkit alarm?
      ... Just today a chkrootkit warning came to my attention: ... "Searching for Showtee... ...
      (comp.os.linux.security)
    • Re: chkrootkit.0.41 problem
      ... the latest version of chkrootkit. ... instruction you are suggesting, I include the code I modified so you ... Warning: Possible LKM Trojan installed ...
      (comp.os.linux.security)
    • Re: chkroot warning
      ... Thanks for all the replies, I did a chkrootkit -x lkm as was suggested in ... I don't know why nscd is running. ... > This is from the Mandrake list, but it also pertains to the lkm trojan, ...
      (comp.os.linux.security)
    • Re: chkrootkit.0.41 problem
      ... > 2.4.20 from CD and I run chkrootkit. ... > Everything seems ok except for this strange error: ... Do a search for "Warning: ... Registered with The Linux Counter. ...
      (comp.os.linux.security)