RE: chkrootkit and lkm

2003-11-25 Thread Michael Bordignon
> I was just running 'chkrootkit' and came across this warning: > > > Checking `lkm'... You have 4 process hidden for ps command > > Warning: Possible LKM Trojan installed I have the same problem.. I believe it's a bug in chkrootkit Michael -- To UNSUBSCRIBE, email to [EMAIL PROTECTED]

RE: chkrootkit and lkm

2003-11-25 Thread Michael Bordignon
> I was just running 'chkrootkit' and came across this warning: > > > Checking `lkm'... You have 4 process hidden for ps command > > Warning: Possible LKM Trojan installed I have the same problem.. I believe it's a bug in chkrootkit Michael

RE: chkrootkit reporting processes hidden

2003-10-29 Thread Michael Bordignon
> two major choices: > > 1) leave it online recording ALL traffic to and from it > > 2) take it offline immediately and analyze it there without > remote interference I'm starting to think it was chkrootkit misreporting what was happening, as after I rebooted the machine, there are now a) no

RE: chkrootkit reporting processes hidden

2003-10-29 Thread Michael Bordignon
> two major choices: > > 1) leave it online recording ALL traffic to and from it > > 2) take it offline immediately and analyze it there without > remote interference I'm starting to think it was chkrootkit misreporting what was happening, as after I rebooted the machine, there are now a) no

chkrootkit reporting processes hidden

2003-10-29 Thread Michael Bordignon
hello, I have chkrootkit running nightly and mailing results to me - last night it reported this: Checking `lkm'... You have 1 process hidden for readdir command You have 1 process hidden for ps command Warning: Possible LKM Trojan installed Checking `sniffer'... PROMISC mode detected in

chkrootkit reporting processes hidden

2003-10-29 Thread Michael Bordignon
hello, I have chkrootkit running nightly and mailing results to me - last night it reported this: Checking `lkm'... You have 1 process hidden for readdir command You have 1 process hidden for ps command Warning: Possible LKM Trojan installed Checking `sniffer'... PROMISC mode detected in