Re: chkrootkit V. 0.47

2007-11-28 Thread Luiz Eduardo Roncato Cordeiro
Hi, On Wednesday, 28 de November de 2007, Robert Watson > wrote: > On Tue, 20 Nov 2007, JP wrote: > > > --and-- > > Checking `lkm'... You have 131 process hidden for readdir command > > chkproc: Warning: Possible LKM Trojan installed > > I wonder if it's trying to use procfs, which isn't mount

Re: chkrootkit V. 0.47

2007-11-28 Thread Robert Watson
On Tue, 20 Nov 2007, JP wrote: --and-- Checking `lkm'... You have 131 process hidden for readdir command chkproc: Warning: Possible LKM Trojan installed I wonder if it's trying to use procfs, which isn't mounted by default in FreeBSD, and as a result reporting that /proc is empty (which is

Re: chkrootkit V. 0.47

2007-11-21 Thread Peter Pentchev
On Tue, Nov 20, 2007 at 07:01:20PM +0200, Nikolay Pavlov wrote: > On Tuesday 20 November 2007 16:41:52 JP wrote: > > Running freeBSD 6.1 > > > > After changing chkrootkit to the latest version V. 0.47 and compiling it > > then running it I get the following: [snip] > > Checking `bindshell'... INFEC

Re: chkrootkit V. 0.47

2007-11-20 Thread Nikolay Pavlov
On Tuesday 20 November 2007 16:41:52 JP wrote: > Running freeBSD 6.1 > > After changing chkrootkit to the latest version V. 0.47 and compiling it > then running it I get the following: > > == > Searching for anomalies in shell history files... nothing found > Checkin