[clug] LKM Trojan problem solved
pearl.louis at anu.edu.au
Mon Mar 29 16:48:08 GMT 2004
After a lot of google searching, came across a link to the chkrootkit mailing
list archives. Apparently in January this year, the developers issued a
chkrootkit currently fails to recognize threads in Linux kernel 2.6 and
therefore warns about LKM. Attached patch fixes that problem: under 2.6
the threads are listed in /proc/$pid/task/$tpid.
Applied the patch to chkproc.c, recompiled, ran chkrootkit again and hey
presto, no complaints.
Thank god. I was worried about my evil xmms program running rampant in my
system :) Who knows what havoc it would have wrecked.
More information about the linux