Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: chkrootkit and LKM?

From: Guille -bisho- <bisho(at)onirica.com>
Date: Tue Jun 17 2003 - 01:15:34 EDT

> I using a RHL9 as my workstation. A few days ago I downloaded chkrootkit

You should reinstall. init is usually reemplaced with a infected one that inserts the rootkit module in the kernel, and the same with many other programs.

If you have the same OS version in another machine you could check the md5sum of all the binaries, and reemplace them from the clean machine, booting from an uninfected source like a CD or in another machine installing without booting from it the infected hard disc.

Anyway, I would never trust that machine anymore. I recomend to backup only the data and reinstall the OS.

-- 
bisho!  _        -=] 17/06/2003 [=-
    _ ^(   )       _
   (  (   )  )     \ \___,,,
  (        )        / _____ >-
    ( :: )       >==-
  '. |::| ,  >==-
    \\:://  [ PAZ SI, GUERRA NO ]



----------------------------------------------------------------------------
Attend the Black Hat Briefings & Training, July 28 - 31 in Las Vegas, the 
world's premier technical IT security event! 10 tracks, 15 training sessions, 
1,800 delegates from 30 nations including all of the top experts, from CSO's to 
"underground" security specialists.  See for yourself what the buzz is about!  
Early-bird registration ends July 3.  This event will sell out. www.blackhat.com
----------------------------------------------------------------------------
Received on Tue Jun 17 21:01:38 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:09 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library