chkrootkit output

Matthew Miller mattdm at mattdm.org
Tue May 31 16:44:30 UTC 2005


On Tue, May 31, 2005 at 05:42:00PM +0100, Andy Green wrote:
> | Checking `chkutmp'...  The tty of the following user process(es) were
> not found
> |  in /var/run/utmp !
> | ! RUID          PID TTY    CMD
> | ! root         4674 tty1   /sbin/mingetty tty1
> Either we are both hacked the same way ;-) or it means chrootkit has
> identified something that is a normal situation on our Fedora machines.

Looks like chkutmp is new in version 0.45, and is being overly aggressive.
This looks like a bug to me; I think it should be reported upstream at
<http://www.chkrootkit.org/>.

-- 
Matthew Miller           mattdm at mattdm.org        <http://www.mattdm.org/>
Boston University Linux      ------>                <http://linux.bu.edu/>
Current office temperature: 79 degrees Fahrenheit.




More information about the users mailing list