Google vs. the script kiddies
2005-07-17 12:47 pmThe
chkrootkit program often gives false positives of the form "Possible LKM trojan detected". It's looking for discrepancies between what ps tells it and what it can find in /proc; these can happen if one or more processes start and/or end between the two tests. That, in turn, can happen if (for example) you're serving a lot of pages from Apache. Um, right.