Re: [OT] Rootkit queston

From: Mike Fedyk
Date: Mon Dec 01 2003 - 18:49:15 EST


On Tue, Dec 02, 2003 at 12:36:07AM +0100, M?ns Rullg?rd wrote:
> "Richard B. Johnson" <root@xxxxxxxxxxxxxxxxxx> writes:
>
> >> They seem to have PID 0, is this normal?
> >
> > Yes. These are kernel threads.
>
> That doesn't necessarily rule out the possibility of them being evil.
> If someone has taken control of the system, he could have loaded some
> module that started a thread disguising itself under a common name.

True, but it would make the thread invisible if they were going to do that...
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/