Red Hat Bugzilla – Bug 80611
possible bug in procps-2.0.7-25.i386.rpm?
Last modified: 2007-04-18 12:49:21 EDT
Description of problem:
ps is accused of possibly being infected with the lkm worm by the latest
Version-Release number of selected component (if applicable):
Run the latest chkrootkit-0.38
Steps to Reproduce:
1. run chkrootkit-0.38.
2. look at things with kpm.
3. note kpm see's processes that ps -ea doesn't.
With gkrellm and mozilla-1.01 running, chkrootkits './chkproc -v -v'
will report 6 processes that are hidden by ps. One will be a 2nd copy of
gkrellm, and 5 will be mozilla children.
No hidden processes.
gnorpm's verify function says procps is exactly the same as the rpm installed it.
Reverting to the 7.3 supplied version of procps-2.0.7-12.i386.rpm apparently
If you read the release notes, you would notice that
ps hides threads of a single process by default, unless
you use the -m parameter (IIRC).
Yes, the pids hidden are the threads. Use -m to see them.