Bug 91214 - creates /proc entries not available to ' ps -aux '
Summary: creates /proc entries not available to ' ps -aux '
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Linux
Classification: Retired
Component: bind
Version: 9
Hardware: i686
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Daniel Walsh
QA Contact: Ben Levenson
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2003-05-20 00:01 UTC by Need Real Name
Modified: 2007-04-18 16:53 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2003-08-12 00:01:48 UTC
Embargoed:


Attachments (Terms of Use)

Description Need Real Name 2003-05-20 00:01:04 UTC
From Bugzilla Helper:
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 
1.0.3705; .NET CLR 1.1.4322)

Description of problem:
Booting in run level 3 with 'named' on, adds 3 entries to the /proc directory. 
These processes are not visible when using the 'ps -aux' commands. 
Using chkrootkit it verifies the existence of the unlisted processes.
Trying to cd into these directories, they change location making it impossible 
for further investigation. 
This happens on a machine NEVER loaded onto any network.


Version-Release number of selected component (if applicable):
bind-9.2.1-16

How reproducible:
Always

Steps to Reproduce:
1.Rebuilt new machines x5, fully patch and 'chkrootkit'
2.Complete new setup - and machine never added to a network, fully patched, 
manual check and 'chkrootkit'
3.Change hardware (within i686) and replicated with all the same tests
    

Actual Results:  Always the same result...3 hidden processes that the process 
manger will not see.
'chkrootkit' views it as a possible lkm

Expected Results:  All process should be registered with the process manager

Additional info:

Each and every time the machine is fully patched.
RH9 - 2.4.20-13.9

Comment 1 Need Real Name 2003-08-12 00:01:48 UTC
fixed in recent kernel patch.


Note You need to log in before you can comment on or make changes to this bug.