Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Fri, 1 May 2020 23:31:26 +0300
From: Nikolay Zorin <zorin@...mel.ru>
To: lkrg-users@...ts.openwall.com
Subject: fake alert (?)

Hello!

I integred LKRG into kernel (not a external module (*.ko)) 0.7 (release) 
- work, but constantly (every 15 sec) writes alerts:
May  1 05:50:33 auto kernel: [  862.594157] [p_lkrg] ALERT !!! _RODATA 
MEMORY BLOCK HASH IS DIFFERENT - it is [0x8c6073d11381f2f1] and should 
be [0x117e94a7b467f213] !!!
May  1 05:50:33 auto kernel: [  862.594157] [p_lkrg] ALERT !!! SYSTEM 
HAS BEEN COMPROMISED - DETECTED DIFFERENT 1 CHECKSUMS !!!

I expanded output:
May  1 12:40:21 auto kernel: [   92.284458] [p_lkrg] ALERT !!! _RODATA 
MEMORY BLOCK HASH IS DIFFERENT - it is [0x3c5d2385a7efe483] and should 
be [0xe437fa03a2808bea] !!!
May  1 12:40:21 auto kernel: [   92.284458] module name (from 'list 
array') - snd_hda_codec_generic
May  1 12:40:21 auto kernel: [   92.284458] module name (from 'kobj 
array'-floppy)
May  1 12:40:21 auto kernel: [   77.180260] [p_lkrg] ALERT !!! SYSTEM 
HAS BEEN COMPROMISED - DETECTED DIFFERENT 1 CHECKSUMS !!!


I unload 'floppy', but message not stop:May  1 12:52:26 auto kernel: [  
817.276319] [p_lkrg] ALERT !!! _RODATA MEMORY BLOCK HASH IS DIFFERENT - 
it is [0x3c5d2385a7efe483] and should be [0xe437fa03a2808bea] !!!
May  1 12:52:26 auto kernel: [  817.276319] module name (from 'list 
array') - snd_hda_codec_generic
May  1 12:52:26 auto kernel: [  817.276319] module name (from 'kobj 
array'-virtio)

If I integrated last version from 'git' (non experimental), then system 
not start and not output messages..

my system (virtual, KVM based CentOS 6.10):
# uname -a
Linux auto 4.19.0-8-amd64 #1 SMP Debian 4.19.98-1.swm.3 (2020-04-27) 
x86_64 GNU/Linux

standard Debian + 'AppArmor' and remove IPv6 (himself rebuild)

what to do next?
what additional information to provide?


Thanks

-- 
Nikolay

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.