|
Date: Fri, 1 May 2020 23:31:26 +0300 From: Nikolay Zorin <zorin@...mel.ru> To: lkrg-users@...ts.openwall.com Subject: fake alert (?) Hello! I integred LKRG into kernel (not a external module (*.ko)) 0.7 (release) - work, but constantly (every 15 sec) writes alerts: May 1 05:50:33 auto kernel: [ 862.594157] [p_lkrg] ALERT !!! _RODATA MEMORY BLOCK HASH IS DIFFERENT - it is [0x8c6073d11381f2f1] and should be [0x117e94a7b467f213] !!! May 1 05:50:33 auto kernel: [ 862.594157] [p_lkrg] ALERT !!! SYSTEM HAS BEEN COMPROMISED - DETECTED DIFFERENT 1 CHECKSUMS !!! I expanded output: May 1 12:40:21 auto kernel: [ 92.284458] [p_lkrg] ALERT !!! _RODATA MEMORY BLOCK HASH IS DIFFERENT - it is [0x3c5d2385a7efe483] and should be [0xe437fa03a2808bea] !!! May 1 12:40:21 auto kernel: [ 92.284458] module name (from 'list array') - snd_hda_codec_generic May 1 12:40:21 auto kernel: [ 92.284458] module name (from 'kobj array'-floppy) May 1 12:40:21 auto kernel: [ 77.180260] [p_lkrg] ALERT !!! SYSTEM HAS BEEN COMPROMISED - DETECTED DIFFERENT 1 CHECKSUMS !!! I unload 'floppy', but message not stop:May 1 12:52:26 auto kernel: [ 817.276319] [p_lkrg] ALERT !!! _RODATA MEMORY BLOCK HASH IS DIFFERENT - it is [0x3c5d2385a7efe483] and should be [0xe437fa03a2808bea] !!! May 1 12:52:26 auto kernel: [ 817.276319] module name (from 'list array') - snd_hda_codec_generic May 1 12:52:26 auto kernel: [ 817.276319] module name (from 'kobj array'-virtio) If I integrated last version from 'git' (non experimental), then system not start and not output messages.. my system (virtual, KVM based CentOS 6.10): # uname -a Linux auto 4.19.0-8-amd64 #1 SMP Debian 4.19.98-1.swm.3 (2020-04-27) x86_64 GNU/Linux standard Debian + 'AppArmor' and remove IPv6 (himself rebuild) what to do next? what additional information to provide? Thanks -- Nikolay
Powered by blists - more mailing lists
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.