Gentoo Archives: gentoo-user

From: Paul Hartman <paul.hartman+gentoo@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Another chkrootkit false positive?
Date: Tue, 05 Apr 2011 14:09:37
Message-Id: BANLkTimzFPbZYVCrTa50CO7QFxYYua16Bw@mail.gmail.com
In Reply to: Re: [gentoo-user] Another chkrootkit false positive? by Mick
1 On Tue, Apr 5, 2011 at 5:38 AM, Mick <michaelkintzios@×××××.com> wrote:
2 > The warnings were generated last time the cron job run chkrootkit.  I
3 > think that the box was rather busy in the middle of emerging stuff at
4 > the time, so I wonder if that had something to do with it.
5
6 I was actually thinking about exactly that situation. I use emerge -j
7 and make -j9 and can have dozens (hundreds?) or processes starting and
8 stopping all the time. If there's even a slight delay between when ps
9 runs and when chkproc checks /proc for itself I can see how there
10 might be a couple discrepancies. The fact that they don't show later I
11 think is a good sign that there's nothing permanently hidden by a
12 modified ps binary.