1 |
On Sunday 16 July 2006 21:36, Hemmann, Volker Armin wrote: |
2 |
> oh, and read this: |
3 |
> http://www.chkrootkit.org/faq/ |
4 |
|
5 |
Interesting ... |
6 |
|
7 |
How accurate is chkproc? |
8 |
If you run chkproc on a server that runs lots of short time processes it |
9 |
could report some false positives. chkproc compares the ps output with |
10 |
the /proc contents. If processes are created/killed during this operation |
11 |
chkproc could point out these PIDs as suspicious. |
12 |
|
13 |
|
14 |
"no, if you chroot, the binaries from the chroot are used. |
15 |
|
16 |
use chkrootkit without chrooting - best with full path (/usr/sbin/chkrootkit)" |
17 |
|
18 |
The problem is if I do not chroot chkrootkit will scan the knoppix CD - tried |
19 |
it :). It needs to access the live proc etc on a running system. |
20 |
|
21 |
Dave |
22 |
-- |
23 |
gentoo-user@g.o mailing list |