Gentoo Archives: gentoo-user

From: Dave S <gentoo@××××××××.net>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] chkrootkit LKM trojan ?
Date: Sun, 16 Jul 2006 20:57:09
Message-Id: 200607162149.56402.gentoo@pusspaws.net
In Reply to: Re: [gentoo-user] chkrootkit LKM trojan ? by "Hemmann
1 On Sunday 16 July 2006 21:36, Hemmann, Volker Armin wrote:
2 > oh, and read this:
3 > http://www.chkrootkit.org/faq/
4
5 Interesting ...
6
7 How accurate is chkproc?
8 If you run chkproc on a server that runs lots of short time processes it
9 could report some false positives. chkproc compares the ps output with
10 the /proc contents. If processes are created/killed during this operation
11 chkproc could point out these PIDs as suspicious.
12
13
14 "no, if you chroot, the binaries from the chroot are used.
15
16 use chkrootkit without chrooting - best with full path (/usr/sbin/chkrootkit)"
17
18 The problem is if I do not chroot chkrootkit will scan the knoppix CD - tried
19 it :). It needs to access the live proc etc on a running system.
20
21 Dave
22 --
23 gentoo-user@g.o mailing list

Replies

Subject Author
Re: [gentoo-user] chkrootkit LKM trojan ? Benno Schulenberg <benno.schulenberg@×××××.com>