ah...right. I see what you mean. 

FWIW, my system and architecture listed above (previous email) were:

> We're running Sarge with kernel 2.6.11, and have tried both
>
> chkrootkit 0.45-1
> chkrootkit 0.46a-2

...and at that time, I was getting:

/etc/cron.daily/chkrootkit:
You have     1 process hidden for readdir command
You have     1 process hidden for ps command
chkproc: Warning: Possible LKM Trojan installed

with the manual results that were shown at that time. 


The more recent results were shown given:

kernel: 2.6.15
chkrootkit: 0.46a-3
arch(unchanged): i386

...and you're right...no more hidden processes for ps or readdir

so I guess this part is ok, now. Sorry for any confusion. I've been
getting these chkrootkit messages for so long that I didn't even notice
that the ps/readdir process messages vanished. 

peace,
Nolan




-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to