On Tuesday 18 July 2006 23:38, Default User wrote: > I just installed chkrootkit. The first run reported as part of the > normal output: > > eth0: PACKET SNIFFER(/sbin/dhclient[1005]) > > Does this mean there is a sniffer on my system?
Most likely no: That's a common false positive from chrootkit. Dhclient is meant to listen on the interface _before_ it has it's IP-Address assigned. This means that dhclient has to look at every incoming packet. And that's the same thing that is done by packet sniffers. Therefore the warning from chrootkit. But it is completely normal for dhclient. -- Lothar -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]