Re: Chkrootkit reports infection

2005-06-29 Thread Brad Sawatzky
On Thu, 30 Jun 2005, Robert S wrote: > > Newer versions of chkrootkit (0.45, for example) allow you to run in a > > "diff mode" that suppresses day-to-day duplicate hits. You can turn > > this option on with 'dpkg-reconfigure chkrootkit'. > > > The Sarge version is 0.44-2. The "diff" mode sound

Re: Chkrootkit reports infection

2005-06-29 Thread Robert S
> Newer versions of chkrootkit (0.45, for example) allow you to run in a > "diff mode" that suppresses day-to-day duplicate hits. You can turn this > option on with 'dpkg-reconfigure chkrootkit'. > The Sarge version is 0.44-2. The "diff" mode sounds good. Is a newer version available in any of

Re: Chkrootkit reports infection

2005-06-29 Thread Brad Sawatzky
On Wed, 29 Jun 2005, Nikita V. Youshchenko wrote: > > I've recently updated to sarge. > > > > When chkrootkit runs daily, I get a (presumed) false positive: > > > > # chkrootkit -q > > > > /usr/lib/mindi/rootfs/proc/.keep /usr/lib/mindi/rootfs/root/.profile > > > > I assume that this is due to

Re: Chkrootkit reports infection

2005-06-29 Thread Nikita V. Youshchenko
> I've recently updated to sarge. > > When chkrootkit runs daily, I get a (presumed) false positive: > > # chkrootkit -q > > /usr/lib/mindi/rootfs/proc/.keep /usr/lib/mindi/rootfs/root/.profile > > I assume that this is due to the presence of "dotfiles" installed by > mindi. I've tried suppre

Chkrootkit reports infection

2005-06-27 Thread Robert S
I've recently updated to sarge. When chkrootkit runs daily, I get a (presumed) false positive: # chkrootkit -q /usr/lib/mindi/rootfs/proc/.keep /usr/lib/mindi/rootfs/root/.profile I assume that this is due to the presence of "dotfiles" installed by mindi. I've tried suppressing this output usi