[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [cobalt-users] chkrootkit



On Mon, 5 Aug 2002, Andy Brown wrote:

> I've seen it before on a RaQ which was never attached to the outside world. Although doing the scan several times, sometimes it came back positive sometimes negative.
> If I read it right, it checks the ps command against /proc values, so i'd assume a process that was quick enough to start/stop could appear in one and not the other.
> Thats the only explanation I could think of, though would be nice somebody to confirm this!!
>

Thanks
Seems like I have heard that before.
And it does seem to be a reasonable explnation.

--
Gerald Waugh <gwaugh@xxxxxxxxxxxxxxxxxxxxxxx>
http://frontstreetnetworks.com | Website Hosts & SOHO Networks
229 Front Street, Ste.#C, New Haven, CT. 06513 United States
voice +1 203-785-0699 | fax +1 203-785-1787