chkrootkit question

This is a discussion on chkrootkit question within the Linux Security forums, part of the System Security and Security Related category; Hi all, I have installed chkrootkit-0.44 on my suse 9.1 and I have it check my machine ...


Go Back   Usenet Forums > System Security and Security Related > Linux Security

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 11-11-2004
rsina
 
Posts: n/a
Default chkrootkit question

Hi all,

I have installed chkrootkit-0.44 on my suse 9.1 and I have it check my
machine every night and email me the results. I have been comparing the
emails for the last month or so and I have noticed that they are consistant
except that there is intermittent jump from

Checking `inetd'... not infected
..
..
Checking `sniffer'... Checking `w55808'... not infected
..
..

to

Checking `inetd'... not tested
..
..
Checking `sniffer'... ppp0: not promisc and no PF_PACKET sockets
Checking `w55808'... not infected
..
..

and vice versa. Does anyone know why that should be the case, i.e. inetd is
not tested occasionally and why the sniffer is cutoff when inetd is
reported not to be infected?

Thanks
Reply With Quote
  #2 (permalink)  
Old 11-14-2004
Bill Marcum
 
Posts: n/a
Default Re: chkrootkit question

On Thu, 11 Nov 2004 14:29:16 GMT, rsina
<rsina.no-ssppaamm@earthlink.net> wrote:
> Hi all,
>
> I have installed chkrootkit-0.44 on my suse 9.1 and I have it check my
> machine every night and email me the results. I have been comparing the
> emails for the last month or so and I have noticed that they are consistant
> except that there is intermittent jump from
>
> Checking `inetd'... not infected
> .
> .
> Checking `sniffer'... Checking `w55808'... not infected
> .
>
> and vice versa. Does anyone know why that should be the case, i.e. inetd is
> not tested occasionally and why the sniffer is cutoff when inetd is
> reported not to be infected?
>


I don't know why inetd is sometimes not tested, but "sniffer" tests
whatever network interfaces are up at the time. I assume you have no
ethernet, just a dial-up connection.

--
"At a scheduled time, the robot would pull the flush lever and scream as
it got sucked down the drain." --Kibo
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 02:19 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0