[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Chkrootkit



hi,

for (1) I guess you can put the binaries in a read-only medium and run them from there, like a CD-ROM or a write-protected floppy/flash-medium.

I am not sure I got what you mean in (2)

-dce.

Kay-Michael Voit wrote:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: MD5

Hi,
I'm just setting up my first webserver in a productive environment.
Now I wonder how I could use chkrootkit.

My first idea was to run a cronjob, butI have two problems with this
solution:

1) An attacker could just change the chkrootkit binaries. If I'm
right, chkrootkit is nearly worthless, unless it has just been
installed.

2) If I use it as a cronjob in spite of point 1), I will use it in
quiet mode for not being notify also nothing is wrong. The problem is,
that it stilll says eth0 is not promisc. But this is no problem, is
it?

Thanks in advance,
Kay-Micahel Voit

- --
Ceterum censeo Iracem esse delendam.

Public Key erhältlich auf den PGP-Keyservern, sowie mit weiteren Informationen auf http:\\www.voits.net.
Fingerprint: 9b482c5c41800ef0f6c8b01ae4df20ac

-----BEGIN PGP SIGNATURE-----
Version: 2.6

iQEVAwUAPqgYFJ9LInC1Fu5pAQH/cQgAnRyWp9Iijz74y32PH0kCX5Yympn2juya
TPHOanYHBDGt5bN7u/zoQcWRccU+AQSNglM2+giROnLw9tJ++/NsiQjWLySueTRm
AZGsMLxhlAf20y5i0l3Jm33Fsscea/XMDsuBEW7aIIje7hkFZ5yx1dYu3O0mJ0Uq
BBqcQZqRvh63y+g0IH2Evzmcy3R+3k2A00NgNWY2beh+57wtpHFpRWLw0oKdPn6R
ock6wG3a+EcmAmIEN3QRAJG4T1dJHrOnoN0USnteXbE26t8OLJ+p66BwxnHADVoY
9I+OBapI6m/RJdXq9XM2DyzqXN2OPBrcRzdk4HBeqMur3D+fZBrUSA==
=MfF3
-----END PGP SIGNATURE-----





Reply to: