Re: Chkrootkit reports infection
> Newer versions of chkrootkit (0.45, for example) allow you to run in a
> "diff mode" that suppresses day-to-day duplicate hits. You can turn this
> option on with 'dpkg-reconfigure chkrootkit'.
>
The Sarge version is 0.44-2. The "diff" mode sounds good. Is a newer
version available in any of the Archives? I can't find it in backports or
volatile. I'd sooner stick with .deb packages than use locally installed
"hacks". Presumably chkrootkit should be reasonably up to date for security
reasons.
Reply to: