[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: how to run debsums for 'ps' and 'readline'



On Fri, Dec 19, 2008 at 12:25:55PM +0100, oneman wrote:
> Hi All,
>
>
> chkrootkit is complaining about processes hidden from ps and readdir. So 
> I'd like to run debsums on them to test the integrity of ps and readdir. 
> However, 'debsums ps' doesn't work. Wich package name should I use to 
> check the integrity of these two?

Something that helped me to get a different point of view on such a 
system was a busybox binary. IIRC we have a package with a rather 
complete and statically-linked busybox binary. You could also try 
'busybox ps' and such. 

Again, not a fix, but a different point of view.

-- 
Tzafrir Cohen         | tzafrir@jabber.org | VIM is
http://tzafrir.org.il |                    | a Mutt's
tzafrir@cohens.org.il |                    |  best
ICQ# 16849754         |                    | friend


Reply to: