[ossec-list] Re: Rootkit check, check?

2007-08-30 Thread Andrew Storms
This is great. Thanks Daniel! On 8/27/07 4:06 PM, Daniel Cid [EMAIL PROTECTED] wrote: Hi Andrew, There is a very subtle acknowledgement that the rootcheck scan ran that is stored on the server side. If you go to /var/ossec/queue/rootcheck you will see one entry for each agent (plus

[ossec-list] Re: Rootkit check, check?

2007-08-27 Thread Daniel Cid
Hi Andrew, There is a very subtle acknowledgement that the rootcheck scan ran that is stored on the server side. If you go to /var/ossec/queue/rootcheck you will see one entry for each agent (plus the one for the server, just named rootcheck). If you look at any of the files in there, you will

[ossec-list] Re: Rootkit check, check?

2007-08-26 Thread Peter M. Abraham
Greetings Andrew: While I don't know the shortest route, a thought came to mind about installing the rootcheck separately on the server and running it manually. If everything is ok, ossec might not report anything (which is what you may or may not be getting). If there are errors, things of