Has anyone seen false positives on a ZK Rootkit alert referring to /etc/sysconfig/console/load.zk? I've gotten it twice on a brand new installation, with nothing having been done other than to install OSSEC-HIDS.
- [ossec-list] ZK Rootkit Joe Barr
- [ossec-list] Re: ZK Rootkit Daniel Cid
- [ossec-list] Re: ZK Rootkit Joe Barr
- [ossec-list] Re: ZK Rootkit Yuri Slobodyanyuk
- [ossec-list] Re: ZK Rootkit Meir Michanie
- [ossec-list] Re: ZK Rootkit Joe Barr
- [ossec-list] Re: ZK Rootkit Joe Barr
- [ossec-list] ZK Rootkit Steven Newson
- [ossec-list] Re: ZK Rootkit Stephen Hawkins
