Hello Patrick,

On Wed, 15 Sep 2010 21:08:26 +0200 Gouin Patrick 
<pg.freez...@free.fr> wrote:
>It seems it's based on the same idea than the "quick" test of the 
next version of unhide-linux26.
>It's basically a fast comparison of all the methods which can 
detect a process.
>The main difference I see is that unhide.rb run ps once at start 
when unhide-linux26 uses it on the fly via a pipe.
>I think the latest way should give less false positives but I may 
be wrong.
>In fact, for now, I have never seen a false positive with the 
quick test.
>About the concern of Johan Walles, the quick test is about 20 time 
>
>faster than sys + proc tests.

Personally, but that's my opinion, I value accuracy over speed. Do 
I read correctly from your reply you say that after running tests 
you conclude both tools end results are the same?


Cheers,
unSpawn
---


------------------------------------------------------------------------------
Start uncovering the many advantages of virtual appliances
and start using them to simplify application deployment and
accelerate your shift to cloud computing.
http://p.sf.net/sfu/novell-sfdev2dev
_______________________________________________
Rkhunter-users mailing list
Rkhunter-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/rkhunter-users

Reply via email to