Re: [Rkhunter-users] hidden process false positives

2010-03-11 Thread unspawn
On Wed, 10 Mar 2010 12:34:24 +0100 William Maddler n...@maddler.net wrote: since about a week I'm getting alerts about hidden processes found on my system (Debian 5.0 stable 32bit). I've just found that reported PIDs are Postfix (2.5.5-1.1) ltmp and smtp mail delivery processes. Any clue? If

Re: [Rkhunter-users] [PATCH] Adding Solaris/Wanuk.A to rkhunter

2010-03-11 Thread lists
On Tue, 2 Feb 2010 at 21:56, unsp...@hushmail.com wrote: Looks like a good addition to me. It's been a long time, so...what's the process here? Should I resend the patch to someone special? Or is this still pending review and I just have to be patient? I could not find a rkhunter routine to

Re: [Rkhunter-users] hidden process false positives

2010-03-11 Thread William Maddler
On 03/11/2010 10:46 PM, unsp...@hushmail.com wrote: On Wed, 10 Mar 2010 12:34:24 +0100 William Maddler n...@maddler.net wrote: since about a week I'm getting alerts about hidden processes found on my system (Debian 5.0 stable 32bit). I've just found that reported PIDs are Postfix

Re: [Rkhunter-users] [PATCH] Adding Solaris/Wanuk.A to rkhunter

2010-03-11 Thread unspawn
Hello Christian, On Thu, 11 Mar 2010 23:04:21 +0100 li...@nerdbynature.de wrote: On Tue, 2 Feb 2010 at 21:56, unsp...@hushmail.com wrote: Looks like a good addition to me. It's been a long time, so...what's the process here? Should I resend the patch to someone special? Or is this still

Re: [Rkhunter-users] [PATCH] Adding Solaris/Wanuk.A to rkhunter

2010-03-11 Thread lists
On Fri, 12 Mar 2010 at 07:44, unsp...@hushmail.com wrote: The latter, really. Unlike other projects we're basically a two-man show... Noted. I'll be patient then :-) Actually there's not a lot of malware that does. The last one I encountered was compromised through the web stack (PHP again