I don't think that chkrootkit alerting about this rootkit is related to upstart init changes, but the output from /proc/1/maps instead. Something like this should improve the test:
expertmode_output "${egrep} '^[^/]+${ROOTDIR}sbin/init.' ${ROOTDIR}proc/1/maps"
What do you think?
I don't think that chkrootkit alerting about this rootkit is related to upstart init changes, but the output from /proc/1/maps instead. Something like this should improve the test:
expertmode_output "${egrep} '^[^/]+ ${ROOTDIR} sbin/init. ' ${ROOTDIR} proc/1/ maps"
What do you think?