[ossec-list] Re: 0.9 rootkit false positives with files > 2GB?

2006-08-09 Thread Unit3
Daniel Cid wrote: > To fix that, just edit src/Config.Make, > add the following to the CFLAGS and recompile ossec: > > -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 Oh, this seems to have worked great, thanks! > *it will be fixed by default in the next version. Sounds good. :) > Thanks for the repo

[ossec-list] 0.9 rootkit false positives with files > 2GB?

2006-08-08 Thread Unit3
This may have been posted already, but I don't see an easy way to search the archives, nor a recent post about it, so I figured I should ask. I'm seeing some false positive rootkit detection on my Ubuntu/dapper system after a fresh install of 0.9: Rule: 14 fired (level 8) -> "Rootkit detection e