Quoting Ben Lutgens (blutgens at sistina.com):
> So grab the tarball, uncompress, cd, type make, then run the bin....
> 
> It's pretty stupid to install it and leave it installed on a box as it
> could be replaced by and cracker upon compromise anyway. Generally one
> compiles and copies to a "rescue" cd or some such.

simple integrity check: rpm --checksig chkrootkit, but if the got root, they
could replace everything

better integrity check: make sure /usr/bin is in your tripwire config

best: burned to a cd, imho


-- 
Bob Tanner <tanner at real-time.com>         | Phone : (952)943-8700
http://www.mn-linux.org, Minnesota, Linux | Fax   : (952)943-8500
http://www.tcwug.org, Minnesota, Wireless | Coding isn't a crime. 
Fingerprint: 02E0 2734 A1A1 DBA1 0E15  623D 0036 7327 93D9 7DA3