LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-05-2008, 06:47 PM   #1
h725
Member
 
Registered: Apr 2008
Posts: 114

Rep: Reputation: 15
Question about rkhunter


Hi all.

Let's suppose I just installed rkhunter (1.3.2).
I've not yet done "rkhunter --propupd", and I do "rkhunter -c".
Rkhunter shows me "OK" for almost every binary.

My questions is: what is the meaning of this "OK", if I've not yet created my database (rkhunter.dat)?

How is compared every single file?

I was thinking about "defaulthashes.dat".. but by doing

"sha1sum /bin/dmesg" or "md5sum /bin/dmesg" (for example) I don't found those values into defaulthashes.dat..

Thank you
 
Old 12-06-2008, 04:20 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by h725 View Post
I've not yet done "rkhunter --propupd", (...) what is the meaning of this "OK", if I've not yet created my database (rkhunter.dat)
If you didn't build the hash database beforehand then deliberately running RKH anyway makes the "OK" mean nothing at all. That's not a flaw in RKH but how we chose to make it function since 1.3.2. While I agree it's beneficial to have "knowngoods" type of central hash databases, from a practical point of view the maintenance of defaulthashes.dat was truly horrible and user submission (at about 2000 downloads per month) nearly nonexistent. From a procedural view, installing RKH or any audit app or integrity checker *after* a (perceived) security breach unfortunately is *not* the correct approach. That doesn't mean those apps will be worthless, just that hash checking should not be done without correlation using an external trusted source. How you do that depends on what distribution you use and if you use prelinking. So that still leaves checks like location, setXid, MAC times, size and strings to help make "foreign" binaries stand out like a sore thumb.

If you think you've got a breach of security on your hands maybe give us more details?
 
Old 12-06-2008, 03:08 PM   #3
h725
Member
 
Registered: Apr 2008
Posts: 114

Original Poster
Rep: Reputation: 15
Quote:
Originally Posted by unSpawn View Post
[...........]
If you think you've got a breach of security on your hands maybe give us more details?
Hi unSpawn,

thank you for your reply.
No, I don't have a server compromised.
I totally agree with you about the error of using RKH AFTER had a violation, or without a proper hash database.

But I think it will be better if RKH, without an hash db, tell the user a message "ERROR: rkhunter.dat not found" or so.

Thank you again and sorry my english
 
Old 12-06-2008, 06:50 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by h725 View Post
But I think it will be better if RKH, without an hash db, tell the user a message "ERROR: rkhunter.dat not found" or so.
I think it will be better if people actually read the "readme" and update the database first :-]
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
RKHunter Output Question cedricd Linux - Security 4 11-25-2008 12:09 PM
RKhunter question, Getting warnings for some directories. M$ISBS Linux - Security 8 03-05-2008 01:38 AM
RKhunter Help please Golgo13 Linux - Software 3 01-16-2008 04:27 PM
rkhunter lumiwa Linux - Newbie 1 09-17-2007 08:51 PM
rkhunter atlaika Linux - Security 7 11-29-2005 10:47 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:51 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration