LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-13-2014, 04:43 PM   #1
netpumber
Member
 
Registered: Sep 2007
Location: In My Box
Distribution: Arch Linux
Posts: 423

Rep: Reputation: 33
rkhunter throws warnings for no system startup files


Hi.

I am using arch linux and systemd. I installed rkhunter and run

Code:
rkhunter -c --enable all --disable none --rwo
which returned me

Quote:
Warning: Checking for possible rootkit strings [ Warning ]
No system startup files found.
Warning: The following processes are using deleted files:
Process: /usr/bin/Xorg.bin PID: 465 File: /usr/bin/Xorg.bin
Process: /usr/bin/vim PID: 1053 File: /home/n3t/dev/http/SOLgene/.excelParse.php.swp
Process: /usr/lib/chromium/chromium PID: 4155 File: /dev/shm/.org.chromium.Chromium.XQLb9g
Process: /usr/lib/chromium/chromium PID: 4191 File: /dev/shm/.org.chromium.Chromium.XQLb9g
Process: /usr/lib/chromium/chromium PID: 5846 File: /dev/shm/.org.chromium.Chromium.THadNo
Process: /usr/lib/chromium/chromium PID: 5885 File: /dev/shm/.org.chromium.Chromium.bzVssl
Process: /usr/lib/chromium/chromium PID: 5900 File: /dev/shm/.org.chromium.Chromium.THadNo
Process: /usr/lib/chromium/chromium PID: 5928 File: /dev/shm/.org.chromium.Chromium.THadNo
Process: /usr/lib/chromium/chromium PID: 5935 File: /dev/shm/.org.chromium.Chromium.THadNo
Process: /usr/lib/chromium/chromium PID: 5947 File: /dev/shm/.org.chromium.Chromium.THadNo
Process: /usr/lib/chromium/chromium PID: 5967 File: /dev/shm/.org.chromium.Chromium.THadNo
Process: /usr/lib/chromium/chromium PID: 5970 File: /dev/shm/.org.chromium.Chromium.THadNo
Process: /usr/lib/chromium/chromium PID: 6022 File: /dev/shm/.org.chromium.Chromium.XQLb9g
Process: /usr/lib/chromium/chromium PID: 12689 File: /dev/shm/.org.chromium.Chromium.XQLb9g
Process: /usr/lib/chromium/chromium PID: 16505 File: /dev/shm/.org.chromium.Chromium.XQLb9g
Process: /usr/lib/chromium/chromium PID: 19049 File: /dev/shm/.org.chromium.Chromium.XQLb9g
Process: /usr/bin/mysqld PID: 25925 File: /tmp/ibjwpbsf
Process: /usr/lib/chromium/chromium PID: 26087 File: /dev/shm/.org.chromium.Chromium.THadNo
Process: /usr/lib/chromium/chromium PID: 28571 File: /dev/shm/.org.chromium.Chromium.XQLb9g
Warning: No system startup files found.
Why returns me these warnings ? Does it look for an init.d or rc.d directory? How can i fix them ? Any idea?

Thank you.

Last edited by netpumber; 11-14-2014 at 02:00 AM.
 
Old 11-14-2014, 01:59 AM   #2
netpumber
Member
 
Registered: Sep 2007
Location: In My Box
Distribution: Arch Linux
Posts: 423

Original Poster
Rep: Reputation: 33
Fixed by changing the values of START UP FILES in /etc/rkhunter.conf
 
Old 11-16-2014, 06:34 PM   #3
abefroman
Senior Member
 
Registered: Feb 2004
Location: lost+found
Distribution: CentOS
Posts: 1,430

Rep: Reputation: 55
Use, Lynis instead of RKhunter.
 
Old 11-17-2014, 03:39 PM   #4
Nix_Enthusiast
LQ Newbie
 
Registered: Nov 2014
Posts: 6

Rep: Reputation: Disabled
Quote:
Originally Posted by abefroman View Post
Use, Lynis instead of RKhunter.
That seems to be the consensus these days i'm noticing. RKHunter seems great, but it's giving me alot of warnings that are unnecessary as the OP experienced.
 
Old 11-17-2014, 04:36 PM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by Nix_Enthusiast View Post
RKHunter seems great, but it's giving me alot of warnings that are unnecessary as the OP experienced.
That's a misconception a lot of users seem to suffer from unfortunately. Rootkit Hunter does not "know" your system nor does it make any assumptions. So after the first run you, a human, has to analyse the output, determine what's worth checking for and customize the configuration accordingly. It's a simple as that. If that's not to your liking you're invited, just like anybody else, to improve it.
 
2 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
rkhunter warnings metzenx Linux - Security 6 12-30-2013 01:52 PM
Rkhunter warnings g4ry Slackware 1 12-12-2012 05:11 AM
rkhunter warnings or suspect files judoka Linux - Security 7 08-21-2010 08:30 AM
rkhunter warnings adityavpratap Slackware 15 02-24-2007 07:11 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:38 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration