LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-28-2018, 06:45 PM   #1
ChuangTzu
Senior Member
 
Registered: May 2015
Location: Where ever needed
Distribution: Slackware/Salix while testing others
Posts: 1,718

Rep: Reputation: 1857Reputation: 1857Reputation: 1857Reputation: 1857Reputation: 1857Reputation: 1857Reputation: 1857Reputation: 1857Reputation: 1857Reputation: 1857Reputation: 1857
Problems with rkhunter 1.4.6


Just an FYI, in case anyone runs rkhunter 1.4.6.

I noticed what is most likely a bug that is reproducible on various distros (yes I will submit the info to the dev., if possible).

When running rkhunter -c (event after --propupd) it will report finding between 2-8 rootkits, depending on the distro (Slackware 14.2, Salix 14.2, Debian 9 and Ubuntu 18.04-and derivatives). Note: Debian version is 1.4.2-6+deb9u1, but produces same results. *Clarify: 1.4.2-6 on Debian 9 does not produce these results, however, 1.4.6-2 from Debian 10 Buster/testing does.*

After downgrading to version 1.4.0, it reports 0 rootkits on the same distros and same machines. Results are same whether run from liveCD, VM or bare metal. There must be a setting or something with v. 1.4.6 that is throwing up more false positives then usual.

Anyone else notice this?

Added: Bug report submitted.

Last edited by ChuangTzu; 05-29-2018 at 02:32 PM. Reason: added clarify **
 
Old 05-29-2018, 09:53 AM   #2
luizlmarins
LQ Newbie
 
Registered: Nov 2012
Location: São Paulo
Distribution: Debian
Posts: 10
Blog Entries: 1

Rep: Reputation: Disabled
Also ... rkhunter shows the Evince pdf reader as rootkit.
 
Old 05-29-2018, 10:24 AM   #3
jsbjsb001
Senior Member
 
Registered: Mar 2009
Location: Earth, unfortunately...
Distribution: Currently: OpenMandriva. Previously: openSUSE, PCLinuxOS, CentOS, among others over the years.
Posts: 3,881

Rep: Reputation: 2063Reputation: 2063Reputation: 2063Reputation: 2063Reputation: 2063Reputation: 2063Reputation: 2063Reputation: 2063Reputation: 2063Reputation: 2063Reputation: 2063
Quote:
Originally Posted by ChuangTzu View Post
Just an FYI, in case anyone runs rkhunter 1.4.6.

I noticed what is most likely a bug that is reproducible on various distros (yes I will submit the info to the dev., if possible).

When running rkhunter -c (event after --propupd) it will report finding between 2-8 rootkits, depending on the distro (Slackware 14.2, Salix 14.2, Debian 9 and Ubuntu 18.04-and derivatives). Note: Debian version is 1.4.2-6+deb9u1, but produces same results.

After downgrading to version 1.4.0, it reports 0 rootkits on the same distros and same machines. Results are same whether run from liveCD, VM or bare metal. There must be a setting or something with v. 1.4.6 that is throwing up more false positives then usual.

Anyone else notice this?

Added: Bug report submitted.
Well, -1 for CentOS 7.4, as nope, not on my system it doesn't;

Code:
[root@jamespc ~]# rkhunter --propupd
[ Rootkit Hunter version 1.4.6 ]
File updated: searched for 176 files, found 136
Code:
[output snipped]
System checks summary
=====================

File properties checks...
    Files checked: 136
    Suspect files: 0

Rootkit checks...
    Rootkits checked : 503
    Possible rootkits: 0
CentOS 7.4 wins!
 
Old 05-29-2018, 12:09 PM   #4
AwesomeMachine
LQ Guru
 
Registered: Jan 2005
Location: USA and Italy
Distribution: Debian testing/sid; OpenSuSE; Fedora; Mint
Posts: 5,524

Rep: Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015
Rkhunter is an advisory program. It's up to the user to check whether its correct. And, in MHO, rkhunter is just a step above hucksterism.
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
rkhunter scan: 1 Rootkit & 6 Possible Suspect Files /var/log/rkhunter.log included Mollusc Linux - Security 10 09-29-2011 08:43 AM
/var/log/rkhunter.log - rkhunter's (rootkit detection) logfile ahartman Linux - Security 1 07-04-2009 05:28 PM
rkhunter lumiwa Linux - Newbie 1 09-17-2007 08:51 PM
rkhunter phatbastard Linux - Security 3 12-08-2004 09:44 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:05 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration