LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-16-2008, 01:13 PM   #1
Golgo13
LQ Newbie
 
Registered: Jan 2008
Posts: 6

Rep: Reputation: 0
Rkhunter Assistance ..


Hi, my name is Ben. Im new here. I have a server that we're using RKhunter on. It seems to work fine. I am just concerned with the Daily run...the run will say [BAD] for "Testing Running Processes" .. I know this means its not running the test. How can I fix this issue if anyone knows out there?
I am running Red Hat 4.1.1-1 with Rootkit Hunter 1.2.8.
Any ideas will be great!
Thanks
Ben
 
Old 01-16-2008, 05:13 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
The oldest still supported RKH version is 1.2.9.
We've released 1.3.0 some time ago.
Please upgrade.
 
Old 01-17-2008, 10:21 AM   #3
mahmoud
Member
 
Registered: Apr 2006
Location: UK
Distribution: Mandriva, Debain, Redhat, Fedora, Ubuntu, FreeBSD
Posts: 269

Rep: Reputation: 30
what happens with rkhunter is when there is an update on your system it recognizes it as a change
and notifies you that there has been a change with a file it doesnt know it was an update by you it just know there was a change
so what u can do is
rkhunter --propupd
then run it again to check of the warning still comes up then you know you have a problem
also check the log files and see what the error is
 
Old 01-17-2008, 02:29 PM   #4
Golgo13
LQ Newbie
 
Registered: Jan 2008
Posts: 6

Original Poster
Rep: Reputation: 0
Thanks for the replies, just to ensure the forum knows where Im coming from.. here's how it looks:
* Suspicious files and malware
Scanning for known rootkit strings [ OK ]
Scanning for known rootkit files [ OK ]
Testing running processes... [ BAD ]
Miscellaneous Login backdoors [ OK ]
Miscellaneous directories [ OK ]
Software related files [ OK ]
Sniffer logs [ OK ]

You'll notice the "Testing Running Processes..." says [BAD]
I will try these other tips. Any more tips out there?
Thanks!
Ben
 
Old 01-17-2008, 03:35 PM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
I can't even *remember* what 1.2.8 output looked like. Detailed account (debug mode aka 'sh -x') output might help.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
RKhunter Help please Golgo13 Linux - Software 3 01-16-2008 04:27 PM
rkhunter lumiwa Linux - Newbie 1 09-17-2007 08:51 PM
rkhunter atlaika Linux - Security 7 11-29-2005 10:47 AM
rkhunter phatbastard Linux - Security 3 12-08-2004 09:44 PM
Snort and rkhunter lord_zoo Linux - Security 5 11-28-2004 08:07 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:17 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration