LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 11-03-2011, 09:09 PM   #1
sneakyimp
Senior Member
 
Registered: Dec 2004
Posts: 1,056

Rep: Reputation: 78
mail to roo and rkhunter complaints


I set up a rackspace cloud server awhile back to host a website and I'm contemplating setting up a site or two there. I noticed that rkhunter is sending emails to root@mydomain.com which gets delivered locally and is filling up the limited storage on this machine.

First, the email is complaining about a few things. Do these problems look serious? Wondering if machine might be compromised or whether these are fine and easily fixed:
Code:
Warning: The file properties have changed:
         File: /usr/bin/awk
         Current hash: c7a7da74a87602ded1bff67da0a33eb29a7b42c5
         Stored hash : 6ef52de269564cb384eaf63e2ee5f4181f715cbb
Warning: The file '/usr/bin/GET' exists on the system, but it is not present in the rkhunter.dat file.
Warning: The file '/usr/bin/gawk' exists on the system, but it is not present in the rkhunter.dat file.
Warning: The file '/usr/bin/lwp-request' exists on the system, but it is not present in the rkhunter.dat file.
Warning: The file '/usr/sbin/unhide' exists on the system, but it is not present in the rkhunter.dat file.
Warning: The file '/usr/sbin/unhide-linux26' exists on the system, but it is not present in the rkhunter.dat file.
Warning: The SSH and rkhunter configuration options should be the same:
         SSH configuration option 'PermitRootLogin': yes
         Rkhunter configuration option 'ALLOW_SSH_ROOT_USER': no
Warning: Suspicious file types found in /dev:
         /dev/shm/network/ifstate: ASCII text
Warning: Application 'gpg', version '1.4.9', is out of date, and possibly a security risk.
Warning: Application 'openssl', version '0.9.8g', is out of date, and possibly a security risk.
Warning: Application 'php', version '5.2.6', is out of date, and possibly a security risk.
Warning: Application 'sshd', version '5.1p1', is out of date, and possibly a security risk.

One or more warnings have been found while checking the system.
Please check the log file (/var/log/rkhunter.log)
Also, is there any sure-fire way to route all mail to be delivered locally to some other address? The machine is running Debian 5 and appears to be running postfix.
 
Old 11-04-2011, 04:36 PM   #2
bathory
LQ Guru
 
Registered: Jun 2004
Location: Piraeus
Distribution: Slackware
Posts: 13,163
Blog Entries: 1

Rep: Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032
Hi,

Quote:
First, the email is complaining about a few things. Do these problems look serious? Wondering if machine might be compromised or whether these are fine and easily fixed:
Most of them are normal warnings. You should run
Code:
rkhunter --propupd
to update rkhunter database, so it stops complaining about file not being in the database. And maybe update the programs mentioned in the log file. The only thing that you may investigate further is the file /dev/shm/network/ifstate

Quote:
Also, is there any sure-fire way to route all mail to be delivered locally to some other address? The machine is running Debian 5 and appears to be running postfix.
Edit rkhunter.conf and change MAIL-ON-WARNING accordingly.

Regards
 
1 members found this post helpful.
Old 11-04-2011, 06:57 PM   #3
sneakyimp
Senior Member
 
Registered: Dec 2004
Posts: 1,056

Original Poster
Rep: Reputation: 78
Thanks once again, bathory.

I have run rkhunter --propupd and I have updated MAIL-ON-WARNING. We'll see what warnings may linger. Am I correct in thinking that rkhunter runs as cron so I don't have to restart anything?

Also, my question about re-routing emails to route was not just about rkhunter emails but about any email at all that might get sent to the root mailbox. I'd like to redirect all of this stuff. Thoughts?

As for /dev/shm/network/ifstate, it is a file containing this:
Code:
# cat /dev/shm/network/ifstate
lo=lo
eth0=eth0
eth1=eth1
That looks pretty innocuous to me, but I have no idea what is supposed to be in this file.
 
Old 11-05-2011, 03:44 AM   #4
bathory
LQ Guru
 
Registered: Jun 2004
Location: Piraeus
Distribution: Slackware
Posts: 13,163
Blog Entries: 1

Rep: Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032
Quote:
Am I correct in thinking that rkhunter runs as cron so I don't have to restart anything?
Correct


Quote:
Also, my question about re-routing emails to route was not just about rkhunter emails but about any email at all that might get sent to the root mailbox. I'd like to redirect all of this stuff. Thoughts?
You can create an alias for the root account to some other mail account

Quote:
That looks pretty innocuous to me, but I have no idea what is supposed to be in this file.
I agree. You may take a look here if you want to stop rkhunter from complaining

Regards
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
rkhunter scan: 1 Rootkit & 6 Possible Suspect Files /var/log/rkhunter.log included Mollusc Linux - Security 10 09-29-2011 08:43 AM
[SOLVED] Centos 5.5, rkhunter result in logwatch mail Zilvermeeuw Linux - Security 2 04-21-2011 03:04 PM
[SOLVED] Which mail service does the program use (rkhunter)? qwertyjjj Linux - Newbie 1 08-15-2009 06:05 AM
/var/log/rkhunter.log - rkhunter's (rootkit detection) logfile ahartman Linux - Security 1 07-04-2009 05:28 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 01:29 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration