==================================================================
  Please DO NOT REPLY to this mail or send email to the developers
  about this bug. Please follow-up to Bugzilla using this link:
    http://bugs.contribs.org/show_bug.cgi?id=7800

  Have you checked the Frequently Asked Questions (FAQ)?
    http://wiki.contribs.org/SME_Server:Documentation:FAQ

  Please also take the time to read the following useful guide:
    http://www.chiark.greenend.org.uk/~sgtatham/bugs.html
==================================================================

--- Comment #7 from Ray Mitchell <[email protected]> ---
(In reply to Ray Mitchell from comment #6)
> (In reply to Unnilennium from comment #5)
> > meserver-rkhunter-1_2_0-9_el5_sme will be available in a few hours to test.
> 
> Will wait overnight for cron job to run & report back here.

The cron job has run the rkhunter report for last two mornings OK, & emailed it
to root.

Resolve fixed & contrib is functional.
Contrib can be moved to smecontribs repo.
After that this bug can be closed.


Copy of latest report generated at 4:12am.
Note that lots of valid admin user changes were detected in an earlier report
that was run, which I prefer not to post here, but it does verify that rkhunter
appears to be doing its job.



--------------------- Start Rootkit Hunter Update ---------------------
[ Rootkit Hunter version 1.4.0 ]

Checking rkhunter data files...
  Checking file mirrors.dat                                  [ No update ]
  Checking file programs_bad.dat                             [ No update ]
  Checking file backdoorports.dat                            [ No update ]
  Checking file suspscan.dat                                 [ No update ]
  Checking file i18n/cn                                      [ No update ]
  Checking file i18n/de                                      [ No update ]
  Checking file i18n/en                                      [ No update ]
  Checking file i18n/zh                                      [ No update ]
  Checking file i18n/zh.utf8                                 [ No update ]

---------------------- Start Rootkit Hunter Scan ----------------------
Warning: Process '/sbin/pppoe' (PID 2204) is listening on the network.
Warning: Process '/sbin/pppoe' (PID 2204) is listening on the network.
Warning: Suspicious file types found in /dev:
         /dev/.udev/db/class@printer@lp0: ASCII text
         /dev/.udev/db/block@sda@sda1: ASCII text
         /dev/.udev/db/block@sda: ASCII text
         /dev/.udev/db/block@hdd: ASCII text
         /dev/.udev/db/block@fd0: ASCII text
         /dev/.udev/db/class@input@input0@event0: ASCII text
         /dev/.udev/db/block@hdc@hdc1: ASCII text
         /dev/.udev/db/block@hdc@hdc2: ASCII text
         /dev/.udev/db/block@hda@hda2: ASCII text
         /dev/.udev/db/block@hda@hda1: ASCII text
         /dev/.udev/db/block@md1: ASCII text
         /dev/.udev/db/block@md2: ASCII text
         /dev/.udev/db/class@[email protected]: ASCII text
         /dev/.udev/db/block@hdc: ASCII text
         /dev/.udev/db/block@hda: ASCII text
         /dev/.udev/db/class@[email protected]: ASCII text
         /dev/.udev/db/block@ram0: ASCII text
         /dev/.udev/db/block@ram1: ASCII text
         /dev/.udev/db/class@misc@device-mapper: ASCII text
         /dev/.udev/db/class@input@mice: ASCII text
         /dev/.udev/uevent_seqnum: ASCII text
Warning: Hidden file found: /usr/bin/.ssh.hmac: ASCII text
Warning: Hidden file found: /usr/bin/.fipscheck.hmac: ASCII text
Warning: Hidden file found: /usr/sbin/.sshd.hmac: ASCII text

----------------------- End Rootkit Hunter Scan -----------------------

-- 
You are receiving this mail because:
You are the QA Contact for the bug.
You are the assignee for the bug.
_______________________________________________
Mail for each SME Contribs bug report
To unsubscribe, e-mail [email protected]
Searchable archive at http://lists.contribs.org/mailman/public/contribteam/

Reply via email to