Hello,

In the results of scanning, rkhunter 1.2.9 send me these messages :

Ready.
No logfile given: using default.
/bin/cat  [ BAD ]
/bin/chmod  [ BAD ]
/bin/chown  [ BAD ]
/bin/date  [ BAD ]
/bin/dmesg  [ BAD ]
/bin/env  [ BAD ]
/bin/grep  [ BAD ]
/bin/kill  [ BAD ]
/bin/login  [ BAD ]
/bin/ls  [ BAD ]
/bin/more  [ BAD ]
/bin/mount  [ BAD ]
/bin/netstat  [ BAD ]
/bin/ps  [ BAD ]
/bin/su  [ BAD ]
/sbin/chkconfig  [ BAD ]
/sbin/depmod  [ BAD ]
/sbin/ifconfig  [ BAD ]
/sbin/insmod  [ BAD ]
/sbin/lsmod  [ BAD ]
/sbin/modinfo  [ BAD ]
/sbin/modprobe  [ BAD ]
/sbin/rmmod  [ BAD ]
/sbin/sysctl  [ BAD ]
/usr/bin/chattr  [ BAD ]
/usr/bin/du  [ BAD ]
/usr/bin/file  [ BAD ]
/usr/bin/head  [ BAD ]
/usr/bin/killall  [ BAD ]
/usr/bin/lsattr  [ BAD ]
/usr/bin/md5sum  [ BAD ]
/usr/bin/pstree  [ BAD ]
/usr/bin/sha1sum  [ BAD ]
/usr/bin/slocate  [ BAD ]
/usr/bin/stat  [ BAD ]
/usr/bin/strings  [ BAD ]
/usr/bin/top  [ BAD ]
/usr/bin/users  [ BAD ]
/usr/bin/vmstat  [ BAD ]
/usr/bin/w  [ BAD ]
/usr/bin/watch  [ BAD ]
/usr/bin/wc  [ BAD ]
/usr/bin/wget  [ BAD ]
/usr/bin/whereis  [ BAD ]
/usr/bin/who  [ BAD ]
/usr/bin/whoami  [ BAD ]
Scanning for hidden files...  [ Warning! ]
-----------------------------------------------------------------

Can you explain me please, why is it a security vulnerability to not have a log 
file for each command ? 

Thanks a lot,
Omar, MailClub, administration services.



-- 




_______________________________________________
Omar Tchikou

Service administration - Mailclub.
http://www.mailclub.fr
04 88 66 22 02


-------------------------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc.
Still grepping through log files to find problems?  Stop.
Now Search log events and configuration files using AJAX and a browser.
Download your FREE copy of Splunk now >>  http://get.splunk.com/
_______________________________________________
Rkhunter-users mailing list
Rkhunter-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/rkhunter-users

Reply via email to