On Tue, 2007-09-25 at 19:02 +0300, sdn wrote:
> Hello
> In a debian SID with rkhunter 1.3.0-1 i get the following warnings:
> 
> #----------------------------------------------------------------------------------------------------------
> 
> Warning: The command '/usr/sbin/ifstatus' has been replaced by a 
> script: /usr/sbin/ifstatus: POSIX shell script text executable
>
Look in the config file, valid script commands can be whitelisted.


> Warning: The SSH and rkhunter configuration options should be the same:
>          SSH configuration option 'PermitRootLogin': yes
>          Rkhunter configuration option 'ALLOW_SSH_ROOT_USER': no
>
You allow 'root' to login directly using SSH. This is not generally
recommended, so the RKH default is 'no'. To avoid the warning you must
set the configuration file value the same as in your sshd_config file.
(That is, set it to 'yes' in the config file.)

> Warning: Suspicious files found in /dev:
>          /dev/shm/network/ifstate: ASCII text
>
This is from the suspcious files test, which is not enabled by default
because it may give false positives.

> Warning: Hidden directory found: /etc/.java
> Warning: Hidden directory found: /dev/.static
> Warning: Hidden directory found: /dev/.udev
> Warning: Hidden directory found: /dev/.initramfs
> Warning: Hidden file found: /usr/share/man/man8/.isdnctrl_conf.8.gz: gzip 
> compressed data, was ".isdnctrl_conf.8", from Unix, last modified: Tue Feb 27 
> 19:55:55 2007, max compression
>
Valid hidden files/dirs can be whitelisted in the config file.

> /usr/bin/rkhunter: line 10003: [: -eq: unary operator expected
> /usr/bin/rkhunter: line 10006: [: -eq: unary operator expected
> /usr/bin/rkhunter: line 10003: [: Warning:: integer expression expected
> /usr/bin/rkhunter: line 10006: [: Warning:: integer expression expected
> /usr/bin/rkhunter: line 10003: [: Warning:: integer expression expected
> /usr/bin/rkhunter: line 10006: [: Warning:: integer expression expected
> /usr/bin/rkhunter: line 10003: [: Warning:: integer expression expected
> /usr/bin/rkhunter: line 10006: [: Warning:: integer expression expected
> /usr/bin/rkhunter: line 10003: [: Warning:: integer expression expected
> /usr/bin/rkhunter: line 10006: [: Warning:: integer expression expected
> /usr/bin/rkhunter: line 10003: [: Warning:: integer expression expected
> /usr/bin/rkhunter: line 10006: [: Warning:: integer expression expected
> /usr/bin/rkhunter: line 10003: [: Warning:: integer expression expected
> /usr/bin/rkhunter: line 10006: [: Warning:: integer expression expected
> 
Can you run 'rkhunter --debug --enable apps'. It won't produce any
output on the screen, but will create the file '/tmp/rkhunter-debug'.
Send me, not the list, the file please.


John.

-- 
---------------------------------------------------------------
John Horne, University of Plymouth, UK  Tel: +44 (0)1752 233914
E-mail: [EMAIL PROTECTED]       Fax: +44 (0)1752 233839

-------------------------------------------------------------------------
This SF.net email is sponsored by: Microsoft
Defy all challenges. Microsoft(R) Visual Studio 2005.
http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/
_______________________________________________
Rkhunter-users mailing list
Rkhunter-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/rkhunter-users

Reply via email to