On Sat, Nov 20, 2010 at 03:50:48PM -0800, Al Varnell wrote:
> On 11/20/10 3:26 PM, "Robert Holtzman" <hol...@cox.net> wrote:
>

            ..........snip..........
 
> > Will --update update to 1.3.8? I'm running the Ubuntu version of 1.3.6-3
> > 
> According to the man "This command option causes rkhunter to check if there
> is a later version of any of its text data files." so it would only update
> the database and not update to 1.3.8.

I missed that inference when I read the man page. 

> 
> > and --update yielded this:
> > 
> > hol...@localhost:~$ sudo rkhunter --update
> > [sudo] password for holtzm:
> > [ Rootkit Hunter version 1.3.6 ]
> > 
> > Checking rkhunter data files...
> >   Checking file mirrors.dat                                  [ No update]
> >   Checking file programs_bad.dat                             [ No update]
> >   Checking file backdoorports.dat                            [ No update]
> >   Checking file suspscan.dat                                 [ No update]
> >   Checking file i18n/cn                                      [ No update]
> >   Checking file i18n/de                                      [ No update]
> >   Checking file i18n/en                                      [ No update]
> >   Checking file i18n/zh                                      [ No update]
> >   Checking file i18n/zh.utf8                                 [ No update]
> > 
> > Any ideas?
> > 
> These are all stored in /private/var/lib/rkhunter/db/.  Check if they are
> all dated Nov 17.  If so then you must have run --update it since then.

hol...@localhost:~$ sudo ls -l /var/lib/rkhunter/db
total 68
-rw-r----- 1 root root  1055 2010-11-18 16:45 backdoorports.dat
drwxr-x--- 2 root root  4096 2010-08-30 16:32 i18n
-rw-r----- 1 root root    58 2010-11-20 16:09 mirrors.dat
-rw-r----- 1 root root  3203 2010-11-18 16:44 programs_bad.dat
-rw-r----- 1 root root 12303 2010-08-30 16:32 rkhunter.dat
-rw-r----- 1 root root 12301 2010-07-05 14:03 rkhunter.dat.old
-rw-r----- 1 root root 15977 2010-11-20 12:41 rkhunter_prop_list.dat
-rw-r----- 1 root root  1904 2010-04-06 06:21 suspscan.dat

I ran --update today (the 20th). Note the dates on the backdoorports.dat,
programs_bad.dat, and suspscan.dat files.

> If not, then I don't know as much as I thought I did about the process.

Me either. Thanks.

Out of curiosity, what OS are you running? Ubuntu has no /private
directory.

-- 
Bob Holtzman
Key ID: 8D549279
"If you think you're getting free lunch,
 check the price of the beer"

Attachment: signature.asc
Description: Digital signature

------------------------------------------------------------------------------
Beautiful is writing same markup. Internet Explorer 9 supports
standards for HTML5, CSS3, SVG 1.1,  ECMAScript5, and DOM L2 & L3.
Spend less time writing and  rewriting code and more time creating great
experiences on the web. Be a part of the beta today
http://p.sf.net/sfu/msIE9-sfdev2dev
_______________________________________________
Rkhunter-users mailing list
Rkhunter-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/rkhunter-users

Reply via email to