On Thu, 2012-06-14 at 16:14 -0600, Kevin Fenzi wrote:
> Greetings. 
> 
> When run on a Fedora 17 instance with the 'netatalk' package installed,
> I am seeing a false positive on the 'Spanish' rootkit: 
> 
> Warning: 'Spanish' Rootkit                        [ Warning ]
>          File '/bin/ad' found
> 
> This is of course /usr/bin/ad in the netatalk rpm, but due to the
> usrmove feature, /bin is just a link to /usr/bin. 
> 
> Perhaps we could detect this symlink case and not warn?
> 
Hi,

Catching up with old mail...
Was this problem resolved? You should be able to use
RTKT_FILE_WHITELIST=/bin/ad in the config file to whitelist the file.




John.

-- 
John Horne, Plymouth University, UK
Tel: +44 (0)1752 587287    Fax: +44 (0)1752 587001


------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Rkhunter-users mailing list
Rkhunter-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/rkhunter-users

Reply via email to