On Mon, 2018-02-05 at 10:05 +0000, Stefan Wolber wrote: > Sorry to molest you but I want my system to be malware free. I searched for > this topic about 2 hours in the internet but couldn´t find an answer. > I have a linux server at server4you (administration by Plesk) with debian > wheezy (7) and rkhunter 1.4.4. > I am little bit confused why rkhunter is skipping the checks for kernel > symbols like “Checking for kernel symbol 'heroin' [ Skipped ]”. > rkhunter does that numerous times. > This is because rkhunter cannot find either the /proc/ksyms or /proc/kallsyms file. Looking at one of our Debian 7 servers, I can see that it has the '/proc/kallsyms' file. The test will be run for each rootkit that uses kernel symbols, that is why it appears so often. I can only think that perhaps some hardening software is preventing access to it?
> I did specify in the rkhunter.conf.local DISABLE_TESTS=os_specific)? > Why? There are specific test for Linux systems, so why not run them. John. -- John Horne | Senior Operations Analyst | Technology and Information Services University of Plymouth | Drake Circus | Plymouth | Devon | PL4 8AA | UK ________________________________ [http://www.plymouth.ac.uk/images/email_footer.gif]<http://www.plymouth.ac.uk/worldclass> This email and any files with it are confidential and intended solely for the use of the recipient to whom it is addressed. If you are not the intended recipient then copying, distribution or other use of the information contained is strictly prohibited and you should not rely on it. If you have received this email in error please let the sender know immediately and delete it from your system(s). Internet emails are not necessarily secure. While we take every care, Plymouth University accepts no responsibility for viruses and it is your responsibility to scan emails and their attachments. Plymouth University does not accept responsibility for any changes made after it was sent. Nothing in this email or its attachments constitutes an order for goods or services unless accompanied by an official order form. ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot _______________________________________________ Rkhunter-users mailing list Rkhunter-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/rkhunter-users