On Tue, 2018-04-03 at 14:50 +0000, Mark Stosberg wrote:
> Chip,
>
> It looks like `rkhunter` stores it's files under `/var/lib/rkhunter`, so copy
> the known-good files from this directory to the questionable server. Expect
> some amount of differences to be reported. For example, the host name will be
> detected as changed.
>
You'll probably get a warning about most files since the inode will (most
likely) have changed.



John.

>     Mark
>
> On Tue, Apr 3, 2018 at 10:47 AM Chip <jeffsch...@gmail.com> wrote:
> > That actually sounds like a good idea - I hadn't thought of the VM
> > approach!  Thank you.
> >
> > Could I do as you suggested and then rather than compare signature by
> > signature which would be onerous, somehow export the signatures from the
> > known-good to the considered-bad?  And if so, what would be the process for
> > that?
> >
> > On 04/03/2018 10:42 AM, Mark Stosberg wrote:
> > > That is outside of the scope of rkhunter. The recommended practice is to
> > > start using rkhunter on a known-good system.
> > >
> > > If you want the correct signatures for a known-good Ubuntu 16.04 server,
> > > you can spin one one in a VM, fully patch it, and then compare file
> > > signatures between that server and yours.
> > >
> > > If you are concerned your box is compromised, there is always the safe
> > > approach of rebuilding it from a known-good state.
> > >
> > >     Mark
> > >
> > > On Tue, Apr 3, 2018 at 9:24 AM Chip <jeffsch...@gmail.com> wrote:
> > > > New to rkhunter.
> > > >
> > > > What is the logic behind using propupd with a system that is already or
> > > > potentially compromised?
> > > >
> > > > It would seem that a lot of people arrive at rkhunter suspicious that
> > > > their system has already been compromised.
> > > >
> > > > So how does someone actually update with propupd against *known* good
> > > > signatures that reside *outside* their box?
> > > >
> > > > Thank you.
> > > >
> > > > ---------------------------------------------------------------------
> > > > ---------
> > > > Check out the vibrant tech community on one of the world's most
> > > > engaging tech sites, Slashdot.org! http://sdm.link/slashdot
> > > > _______________________________________________
> > > > Rkhunter-users mailing list
> > > > Rkhunter-users@lists.sourceforge.net
> > > > https://lists.sourceforge.net/lists/listinfo/rkhunter-users
> > > >
> > > --
> > >  Mark Stosberg
> > >
> > >  Senior Systems Engineer | RideAmigos | 765-277-1916 | m...@rideamigos.co
> > > m
>
> --
> Mark Stosberg
> Senior Systems Engineer | RideAmigos | 765-277-1916 | m...@rideamigos.com
> ---------------------------------------------------------------------------
> ---
> Check out the vibrant tech community on one of the world's most
> engaging tech sites, Slashdot.org! http://sdm.link/slashdot
> _______________________________________________
> Rkhunter-users mailing list
> Rkhunter-users@lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/rkhunter-users
--
John Horne | Senior Operations Analyst | Technology and Information Services
University of Plymouth | Drake Circus | Plymouth | Devon | PL4 8AA | UK
________________________________
[http://www.plymouth.ac.uk/images/email_footer.gif]<http://www.plymouth.ac.uk/worldclass>

This email and any files with it are confidential and intended solely for the 
use of the recipient to whom it is addressed. If you are not the intended 
recipient then copying, distribution or other use of the information contained 
is strictly prohibited and you should not rely on it. If you have received this 
email in error please let the sender know immediately and delete it from your 
system(s). Internet emails are not necessarily secure. While we take every 
care, Plymouth University accepts no responsibility for viruses and it is your 
responsibility to scan emails and their attachments. Plymouth University does 
not accept responsibility for any changes made after it was sent. Nothing in 
this email or its attachments constitutes an order for goods or services unless 
accompanied by an official order form.
------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
Rkhunter-users mailing list
Rkhunter-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/rkhunter-users

Reply via email to