On Mon, 2019-10-28 at 10:20 +0000, Koblenz Thomas wrote: > Hi > > the whitelist is working, I see that in the logs. but I still get a warning > via e-mail. > > Info: Found process pathname '/opt/commvault2/Base64/cvd': it is whitelisted. > > Is it possible to disable e-mail warnings for whitelisted things? > Would you send me a copy of the log file please? Or at least the part containing the output from the whole of the test.
Thanks, John. > > > -----Ursprüngliche Nachricht----- > Von: Al Varnell <alvarn...@mac.com> > Gesendet: Montag, 28. Oktober 2019 09:27 > An: RKHunter-Users <rkhunter-users@lists.sourceforge.net> > Cc: Koblenz Thomas <thomas.kobl...@zeppelin.com> > Betreff: Re: [Rkhunter-users] Suspicious Shared Memory segments | warning per > mail > > On Mon, Oct 28, 2019 at 00:31 AM, Koblenz Thomas wrote: > > Hello, > > > > I have a problem with a false-positive for Suspicious Shared Memory > > segments. Since the last update of the Commvault Agent I always get > > warnings for Suspicious Shared Memory segments. > > > > [08:18:25] Process: /opt/commvault/Base64/cvd PID: 758 Owner: root > > [ Found ] > > [08:18:25] Process: /opt/commvault/Base64/cvd PID: 758 Owner: root > > [ Found ] > > > > > > I have already made the following entry in the rkhunter.log > > ALLOWIPCPROC= "/opt/commvault/Base64/cvd > > I suspect you meant to say in the rkhunter.conf file, but I think the error > is in placing a space and quote before the path. Shouldn't it read: > ALLOWIPCPROC=/opt/commvault/Base64/cvd > > -Al- > > > Unfortunately we still get mails informing us about a warning. Is it > > possible to configure rkhunter to stop sending mail when a whitelist has > > been configured? > > > > Version : Rootkit Hunter 1.4.2, Deb9.11 > > > > > > > > Thomas > > [K FAIR] > Um mehr über unser komplettes Produktportfolio zu erfahren, laden Sie unsere > neue kostenlose PLANT.BOOK-App in Ihrem Apple App Store< > https://itunes.apple.com/us/app/plantbook/id1287430289?mt=8> und Microsoft > Store< > https://www.microsoft.com/en-us/p/plantbook/9nt0fm3hssls?source=lp&activetab=pivot%3Aoverviewtab > > herunter. > To find more details about our complete product portfolio, download our new > free PLANT.BOOK app from your Apple App Store< > https://itunes.apple.com/us/app/plantbook/id1287430289?mt=8> and Microsoft > Store< > https://www.microsoft.com/en-us/p/plantbook/9nt0fm3hssls?source=lp&activetab=pivot%3Aoverviewtab> > ;. > > [ > https://www.zeppelin-systems.com/files/website.png]<https://www.zeppelin-systems.com/videos.html > > [https://www.zeppelin-systems.com/files/newsletter.png] < > https://www.zeppelin-systems.com/en/meta/newsletter.html> [ > https://www.zeppelin-systems.com/files/youtube.png] < > https://www.youtube.com/channel/UC3zqgeXXj7i1-CNwr6sUW5w/playlists> > ________________________________________ > > Zeppelin Systems GmbH > Handelsregister - Commercial Register: AG Ulm HRB 729780 > Sitz - Registered Domicile: D-88045 Friedrichshafen > > Aufsichtsratsvorsitzender - Chairman of the supervisory board: Peter > Gerstmann > Geschäftsführung - Management board: Alexander Wassermann (Vorsitzender - > Chairman), Rochus C. Hofmann > ________________________________________ > > > _______________________________________________ > Rkhunter-users mailing list > Rkhunter-users@lists.sourceforge.net > https://lists.sourceforge.net/lists/listinfo/rkhunter-users -- John Horne | Senior Operations Analyst | Technology and Information Services University of Plymouth | Drake Circus | Plymouth | Devon | PL4 8AA | UK ________________________________ [http://www.plymouth.ac.uk/images/email_footer.gif]<http://www.plymouth.ac.uk/worldclass> This email and any files with it are confidential and intended solely for the use of the recipient to whom it is addressed. If you are not the intended recipient then copying, distribution or other use of the information contained is strictly prohibited and you should not rely on it. If you have received this email in error please let the sender know immediately and delete it from your system(s). Internet emails are not necessarily secure. While we take every care, University of Plymouth accepts no responsibility for viruses and it is your responsibility to scan emails and their attachments. University of Plymouth does not accept responsibility for any changes made after it was sent. Nothing in this email or its attachments constitutes an order for goods or services unless accompanied by an official order form. _______________________________________________ Rkhunter-users mailing list Rkhunter-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/rkhunter-users