Bug#626643: rkhunter: Multiple ALLOWPROCDELFILE options not working anymore

2011-05-13 Thread Francois Marier
Package: rkhunter Version: 1.3.8-4 Severity: normal Among other things, when the daily cronjob runs, I get the following processes with open deleted files: Process: /usr/bin/kdeinit4PID: 599File: /dev/pts/2 Process: /usr/bin/gnome-terminalPID: 4971File: /tmp/vteLAK4UV If I

Bug#751347: grep: write error

2014-07-19 Thread Francois Marier
that error even means. There's plenty of free space on all of my disk partitions. Francois -- Francois Marier identi.ca/fmarier http://fmarier.org twitter.com/fmarier ___ forensics-devel mailing list forensics-devel

Bug#743725: Fixed in 1.4.2-0.1 NMU

2014-10-14 Thread Francois Marier
I have just uploaded an NMU of the latest upstream to the DELAYED/4 queue. If it's accepted, it will hopefully bring that version to jessie. Francois -- Francois Marier identi.ca/fmarier http://fmarier.org twitter.com/fmarier

Bug#765911: rkhunter: 1.4.2-0.1 breaks the apt hook

2014-10-19 Thread Francois Marier
Package: rkhunter Version: 1.4.2-0.1 Severity: normal The last NMU broke the apt hook. After installing/remove packages, we now get the following error message: Invalid SCRIPTWHITELIST configuration option: Non-existent pathname: /usr/sbin/prelink E: Problem executing scripts

Bug#765912: rkhunter: 1.4.2-0.2 NMU

2014-10-19 Thread Francois Marier
+ + * Non-maintainer upload. + * Fix apt hook (closes: #765911) + * Mention unhide.rb in conffile comment (closes: #765878) + + -- Francois Marier franc...@debian.org Sun, 19 Oct 2014 20:07:10 +1300 + rkhunter (1.4.2-0.1) unstable; urgency=medium * Non-maintainer upload. diff -Nru rkhunter

Bug#766096: rkhunter: The daily cronjob in 1.4.2-0.2 has warnings

2014-10-20 Thread Francois Marier
Package: rkhunter Version: 1.4.2-0.2 Severity: normal rkhunter sends the following email once a day: From: root root@hostname To: root@hostname Subject: [rkhunter] hostname - Daily report Invalid RTKT_FILE_WHITELIST configuration option: Non-existent pathname:

Bug#768396: rkhunter: 1.4.2-0.3 NMU

2014-11-06 Thread Francois Marier
IPCS command on non-English locales (closes: #767731) + + -- Francois Marier franc...@debian.org Fri, 07 Nov 2014 14:34:19 +1300 + rkhunter (1.4.2-0.2) unstable; urgency=medium * Non-maintainer upload. diff -Nru rkhunter-1.4.2/debian/patches/20_fix-ipcs-language.diff rkhunter-1.4.2/debian

Bug#770242: Tentative patch

2014-11-28 Thread Francois Marier
The attached patch fixes installation when /etc/rkhunter.conf is missing. -- Francois Marier identi.ca/fmarier http://fmarier.org twitter.com/fmarier commit f91d229ad51b19d52b979720f8a1edf1e2aea385 Author: Francois Marier franc...@debian.org Date: Sat Nov 29 00:27:20 2014 +1300

Bug#770242: Broken postinst script?

2014-11-28 Thread Francois Marier
This bug looks similar to https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=765911 which got fixed in 1.4.2-0.3 by removing the /usr/sbin/prelink line from the config file. I've chosen to keep currently-installed version of /etc/rkhunter.conf That's a problem and won't work because the

Re: rkhunter is marked for autoremoval from testing

2014-11-28 Thread Francois Marier
On 2014-11-28 at 12:29:53, Michael Prokop wrote: * Francois Marier [Sat Nov 29, 2014 at 12:07:49AM +1300]: On 2014-11-28 at 11:08:13, Michael Prokop wrote: * Debian testing autoremoval watch [Thu Nov 27, 2014 at 04:39:04AM +]: rkhunter 1.4.2-0.3 is marked for autoremoval from testing

Bug#765902: Suggestion?

2015-04-26 Thread Francois Marier
Hi Christoph, I just pushed out a big update (1.4.2-1) to the dependencies and have addressed a few of the things you pointed out. Would you like to suggest actual wording (for the package description) for the suggests/recommends that are left? Francois

Bug#765898: rkhunter: default values of file/command/pathname exceptions

2015-04-28 Thread Francois Marier
On 2015-04-29 11:15, Christoph Anton Mitterer wrote: #SYSLOG_CONFIG_FILE=/etc/syslog.conf = while rkhunter will determine this automatically, it may still be nice to set it to /etc/rsyslog.conf on Debian, since rsyslog is the default I'm not sure I enough about this (since it's working)

Bug#791486: /usr/bin/rkhunter: 7439: [: Binary: unexpected operator

2015-08-03 Thread Francois Marier
On 2015-07-05 at 16:52:04, Pedro Beja wrote: doing an update I get the following error line: $ sudo rkhunter --update [snip] /usr/bin/rkhunter: 7439: [: Binary: unexpected operator Checking file i18n/tr[ No update ] Checking file i18n/tr.utf8

Bug#816170: False positive deleted files after upgrade from wheezy to jessie

2016-07-03 Thread Francois Marier
On 2016-04-26 at 13:50:21, Klaus Ethgen wrote: > Find attached a patch, cherry-picked from upstream, that fixes the > issue. Particular, it is c4d6d8b, 1e5e79a and b4a21a8. Which upstream repo did you pull that from? The only repo I know about is a CVS one on Sourceforge:

Bug#865972: #865972 - same problem of false positive regarding PermitRootLogin parameter

2017-08-09 Thread Francois Marier
On 2017-08-08 at 18:57:25, Jean-Marc wrote: > So, if the default value "prohibit-password" is secure enough, maybe changing > this line > > ALLOW_SSH_ROOT_USER=unset > > can solve this. It looks fine to me, but I'm not entirely sure that we should stop recommending that root logins be

Bug#868099: rkhunter: clean up legacy conffile

2017-07-11 Thread Francois Marier
On 2017-07-12 at 02:50:27, Christoph Anton Mitterer wrote: > Apparently the package used to contain: > /etc/default/rkhunter > as a dpkg conffile but no longer does and ships it manually managed instead. > > This file was however not properly cleaned up as conffile and is still marked > as such.

Re: Wheezy update of rkhunter?

2017-07-02 Thread Francois Marier
On 2017-07-02 at 16:46:40, Thorsten Alteholz wrote: > The Debian LTS team would like to fix the security issues which are > currently open in the Wheezy version of rkhunter: > https://security-tracker.debian.org/tracker/CVE-2017-7480 > > Would you like to take care of this yourself? I'm thinking

Accepted rkhunter 1.4.6-1 (source all) into unstable

2018-02-25 Thread Francois Marier
hanged-By: Francois Marier <franc...@debian.org> Description: rkhunter - rootkit, backdoor, sniffer and exploit scanner Closes: 848666 887210 Changes: rkhunter (1.4.6-1) unstable; urgency=medium . * New upstream release . * Bump Standards-Version up to 4.1.3 * Bump debhelper compati

Accepted rkhunter 1.4.6-2 (source all) into unstable

2018-03-04 Thread Francois Marier
hanged-By: Francois Marier <franc...@debian.org> Description: rkhunter - rootkit, backdoor, sniffer and exploit scanner Closes: 892012 Changes: rkhunter (1.4.6-2) unstable; urgency=medium . [ Raphaƫl Hertzog ] * Update team maintainer address to Debian Security Tools . [ Fra