Re: [Rkhunter-users] Unhide testers wanted for Ruby version

2010-09-18 Thread John Horne
On Fri, 2010-09-17 at 19:18 +0200, Gouin Patrick wrote: > > On a totally different subject, rkhunter uses : > HIDDEN_PROCS=`${UNHIDE_CMD} sys | grep '^F' | awk -F':' '{ print $2 }'` > which is fine in all cases but one where "unhide sys" output is : > "HIDDEN Processes Found: number_of_hidden_p

Re: [Rkhunter-users] false postive

2010-09-18 Thread Alexander Griesser
Am 18.09.2010 21:42, Richard Spencer wrote: > [19:55:25] /usr/bin/curl [ Warning ] > [19:55:25] Warning: The file '/usr/bin/curl' exists on the system, but > it is not present in the rkhunter.dat file. This is most likely because you installed curl and haven't u

Re: [Rkhunter-users] false postive

2010-09-18 Thread Alexander Griesser
Am 18.09.2010 21:51, Richard Spencer wrote: > I dont recall installing curlthoughas i have a ubuntu > lucid but it might have come with the other thingsi have > installed as a dependence curl almost always comes as a dependency to something else. Since you're runn

[Rkhunter-users] false postive

2010-09-18 Thread Richard Spencer
[19:55:25] /usr/bin/curl [ Warning ] [19:55:25] Warning: The file '/usr/bin/curl' exists on the system, but it is not present in the rkhunter.dat file. -- Start uncovering the many advant

Re: [Rkhunter-users] USER_FILEPROP_FILES_DIRS file generates complaint

2010-09-18 Thread John Horne
On Sat, 2010-09-18 at 09:44 -0700, Geoffrey Leach wrote: > My rkhunter.conf has USER_FILEPROP_FILES_DIRS="!/usr/local/bin/perl" > and rkhunter --propupd has been run, yet, > -- Start Rootkit Hunter Scan -- > Warning: No hash value found for file '/usr/local/

[Rkhunter-users] USER_FILEPROP_FILES_DIRS file generates complaint

2010-09-18 Thread Geoffrey Leach
My rkhunter.conf has USER_FILEPROP_FILES_DIRS="!/usr/local/bin/perl" and rkhunter --propupd has been run, yet, -- Start Rootkit Hunter Scan -- Warning: No hash value found for file '/usr/local/bin/perl' in the rkhunter.dat file. Rootkit Hunter version 1.3.

[Rkhunter-users] New version of unhide

2010-09-18 Thread Gouin Patrick
Hi, After long testing, the last version of unhide (19-08-2010) is out. The main changes are : - Add new test 'procfs' (via readdir& chdir) - Add new test 'reverse' - Add new test 'quick' - Add option verbose (-v) to allow warning display - Add option morecheck (-m), only affect procfs test for