Author Topic: Warnings from new install of rkhunter  (Read 153 times)

Offline peter_pclos

  • Full Member
  • ***
  • Posts: 158
Warnings from new install of rkhunter
« on: March 20, 2013, 11:15:34 AM »
After a number of attacks intercepted by a router firewall, plus an inadvertent opening of a suspect e-mail message, I decided that I really ought to do something to guard against rootkits, so installed rkhunter.

I started things up in accordance with the advice from Synaptic:

Quote
Please run rkhunter --propupd before running
rkhunter -c to check your files.

and was pleased to see the clean bill of health my system was getting.  However, as the check continued one of the sections contained two warnings:

Quote
Performing group and account checks
    Checking for passwd file                                 [ Found ]
    Checking for root equivalent (UID 0) accounts            [ None found ]
    Checking for passwordless accounts                       [ None found ]
    Checking for passwd file changes                         [ Warning ]
    Checking for group file changes                          [ Warning ]
    Checking root account shell history files                [ OK ]

Despite these warnings, the log file at /var/log/rkhunter.log appears to be empty.

Hopefully the two warnings are false positives, but if not, what do I need to do about them?

Offline µT6

  • Hero Member
  • *****
  • Posts: 2088
Re: Warnings from new install of rkhunter
« Reply #1 on: March 20, 2013, 12:08:05 PM »
about the things blocked by your router, that means that a attempt to reach your machine was stopped by the router, so the machine doesn't know about it

the mail, rarely could do anything on linux, unless it is a virus and you have wine installed, and that is easy to fix, i had installed viruses on wine just for the fun of seeing work, it is easy to stop wine service and delete the problematic file/virus

there should be a manual somewhere explaining what is a warning and what is the rest of the results given by this tool

i did a small search and found this

http://sourceforge.net/apps/trac/rkhunter/wiki/SPRKH

read the part where says scan manual and automatic, the important part, from what i understand is the result telling you what rootkits, suspicious files and and similar stuff was found or not found
« Last Edit: March 20, 2013, 12:12:28 PM by µT6 »
“Out of everything I've lost, I miss my mind the most!”

Ozzy Osbourne