WebHostGear.com - the hosting resource for professionalshosting tutorials 
hosting howto webhost guide server managementJuly 23, 2008
server management, apache tutorials, hosting tutorials, cpanel, server security
Home / Hosting Tutorials / Server Security / Rkhunter Installation

Rkhunter Installation



Printer Friendly Printer Friendly Send to a friend Send to a friend
By : Rack911 Rating : Average Rating : 8.05 From 40 Voter(s)

Rkhunter is a very useful tool that is used to check for trojans, rootkits, and other security problems. This tutorial will touch on installing and setting up a daily report for rkhunter.

Update Aug. 23, 2005

Installing:

wget http://downloads.rootkit.nl/rkhunter-1.2.7.tar.gz
tar -zxvf rkhunter-1.2.7.tar.gz
cd rkhunter-1.2.7
./installer.sh

Now you can run a test scan with the following command:

/usr/local/bin/rkhunter -c

How to setup a daily scan report?

pico /etc/cron.daily/rkhunter.sh

add the following replacing your email address:

#!/bin/bash
(/usr/local/bin/rkhunter -c --cronjob 2>&1 | mail -s "Daily Rkhunter Scan Report" email@domain.com)

chmod +x /etc/cron.daily/rkhunter.sh

Updating rkhunter
gets the latest database updates from their central server and matches your OS better to prevent false positives.

Article provided by WebHostGear.com
rkhunter --update

 I just got a false positive!! What do i do?



Article provided by WebHostGear.com

False positives are warnings which indicates there is a problem, but aren't really a problem. Example: some Linux distro updated a few common used binaries like `ls` and `ps`. You (as a good sysadmin) update the new packages and run (ofcourse) daily Rootkit Hunter. Rootkit Hunter isn't yet aware of these new files and while scanning it resports some "bad" files. In this case we have a false positive. You could always have your datacenter or a system administrator check out the server to verify that it is not compromised.

More information on rkhunter can be found here: http://www.rootkit.nl

New! - Need server help? Hire an Expert

Get professional help with your configuration, script installation or server issue.
Learn how we can help you with any server problem and make your server run like new. Professional staff will contact you, after submitting a quote request, by phone or email.

Rate this Article :

1

2

3

4

5

6

7

8

9

10
Poor Excellent

Related Articles


» Guide to Chkrootkit - checking for intruders
» Creating a Welcome message for SSH logins
» Securing Your /tmp Partition with Cpanel/WHM
» How to install BFD (Brute Force Detection)
» How to install APF (Advanced Policy Firewall)
» How to install mod_security for Apache
» Installing DrWEB server antivirus for Linux CPanel
» Compile 2.6.7 Kernel w/module-init-tools
» Preventing Brute Force Attacks


Discuss this article with others in our new hosting forums

Comments / Feedback

Chris
You should update this to:

wget http://downloads.rootkit.nl/rkhunter-1.1.6.tar.gz
mct
make that 1.1.9 as of 12/28/04. :)
Amr
wget http://downloads.rootkit.nl/rkhunter-1.2.1.tar.gz

as of 16 March 2005
mjm
updated yet again:

wget http://downloads.rootkit.nl/rkhunter-1.2.5.tar.gz

05-05-2005
Brad
Make that 1.2.7 as of 6/18/05
accyroy
updated again...

wget http://downloads.rootkit.nl/rkhunter-1.2.7.tar.gz

BoO_SuLtAn
The Latest Version Is :

http://downloads.rootkit.nl/rkhunter-1.2.7.tar.gz

Best Regards"
Arif Kanji
Hi,
How do u make a scan at (for example) 3am everyday.
Cheers
Miguel Costa
Hy

New version:)

wget http://downloads.rootkit.nl/rkhunter-1.2.8.tar.gz
harry
Very helpful for level3 issues
Chanchal
The following binaries to be reported bad while checking Red Hat Linux release 9 (Shrike) servers using rkhunter. Checked 3 servers and confirmed on all.

/bin/dmesg [ BAD ]
/bin/kill [ BAD ]
/bin/login [ BAD ]
/bin/mount [ BAD ]

The package installed is util-linux-2.11y-9.2.legacy
Will
New version:

wget http://downloads.rootkit.nl/rkhunter-1.2.9.tar.gz
Mahdi
whats the new version link
i can not open the downloads.rootkit.nl url :(
please take te new version download link
cdixon311
http://superb-east.dl.sourceforge.net/sourceforge/rkhunter/rkhunter-1.3.0.tar.gz

It seems there is a latter version out now.
Ritesh
Error while running rkhunter

rkhunter-1.3.0

/usr/local/bin/rkhunter -c
Default logfile will be used (/var/log/rkhunter.log).
The internationalisation directory does not exist: /var/rkhunter/db/i18n

 Add Comment
Name
Email
Image Code
Refresh Image

Comments / Feedback



Web Hosting News RSS ?


WebHostGear Hire an Expert - NEW!
Let us improve your servers performance, find that spammer and take care of that kernel upgrade. Hire us to help with any tutorials listed on the site or any other services needed. Get your free, NO obligation quote now

Our site offers free hosting tutorials, cpanel tutorial, web hosting news, shell commands, running a web hosting business, dedicated guides, linux tutorial, apache install, home web server, web server guide, ssh commands, dedicated servers, DNS nameservers, chkrootkit, apf firewall, exim configuration, server compromised, cron backup solution, ftp backup script

Server Tutorials


WebHostGear Reviewed by Ping Zine - Click here

Special Offer:


Links:
cPanel server administration

MidPhase Coupons

Reseller Hosting

Reseller Hosting FAQ

Icon

Web Hosting

Datacenter Discussion Forum

Lunarpages Coupon

Hosting Coupon



WebhostGear Sponsors
Going Up Advertise Hosting Free Uptime Check Web Hosting Chat Icons Banners Mall