WebHostGear.com - the hosting resource for professionalshosting tutorials 
hosting howto webhost guide server managementFebruary 09, 2010
server management, apache tutorials, hosting tutorials, cpanel, server security
Home / Hosting Tutorials / Server Security / Rkhunter Installation

Rkhunter Installation



Printer Friendly Printer Friendly Send to a friend Send to a friend
By : Rack911 Rating : Average Rating : 7.80 From 49 Voter(s)

Rkhunter is a very useful tool that is used to check for trojans, rootkits, and other security problems. This tutorial will touch on installing and setting up a daily report for rkhunter.

Update Aug. 23, 2005

Installing:

wget http://downloads.rootkit.nl/rkhunter-1.2.7.tar.gz
tar -zxvf rkhunter-1.2.7.tar.gz
cd rkhunter-1.2.7
./installer.sh

Now you can run a test scan with the following command:

/usr/local/bin/rkhunter -c

How to setup a daily scan report?

pico /etc/cron.daily/rkhunter.sh

add the following replacing your email address:

#!/bin/bash
(/usr/local/bin/rkhunter -c --cronjob 2>&1 | mail -s "Daily Rkhunter Scan Report" email@domain.com)

chmod +x /etc/cron.daily/rkhunter.sh

Updating rkhunter
gets the latest database updates from their central server and matches your OS better to prevent false positives.

Article provided by WebHostGear.com

rkhunter --update

 I just got a false positive!! What do i do?

False positives are warnings which indicates there is a problem, but aren't really a problem. Example: some Linux distro updated a few common used binaries like `ls` and `ps`. You (as a good sysadmin) update the new packages and run (ofcourse) daily Rootkit Hunter. Rootkit Hunter isn't yet aware of these new files and while scanning it resports some "bad" files. In this case we have a false positive. You could always have your datacenter or a system administrator check out the server to verify that it is not compromised.

More information on rkhunter can be found here: http://www.rootkit.nl

New! - Need server help? Hire an Expert

Get professional help with your configuration, script installation or server issue.
Learn how we can help you with any server problem and make your server run like new. Professional staff will contact you, after submitting a quote request, by phone or email.

Rate this Article :

1

2

3

4

5

6

7

8

9

10
Poor Excellent

Related Articles


Guide to Chkrootkit - checking for intruders
Creating a Welcome message for SSH logins
Securing Your /tmp Partition with Cpanel/WHM
How to install BFD (Brute Force Detection)
How to install APF (Advanced Policy Firewall)
How to install mod_security for Apache
Installing DrWEB server antivirus for Linux CPanel
Compile 2.6.7 Kernel w/module-init-tools
Preventing Brute Force Attacks


Discuss this article with others in our new hosting forums

Comments / Feedback

Chris
You should update this to:

wget http://downloads.rootkit.nl/rkhunter-1.1.6.tar.gz
mct
make that 1.1.9 as of 12/28/04. :)
Amr
wget http://downloads.rootkit.nl/rkhunter-1.2.1.tar.gz

as of 16 March 2005
mjm
updated yet again:

wget http://downloads.rootkit.nl/rkhunter-1.2.5.tar.gz

05-05-2005
Brad
Make that 1.2.7 as of 6/18/05
accyroy
updated again...

wget http://downloads.rootkit.nl/rkhunter-1.2.7.tar.gz

BoO_SuLtAn
The Latest Version Is :

http://downloads.rootkit.nl/rkhunter-1.2.7.tar.gz

Best Regards"
Arif Kanji
Hi,
How do u make a scan at (for example) 3am everyday.
Cheers
Miguel Costa
Hy

New version:)

wget http://downloads.rootkit.nl/rkhunter-1.2.8.tar.gz
harry
Very helpful for level3 issues
Chanchal
The following binaries to be reported bad while checking Red Hat Linux release 9 (Shrike) servers using rkhunter. Checked 3 servers and confirmed on all.

/bin/dmesg [ BAD ]
/bin/kill [ BAD ]
/bin/login [ BAD ]
/bin/mount [ BAD ]

The package installed is util-linux-2.11y-9.2.legacy
Will
New version:

wget http://downloads.rootkit.nl/rkhunter-1.2.9.tar.gz
Mahdi
whats the new version link
i can not open the downloads.rootkit.nl url :(
please take te new version download link
cdixon311
http://superb-east.dl.sourceforge.net/sourceforge/rkhunter/rkhunter-1.3.0.tar.gz

It seems there is a latter version out now.
Ritesh
Error while running rkhunter

rkhunter-1.3.0

/usr/local/bin/rkhunter -c
Default logfile will be used (/var/log/rkhunter.log).
The internationalisation directory does not exist: /var/rkhunter/db/i18n

 Add Comment
Name
Email
Image Code
Refresh Image

Comments / Feedback



Our site offers free hosting tutorials, cpanel tutorial, web hosting news, shell commands, running a web hosting business, dedicated guides, linux tutorial, apache install, home web server, web server guide, ssh commands, dedicated servers, DNS nameservers, chkrootkit, apf firewall, exim configuration, server compromised, cron backup solution, ftp backup script

Server Tutorials


WebHostGear Reviewed by Ping Zine - Click here

Links:
Lunarpages Coupon