Things You Don't Want To Hear From Technical Support Published: Nov 26, 2003
  • Rating

    5/5

Rkhunter is a very useful tool that is used to check for trojans, rootkits, and other security problems.

Rkhunter is a very useful tool that is used to check for trojans, rootkits, and other security problems. This tutorial will touch on installing and setting up a daily report for rkhunter.

Update Aug. 23, 2005

Installing:

wget http://downloads.rootkit.nl/rkhunter-1.2.7.tar.gz
tar -zxvf rkhunter-1.2.7.tar.gz
cd rkhunter-1.2.7
./installer.sh

Now you can run a test scan with the following command:

/usr/local/bin/rkhunter -c

How to setup a daily scan report?

pico /etc/cron.daily/rkhunter.sh

add the following replacing your email address:

#!/bin/bash
(/usr/local/bin/rkhunter -c --cronjob 2>&1 | mail -s "Daily Rkhunter Scan Report" [email protected])

chmod +x /etc/cron.daily/rkhunter.sh

Updating rkhunter
gets the latest database updates from their central server and matches your OS better to prevent false positives.

rkhunter --update

 I just got a false positive!! What do i do?

False positives are warnings which indicates there is a problem, but aren't really a problem. Example: some Linux distro updated a few common used binaries like `ls` and `ps`. You (as a good sysadmin) update the new packages and run (ofcourse) daily Rootkit Hunter. Rootkit Hunter isn't yet aware of these new files and while scanning it resports some "bad" files. In this case we have a false positive. You could always have your datacenter or a system administrator check out the server to verify that it is not compromised.

More information on rkhunter can be found here: http://www.rootkit.nl

  • Rating

    5/5

Related Articles

Comments (3)

  • Gravatar - Daejuan Jacobs
    Daejuan Jacobs 02:52, December 16, 2003
    This is by far the funniest thing i've read all day,
    Really makes you think of what could happend. lol
  • Gravatar - lightme
    lightme 17:25, May 7, 2004
    jajajajja great.......and that is nothing compared whit the real anwser of a technical suport...of course, if they have time to suport you......... :D
  • Gravatar - Jonathan
    Jonathan 00:40, September 20, 2006
    Our building roof was on fire and the fireman disabled the electricity in the entire building..<br />
    <br />
    PS- Rackforce <_<

Add Your Thoughts

WebHostGear.com is a hosting directory, not a web host.

Copyright © 1998-2024 WebHostGear.com