Re: rkhunter question

2009-10-24 Thread Bill Davidsen
Frank Murphy (Frankly3D) wrote: On 23/10/09 14:39, François Patte wrote: Frank Murphy (Frankly3D) a écrit : On 23/10/09 12:09, François Patte wrote: Bonjour, --snip-- Have you updated any files with yum\PackageKit? Installed new packages with yum. If the updateed pkgs names, match the

rkhunter question

2009-10-23 Thread François Patte
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Bonjour, rkhunter is running daily on my machine and for a while now I have this kind of message: [ Rootkit Hunter version 1.3.4 ] Checking rkhunter data files... Checking file mirrors.dat[ No update Checking file programs_bad.dat [

Re: rkhunter question

2009-10-23 Thread Frank Murphy (Frankly3D)
On 23/10/09 12:09, François Patte wrote: Bonjour, --snip-- Today: Warning: Package manager verification has failed: File: /bin/rpm Try running the command 'prelink /bin/rpm' to resolve dependency errors. The file hash value has changed The

Re: rkhunter question

2009-10-23 Thread John Horne
On Fri, 2009-10-23 at 13:09 +0200, François Patte wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Bonjour, rkhunter is running daily on my machine and for a while now I have this kind of message: [ Rootkit Hunter version 1.3.4 ] Checking rkhunter data files... Checking file

Re: rkhunter question

2009-10-23 Thread François Patte
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Frank Murphy (Frankly3D) a écrit : On 23/10/09 12:09, François Patte wrote: Bonjour, --snip-- Today: Warning: Package manager verification has failed: File: /bin/rpm Try running the command 'prelink /bin/rpm' to resolve

Re: rkhunter question

2009-10-23 Thread Frank Murphy (Frankly3D)
On 23/10/09 14:39, François Patte wrote: Frank Murphy (Frankly3D) a écrit : On 23/10/09 12:09, François Patte wrote: Bonjour, --snip-- Have you updated any files with yum\PackageKit? Installed new packages with yum. If the updateed pkgs names, match the rkhunter changed pkgs. That

Re: Another rkhunter question

2009-05-18 Thread Bill Davidsen
Paulo Cavalcanti wrote: On Sun, May 17, 2009 at 10:35 AM, Gene Heskett gene.hesk...@verizon.net mailto:gene.hesk...@verizon.net wrote: Greetings all; What is /dev/shm? I've given up on rkhunter ever shutting up about the group and passwd files, but fussing about this

Re: Another rkhunter question

2009-05-18 Thread Gene Heskett
On Monday 18 May 2009, Bill Davidsen wrote: Paulo Cavalcanti wrote: On Sun, May 17, 2009 at 10:35 AM, Gene Heskett gene.hesk...@verizon.net mailto:gene.hesk...@verizon.net wrote: Greetings all; What is /dev/shm? I've given up on rkhunter ever shutting up about the group and

Re: Another rkhunter question

2009-05-18 Thread Tim
On Mon, 2009-05-18 at 16:34 -0400, Bill Davidsen wrote: And might you ever accidentally have used it as root? Just looking at the name, I know you're old enough to know better. ;-) Harrumph! ;-) We *know* he does things as root, *we* know that's a bad idea in general, *we* also know that the

Re: Another rkhunter question

2009-05-18 Thread Gene Heskett
On Monday 18 May 2009, Tim wrote: On Mon, 2009-05-18 at 16:34 -0400, Bill Davidsen wrote: And might you ever accidentally have used it as root? Just looking at the name, I know you're old enough to know better. ;-) Harrumph! ;-) We *know* he does things as root, *we* know that's a bad idea in

Another rkhunter question

2009-05-17 Thread Gene Heskett
Greetings all; What is /dev/shm? I've given up on rkhunter ever shutting up about the group and passwd files, but fussing about this is new. -- Start Rootkit Hunter Scan -- Warning: Suspicious file types found in /dev: /dev/shm/sem.ADBE_REL_root:

Re: Another rkhunter question

2009-05-17 Thread Georgi Hristozov
Hi, On 17/05/09 16:35, Gene Heskett wrote: Greetings all; What is /dev/shm? I've given up on rkhunter ever shutting up about the group and passwd files, but fussing about this is new. -- Start Rootkit Hunter Scan -- Warning: Suspicious file types

Re: Another rkhunter question

2009-05-17 Thread John Horne
On Sun, 2009-05-17 at 09:35 -0400, Gene Heskett wrote: Greetings all; What is /dev/shm? I've given up on rkhunter ever shutting up about the group and passwd files, What is it saying about the files? If necessary disable the relevant passwd/group tests (use 'rkhunter --list test' to see

Re: Another rkhunter question

2009-05-17 Thread Gene Heskett
On Sunday 17 May 2009, John Horne wrote: On Sun, 2009-05-17 at 09:35 -0400, Gene Heskett wrote: Greetings all; What is /dev/shm? I've given up on rkhunter ever shutting up about the group and passwd files, What is it saying about the files? If necessary disable the relevant passwd/group

Re: Another rkhunter question

2009-05-17 Thread John Horne
On Sun, 2009-05-17 at 13:41 -0400, Gene Heskett wrote: On Sunday 17 May 2009, John Horne wrote: On Sun, 2009-05-17 at 09:35 -0400, Gene Heskett wrote: I've given up on rkhunter ever shutting up about the group and passwd files, What is it saying about the files? If necessary disable

Re: rkhunter Question.

2009-01-17 Thread Kevin Fenzi
On Fri, 16 Jan 2009 10:14:19 -0500 Gene Heskett gene.hesk...@verizon.net wrote: It is running here, silently. I added the two files it thought were funkity to the config and haven't had a message from it since. And I did have the - copies in /etc. I think it was these two it was fussing

Re: rkhunter Question.

2009-01-17 Thread Gene Heskett
On Saturday 17 January 2009, Kevin Fenzi wrote: On Fri, 16 Jan 2009 10:14:19 -0500 Gene Heskett gene.hesk...@verizon.net wrote: It is running here, silently. I added the two files it thought were funkity to the config and haven't had a message from it since. And I did have the - copies in

Re: rkhunter Question.

2009-01-16 Thread Paulo Cavalcanti
On Sun, Jan 11, 2009 at 4:06 PM, Gene Heskett gene.hesk...@verizon.netwrote: On Sunday 11 January 2009, Kevin Fenzi wrote: On Thu, 08 Jan 2009 20:29:49 + John Horne john.ho...@plymouth.ac.uk wrote: On Thu, 2009-01-08 at 15:22 -0500, Gene Heskett wrote: On Thursday 08 January 2009,

Re: rkhunter Question.

2009-01-16 Thread John Horne
On Fri, 2009-01-16 at 12:18 -0200, Paulo Cavalcanti wrote: I have run rkhunter --propupd many times, I do have a copy of group and passwd in /var/run/rkhunter, but I always receive an email saying that there is no copy of group and passwd. Upgrading to 1.3.4 did not change anything. This

Re: rkhunter Question.

2009-01-16 Thread Gene Heskett
On Friday 16 January 2009, Paulo Cavalcanti wrote: On Sun, Jan 11, 2009 at 4:06 PM, Gene Heskett gene.hesk...@verizon.netwrote: On Sunday 11 January 2009, Kevin Fenzi wrote: On Thu, 08 Jan 2009 20:29:49 + John Horne john.ho...@plymouth.ac.uk wrote: On Thu, 2009-01-08 at 15:22 -0500,

Re: rkhunter Question.

2009-01-11 Thread Kevin Fenzi
On Thu, 08 Jan 2009 20:29:49 + John Horne john.ho...@plymouth.ac.uk wrote: On Thu, 2009-01-08 at 15:22 -0500, Gene Heskett wrote: On Thursday 08 January 2009, John Horne wrote: ...snip... Should the rpm installer have over written them? I dunno, there could be problems intro'd

rkhunter Question.

2009-01-08 Thread Gene Heskett
They say a little paranoia is a good thing, so I installed the rkhunter rpm, which in turn apparently sets itself up as a cron job. I got emails from it bitching about a couple of perfectly legit files, and I found out where to whitelist them, so that warning is gone. While I was at it I

Re: rkhunter Question.

2009-01-08 Thread Gene Heskett
On Thursday 08 January 2009, John Horne wrote: On Thu, 2009-01-08 at 09:38 -0500, Gene Heskett wrote: [...] Now it is complaining about the lack of copies for passwd and group, but they do exist as name- files. Is this a foible of rkhunter, or a redhatism? Recommended fix? Do nothing. When

Re: rkhunter Question.

2009-01-08 Thread Gene Heskett
On Thursday 08 January 2009, John Horne wrote: On Thu, 2009-01-08 at 16:42 +, John Horne wrote: On Thu, 2009-01-08 at 09:38 -0500, Gene Heskett wrote: They say a little paranoia is a good thing, so I installed the rkhunter rpm, which in turn apparently sets itself up as a cron job. I

Re: rkhunter Question.

2009-01-08 Thread Gene Heskett
On Thursday 08 January 2009, Colin J Thomson - G6AVK wrote: On Thursday 08 January 2009 14:38:25 Gene Heskett wrote: They say a little paranoia is a good thing, so I installed the rkhunter rpm, which in turn apparently sets itself up as a cron job. I got emails from it bitching about a couple

Re: rkhunter Question.

2009-01-08 Thread John Horne
On Thu, 2009-01-08 at 15:22 -0500, Gene Heskett wrote: On Thursday 08 January 2009, John Horne wrote: On Thu, 2009-01-08 at 16:42 +, John Horne wrote: On Thu, 2009-01-08 at 09:38 -0500, Gene Heskett wrote: They say a little paranoia is a good thing, so I installed the rkhunter rpm,

Re: rkhunter Question.

2009-01-08 Thread Colin J Thomson - G6AVK
On Thursday 08 January 2009 20:24:35 Gene Heskett wrote: On Thursday 08 January 2009, Colin J Thomson - G6AVK wrote: On Thursday 08 January 2009 14:38:25 Gene Heskett wrote: They say a little paranoia is a good thing, so I installed the rkhunter rpm, which in turn apparently sets itself up

Re: rkhunter Question.

2009-01-08 Thread Gene Heskett
On Thursday 08 January 2009, John Horne wrote: On Thu, 2009-01-08 at 15:22 -0500, Gene Heskett wrote: On Thursday 08 January 2009, John Horne wrote: On Thu, 2009-01-08 at 16:42 +, John Horne wrote: On Thu, 2009-01-08 at 09:38 -0500, Gene Heskett wrote: They say a little paranoia is a

Re: rkhunter Question.

2009-01-08 Thread Gene Heskett
On Thursday 08 January 2009, Todd Zullinger wrote: Gene Heskett wrote: Will the other get to f8 before the shutdown? Fedora 8 has had its last updates push. So if the package isn't in the repo, it won't be. (And it looks like it's not on the master mirror at