Re: [Rkhunter-users] [Skdet] More include files missing from skdet.

2017-10-03 Thread Dick Gevers
> On 3 Oct 2017, at 18:55, Dick Gevers wrote: > > >> On 3 Oct 2017, at 18:42, Patrick Gouin wrote: >> >> Le 01/10/2017 à 16:11, Dick Gevers a écrit : >>>> On 1 Oct 2017, at 15:13, Patrick Gouin wrote: >>>> >>>> Hi, >>

Re: [Rkhunter-users] [Skdet] More include files missing from skdet.

2017-10-03 Thread Dick Gevers
> On 3 Oct 2017, at 18:42, Patrick Gouin wrote: > > Le 01/10/2017 à 16:11, Dick Gevers a écrit : >>> On 1 Oct 2017, at 15:13, Patrick Gouin wrote: >>> >>> Hi, >>> >>> Note; I'm not sure if email address of dvgevers is still the good

Re: [Rkhunter-users] [Skdet] More include files missing from skdet.

2017-10-01 Thread Dick Gevers
o need to apply the two patch files. I only made it available here as there didnt seem to be a better place, but i did not make it. Happened to install the rpm as is on a Mageia Cauldron machine this week w/o any pro

Re: [Rkhunter-users] 'suspicious shared memory segments have been found'

2017-07-10 Thread Dick Gevers
On Mon, 10 Jul 2017 14:27:37 +0300, Nerijus Baliunas via Rkhunter-users wrote about Re: [Rkhunter-users] 'suspicious shared memory segments have been found': >On Mon, 10 Jul 2017 14:19:41 +0300 ellanios82 wrote: > >> - rkhunter cron job today shows warning: >> >> "suspicious shared memory segmen

Re: [Rkhunter-users] How can I check for setUID files in specific directories?

2011-10-10 Thread Dick Gevers
esult to logs, as well as any changes to the md5sum of each file on the list. Ciao, =Dick Gevers= -- All the data continuously generated in your IT infrastructure contains a definitive record of customers, application pe

Re: [Rkhunter-users] compair rkhunter.log with rkhunter.log.old

2010-12-15 Thread Dick Gevers
On Wed, 15 Dec 2010 09:22:37 +, John Horne wrote about Re: [Rkhunter-users] compair rkhunter.log with rkhunter.log.old: > cat rkhunter.log | cut -d' ' -f2- >/tmp/rkh1 or ... cut -b 12- ... Ci

Re: [Rkhunter-users] rkh 1.3.8 ignores processes allowed to use deleted files

2010-11-20 Thread Dick Gevers
, and could >see none. Thanks v.m. The fix is good. Unfortunately I didn't have chance to test the new version when asked, because my 32 bit version was breaking up and had to wait for new parts (64 bit) and do a reinstall and fix everything before I was able to get

[Rkhunter-users] rkh 1.3.8 ignores processes allowed to use deleted files

2010-11-20 Thread Dick Gevers
sist. Probably I am doing stg stupid somewhere, but I can't find what it might be. Any ideas please? Thanks & kind regards, =Dick Gevers= -- Beautiful is writing same markup. Internet Explorer 9 supports standards

Re: [Rkhunter-users] Rkhunter tells me that /usr/bin/rkhunter file properties has changed

2010-01-26 Thread Dick Gevers
verifying diff was okay with original tarball), I worked around it for the moment with this cron job which gets mailed 9 minutes after the rkh logs: #!/bin/bash # check integrity of rhunter executable despite rkh warning grep \/bin\/rkhu /var/lib/rkhunter/db/rkhunter.dat sha1su

Re: [Rkhunter-users] A few small remarks using rkh 1.3.6

2009-12-29 Thread Dick Gevers
On Tue, 29 Dec 2009 22:14:35 +, Dick Gevers wrote about Re: [Rkhunter-users] A few small remarks using rkh 1.3.6: >Does remain that '--propupd [ file ] ' is not doing what it says it should. I am wrong there: after the ROOTDIR is disabled, it says ' 1 of 137' . S

Re: [Rkhunter-users] A few small remarks using rkh 1.3.6

2009-12-29 Thread Dick Gevers
[ file ] ' is not doing what it says it should. So I hope this was of some help. Best regards, =Dick Gevers= -- This SF.Net email is sponsored by the Verizon Developer Community Take advantage of Verizon's best-

Re: [Rkhunter-users] A few small remarks using rkh 1.3.6

2009-12-29 Thread Dick Gevers
On Tue, 29 Dec 2009 21:22:20 +, Dick Gevers wrote about [Rkhunter-users] A few small remarks using rkh 1.3.6: >File:usr/local/etc/rkhunter.conf:0db1e4bf8bc5847335d72b09b1482fdaa0d05cab:345126:0600:0:0:33811:1259527434:: > >Note the missing slash before 'usr', while all oth

[Rkhunter-users] A few small remarks using rkh 1.3.6

2009-12-29 Thread Dick Gevers
cluding the data for rkhunter.conf. But: according to 'rkhunter --help', the option '--propud [ file ]' should only have updated only the specified entry in the db, not all entries. HTH Kind regards & happy new year, =Dick Gevers= ---

Re: [Rkhunter-users] [Rkhunter-announce] Rootkit Hunter release 1.3.6

2009-11-29 Thread Dick Gevers
On Sun, 29 Nov 2009 19:04:12 +, John Horne wrote about Re: [Rkhunter-users] [Rkhunter-announce] Rootkit Hunter release 1.3.6: >Look at the RTKT_FILE_WHITELIST option and put it into your >rkhunter.conf.local file. Thanks v.m. ! I overlooked that one. Cheers, =Dick

Re: [Rkhunter-users] [Rkhunter-announce] Rootkit Hunter release 1.3.6

2009-11-29 Thread Dick Gevers
quot;Setting hard drive parameters for %s: " ${disk[$device]} /sbin/hdparm ${HDFLAGS[$device]} /dev/${disk[$device]} Is there a way I can exclude this file?: I searched, but didn't see an option for this check. Thanks & BFN, =Dick Gevers= ---

Re: [Rkhunter-users] aptitude updates file properties automatically on one system but not another

2009-06-17 Thread Dick Gevers
On Tue, 16 Jun 2009 13:46:53 -0500, Mike McCarty wrote about Re: [Rkhunter-users] aptitude updates file properties automatically on one system but not another: >Dick Gevers wrote: >> On Tue, 16 Jun 2009 10:59:17 -0400, Brian McKee wrote about >> [Rkhunter-users] aptitude updates

Re: [Rkhunter-users] aptitude updates file properties automatically on one system but not another

2009-06-16 Thread Dick Gevers
n updated, it will also not warn for hash changes that are not due to a regular package manager update. I'd rather be warned of all hash changes and determine by myself whether they are a result of such updates or if they are potentially unwarranted change

Re: [Rkhunter-users] Warning: Found passwordless account: mpi

2009-01-11 Thread Dick Gevers
is package provides the libraries that use the standard p4 device. The package PREIN script reads: /usr/sbin/groupadd -g 12384 -r -f mpi > /dev/null 2>&1 ||: /usr/sbin/useradd -u 12384 -g mpi -d /var/lib/mpi -r \ > -s /bin/bash mpi -p "" -m > /dev/null 2>&1

Re: [Rkhunter-users] low priority ..possible gpg issue?

2009-01-04 Thread Dick Gevers
a trusted signature! In your case that would be odd if it is not yourself (and normal in our case), because if it is your own key you should have ultimate trust in it. But you can 'hush' the answer on this point

Re: [Rkhunter-users] low priority ..possible gpg issue?

2009-01-02 Thread Dick Gevers
Can't check signature: general error Additionally there's a little oddity that the key owner's name is between quotes inside the name. But anyway I like to thank unspawn and John et

Re: [Rkhunter-users] False warning about /usr/sbin/vipw

2008-11-05 Thread Dick Gevers
package manager (and/or prelinking) sorts itself out. If you feel that maybe rpm (my version is from rpm-4.4.2.3-22mnb2.i586.rpm) is not stable, shouldn't we take this upstream with rpm? >As >said, I'll s

Re: [Rkhunter-users] False warning about /usr/sbin/vipw

2008-11-04 Thread Dick Gevers
On Tue, 04 Nov 2008 22:28:09 +, John Horne wrote about Re: [Rkhunter-users] False warning about /usr/sbin/vipw: >On Tue, 2008-11-04 at 22:03 +0000, Dick Gevers wrote: >> On Tue, 04 Nov 2008 12:33:05 +, John Horne wrote about Re: >> [Rkhunter-users] False warning about

Re: [Rkhunter-users] howto use skdet?

2008-11-04 Thread Dick Gevers
then 'su -' to root and it'll be fixed once you have run 'rkhunter --propupd'. But (again if I'm right) you'll keep the problem with sudo if skdet is not in the path of the user running rkh. A cron job of root should not have that problem, though. Cheers, =Dick Ge

Re: [Rkhunter-users] False warning about /usr/sbin/vipw

2008-11-04 Thread Dick Gevers
On Tue, 04 Nov 2008 12:33:05 +, John Horne wrote about Re: [Rkhunter-users] False warning about /usr/sbin/vipw: >On Fri, 2008-10-31 at 18:14 +0000, Dick Gevers wrote: >> Using rkhunter 1.3.3. cvs of 6th October 2008 I have to report that once >> only I get a warning for this

Re: [Rkhunter-users] False warning about /usr/sbin/vipw

2008-11-01 Thread Dick Gevers
On Fri, 31 Oct 2008 23:22:46 +, John Horne wrote about Re: [Rkhunter-users] False warning about /usr/sbin/vipw: >Are you using a package manager? Sure: rpm on Mandriva Linux Cooker. Cheers, =Dick Gevers= - This SF.

[Rkhunter-users] False warning about /usr/sbin/vipw

2008-10-31 Thread Dick Gevers
don't know how to look further into this freak occurrence (which it is, I suppose), but I thought you might want to know of it anyway. HTH Kind regards, =Dick Gevers= - This SF.Net email is sponsored by the Moblin Your Move

Re: [Rkhunter-users] Thanks rkhunter

2008-10-06 Thread Dick Gevers
ble today tested on Mandriva Linux Cooker (2009.0) and working quite well. Cheers, =Dick Gevers= - This SF.Net email is sponsored by the Moblin Your Move Developer's challenge Build the coolest Linux based applications with Mo

Re: [Rkhunter-users] US-CERT: Active attacks using stolen SSH keys (Phalanx2 rootkit)

2008-08-28 Thread Dick Gevers
t is for users to "bless" the release >by testing the CVS tarball RSN, so please do. Tried today's cvs of rkh 1.3.3. and works very well on Mandriva Linux Cooker. Cheers, =Dick Gevers= - This SF.Net email

[Rkhunter-users] skdet available

2008-06-06 Thread Dick Gevers
EADME /usr/local/share/skdet/SucKIT.test /usr/local/share/skdet/adore-ng.test /usr/local/share/skdet/adore.test /usr/local/share/skdet/frontkey.test If anyone makes improvements on the 'skdet' tool please let me know so I can update the posted files or link to your URL. Thanks in advance. u

Re: [Rkhunter-users] RFE: no warning for tcb enabled system

2008-05-25 Thread Dick Gevers
5&group_id=155034&atid=794190 Ciao, =Dick Gevers= - This SF.net email is sponsored by: Microsoft Defy all challenges. Microsoft(R) Visual Studio 2008. http://clk.atdmt.com/MRT/go/vse01200

[Rkhunter-users] RFE: no warning for tcb enabled system

2008-05-25 Thread Dick Gevers
. for your time. I shall gladly post a bugreport for this if you prefer. Ciao, =Dick Gevers= - This SF.net email is sponsored by: Microsoft Defy all challenges. Microsoft(R) Visual Studio 2008. http://clk.atdmt.com/MRT/go

Re: [Rkhunter-users] One ALLOWPROCDELFILE entry is ignored

2008-05-05 Thread Dick Gevers
On Sun, 30 Mar 2008 21:20:31 +, Dick Gevers wrote about Re: [Rkhunter-users] One ALLOWPROCDELFILE entry is ignored: >On Sun, 30 Mar 2008 22:03:35 +0100, John Horne wrote about Re: >[Rkhunter-users] One ALLOWPROCDELFILE entry is ignored: > >>RKH does not impose any limit of it

Re: [Rkhunter-users] One ALLOWPROCDELFILE entry is ignored

2008-03-30 Thread Dick Gevers
appears only about once per 1 or 2 weeks. Thanks & BFN =Dick Gevers= - Check out the new SourceForge.net Marketplace. It's the best place to buy or sell services for just about anything Open Source. http://ad.d

[Rkhunter-users] One ALLOWPROCDELFILE entry is ignored

2008-03-29 Thread Dick Gevers
is ignored: Warning: The following processes are using deleted files: Process: setiathom PID: 15935 File: /home/dvg/.boinc/BOINC/slots/1/stderr.txt Maybe the line ALLOWPROCDELFILE is too long for rkhunter? Thanks and best regards, =D

Re: [Rkhunter-users] rkhunter 1.3.2 - sed error

2008-03-01 Thread Dick Gevers
On Sat, 01 Mar 2008 13:00:27 +0100, [EMAIL PROTECTED] wrote about Re: [Rkhunter-users] rkhunter 1.3.2 - sed error: >On Sat, 01 Mar 2008 07:46:44 +0100 Dick Gevers <[EMAIL PROTECTED]> >wrote: >>One small thing: it seems to use sed in a way that is not >>recognized >

[Rkhunter-users] rkhunter 1.3.2 - sed error

2008-02-29 Thread Dick Gevers
None found ] Cheers, =Dick Gevers= - This SF.net email is sponsored by: Microsoft Defy all challenges. Microsoft(R) Visual Studio 2008. http://clk.atdmt.com/MRT/go/vse012070mrt/direct/01/

Re: [Rkhunter-users] baffling warning

2007-12-07 Thread Dick Gevers
original version and rkhunter will notify >you of this. Thanks very much for your explanations. Best regards, =Dick Gevers= - SF.Net email is sponsored by: Check out the new SourceForge.net Marketplace. It's the bes

Re: [Rkhunter-users] baffling warning

2007-12-06 Thread Dick Gevers
ership have changed from what the RPM >database expects. Ah; thanks for that: I was not aware of that; sorry. Best regards, =Dick Gevers= - SF.Net email is sponsored by: Check out the new SourceForge.net Marketplace. It

Re: [Rkhunter-users] baffling warning

2007-12-06 Thread Dick Gevers
ously, you know more than I do. Is there a suggested way to deal with this? Thanks v.m. =Dick Gevers= - SF.Net email is sponsored by: Check out the new SourceForge.net Marketplace. It's the best place to buy or sell se

Re: [Rkhunter-users] baffling warning

2007-12-06 Thread Dick Gevers
am.d/su .MG./usr/bin/who Looks okay to me. But I'll appreciate any ideas. Thank and BFN =Dick Gevers= - SF.Net email is sponsored by: Check out the new SourceForge.net Marketplace. It's the best place to buy or

[Rkhunter-users] baffling warning

2007-12-06 Thread Dick Gevers
documentation, but I wouldn't know what. I run Mandriva Cooker (development version) which is updated daily, so I often have to run '--propupd', but these 3 keep haunting me. Thanks i.a. for any ideas Cheers, =Dick Gevers=

Re: [Rkhunter-users] feedback for Dick - unhide stops box

2007-12-05 Thread Dick Gevers
On Mon, 26 Nov 2007 18:50:33 +, Dick Gevers wrote about Re: [Rkhunter-users] feedback for Dick - unhide stops box: >It's now reported to the author of unhide (haven't heard from him yet) and >in Mandriva Bugzilla as http://qa.mandriva.com/show_bug.cgi?id=35822 For anyone in

Re: [Rkhunter-users] feedback for Dick - unhide stops box

2007-11-26 Thread Dick Gevers
oblem occurs only with the latest Cooker kernel (maybe it's flawed, it is a 'rc' after all. I appreciate your trying to help. It's now reported to the author of unhide (haven't heard from him yet) and in Mand

Re: [Rkhunter-users] unhide stops my box with new kernel

2007-11-23 Thread Dick Gevers
On Fri, 23 Nov 2007 17:38:11 +, John Horne wrote about Re: [Rkhunter-users] unhide stops my box with new kernel: > >On Fri, 2007-11-23 at 16:08 +, Dick Gevers wrote: >> Yesterday I installed kernel-server-2.6.24-0.rc3.1mdv-1-1mdv2008.1 >> on my Mandriva Cooker box. >

[Rkhunter-users] unhide stops my box with new kernel

2007-11-23 Thread Dick Gevers
appears on the halted screen, but I don't know if that will do much good (to me at least it's klingon anyway): I tried capturing the output to file, but nothing showed up. I hope someone has any ideas how to overcome the problem. Thanks beforehand. regards, =D

Re: [Rkhunter-users] rkh 1.3.0 config note

2007-10-07 Thread Dick Gevers
s for a stupid post. Regards, =Dick Gevers= - This SF.net email is sponsored by: Splunk Inc. Still grepping through log files to find problems? Stop. Now Search log events and configuration files using AJAX and a browser. Downloa

[Rkhunter-users] rkh 1.3.0 config note

2007-09-28 Thread Dick Gevers
er behaves when these options are "used." However, I didn't grep any relevant 'test' or 'able' in the readme. Perhaps those details can be added in a future revision? Thanks so much. HTH Regards, =Dick Gevers= -

Re: [Rkhunter-users] CRON warning

2007-01-23 Thread Dick Gevers
gt;happened. (Default location is /var/log/rkhunter.log). Perhaps running >rkhunter interactively will show want went wrong too (just use 'rkhunter >-c -sk'). > > > >John. Or could it ph be generated by 'logcheck' package or similar? HTH Ciao, =Dick Gevers= -

Re: [Rkhunter-users] RKH CVS tarball available: testers wanted

2006-12-12 Thread Dick Gevers
On Tue, 12 Dec 2006 16:57:22 +, John Horne wrote about Re: [Rkhunter-users] RKH CVS tarball available: testers wanted: >On Tue, 2006-12-12 at 10:21 +0000, Dick Gevers wrote: >> >> "rkhunter -c" gives: >> The language specified is not available: en >> Use

Re: [Rkhunter-users] RKH CVS tarball available: testers wanted

2006-12-12 Thread Dick Gevers
files to be hashed are safe and have been installed from a reliable source? Otherwise the whole exercise of running rkh could become ambiguous? >If you could find the time to run it once in a while and report >back we would appreciate it very much. So fa

Re: [Rkhunter-users] Apache configuration absent but ...[ OK ]

2006-11-26 Thread Dick Gevers
guration ... [ OK ] >> However, since I do not have apache(2) installed at all, wouldn't "Not >> found" be a better displaystring? >Would you submit this as a bug on the sourceforge web page please. Done: http://sourceforge.net/tracker/index.php?func=

[Rkhunter-users] Apache configuration absent but ...[ OK ]

2006-11-25 Thread Dick Gevers
's due to not finding /etc/apa*, I think. However, since I do not have apache(2) installed at all, wouldn't "Not found" be a better displaystring? Just my nlg 0.02. Keep up the good work. I am rooting for you ;) =Dick Geve

Re: [Rkhunter-users] Unkown application versions..

2006-11-12 Thread Dick Gevers
On Sun, 12 Nov 2006 20:45:35 +, John Horne wrote about Re: [Rkhunter-users] Unkown application versions..: >On Sun, 2006-11-12 at 20:36 +0000, Dick Gevers wrote: >> On Sun, 12 Nov 2006 20:02:12 +0100, Jacob Willig wrote about >> [Rkhunter-users] Unkown appli

Re: [Rkhunter-users] Unkown application versions..

2006-11-12 Thread Dick Gevers
-q openssh openssh-4.5p1-2mdv2007.1 although I grant that I don't have an sshd_config. But I think the 'application not found' is a wrong finding. Cheers, =Dick Gevers= - Using Tomcat but need to do more? Need to su

Re: [Rkhunter-users] Hashes updated - but no hashes available.

2006-11-06 Thread Dick Gevers
On Mon, 06 Nov 2006 12:10:48 +0100, [EMAIL PROTECTED] wrote about Re: [Rkhunter-users] Hashes updated - but no hashes available.: >On Mon, 06 Nov 2006 03:58:16 +0100 Dick Gevers <[EMAIL PROTECTED]> >wrote: >>On Sun, 05 Nov 2006 23:32:58 +0100, [EMAIL PROTECTED] wrote >&g

Re: [Rkhunter-users] Hashes updated - but no hashes available.

2006-11-05 Thread Dick Gevers
On Sun, 05 Nov 2006 23:32:58 +0100, [EMAIL PROTECTED] wrote about Re: [Rkhunter-users] Hashes updated - but no hashes available.: >On Sat, 04 Nov 2006 08:41:21 +0100 Dick Gevers <[EMAIL PROTECTED]> >wrote: >>As always I then have to add my own system > >That what

[Rkhunter-users] Hashes updated - but no hashes available.

2006-11-03 Thread Dick Gevers
he return from rkh is the same every time. Perhaps a bug? Thanks, =Dick Gevers= - Using Tomcat but need to do more? Need to support web services, security? Get stuff done quickly with pre-integrated technology to make your job