store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Wed Jun 19, 2013 1:24 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 5 posts ] 
Author Message
 Post subject: rkhunter warning
Unread postPosted: Tue Nov 15, 2011 6:05 pm 
Offline
Forum Regular
Forum Regular
User avatar

Joined: Wed Jan 13, 2010 9:11 am
Posts: 180
Location: Bali
Anyone know what I can do about these rkhunter warnings?

Warning: No output found from the lsmod command or the /proc/modules file:
/proc/modules output:
lsmod output:
Warning: The kernel modules directory '/lib/modules' is missing or empty.
Warning: Found passwordless account in shadow file: atomic

_________________
They say that good intentions, pave the road to hell;
If a thing is not worth doing, it's not worth doing well.


Top
 Profile  
 
 Post subject: Re: rkhunter warning
Unread postPosted: Tue Nov 15, 2011 6:22 pm 
Offline
Forum User
Forum User

Joined: Tue Apr 20, 2010 2:49 am
Posts: 74
Hi,

The first two look like they're because you're running within Virtuozzo or OpenVZ, so just disable the checks in the rkhunter.conf .

The last one I haven't a clue on I'm afraid,

Paul.


Top
 Profile  
 
 Post subject: Re: rkhunter warning
Unread postPosted: Tue Nov 15, 2011 6:32 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3264
Location: Chantilly, VA
Quote:
Warning: The kernel modules directory '/lib/modules' is missing or empty.


You dont have a kernel, so you wont have any modules. You can ignore that (if thats true for you, which if its a virtual system it would be true)

Quote:
Warning: Found passwordless account in shadow file: atomic


That means you have given us access to the system and that account uses only keys to log in. You can ignore that.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: rkhunter warning
Unread postPosted: Tue Nov 15, 2011 6:57 pm 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
Instead of ignoring it (which might be hard if rkhunter is e-mailing you about it every day) you can also disable the tests that check for kernel modules. You'll want to add 'avail_modules' and 'loaded_modules' to DISABLE_TESTS in /etc/rkhunter.conf or leave /etc/rkhunter.conf unmodified and override DISABLE_TESTS in /etc/rkhunter.conf.local (create that file if it doesn't exist yet).

Maybe ASL could disable these tests automatically if it detects a kernel without modules?

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
 Post subject: Re: rkhunter warning
Unread postPosted: Sun Jan 27, 2013 9:08 am 
Offline
Forum Regular
Forum Regular
User avatar

Joined: Wed Jan 13, 2010 9:11 am
Posts: 180
Location: Bali
breun wrote:
Maybe ASL could disable these tests automatically if it detects a kernel without modules?

Sounds like a good idea.

_________________
They say that good intentions, pave the road to hell;
If a thing is not worth doing, it's not worth doing well.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 5 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
cron
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group