store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Wed May 22, 2013 2:14 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 9 posts ] 
Author Message
 Post subject: hashupd.sh script for rkhunter
Unread postPosted: Wed Oct 18, 2006 12:07 pm 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
I'm using ART's rkhunter package, but I just had to use the hashupd.sh script because apparently the prelinking database became out of step with the rkhunter local MD5 hash values. Could you maybe include this script in your RPM?

I found running this script was the solution in section 4.4 of the rkhunter FAQ.

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
 Post subject:
Unread postPosted: Thu Oct 19, 2006 3:45 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
Some clarification from one of the current maintainers on the rkhunter users mailinglist:

Quote:
"Hashupd is a community made and supported add-on by me and John Horne. It was only promoted on this list (slight advantage for those that kept in touch) and is now being incorporated in RKH phasing out the "old" hash system."

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
 Post subject:
Unread postPosted: Thu Dec 07, 2006 12:35 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7425
Location: earth
Got it, hashupd and a whole redesign of the nightly reporting events are in 1.2.9-3. Ive got it set now so that by default, it wont send you anything unless theres something to worry about. If you do want the nightly reports like the old version, you just modify the /etc/sysconfig/rkhunter file.


Top
 Profile  
 
 Post subject:
Unread postPosted: Thu Dec 07, 2006 4:02 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
Thanks, great!

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
 Post subject:
Unread postPosted: Thu Dec 07, 2006 4:10 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
I already upgraded to 1.2.9-2 on two boxes yesterday and I noticed that upon upgrading to 1.2.9-3 /etc/sysconfig/rkhunter was overwritten so I had to set the MAILTO again.

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
 Post subject:
Unread postPosted: Thu Dec 07, 2006 12:43 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7425
Location: earth
OK -5 should be hitting the archive shortly. Ive corrected the config settings on /etc/sysconfig/rkhunter and /etc/rkhunter.conf, and added in a hashupd.sh event on an upgrade detection. I also changed the MAILTO variable to root, instead of root@localhost. That should make it so alerts will still be sent, even if you arent running a local MTA.


Top
 Profile  
 
 Post subject:
Unread postPosted: Fri Dec 08, 2006 7:28 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
So now there's a MAILTO setting in /etc/sysconfig/rkhunter and a MAIL-ON-WARNING setting in /etc/rkhunter.conf? The first one is used for sending full reports and the other for sending an e-mail when there is a warning? Do you have to set both?

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
 Post subject:
Unread postPosted: Fri Dec 08, 2006 10:42 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7425
Location: earth
Yeah so what I did is modify the package so the only config you should have to deal with is /etc/sysconfig/rkhunter. By default its only going to email you if something has been detected. I see rkhunter as more of a forensics tool, if it tells you something is wrong, its the worst case scenario and you're looking at a reinstall. Assuming its not a false positive that is, the hash table updates are consistantly ugly and will get out of sync frequently resulting in misfires.

The daily everything is OK full report is still available, I just tied it to the DIAG_SCAN setting in /etc/sysconfig/rkhunter, change that to "yes" and you'll get that, plus the application scan (checks versions on openssh, apache, etc. High false positive rate, be advised).


Top
 Profile  
 
 Post subject:
Unread postPosted: Fri Dec 08, 2006 11:33 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
Ok, great. Thanks.

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 9 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group