Go Back   Defender Hosting Forums > PowerVPS Virtual Private Servers > Linux VPS - Security and Tuning

Linux VPS - Security and Tuning Security and Tuning Discussion for Linux Virtual Private Servers based on Virtuozzo by SWsoft

Reply
 
Thread Tools Display Modes

  #1  
Old 12-20-2005, 04:18 AM
Izzy
Guest
 
Posts: n/a
Default Strange RKHunter MD5 BAD Find

MD5 compared: 51
Incorrect MD5 checksums: 4

Strange rkhunter find yesterday after the daily cron check.
There was no update yesterday as the file dates are way back last month.

No BAD report till yesterday.

Any one else found this on their VPS?

Anyone have a clue as to why all of sudden these files come up BAD?

Thanks for any light on this.

First reported after daily cron check 19/12/2005 6:20:21PM
Next daily cron check 20/12/2005 6:20:19PM
Still BAD after rkhunter --update 20/12/2005 6:40:00PM

/bin/dmesg [ BAD ] 18/11/2005 2:24:25PM
/bin/kill [ BAD ] 18/11/2005 2:24:25PM
/bin/login [ BAD ] 18/11/2005 2:24:25PM
/bin/mount [ BAD ] 18/11/2005 2:24:25PM


These are the only other files with the same dates in /bin/:
/bin/arch 18/11/2005 2:24:25PM
/bin/more 18/11/2005 2:24:25PM
/bin/unmount 18/11/2005 2:24:25PM
Reply With Quote

  #2  
Old 12-20-2005, 05:32 AM
PvUtrix's Avatar
PvUtrix PvUtrix is offline
Senior Member
 
Join Date: Apr 2005
Posts: 199
PvUtrix is on a distinguished road
Default

Yep, same thing here...

rkhunter --update doesn't help...
Reply With Quote

  #3  
Old 12-20-2005, 06:40 AM
ozgreg
Guest
 
Posts: n/a
Default

I whitelisted those files by adding the md5 hashing into the rkhunter.conf file located in /usr/local/etc

perl /usr/local/rkhunter/lib/rkhunter/scripts/filehashmd5.pl location of file
Reply With Quote

  #4  
Old 12-20-2005, 10:19 AM
chief's Avatar
chief chief is offline
Senior Member
 
Join Date: Jul 2005
Location: Schenectady, NY
Posts: 118
chief is on a distinguished road
Send a message via AIM to chief
Default

Same thing here, except there were no programs listed just [BAD] in the e-mail. Charles?
Reply With Quote

  #5  
Old 12-20-2005, 10:49 AM
Sergey
Guest
 
Posts: n/a
Default

The package in your system is newer than in rhhunter database. When Michael Boelen (the author of rkhunter) will update rkhunter database for RH everything will be ok. I checked all binaries manually and checksum matches with the signature of rpm.
Reply With Quote

  #6  
Old 12-20-2005, 11:15 AM
dario dario is offline
Junior Member
 
Join Date: Oct 2005
Posts: 17
dario is on a distinguished road
Default

All those files are part of util-linux package. Fedora released yesterday updated package. If you have yum running as cron job, that could be answer. They are updated.

Dario
Reply With Quote

  #7  
Old 12-20-2005, 11:52 AM
azc
Guest
 
Posts: n/a
Default

Thanks for posting this. I've been getting 5 "Line: [ BAD ]" entries the last couple of days.
Reply With Quote

  #8  
Old 12-24-2005, 03:01 AM
Izzy
Guest
 
Posts: n/a
Default

Quote:
Originally Posted by Sergey
The package in your system is newer than in rhhunter database. When Michael Boelen (the author of rkhunter) will update rkhunter database for RH everything will be ok. I checked all binaries manually and checksum matches with the signature of rpm.
Still not convinced, as the day before I noticed it there was no changes to the system or the files and there was no BAD files. Check out the dates in my original post. These are fact not theory.
The next day there was still no changes to the system or the files yet rkhunter decided there were 4 files with BAD checksums. Obviously something changed but not the files as the dates are indicative of no change for a month. Rkhunter has not been upgraded by me for over a month. Did something happen at the VPS level that I have not been made aware of perhaps?
Anyway, its all Dutch to me .
Reply With Quote

  #9  
Old 12-25-2005, 08:31 AM
Norm1322
Guest
 
Posts: n/a
Default

I didn't get the names of the BAD files either.

Is there a way to update rkhunter to show the filenames in the report, before I'm too far gone?

--
Norm
Reply With Quote

  #10  
Old 12-25-2005, 10:19 AM
Izzy
Guest
 
Posts: n/a
Default

What do you get when you type rkhunter -c at the shell prompt?

Also at the shell prompt type rkhunter -h will give you the parameters.

The daily cron looks like this on my server.
/etc/cron.daily/rkhunter.sh
Code:
#!/bin/bash
(/usr/local/bin/rkhunter -c --cronjob 2>&1 | mail -s "RKhunter Scan Details" youremail@youraddress)
Replace youremail@youraddress with yours.
HTH

Last edited by Izzy; 12-25-2005 at 10:29 AM.. Reason: Fix typo
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



All times are GMT -4. The time now is 12:33 AM.


vBulletin skin developed by: eXtremepixels
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright Defender Technologies Group, LLC 2006