EanderAlx.org

Linux, Virtualization and whatever I find interesting ...

User Tools


Site Tools


linux:rkhunter

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
blog:linux:rkhunter [03.12.2010 16:51] – [Ubuntu] eanderalxlinux:rkhunter [23.03.2013 18:42] (current) – Page moved from blog:linux:rkhunter to linux:rkhunter eanderalx
Line 3: Line 3:
   * As the name implies, its a tool to detect rootkits.   * As the name implies, its a tool to detect rootkits.
   * I will describe installation and configuration for arch and ubuntu   * I will describe installation and configuration for arch and ubuntu
 +
 +~~READMORE~~
  
 ===== Links ===== ===== Links =====
Line 14: Line 16:
 ==== Installation ==== ==== Installation ====
  
-  * You need two packages: unhide and rkhunter itself both available in the[https://aur.archlinux.org/|AUR].+  * You need two packages: unhide and rkhunter itself both available in the [[https://aur.archlinux.org/|AUR]].
  
-  * download pkgbuild (I use [https://aur.archlinux.org/packages.php?ID=28285|slurpy] you also can download the pkgbuild manual) an install it.+  * download pkgbuild (I use [[https://aur.archlinux.org/packages.php?ID=28285|slurpy]] you also can download the pkgbuild manual) an install it.
 <code> <code>
 slurpy -d rkhunter slurpy -d rkhunter
Line 151: Line 153:
 ENABLE_TESTS="all" ENABLE_TESTS="all"
 DISABLE_TESTS="suspscan hidden_procs deleted_files packet_cap_apps apps" DISABLE_TESTS="suspscan hidden_procs deleted_files packet_cap_apps apps"
-#SCRIPTWHITELIST=/bin/egrep 
-#SCRIPTWHITELIST=/bin/fgrep 
 SCRIPTWHITELIST=/bin/which SCRIPTWHITELIST=/bin/which
-#SCRIPTWHITELIST=/usr/bin/groups 
 SCRIPTWHITELIST=/usr/bin/ldd SCRIPTWHITELIST=/usr/bin/ldd
 SCRIPTWHITELIST=/usr/bin/lwp-request SCRIPTWHITELIST=/usr/bin/lwp-request
 SCRIPTWHITELIST=/usr/sbin/adduser SCRIPTWHITELIST=/usr/sbin/adduser
-#SCRIPTWHITELIST=/usr/sbin/prelink 
-SCRIPTWHITELIST=/etc/cron.daily/inventur 
 ALLOWHIDDENDIR=/dev/.udev ALLOWHIDDENDIR=/dev/.udev
 ALLOWHIDDENDIR=/dev/.static ALLOWHIDDENDIR=/dev/.static
linux/rkhunter.txt · Last modified: 23.03.2013 18:42 by eanderalx