| Summary: | 3_a3: rkhunter Warnings (syslog, .k5identity.5.xz) | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | Bit Twister <bittwister2> |
| Component: | RPM Packages | Assignee: | Remco Rijnders <remco> |
| Status: | RESOLVED FIXED | QA Contact: | |
| Severity: | minor | ||
| Priority: | Normal | CC: | remco, rverschelde |
| Version: | 3 | Keywords: | NEEDINFO |
| Target Milestone: | --- | ||
| Hardware: | x86_64 | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Source RPM: | rkhunter-1.4.0-1.mga3.src.rpm | CVE: | |
| Status comment: | |||
| Bug Depends on: | 9313 | ||
| Bug Blocks: | |||
|
Description
Bit Twister
2012-11-21 14:42:42 CET
Bit Twister
2012-11-21 14:43:12 CET
Summary:
2_a3: rkhunter Warnings (syslog, .k5identity.5.xz) =>
3_a3: rkhunter Warnings (syslog, .k5identity.5.xz) Oops, out of order steps for root should have
rkhunter --skip-keypress -C
/bin/rm -f /dev/shm/pulse*
rkhunter --propupd
rkhunter --skip-keypress -c
I also can recommend adding
RTKT_FILE_WHITELIST="/etc/crontab"
to /etc/rkhunter.conf.
That has suppressed the warning messages I get from the /etc/cron.daily run
like this snippet:
Warning: The following processes are using suspicious files:
Command: crond
UID: 0 PID: 805
Pathname: /etc/crontab
Possible Rootkit: Unknown rootkit
<snipped 8 more of the above message>
run-parts: /etc/cron.daily/rkhunter exited with return code 1
Manuel Hiebel
2012-11-25 11:56:24 CET
Assignee:
bugsquad =>
remco
Remco Rijnders
2012-11-25 13:46:53 CET
Status:
NEW =>
ASSIGNED FYI: Last night updates have removed/relocated several files. One of which has been removed is Invalid RTKT_FILE_WHITELIST configuration option: Non-existent pathname: /etc/rc.d/rc.sysinit
Remco Rijnders
2013-06-23 17:26:26 CEST
Blocks:
(none) =>
9398 Hi, thank you for your report. I believe the update in updates_testing rkhunter-1.4.0-3.1.mga3 fixes this problem. Please test it, I hope it solves this problem. Additionally, it should also cover the issues reported in #9398 and #9313 Assignee:
remco =>
qa-bugs
Remco Rijnders
2013-06-23 18:34:09 CEST
Version:
Cauldron =>
3
David Walser
2013-06-23 21:05:17 CEST
Depends on:
(none) =>
9313
David Walser
2013-06-23 21:05:48 CEST
Assignee:
qa-bugs =>
remco (In reply to Remco Rijnders from comment #3) > Hi, thank you for your report. I believe the update in updates_testing > rkhunter-1.4.0-3.1.mga3 fixes this problem. Installed rkhunter-1.4.0 and executed rkhunter --skip-keypress -C rkhunter --skip-keypress -c and saw no problems on $ cat /etc/release Mageia release 3 (Official) for x86_64 I can't reproduce the bug with rkhunter-1.4.0-3.mga3 (Core/Release), maybe it was fixed between 1.mga3 and 3.mga3? CC:
(none) =>
remi /etc/cron.daily/rkhunter was reporting this warning prior to the update. From cron's email on 24/06/13:
/etc/cron.daily/rkhunter:
Warning: GasKit Rootkit [ Warning ]
Directory '/dev/dev' found
Warning: Hidden file found: /usr/share/man/man5/.k5identity.5.xz: XZ compressed data
run-parts: /etc/cron.daily/rkhunter exited with return code 1
what is the status of this bug with the last update of rkhunter which is coming ? Keywords:
(none) =>
NEEDINFO ok Status:
ASSIGNED =>
RESOLVED |