Rkhunter is a very useful tool that is used to check for trojans, rootkits, and other security problems. This tutorial will touch on installing and setting up a daily report for rkhunter.
Installing:
# wget -c http://downloads.rootkit.nl/rkhunter-1.2.9.tar.gz
# tar -xvf rkhunter-1.2.9.tar.gz
# cd rkhunter-1.2.9
# ./installer.sh
Now you can run a test scan with the following command:
# /usr/local/bin/rkhunter -c
How to setup a daily scan report?
# pico -w /etc/cron.daily/rkhunter.sh
Add the following (replace with your email address):
#!/bin/bash
(/usr/local/bin/rkhunter -c –cronjob 2>&1 | mail -s “Daily Rkhunter Scan Report” youremail@yourdomain.com)
Save it and exit, then:
# chmod +x /etc/cron.daily/rkhunter.sh
I just got a false positive!! What do i do?
False positives are warnings which indicates there is a problem, but aren’t really a problem. Example: some Linux distro updated a few common used binaries like `ls` and `ps`. You (as a good sysadmin) update the new packages and run (ofcourse) daily Rootkit Hunter. Rootkit Hunter isn’t yet aware of these new files and while scanning it resports some “bad” files. In this case we have a false positive. You could always have your datacenter or a system administrator check out the server to verify that it is not compromised.
More information on rkhunter can be found here: http://www.rootkit.nl
|
Print This Post
Blogsphere: TechnoratiFeedsterBloglines
Bookmark: Del.icio.usSpurlFurlSimpyBlinkDigg
RSS feed for comments on this post | TrackBack URI for this post
Related Post:
- Howto Install Zend Optimizer on cPanel/WHM
- Howto Install .deb Packages on Ubuntu Linux
- Howto Install LxAdmin
- Howto Install ImageMagick
- Howto Upgrade Perl on cPanel
