Questions tagged «rkhunter»

1
rkhunter关于/etc/.java /etc/.udev /etc/.initramfs的警告
我正在运行Ubuntu 10.04.1 LTS。我正在运行rkhunter来检查rootkit。 rkhunter抱怨以下隐藏的文件和目录。我认为这些文件在我的系统上不是真正的问题,但是如何检查这些文件是否为合法文件? [07:57:45] Checking for hidden files and directories [ Warning ] [07:57:45] Warning: Hidden directory found: /etc/.java [07:57:45] Warning: Hidden directory found: /dev/.udev [07:57:45] Warning: Hidden directory found: /dev/.initramfs 更新资料 原来,这些目录在/etc/rkhunter.conf中特别提到,这表明这是一个常见的rkhunter问题。从rkhunter.conf: # # Allow the specified hidden directories. # One directory per line (use multiple ALLOWHIDDENDIR lines). …

7
cron.daily作业未运行
我创建了3个每日Cron作业来运行。 以下是放置在etc / cron.daily中的三个 rkhunter.sh #!/bin/sh ( rkhunter --versioncheck rkhunter --update rkhunter --cronjob --report-warnings-only ) | mail -s 'rkhunter Daily Run (my server)' me@email.com chkrootkit.sh #!/bin/bash chkrootkit | mail -s "chkrootkit Daily Run (my server)" me@email.com logwatch.sh #!/bin/sh ( logwatch ) | mail -s 'logwatch Daily Log (my server)' me@email.com …

1
我的系统上的沙箱用户“ _apt”是什么
我跑rkhunter了出来,发现一条警告,_apt我的Ubuntu 16.04上有一个新用户叫 $ grep _apt /etc/passwd _apt:x:124:65534::/nonexistent:/bin/false 我发现的一切似乎是,这是“高级持续威胁”的沙盒用户。但是,这到底是什么?
17 apt  users  rkhunter 


2
rkhunter:正确处理警告的正确方法是什么?
我在Google上搜索了一下,并查看了找到的两个第一个链接: http://www.skullbox.net/rkhunter.php http://www.techerator.com/2011/07/how-to-detect-rootkits-in-linux-with-rkhunter/ 他们没有提到在出现此类警告时该怎么办: Warning: The command '/bin/which' has been replaced by a script: /bin/which: POSIX shell script text executable Warning: The command '/usr/sbin/adduser' has been replaced by a script: /usr/sbin/adduser: a /usr/bin/perl script text executable Warning: The command '/usr/bin/ldd' has been replaced by a script: /usr/bin/ldd: Bourne-Again shell script …
8 rkhunter 
By using our site, you acknowledge that you have read and understand our Cookie Policy and Privacy Policy.
Licensed under cc by-sa 3.0 with attribution required.