RKHunter : Install2022/06/28 |
Install RKHunter which is the Rootkit Detection tool. |
|
[1] | Install RKHunter. |
# install from EPEL [root@dlp ~]# dnf --enablerepo=epel -y install rkhunter
|
[2] | Configure and Use RKHunter. For regular checking, checking script is installed under the [/etc/cron.daily] directory and it is executed everyday by Cron. |
[root@dlp ~]#
vi /etc/sysconfig/rkhunter # recipient address for report MAILTO=root@localhost # if specified [yes], scan more detaily DIAG_SCAN=no # update database [root@dlp ~]# rkhunter --update [ Rootkit Hunter version 1.4.6 ] Checking rkhunter data files... Checking file mirrors.dat [ Updated ] Checking file programs_bad.dat [ Updated ] Checking file backdoorports.dat [ Updated ] Checking file suspscan.dat [ Updated ] Checking file i18n/cn [ No update ] Checking file i18n/de [ Updated ] Checking file i18n/en [ No update ] Checking file i18n/tr [ Updated ] Checking file i18n/tr.utf8 [ Updated ] Checking file i18n/zh [ Updated ] Checking file i18n/zh.utf8 [ Updated ] Checking file i18n/ja [ Updated ] # update system file properties [root@dlp ~]# rkhunter --propupd [ Rootkit Hunter version 1.4.6 ] File created: searched for 176 files, found 133 # run checking # [--sk] means skipping to push Enter key # [--rwo] means display only warnings [root@dlp ~]# rkhunter --check --sk
[ Rootkit Hunter version 1.4.6 ] Checking system commands... Performing 'strings' command checks Checking 'strings' command [ OK ] Performing 'shared libraries' checks Checking for preloading variables [ None found ] Checking for preloaded libraries [ None found ] Checking LD_LIBRARY_PATH variable [ Not found ] Performing file properties checks Checking for prerequisites [ OK ] /usr/sbin/adduser [ OK ] /usr/sbin/chroot [ OK ] /usr/sbin/depmod [ OK ] /usr/sbin/fsck [ OK ] /usr/sbin/fuser [ OK ] /usr/sbin/groupadd [ OK ] /usr/sbin/groupdel [ OK ] /usr/sbin/groupmod [ OK ] /usr/sbin/grpck [ OK ] ..... ..... System checks summary ===================== File properties checks... Files checked: 133 Suspect files: 0 Rootkit checks... Rootkits checked : 494 Possible rootkits: 0 Applications checks... All checks skipped The system checks took: 1 minute and 14 seconds All results have been written to the log file: /var/log/rkhunter/rkhunter.log One or more warnings have been found while checking the system. Please check the log file (/var/log/rkhunter/rkhunter.log) |
Sponsored Link |