RKHunter : インストール2022/08/30 |
Rootkit 検出ツール RKHunter のインストールと設定です。 |
|
[1] | RKHunter をインストールします。 |
root@dlp:~# apt -y install rkhunter curl
|
[2] | RKHunter の設定と利用方法です。 |
root@dlp:~#
vi /etc/default/rkhunter # [yes] を設定すると日時チェック実行 CRON_DAILY_RUN="" # レポートを送信する宛先メールアドレス REPORT_EMAIL="root"
root@dlp:~#
vi /etc/rkhunter.conf # 107行目 : 変更 UPDATE_MIRRORS= 1
# 122行目 : 変更 MIRRORS_MODE= 0
# 1190行目 : ブランクに変更 WEB_CMD="" # データベースをアップデート root@dlp:~# rkhunter --update [ Rootkit Hunter version 1.4.6 ] Checking rkhunter data files... Checking file mirrors.dat [ Updated ] Checking file programs_bad.dat [ No update ] Checking file backdoorports.dat [ No update ] Checking file suspscan.dat [ No update ] Checking file i18n/cn [ Skipped ] Checking file i18n/de [ Skipped ] Checking file i18n/en [ No update ] Checking file i18n/tr [ Skipped ] Checking file i18n/tr.utf8 [ Skipped ] Checking file i18n/zh [ Skipped ] Checking file i18n/zh.utf8 [ Skipped ] Checking file i18n/ja [ Skipped ] # システムのファイル情報をアップデート root@dlp:~# rkhunter --propupd [ Rootkit Hunter version 1.4.6 ] File updated: searched for 180 files, found 142 # チェック実行 # --sk で Enterキー押下をスキップ # --rwo を指定すると、警告のみ表示 root@dlp:~# rkhunter --check --sk
[ Rootkit Hunter version 1.4.6 ] Checking system commands... Performing 'strings' command checks Checking 'strings' command [ OK ] Performing 'shared libraries' checks Checking for preloading variables [ None found ] Checking for preloaded libraries [ None found ] Checking LD_LIBRARY_PATH variable [ Not found ] Performing file properties checks Checking for prerequisites [ OK ] /usr/sbin/adduser [ OK ] /usr/sbin/chroot [ OK ] /usr/sbin/cron [ OK ] /usr/sbin/depmod [ OK ] /usr/sbin/fsck [ OK ] /usr/sbin/groupadd [ OK ] /usr/sbin/groupdel [ OK ] /usr/sbin/groupmod [ OK ] /usr/sbin/grpck [ OK ] /usr/sbin/ifconfig [ OK ] /usr/sbin/init [ OK ] /usr/sbin/insmod [ OK ] /usr/sbin/ip [ OK ] /usr/sbin/lsmod [ OK ] /usr/sbin/modinfo [ OK ] /usr/sbin/modprobe [ OK ] /usr/sbin/nologin [ OK ] /usr/sbin/pwck [ OK ] /usr/sbin/rmmod [ OK ] ..... ..... System checks summary ===================== File properties checks... Files checked: 142 Suspect files: 0 Rootkit checks... Rootkits checked : 498 Possible rootkits: 0 Applications checks... All checks skipped The system checks took: 40 seconds All results have been written to the log file: /var/log/rkhunter.log One or more warnings have been found while checking the system. Please check the log file (/var/log/rkhunter.log) |
Sponsored Link |