niller
September 3rd, 2008, 11:44 AM
Hi all
I've just discovered rkhunter and took it for a spin.
I have these issues in the log file, is it something I should be worried about and what have to be done ?
[17:35:59] Performing system configuration file checks
[17:35:59] Info: Starting test name 'system_configs'
[17:35:59] Checking for SSH configuration file [ Found ]
[17:35:59] Info: Found SSH configuration file: /etc/ssh/sshd_config
[17:35:59] Info: Rkhunter option ALLOW_SSH_ROOT_USER set to 'no'.
[17:35:59] Checking if SSH root access is allowed [ Warning ]
[17:35:59] Warning: The SSH and rkhunter configuration options should be the same:
[17:35:59] SSH configuration option 'PermitRootLogin': yes
[17:35:59] Rkhunter configuration option 'ALLOW_SSH_ROOT_USER': no
[17:35:59] Checking if SSH protocol v1 is allowed [ Not allowed ]
[17:35:59] Checking for running syslog daemon [ Found ]
[17:35:59] Checking for syslog configuration file [ Found ]
[17:35:59] Info: Found syslog configuration file: /etc/syslog.conf
[17:36:00] Checking if syslog remote logging is allowed [ Not allowed ]
[17:36:00]
[17:36:00] Performing filesystem checks
[17:36:00] Info: Starting test name 'filesystem'
[17:36:00] Info: SCAN_MODE_DEV set to 'THOROUGH'
[17:36:14] Checking /dev for suspicious file types [ Warning ]
[17:36:14] Warning: Suspicious files found in /dev:
[17:36:14] /dev/shm/pulse-shm-2448036307: data
[17:36:14] /dev/shm/pulse-shm-803441736: data
[17:36:15] Checking for hidden files and directories [ Warning ]
[17:36:15] Warning: Hidden directory found: /etc/.java
[17:36:15] Warning: Hidden directory found: /dev/.static
[17:36:15] Warning: Hidden directory found: /dev/.udev
[17:36:15] Warning: Hidden directory found: /dev/.initramfs
Any pointers is highly appreciated as I dont have a clue :-/
Thanks
Niller
I've just discovered rkhunter and took it for a spin.
I have these issues in the log file, is it something I should be worried about and what have to be done ?
[17:35:59] Performing system configuration file checks
[17:35:59] Info: Starting test name 'system_configs'
[17:35:59] Checking for SSH configuration file [ Found ]
[17:35:59] Info: Found SSH configuration file: /etc/ssh/sshd_config
[17:35:59] Info: Rkhunter option ALLOW_SSH_ROOT_USER set to 'no'.
[17:35:59] Checking if SSH root access is allowed [ Warning ]
[17:35:59] Warning: The SSH and rkhunter configuration options should be the same:
[17:35:59] SSH configuration option 'PermitRootLogin': yes
[17:35:59] Rkhunter configuration option 'ALLOW_SSH_ROOT_USER': no
[17:35:59] Checking if SSH protocol v1 is allowed [ Not allowed ]
[17:35:59] Checking for running syslog daemon [ Found ]
[17:35:59] Checking for syslog configuration file [ Found ]
[17:35:59] Info: Found syslog configuration file: /etc/syslog.conf
[17:36:00] Checking if syslog remote logging is allowed [ Not allowed ]
[17:36:00]
[17:36:00] Performing filesystem checks
[17:36:00] Info: Starting test name 'filesystem'
[17:36:00] Info: SCAN_MODE_DEV set to 'THOROUGH'
[17:36:14] Checking /dev for suspicious file types [ Warning ]
[17:36:14] Warning: Suspicious files found in /dev:
[17:36:14] /dev/shm/pulse-shm-2448036307: data
[17:36:14] /dev/shm/pulse-shm-803441736: data
[17:36:15] Checking for hidden files and directories [ Warning ]
[17:36:15] Warning: Hidden directory found: /etc/.java
[17:36:15] Warning: Hidden directory found: /dev/.static
[17:36:15] Warning: Hidden directory found: /dev/.udev
[17:36:15] Warning: Hidden directory found: /dev/.initramfs
Any pointers is highly appreciated as I dont have a clue :-/
Thanks
Niller