Results 1 to 9 of 9

Thread: Data from Rootkit Hunter. Do I need to take any action?

  1. #1
    Join Date
    Mar 2010
    Location
    UK
    Beans
    481
    Distro
    Kubuntu 16.04 Xenial Xerus

    Question Data from Rootkit Hunter. Do I need to take any action?

    Data from Rootkit Hunter (Edited Data)

    [01:53:36] /usr/bin/curl [ Warning ]

    [01:53:38] /usr/bin/ldd [ Warning ]
    [01:53:38] Warning: The file properties have changed:

    [01:53:43] /usr/bin/unhide.rb [ Warning ]
    [
    [01:53:45] /sbin/ip [ Warning ]
    [01:53:45] Warning: The file properties have changed:
    [
    [01:53:48] /bin/ip [ Warning ]
    [01:53:48] Warning: The file properties have changed:



    [01:54:52] Checking /dev for suspicious file types [ Warning ]
    [01:54:52] Warning: Suspicious file types found in /dev:
    [01:54:52] /dev/.udev/rules.d/root.rules: ASCII text
    [01:54:52] Checking for hidden files and directories [ Warning ]

    PS. Do I need to update this programme. If so, what is the method?
    Last edited by anon_private; February 12th, 2018 at 03:15 AM.
    Dell Dimension E 520 Viiv
    Pentium D 2.8 GHz. Presler Dual Core 2.8GHz, 800MHz FSB 2x2MB cache
    RAM 4 GB. Dual Channel (4x1024GB) 667MHz DDR2
    Browser: Firefox

  2. #2

    Re: Data from Rootkit Hunter. Do I need to take any action?

    Yes, you need to take action.
    Great Question.
    See To avoid these warnings section.

    Also scour /etc/rkhunter.conf for very important tips,
    like using your own rkhunter settings in /etc/rkhunter.conf.local

    Step2: Verify output of /var/log/rkhunter.log
    "To avoid these warnings" will help.


    The file properties have changed
    indicate a couple of possibles:
    You're hacked, or the more likely
    Someone ran an "apt-get" and updated some software w\OUT running
    rkhunter --propupd, afterwards.
    Windows assumes the user is an idiot.
    Linux demands proof.

  3. #3
    Join Date
    Mar 2010
    Location
    UK
    Beans
    481
    Distro
    Kubuntu 16.04 Xenial Xerus

    Re: Data from Rootkit Hunter. Do I need to take any action?

    Thank you for responding.

    I will read the link you have given.

    I get the impression that these warnings are nothing to worry about.

    Have I interpreted your response correctly?

    Regards
    Dell Dimension E 520 Viiv
    Pentium D 2.8 GHz. Presler Dual Core 2.8GHz, 800MHz FSB 2x2MB cache
    RAM 4 GB. Dual Channel (4x1024GB) 667MHz DDR2
    Browser: Firefox

  4. #4
    Join Date
    Mar 2010
    Location
    UK
    Beans
    481
    Distro
    Kubuntu 16.04 Xenial Xerus

    Re: Data from Rootkit Hunter. Do I need to take any action?

    I note that my rkhunter.conf file has only one of the three (static) commands?


    /var/log/rkhunter.log is empty
    Last edited by anon_private; February 12th, 2018 at 11:29 PM.
    Dell Dimension E 520 Viiv
    Pentium D 2.8 GHz. Presler Dual Core 2.8GHz, 800MHz FSB 2x2MB cache
    RAM 4 GB. Dual Channel (4x1024GB) 667MHz DDR2
    Browser: Firefox

  5. #5

    Re: Data from Rootkit Hunter. Do I need to take any action?

    When was the last time you ran rkhunter?
    Where did
    Code:
    [01:53:48] /bin/ip [ Warning ]
    [01:53:48] Warning: The file properties have changed:
    come from?

    Is it, or has it been configured?

    I got the impression rkhunter was installed but the system has since had upgrades done to it since rkhunter was installed.

    Unconfigured rkhunter will issue "Warnings" as per
    Code:
    man rkhunter
    DESCRIPTION:second paragraph

    Does /etc/rkhunter have "more" than "3 static commands"? I read that as "has only 3 lines in it."
    mine has > 40 uncommented directives.

    https://help.ubuntu.com/community/RKhunter as a resource.
    Last edited by Habitual; February 14th, 2018 at 01:07 AM.
    Windows assumes the user is an idiot.
    Linux demands proof.

  6. #6
    Join Date
    Mar 2010
    Location
    UK
    Beans
    481
    Distro
    Kubuntu 16.04 Xenial Xerus

    Re: Data from Rootkit Hunter. Do I need to take any action?

    Quote Originally Posted by Habitual View Post
    When was the last time you ran rkhunter?
    Where did
    Code:
    [01:53:48] /bin/ip [ Warning ]
    [01:53:48] Warning: The file properties have changed:
    come from?

    Is it, or has it been configured?

    I got the impression rkhunter was installed but the system has since had upgrades done to it since rkhunter was installed.

    Unconfigured rkhunter will issue "Warnings" as per
    Code:
    man rkhunter
    DESCRIPTION:second paragraph

    Does /etc/rkhunter have "more" than "3 static commands"? I read that as "has only 3 lines in it."
    mine has > 40 uncommented directives.

    https://help.ubuntu.com/community/RKhunter as a resource.
    1:53:48 came from the scan I did a few days ago.

    I don't think it has been configured

    Yes, upgrades from the repository have been installed whenever they have been issued, and certainly since rkhunter was installed.

    There are lots of lines in rkhunter, some are uncommented. I gave the ones mentioned in the help page
    Dell Dimension E 520 Viiv
    Pentium D 2.8 GHz. Presler Dual Core 2.8GHz, 800MHz FSB 2x2MB cache
    RAM 4 GB. Dual Channel (4x1024GB) 667MHz DDR2
    Browser: Firefox

  7. #7

    Re: Data from Rootkit Hunter. Do I need to take any action?

    Quote Originally Posted by anon_private View Post
    I don't think it has been configured
    See To avoid these warnings section.
    and
    https://ubuntuforums.org/showthread....3#post13603673
    Last edited by Habitual; February 14th, 2018 at 05:37 PM.
    Windows assumes the user is an idiot.
    Linux demands proof.

  8. #8
    Join Date
    Mar 2010
    Location
    UK
    Beans
    481
    Distro
    Kubuntu 16.04 Xenial Xerus

    Re: Data from Rootkit Hunter. Do I need to take any action?

    I only have the middle one from this grouping

    #ALLOWHIDDENDIR=/dev/.udev
    #ALLOWHIDDENDIR=/dev/.static
    #ALLOWHIDDENDIR=/dev/.initramfs

    Should I add the other two to the file?
    Last edited by anon_private; February 15th, 2018 at 01:05 PM.
    Dell Dimension E 520 Viiv
    Pentium D 2.8 GHz. Presler Dual Core 2.8GHz, 800MHz FSB 2x2MB cache
    RAM 4 GB. Dual Channel (4x1024GB) 667MHz DDR2
    Browser: Firefox

  9. #9
    Join Date
    Mar 2010
    Location
    UK
    Beans
    481
    Distro
    Kubuntu 16.04 Xenial Xerus

    Re: Data from Rootkit Hunter. Do I need to take any action?

    An answer to the above would be appreciated
    Dell Dimension E 520 Viiv
    Pentium D 2.8 GHz. Presler Dual Core 2.8GHz, 800MHz FSB 2x2MB cache
    RAM 4 GB. Dual Channel (4x1024GB) 667MHz DDR2
    Browser: Firefox

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •