Announcement

Collapse
No announcement yet.

rkhunter error messages

Collapse
This topic is closed.
X
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    rkhunter error messages

    Hi

    I've just installed and ran rkhunter. There were no error messages until right at the end at which point I got this:

    Code:
    Performing filesystem checks
    [11:17:34] Info: Starting test name 'filesystem'
    [11:17:34] Info: SCAN_MODE_DEV set to 'THOROUGH'
    [11:17:35]  Checking /dev for suspicious file types     [ Warning ]
    [11:17:36] Warning: Suspicious file types found in /dev:
    [11:17:36]     /dev/shm/pulse-shm-2396062964: data
    [11:17:36]     /dev/shm/pulse-shm-3015296358: data
    [11:17:36]     /dev/shm/pulse-shm-3976522337: data
    [11:17:36]     /dev/shm/pulse-shm-1253536244: data
    [11:17:36]     /dev/shm/pulse-shm-892951565: data
    [11:17:36]     /dev/shm/pulse-shm-846155629: AmigaOS bitmap font
    [11:17:36]  Checking for hidden files and directories    [ Warning ]
    [11:17:36] Warning: Hidden directory found: /etc/.java
    [11:17:36] Warning: Hidden directory found: /dev/.udev
    [11:17:36] Warning: Hidden directory found: /dev/.initramfs
    Should I be concerned about these at all please?

    TIA

    Ian

    #2
    Re: rkhunter error messages

    No cause for concern, I have all of those, too.

    Expect a boatload of rkhunter messages after updates, when will give you warnings about system files being changed.

    For information about rkhunter messages, and what to do (or not do) about them, see:

    http://rkhunter.cvs.sourceforge.net/...nter/files/FAQ


    We only have to look at ourselves to see how intelligent life might develop into something we wouldn't want to meet. -- Stephen Hawking

    Comment


      #3
      Re: rkhunter error messages

      Nope.
      You can ignore those messages.

      It's a good idea to supplement rkhunter with chkrootkit, and compare their outputs
      "A nation that is afraid to let its people judge the truth and falsehood in an open market is a nation that is afraid of its people.”
      – John F. Kennedy, February 26, 1962.

      Comment


        #4
        Re: rkhunter error messages

        Nice one.

        I saw this post and thought I would try it out.

        Got exactly the same results - nice to know I am (the PC) 'normal' for once.

        Is this product mainly aimed at those who run in server mode?

        Celeron CPU G1610@2.60GHz x 2
        GeForce 8400 GS/PCle/SSE2
        Kubuntu 14.04 - 64 bit Linux - KDE 4.13.0

        Comment


          #5
          Re: rkhunter error messages

          Nope. It's aimed at those who run Linux and want to be informed in a timely manner (it's run by a cron script) of any unauthorized changes to their file system, what ever the cause. The most likely cause would be a 3rd party gaining physical access to the computer, not email or backdoor attacks.
          "A nation that is afraid to let its people judge the truth and falsehood in an open market is a nation that is afraid of its people.”
          – John F. Kennedy, February 26, 1962.

          Comment


            #6
            Re: rkhunter error messages

            Ah right - not much chance of that although I've noticed the dog looking guilty from time to time. (The study is also her 'kennel'!)

            I suppose on that basis i.e. not email or backdoor attacks, I can do without it.

            Thanks
            Celeron CPU G1610@2.60GHz x 2
            GeForce 8400 GS/PCle/SSE2
            Kubuntu 14.04 - 64 bit Linux - KDE 4.13.0

            Comment


              #7
              Re: rkhunter error messages

              If he's learned to type then I'd change the password when he's not looking!
              "A nation that is afraid to let its people judge the truth and falsehood in an open market is a nation that is afraid of its people.”
              – John F. Kennedy, February 26, 1962.

              Comment


                #8
                Re: rkhunter error messages

                Thanks for the reassurances folks

                Comment

                Working...
                X