Results 1 to 3 of 3

Thread: rkhunter - chkrootkit

  1. #1
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Dec 2002
    Location
    Kungsbacka, Sweden
    Posts
    103

    Default rkhunter - chkrootkit

    Hi there

    Wich one of those should we trust more?

    We have one server with a issue in cron mails sent fron rkhunter jobs:

    * MD5 scan
    MD5 compared : 0
    Incorrect MD5 checksums : 0

    but no problem runnig it from prmpt.

    chkrootkit say it found about 40 hidden processes from ps but that is just mysql porsesses
    and stunnel.

    Do not know wich one to trust n no 100% report

  2. #2
    Member sawbuck's Avatar
    Join Date
    Jan 2004
    Posts
    1,342
    cPanel/WHM Access Level

    Root Administrator

    Default

    Rkhunter tends to be more reliable and certainly more often updated.

  3. #3
    Member
    Join Date
    Jun 2003
    Posts
    280

    Default

    Run both (I do).

    Check Rkhunter is up to date: we ran version which would not hash check files on our RHE3 boxes. Upgrading rkhunter - and suddenly hash checks started working properly for the first time. Of course, if it _was_ working correctly and is no longer and you haven't updated rkhunter and other systems (such as chkrootkit and tripwire and even /scripts/hackcheck) are reporting inconsistencies, then you've probably got a trojan/worm/virus on your machine which has deliberterly disabled Rkhunter to stop itself from being found...

Similar Threads

  1. Rkhunter
    By jestin_virtual in forum cPanel & WHM Discussions
    Replies: 7
    Last Post: 10-30-2009, 01:59 PM
  2. rkhunter and chkrootkit place
    By modom in forum New User Questions
    Replies: 0
    Last Post: 05-09-2009, 09:47 AM
  3. /bin/sh: /root/chkrootkit-0.46a/chkrootkit: Permission denied
    By jsimon in forum cPanel & WHM Discussions
    Replies: 2
    Last Post: 10-05-2006, 02:04 AM
  4. RKHUNTER tell me this...
    By duranduran in forum cPanel & WHM Discussions
    Replies: 1
    Last Post: 08-20-2005, 03:58 AM