Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 8 of 8
  1. #1
    Member
    Join Date
    Mar 2003
    Posts
    601

    Default rkhunter - System tools - syslogd bad?

    I got this output from my rkhunter....

    * System tools
    Performing 'known good' check...
    /sbin/ifconfig [ OK ]
    /usr/bin/watch [ OK ]
    /usr/bin/w [ OK ]
    /usr/bin/whoami [ OK ]
    /usr/bin/who [ OK ]
    /usr/bin/users [ OK ]
    /usr/bin/stat [ OK ]
    /usr/bin/sha1sum [ OK ]
    /usr/bin/kill [ OK ]
    /usr/bin/find [ OK ]
    /usr/bin/file [ OK ]
    /usr/bin/pstree [ OK ]
    /usr/bin/killall [ OK ]
    /usr/bin/lsattr [ OK ]
    /bin/mount [ OK ]
    /bin/netstat [ OK ]
    /bin/egrep [ OK ]
    /bin/fgrep [ OK ]
    /bin/grep [ OK ]
    /bin/cat [ OK ]
    /bin/chmod [ OK ]
    /bin/chown [ OK ]
    /bin/env [ OK ]
    /bin/ls [ OK ]
    /bin/su [ OK ]
    /bin/ps [ OK ]
    /bin/dmesg [ OK ]
    /bin/kill [ OK ]
    /bin/login [ OK ]
    /sbin/chkconfig [ OK ]
    /sbin/depmod [ OK ]
    /sbin/insmod [ OK ]
    /sbin/modinfo [ OK ]
    /sbin/sysctl [ OK ]
    /sbin/syslogd [ BAD ]
    /sbin/init [ OK ]
    /sbin/runlevel [ OK ]


    MD5
    MD5 compared: 50
    Incorrect MD5 checksums: 1


    Now, how do I know it is for sure bad, and if it is, how do I fix? Will a upcp fix it?

  2. #2
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    Are you running the latest rkhunter (v1.2.0) with the latest updates:

    rkhunter --update

    If you are, what OS are you running and what is the rpm installed version for sysklogd:

    rpm -q sysklogd
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  3. #3
    Member
    Join Date
    Mar 2003
    Posts
    601

    Default

    Quote Originally Posted by chirpy
    Are you running the latest rkhunter (v1.2.0) with the latest updates:

    rkhunter --update

    If you are, what OS are you running and what is the rpm installed version for sysklogd:

    rpm -q sysklogd

    Old version...good call. I thought we were running up to date versions on all systems, but this server had a really old version....

    Thanks!

  4. #4
    Member
    Join Date
    May 2004
    Posts
    114

    Default I'VE SAME problem with Rkhunter

    I've the latest Rkhunter

    I get the following Errors when i receive an e-mail (

    /sbin/depmod [ BAD ]
    /sbin/insmod [ BAD ]
    /sbin/lsmod [ BAD ]
    /sbin/modinfo [ BAD ]
    /sbin/modprobe [ BAD ]

    - /usr/local/etc/rc.local [ Not found ]
    - /usr/local/etc/rc.d/rc.local [ Not found ]
    - /etc/conf.d/local.start [ Not found ]
    - /etc/init.d/boot.local [ Not found ]



    I'm using
    sysklogd-1.4.1-13

    can anyone help please.
    Last edited by webits; 05-04-2005 at 07:38 AM. Reason: added right stuff
    ------------------------
    Greeeting from me
    How are you doing ?
    Keep it real
    ------------------------

  5. #5
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Mar 2003
    Location
    NC
    Posts
    725
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by webits
    I've the latest Rkhunter

    I get the following Errors when i receive an e-mail (

    /sbin/depmod [ BAD ]
    /sbin/insmod [ BAD ]
    /sbin/lsmod [ BAD ]
    /sbin/modinfo [ BAD ]
    /sbin/modprobe [ BAD ]
    Have you upgraded your kernel to a 2.6.x kernel recently OR attempted to? That looks like you installed modtools from source. It could be the sign up more problems but it also may not be.

  6. #6
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Mar 2003
    Location
    NC
    Posts
    725
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by webits
    Yeah tried to but didn't come right, I think I'll leave it in the hands of Proffesioanls to update
    So you did update the module-tools? If so you are fine, that is just because rkhunter only recognizes the rpm version.

  7. #7
    Member
    Join Date
    May 2004
    Posts
    114

    Default

    Yeah tried to but didn't come right, I think I'll leave it in the hands of Proffesioanls to update
    ------------------------
    Greeeting from me
    How are you doing ?
    Keep it real
    ------------------------

  8. #8
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Mar 2003
    Location
    NC
    Posts
    725
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by webits
    Yeah tried to but didn't come right, I think I'll leave it in the hands of Proffesioanls to update
    So you did update the module-tools? If so you are fine, that is just because rkhunter only recognizes the rpm version and not the source version you installed.

Similar Threads & Tags
Similar threads

  1. Article: 20 Linux System Monitoring Tools Every SysAdmin Should Know
    By Brook in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 07-10-2009, 09:41 PM
  2. rkhunter : I have some bad "System tools" ?
    By Nikoms in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 12-03-2007, 04:59 AM
  3. wrong fs type, bad option, bad superblock
    By katmai in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 06-05-2007, 02:40 PM
  4. Rootkit Hunter System tools BAD markers
    By sandy25 in forum cPanel and WHM Discussions
    Replies: 10
    Last Post: 11-14-2005, 05:03 PM
  5. rkhunter and bad MD5 hashes
    By Stellar in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 09-04-2004, 03:04 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube