#1 (permalink)  
Old 02-18-2005, 02:53 AM
Registered User
 
Join Date: Mar 2003
Posts: 577
noimad1
rkhunter - System tools - syslogd bad?

I got this output from my rkhunter....

* System tools
Performing 'known good' check...
/sbin/ifconfig [ OK ]
/usr/bin/watch [ OK ]
/usr/bin/w [ OK ]
/usr/bin/whoami [ OK ]
/usr/bin/who [ OK ]
/usr/bin/users [ OK ]
/usr/bin/stat [ OK ]
/usr/bin/sha1sum [ OK ]
/usr/bin/kill [ OK ]
/usr/bin/find [ OK ]
/usr/bin/file [ OK ]
/usr/bin/pstree [ OK ]
/usr/bin/killall [ OK ]
/usr/bin/lsattr [ OK ]
/bin/mount [ OK ]
/bin/netstat [ OK ]
/bin/egrep [ OK ]
/bin/fgrep [ OK ]
/bin/grep [ OK ]
/bin/cat [ OK ]
/bin/chmod [ OK ]
/bin/chown [ OK ]
/bin/env [ OK ]
/bin/ls [ OK ]
/bin/su [ OK ]
/bin/ps [ OK ]
/bin/dmesg [ OK ]
/bin/kill [ OK ]
/bin/login [ OK ]
/sbin/chkconfig [ OK ]
/sbin/depmod [ OK ]
/sbin/insmod [ OK ]
/sbin/modinfo [ OK ]
/sbin/sysctl [ OK ]
/sbin/syslogd [ BAD ]
/sbin/init [ OK ]
/sbin/runlevel [ OK ]


MD5
MD5 compared: 50
Incorrect MD5 checksums: 1


Now, how do I know it is for sure bad, and if it is, how do I fix? Will a upcp fix it?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 02-18-2005, 04:09 AM
chirpy's Avatar
Moderator
 
Join Date: Jun 2002
Location: Go on, have a guess
Posts: 13,495
chirpy will become famous soon enough
Are you running the latest rkhunter (v1.2.0) with the latest updates:

rkhunter --update

If you are, what OS are you running and what is the rpm installed version for sysklogd:

rpm -q sysklogd
__________________
Jonathan Michaelson
cPanel Forum Moderator

Need your cPanel servers secured and tuned?
cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
http://www.configserver.com
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 02-18-2005, 04:02 PM
Registered User
 
Join Date: Mar 2003
Posts: 577
noimad1
Quote:
Originally Posted by chirpy
Are you running the latest rkhunter (v1.2.0) with the latest updates:

rkhunter --update

If you are, what OS are you running and what is the rpm installed version for sysklogd:

rpm -q sysklogd

Old version...good call. I thought we were running up to date versions on all systems, but this server had a really old version....

Thanks!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 05-04-2005, 05:29 AM
Registered User
 
Join Date: May 2004
Posts: 114
webits
I'VE SAME problem with Rkhunter

I've the latest Rkhunter

I get the following Errors when i receive an e-mail (

/sbin/depmod [ BAD ]
/sbin/insmod [ BAD ]
/sbin/lsmod [ BAD ]
/sbin/modinfo [ BAD ]
/sbin/modprobe [ BAD ]

- /usr/local/etc/rc.local [ Not found ]
- /usr/local/etc/rc.d/rc.local [ Not found ]
- /etc/conf.d/local.start [ Not found ]
- /etc/init.d/boot.local [ Not found ]



I'm using
sysklogd-1.4.1-13

can anyone help please.
__________________
------------------------
Greeeting from me
How are you doing ?
Keep it real
------------------------

Last edited by webits; 05-04-2005 at 06:38 AM. Reason: added right stuff
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 05-04-2005, 10:22 AM
cPanel Partner NOC
cPanel Partner NOC Badge
 
Join Date: Mar 2003
Location: Washington DC
Posts: 639
eth00 is on a distinguished road
Quote:
Originally Posted by webits
I've the latest Rkhunter

I get the following Errors when i receive an e-mail (

/sbin/depmod [ BAD ]
/sbin/insmod [ BAD ]
/sbin/lsmod [ BAD ]
/sbin/modinfo [ BAD ]
/sbin/modprobe [ BAD ]
Have you upgraded your kernel to a 2.6.x kernel recently OR attempted to? That looks like you installed modtools from source. It could be the sign up more problems but it also may not be.
__________________
John W
Security and general linux how-to's
w w w . t o t a l s e r v e r s o l u t i o n s . c o m
Tss -- Live Support! Tweaking, Securing, 24x7 Service Monitoring, Monthly Management, Migrations, Restores, Optimization, Consulting
English And Spanish Support!
We do it all @ TotalServerSolutions
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 05-04-2005, 10:29 AM
cPanel Partner NOC
cPanel Partner NOC Badge
 
Join Date: Mar 2003
Location: Washington DC
Posts: 639
eth00 is on a distinguished road
Quote:
Originally Posted by webits
Yeah tried to but didn't come right, I think I'll leave it in the hands of Proffesioanls to update
So you did update the module-tools? If so you are fine, that is just because rkhunter only recognizes the rpm version.
__________________
John W
Security and general linux how-to's
w w w . t o t a l s e r v e r s o l u t i o n s . c o m
Tss -- Live Support! Tweaking, Securing, 24x7 Service Monitoring, Monthly Management, Migrations, Restores, Optimization, Consulting
English And Spanish Support!
We do it all @ TotalServerSolutions
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 05-04-2005, 10:30 AM
Registered User
 
Join Date: May 2004
Posts: 114
webits
Yeah tried to but didn't come right, I think I'll leave it in the hands of Proffesioanls to update
__________________
------------------------
Greeeting from me
How are you doing ?
Keep it real
------------------------
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old 05-04-2005, 10:31 AM
cPanel Partner NOC
cPanel Partner NOC Badge
 
Join Date: Mar 2003
Location: Washington DC
Posts: 639
eth00 is on a distinguished road
Quote:
Originally Posted by webits
Yeah tried to but didn't come right, I think I'll leave it in the hands of Proffesioanls to update
So you did update the module-tools? If so you are fine, that is just because rkhunter only recognizes the rpm version and not the source version you installed.
__________________
John W
Security and general linux how-to's
w w w . t o t a l s e r v e r s o l u t i o n s . c o m
Tss -- Live Support! Tweaking, Securing, 24x7 Service Monitoring, Monthly Management, Migrations, Restores, Optimization, Consulting
English And Spanish Support!
We do it all @ TotalServerSolutions
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 09:04 PM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
© cPanel Inc