Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 6 of 6
  1. #1
    Member isputra's Avatar
    Join Date
    May 2003
    Location
    Mbelitar
    Posts
    593

    Default Warning at RootKit Hunter 1.3 Output

    Hi,

    Yesterday i have done upgraded RKHunter from 1.2.9 to 1.3.0. Today i have receive RootKit Hunter Output Daily Run from cron and full of warning as you can see below :

    --------------------------------
    Warning: Checking for preload file [ Warning ]
    Warning: Found library preload file: /etc/ld.so.preload
    Warning: The command '/usr/bin/groups' has been replaced by a script: /usr/bin/groups: Bourne shell script text executable
    Warning: The command '/usr/bin/ldd' has been replaced by a script: /usr/bin/ldd: Bourne shell script text executable
    Warning: The command '/usr/bin/whatis' has been replaced by a script: /usr/bin/whatis: Bourne shell script text executable
    Warning: The command '/sbin/ifdown' has been replaced by a script: /sbin/ifdown: Bourne-Again shell script text executable
    Warning: The command '/sbin/ifup' has been replaced by a script: /sbin/ifup: Bourne-Again shell script text executable
    Warning: Hidden file found: /usr/share/man/man1/..1.gz: gzip compressed data, from Unix, max compression
    -------------------------------------

    Seach on this forum and found nothing about above warning. Anyone, can explain to me what is the meaning of above warning and how to avoid the warning.

    Or is this just false warning again from RKHunter like happen at the earlier version before ?

    Thanks.
    It's me ...... It's me ......

  2. #2
    Member
    Join Date
    Dec 2001
    Posts
    746

    Default

    It is noting that these files do not match previous versions and are executable. You'll want to verify the contents of those files. You can do a diff on the files from that system a homogeneous system if you have one.

  3. #3
    Member isputra's Avatar
    Join Date
    May 2003
    Location
    Mbelitar
    Posts
    593

    Default

    AH, thanks cpaneldave.
    It's me ...... It's me ......

  4. #4
    Member
    Join Date
    Dec 2007
    Posts
    104

    Default

    Sorry to dig up an old thread, but I got the same exact warnings on the same bin files.

    Code:
    Warning: The command '/usr/bin/groups' has been replaced by a script: /usr/bin/groups: Bourne shell script text executable
    Warning: The command '/usr/bin/ldd' has been replaced by a script: /usr/bin/ldd: Bourne shell script text executable
    Warning: The command '/usr/bin/whatis' has been replaced by a script: /usr/bin/whatis: Bourne shell script text executable
    Warning: The command '/sbin/ifdown' has been replaced by a script: /sbin/ifdown: Bourne-Again shell script text executable
    Warning: The command '/sbin/ifup' has been replaced by a script: /sbin/ifup: Bourne-Again shell script text executable
    Warning: No output found from the lsmod command or the /proc/modules file:
            /proc/modules output: 
            lsmod output: 
    Warning: Hidden file found: /usr/share/man/man1/..1.gz: gzip compressed data, from Unix, max compression
    
    One or more warnings have been found while checking the system.
    Please check the log file (/var/log/rkhunter.log)
    I don't have an additional system to compare the files to.

    Is there anyway I can tell that they are ok? Is there a way I can overwrite them with known, good versions?
    Last edited by betoranaldi; 12-19-2008 at 10:18 AM.

  5. #5
    Member nichiyume's Avatar
    Join Date
    Nov 2004
    Location
    Phoenix, Az
    Posts
    18

    Default

    Was this your first time running rkhunter in a while? they could have been updated by yum updating a package. I've seen those, however if an attacker gained elevated privileges needed to modify those files, you would have bigger and likely more visual problems.

    You can uncomment:
    ALLOWHIDDENFILE=/usr/share/man/man1/..1.gz
    from /etc/rkhunter.conf because it is quite common to get that error.

    You could find out which package those binaries are from and re-install it.

    If you are worried about being rooted, look at ps auxf | less and see if there is something different than before. A good time to research what should be there.
    --rayrayisforever
    TranceDesign Podcast | Hardcoredreamer Blog | Gallery

  6. #6
    Member verdon's Avatar
    Join Date
    Nov 2003
    Location
    Northern Ontario, Canada
    Posts
    792

    Default

    rkhunter has a pretty good mailing list too, I think from the sourceforge page.

Similar Threads & Tags
Similar threads

  1. RootKit Hunter Scan
    By GaryT in forum Security
    Replies: 6
    Last Post: 12-11-2010, 01:58 PM
  2. rootkit hunter
    By Sheldon in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 03-14-2010, 10:20 AM
  3. The most reliable/accurate rootkit hunter?
    By santrix in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 09-17-2009, 10:10 AM
  4. Rootkit Hunter Question
    By mickalo in forum cPanel and WHM Discussions
    Replies: 6
    Last Post: 01-13-2007, 04:49 PM
  5. Rootkit Hunter 1.1.5
    By eazistore in forum cPanel Developers
    Replies: 26
    Last Post: 07-06-2005, 02:33 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube