FAQ Search Today's Posts Mark Forums Read
» Video Reviews

» Linux Archive

Linux-archive is a website aiming to archive linux email lists and to make them easily accessible for linux users/developers.

» Sponsor

» Partners

» Sponsor

Go Back   Linux Archive > Ubuntu > Ubuntu User

LinkBack Thread Tools
Old 12-18-2008, 12:06 AM
Default RootkitHunter specific tests not running

les.etincelles@gmail.com wrote:
> Greetings everyone,
> this is my first post to this forum, although i have been following the
lists for a while now in the hopes of complementing my training as a
sysadmin. so hello there!!
> my question relates to Rootkithunter,
> http://www.rootkit.nl/projects/rootkit_hunter.html
> i am using version 1.3.2, the latest release. my machine is an older
ibm thinkpad running PCLinuxOS 2007 which is based on Mandriva with KDE.
> After performing a couple of system scans, I noticed the scan logged
that it did not perform a couple of checks, specifically the "hidden
processes" check. saying that this test was skipped via user's request.
> upon looking into the configuration file /etc/rkhunter.config i noticed
that it states its default is to perform ALL tests and disable NONE
> however i noticed there were a couple of tests listed as disabled. i
then proceeded to edit the file in vi, changing the disabled tests field
to "none"
> i then ran another scan, and found that the hidden processes check is
STILL not running, it is still being skipped. if anyone has any insight
as to why this is happening, please post. i am preliminarily thinking
it may have something to do with the way this particular linux distro is
laid out? thx in advance.
I believe you need the unhide package.

ubuntu-users mailing list
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-users

Thread Tools

All times are GMT. The time now is 09:24 PM.

VBulletin, Copyright ©2000 - 2014, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO ©2007, Crawlability, Inc.
Copyright 2007 - 2008, www.linux-archive.org