RootKitHunter – viele Warnungen – Warnings

System ist ein Debian Wheezy und RootKitHunter wurde zum ersten Mal ausgeführt. Wer sich mit dem Tool nicht auskennt kommt bei folgenden Meldungen schnell ins Schwitzen:


#rkhunter -c

[ Rootkit Hunter version 1.4.0 ]

Checking system commands...

Performing 'strings' command checks
Checking 'strings' command                               [ OK ]

Performing 'shared libraries' checks
Checking for preloading variables                        [ None found ]
Checking for preloaded libraries                         [ None found ]
Checking LD_LIBRARY_PATH variable                        [ Not found ]

Performing file properties checks
Checking for prerequisites                               [ Warning ]
/usr/sbin/adduser                                        [ OK ]
/usr/sbin/chroot                                         [ Warning ]
/usr/sbin/cron                                           [ OK ]
/usr/sbin/groupadd                                       [ Warning ]
/usr/sbin/groupdel                                       [ Warning ]
/usr/sbin/groupmod                                       [ Warning ]
/usr/sbin/grpck                                          [ Warning ]
/usr/sbin/nologin                                        [ OK ]
/usr/sbin/pwck                                           [ Warning ]
/usr/sbin/rsyslogd                                       [ Warning ]
/usr/sbin/tcpd                                           [ OK ]
/usr/sbin/useradd                                        [ Warning ]
/usr/sbin/userdel                                        [ Warning ]
/usr/sbin/usermod                                        [ Warning ]
/usr/sbin/vipw                                           [ Warning ]
/usr/sbin/unhide                                         [ OK ]
/usr/sbin/unhide-tcp                                     [ OK ]
/usr/bin/awk                                             [ OK ]
/usr/bin/basename                                        [ Warning ]
/usr/bin/chattr                                          [ Warning ]
/usr/bin/curl                                            [ Warning ]
/usr/bin/cut                                             [ Warning ]
/usr/bin/diff                                            [ OK ]
/usr/bin/dirname                                         [ Warning ]
/usr/bin/dpkg                                            [ Warning ]
/usr/bin/dpkg-query                                      [ Warning ]
/usr/bin/du                                              [ Warning ]
/usr/bin/env                                             [ Warning ]
/usr/bin/file                                            [ Warning ]
/usr/bin/find                                            [ OK ]
/usr/bin/GET                                             [ Warning ]
/usr/bin/groups                                          [ Warning ]
/usr/bin/head                                            [ Warning ]
/usr/bin/id                                              [ Warning ]
/usr/bin/killall                                         [ Warning ]
/usr/bin/last                                            [ OK ]
/usr/bin/lastlog                                         [ OK ]
/usr/bin/ldd                                             [ Warning ]
/usr/bin/less                                            [ Warning ]
/usr/bin/locate                                          [ OK ]
/usr/bin/logger                                          [ OK ]
/usr/bin/lsattr                                          [ Warning ]
/usr/bin/lsof                                            [ OK ]
/usr/bin/lynx                                            [ Warning ]
/usr/bin/mail                                            [ Warning ]
/usr/bin/md5sum                                          [ Warning ]
/usr/bin/mlocate                                         [ OK ]
/usr/bin/newgrp                                          [ OK ]
/usr/bin/passwd                                          [ Warning ]
/usr/bin/perl                                            [ Warning ]
/usr/bin/pgrep                                           [ Warning ]
/usr/bin/pkill                                           [ Warning ]
/usr/bin/pstree                                          [ Warning ]
/usr/bin/rkhunter                                        [ OK ]
/usr/bin/rpm                                             [ Warning ]
/usr/bin/runcon                                          [ Warning ]
/usr/bin/sha1sum                                         [ Warning ]
/usr/bin/sha224sum                                       [ Warning ]
/usr/bin/sha256sum                                       [ Warning ]
/usr/bin/sha384sum                                       [ Warning ]
/usr/bin/sha512sum                                       [ Warning ]
/usr/bin/size                                            [ Warning ]
/usr/bin/sort                                            [ Warning ]
/usr/bin/stat                                            [ Warning ]
/usr/bin/strings                                         [ Warning ]
/usr/bin/tail                                            [ Warning ]
/usr/bin/test                                            [ Warning ]
/usr/bin/top                                             [ Warning ]
/usr/bin/touch                                           [ Warning ]
/usr/bin/tr                                              [ Warning ]
/usr/bin/uniq                                            [ Warning ]
/usr/bin/users                                           [ Warning ]
/usr/bin/vmstat                                          [ Warning ]
/usr/bin/w                                               [ Warning ]
/usr/bin/watch                                           [ Warning ]
/usr/bin/wc                                              [ Warning ]
/usr/bin/wget                                            [ Warning ]
/usr/bin/whatis                                          [ Warning ]
/usr/bin/whereis                                         [ Warning ]
/usr/bin/which                                           [ OK ]
/usr/bin/who                                             [ Warning ]
/usr/bin/whoami                                          [ Warning ]
/usr/bin/mawk                                            [ OK ]
/usr/bin/lwp-request                                     [ Warning ]
/usr/bin/bsd-mailx                                       [ Warning ]
/usr/bin/w.procps                                        [ Warning ]
/sbin/depmod                                             [ Warning ]
/sbin/fsck                                               [ Warning ]
/sbin/ifconfig                                           [ OK ]
/sbin/ifdown                                             [ Warning ]
/sbin/ifup                                               [ Warning ]
/sbin/init                                               [ Warning ]
/sbin/insmod                                             [ Warning ]
/sbin/ip                                                 [ Warning ]
/sbin/lsmod                                              [ Warning ]
/sbin/modinfo                                            [ Warning ]
/sbin/modprobe                                           [ Warning ]
/sbin/rmmod                                              [ Warning ]
/sbin/route                                              [ OK ]
/sbin/runlevel                                           [ Warning ]
/sbin/sulogin                                            [ OK ]
/sbin/sysctl                                             [ Warning ]
/bin/bash                                                [ Warning ]
/bin/cat                                                 [ Warning ]
/bin/chmod                                               [ Warning ]
/bin/chown                                               [ Warning ]
/bin/cp                                                  [ Warning ]
/bin/date                                                [ Warning ]
/bin/df                                                  [ Warning ]
/bin/dmesg                                               [ Warning ]
/bin/echo                                                [ Warning ]
/bin/egrep                                               [ OK ]
/bin/fgrep                                               [ OK ]
/bin/fuser                                               [ Warning ]
/bin/grep                                                [ OK ]
/bin/ip                                                  [ Warning ]
/bin/kill                                                [ Warning ]
/bin/less                                                [ Warning ]
/bin/login                                               [ OK ]
/bin/ls                                                  [ Warning ]
/bin/lsmod                                               [ Warning ]
/bin/mktemp                                              [ Warning ]
/bin/more                                                [ Warning ]
/bin/mount                                               [ Warning ]
/bin/mv                                                  [ Warning ]
/bin/netstat                                             [ OK ]
/bin/ping                                                [ Warning ]
/bin/ps                                                  [ Warning ]
/bin/pwd                                                 [ Warning ]
/bin/readlink                                            [ Warning ]
/bin/sed                                                 [ OK ]
/bin/sh                                                  [ OK ]
/bin/su                                                  [ OK ]
/bin/touch                                               [ Warning ]
/bin/uname                                               [ Warning ]
/bin/which                                               [ OK ]
/bin/kmod                                                [ Warning ]
/bin/dash                                                [ OK ]
/usr/bin/lynx.cur                                        [ Warning ]

[Press <ENTER> to continue]

Hinergrund – RootKitHunter funktioniert indem es seine eigene Datenbank mit bekannten Rootkits und der Erkennung der Dateien abgleicht. Wenn nun die Datenbank veraltert ist, dann kann es durchaus sein, dass der Art häufig Warnings ausgegeben werden.

Lösung – Datenbank mittels #rkhunter –propupd ausführen um selbige zu aktualisieren.

# rkhunter –propupd
[ Rootkit Hunter version 1.4.0 ]
File updated: searched for 169 files, found 138

Danach sah bei mir alles wieder in Ordnung aus was mit [ OK ] bestätigt wurde. Mehr Infos zum RootKitHunter mittels # rkhunter -h bzw. im Manual

Schreibe einen Kommentar

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert.

Diese Website verwendet Akismet, um Spam zu reduzieren. Erfahre mehr darüber, wie deine Kommentardaten verarbeitet werden.