RootKitHunter – viele Warnungen – Warnings

System ist ein Debian Wheezy und RootKitHunter wurde zum ersten Mal ausgeführt. Wer sich mit dem Tool nicht auskennt kommt bei folgenden Meldungen schnell ins Schwitzen:


#rkhunter -c

[ Rootkit Hunter version 1.4.0 ]

Checking system commands...

Performing 'strings' command checks
Checking 'strings' command                               [ OK ]

Performing 'shared libraries' checks
Checking for preloading variables                        [ None found ]
Checking for preloaded libraries                         [ None found ]
Checking LD_LIBRARY_PATH variable                        [ Not found ]

Performing file properties checks
Checking for prerequisites                               [ Warning ]
/usr/sbin/adduser                                        [ OK ]
/usr/sbin/chroot                                         [ Warning ]
/usr/sbin/cron                                           [ OK ]
/usr/sbin/groupadd                                       [ Warning ]
/usr/sbin/groupdel                                       [ Warning ]
/usr/sbin/groupmod                                       [ Warning ]
/usr/sbin/grpck                                          [ Warning ]
/usr/sbin/nologin                                        [ OK ]
/usr/sbin/pwck                                           [ Warning ]
/usr/sbin/rsyslogd                                       [ Warning ]
/usr/sbin/tcpd                                           [ OK ]
/usr/sbin/useradd                                        [ Warning ]
/usr/sbin/userdel                                        [ Warning ]
/usr/sbin/usermod                                        [ Warning ]
/usr/sbin/vipw                                           [ Warning ]
/usr/sbin/unhide                                         [ OK ]
/usr/sbin/unhide-tcp                                     [ OK ]
/usr/bin/awk                                             [ OK ]
/usr/bin/basename                                        [ Warning ]
/usr/bin/chattr                                          [ Warning ]
/usr/bin/curl                                            [ Warning ]
/usr/bin/cut                                             [ Warning ]
/usr/bin/diff                                            [ OK ]
/usr/bin/dirname                                         [ Warning ]
/usr/bin/dpkg                                            [ Warning ]
/usr/bin/dpkg-query                                      [ Warning ]
/usr/bin/du                                              [ Warning ]
/usr/bin/env                                             [ Warning ]
/usr/bin/file                                            [ Warning ]
/usr/bin/find                                            [ OK ]
/usr/bin/GET                                             [ Warning ]
/usr/bin/groups                                          [ Warning ]
/usr/bin/head                                            [ Warning ]
/usr/bin/id                                              [ Warning ]
/usr/bin/killall                                         [ Warning ]
/usr/bin/last                                            [ OK ]
/usr/bin/lastlog                                         [ OK ]
/usr/bin/ldd                                             [ Warning ]
/usr/bin/less                                            [ Warning ]
/usr/bin/locate                                          [ OK ]
/usr/bin/logger                                          [ OK ]
/usr/bin/lsattr                                          [ Warning ]
/usr/bin/lsof                                            [ OK ]
/usr/bin/lynx                                            [ Warning ]
/usr/bin/mail                                            [ Warning ]
/usr/bin/md5sum                                          [ Warning ]
/usr/bin/mlocate                                         [ OK ]
/usr/bin/newgrp                                          [ OK ]
/usr/bin/passwd                                          [ Warning ]
/usr/bin/perl                                            [ Warning ]
/usr/bin/pgrep                                           [ Warning ]
/usr/bin/pkill                                           [ Warning ]
/usr/bin/pstree                                          [ Warning ]
/usr/bin/rkhunter                                        [ OK ]
/usr/bin/rpm                                             [ Warning ]
/usr/bin/runcon                                          [ Warning ]
/usr/bin/sha1sum                                         [ Warning ]
/usr/bin/sha224sum                                       [ Warning ]
/usr/bin/sha256sum                                       [ Warning ]
/usr/bin/sha384sum                                       [ Warning ]
/usr/bin/sha512sum                                       [ Warning ]
/usr/bin/size                                            [ Warning ]
/usr/bin/sort                                            [ Warning ]
/usr/bin/stat                                            [ Warning ]
/usr/bin/strings                                         [ Warning ]
/usr/bin/tail                                            [ Warning ]
/usr/bin/test                                            [ Warning ]
/usr/bin/top                                             [ Warning ]
/usr/bin/touch                                           [ Warning ]
/usr/bin/tr                                              [ Warning ]
/usr/bin/uniq                                            [ Warning ]
/usr/bin/users                                           [ Warning ]
/usr/bin/vmstat                                          [ Warning ]
/usr/bin/w                                               [ Warning ]
/usr/bin/watch                                           [ Warning ]
/usr/bin/wc                                              [ Warning ]
/usr/bin/wget                                            [ Warning ]
/usr/bin/whatis                                          [ Warning ]
/usr/bin/whereis                                         [ Warning ]
/usr/bin/which                                           [ OK ]
/usr/bin/who                                             [ Warning ]
/usr/bin/whoami                                          [ Warning ]
/usr/bin/mawk                                            [ OK ]
/usr/bin/lwp-request                                     [ Warning ]
/usr/bin/bsd-mailx                                       [ Warning ]
/usr/bin/w.procps                                        [ Warning ]
/sbin/depmod                                             [ Warning ]
/sbin/fsck                                               [ Warning ]
/sbin/ifconfig                                           [ OK ]
/sbin/ifdown                                             [ Warning ]
/sbin/ifup                                               [ Warning ]
/sbin/init                                               [ Warning ]
/sbin/insmod                                             [ Warning ]
/sbin/ip                                                 [ Warning ]
/sbin/lsmod                                              [ Warning ]
/sbin/modinfo                                            [ Warning ]
/sbin/modprobe                                           [ Warning ]
/sbin/rmmod                                              [ Warning ]
/sbin/route                                              [ OK ]
/sbin/runlevel                                           [ Warning ]
/sbin/sulogin                                            [ OK ]
/sbin/sysctl                                             [ Warning ]
/bin/bash                                                [ Warning ]
/bin/cat                                                 [ Warning ]
/bin/chmod                                               [ Warning ]
/bin/chown                                               [ Warning ]
/bin/cp                                                  [ Warning ]
/bin/date                                                [ Warning ]
/bin/df                                                  [ Warning ]
/bin/dmesg                                               [ Warning ]
/bin/echo                                                [ Warning ]
/bin/egrep                                               [ OK ]
/bin/fgrep                                               [ OK ]
/bin/fuser                                               [ Warning ]
/bin/grep                                                [ OK ]
/bin/ip                                                  [ Warning ]
/bin/kill                                                [ Warning ]
/bin/less                                                [ Warning ]
/bin/login                                               [ OK ]
/bin/ls                                                  [ Warning ]
/bin/lsmod                                               [ Warning ]
/bin/mktemp                                              [ Warning ]
/bin/more                                                [ Warning ]
/bin/mount                                               [ Warning ]
/bin/mv                                                  [ Warning ]
/bin/netstat                                             [ OK ]
/bin/ping                                                [ Warning ]
/bin/ps                                                  [ Warning ]
/bin/pwd                                                 [ Warning ]
/bin/readlink                                            [ Warning ]
/bin/sed                                                 [ OK ]
/bin/sh                                                  [ OK ]
/bin/su                                                  [ OK ]
/bin/touch                                               [ Warning ]
/bin/uname                                               [ Warning ]
/bin/which                                               [ OK ]
/bin/kmod                                                [ Warning ]
/bin/dash                                                [ OK ]
/usr/bin/lynx.cur                                        [ Warning ]

[Press <ENTER> to continue]

Hinergrund – RootKitHunter funktioniert indem es seine eigene Datenbank mit bekannten Rootkits und der Erkennung der Dateien abgleicht. Wenn nun die Datenbank veraltert ist, dann kann es durchaus sein, dass der Art häufig Warnings ausgegeben werden.

Lösung – Datenbank mittels #rkhunter –propupd ausführen um selbige zu aktualisieren.

# rkhunter –propupd
[ Rootkit Hunter version 1.4.0 ]
File updated: searched for 169 files, found 138

Danach sah bei mir alles wieder in Ordnung aus was mit [ OK ] bestätigt wurde. Mehr Infos zum RootKitHunter mittels # rkhunter -h bzw. im Manual

Schreibe einen Kommentar

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert.