On Wed, 20 May 2009 14:14:39 +0200 Mike Blezien 
<[email protected]> wrote:
>File updated: searched for 150 files, found 133, missing hashes 33

Missing hashes. Did you run --propupd?


>Warning: File '/bin/awk' has the immutable-bit set.

There's a whitelisting option for this, check your rkhunter.conf.


>Warning: Hidden directory found: /dev/.udev
>Warning: Hidden file found: /usr/share/man/man1/..1.gz

This is whitelisting as well.


>Warning: Suspicious file types found in /dev:
>         /dev/null.21806: ELF 32-bit LSB core file Intel 80386, 

Hmm. Makes me wonder if and why 'imake' 0) should dump core, 1) 
place core files in /dev/ and 2) name the file "null.something'. It 
may be legitimate, the suffixed natural number may represent say a 
session, but still. Quick check running stat first and then strings 
against it wouldn't hurt.


Regards, 
unSpawn
---

--
The difference is clear. Click now for a great laminating machine!
 
http://tagline.hushmail.com/fc/BLSrjkqcgmzlW3axjqF7hZQuBdBSZkbJFmIiUmtDSeg3kyAnzbeYKbitVHi/


------------------------------------------------------------------------------
Crystal Reports - New Free Runtime and 30 Day Trial
Check out the new simplified licensing option that enables 
unlimited royalty-free distribution of the report engine 
for externally facing server and web deployment. 
http://p.sf.net/sfu/businessobjects
_______________________________________________
Rkhunter-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/rkhunter-users

Reply via email to