On Tuesday 08 May 2012 9:37:30 am Tomas Ligursky wrote:
> Hello,
>
> I am new to rkhunter and would like to ask for a help. I use Kubuntu
> 11.10 and I have performed a scan by rkhunter version 1.4.0. Besides
> other warnings discussed many times before, I have got the following:
> ...
> [12:30:18] Info: Starting test name 'filesystem'
> [12:30:18] Performing filesystem checks
> [12:30:18] Info: SCAN_MODE_DEV set to 'THOROUGH'
> [12:30:18]   Checking /dev for suspicious file types         [ Warning ]
> [12:30:18] Warning: Suspicious file types found in /dev:
> [12:30:18]          /dev/.udev/rules.d/root.rules: ASCII text
> ...
>
> Although I guess that /dev/.udev/rules.d/root.rules is a regular file,
> I am no Ubuntu expert and I do not know whether the one of mine is not
> corrupted in some way. Find attached its copy.
>
> Thanks for any commentary.
>
> Tomas.


Tomas,

In rkhunter.conf, uncomment the following directive:

ALLOWHIDDENDIR="/dev/.udev /dev/.udevdb /dev/.udev.tdb"

I believe that should stop the warning.

Dimitri

-- 
This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean.


------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Rkhunter-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/rkhunter-users

Reply via email to