On Thu, 09 Aug 2012 19:48:04 +0100 John Horne <[email protected]> wrote:
> On Thu, 2012-06-14 at 16:14 -0600, Kevin Fenzi wrote: > > Greetings. > > > > When run on a Fedora 17 instance with the 'netatalk' package > > installed, I am seeing a false positive on the 'Spanish' rootkit: > > > > Warning: 'Spanish' Rootkit [ Warning ] > > File '/bin/ad' found > > > > This is of course /usr/bin/ad in the netatalk rpm, but due to the > > usrmove feature, /bin is just a link to /usr/bin. > > > > Perhaps we could detect this symlink case and not warn? > > > Hi, > > Catching up with old mail... > Was this problem resolved? You should be able to use > RTKT_FILE_WHITELIST=/bin/ad in the config file to whitelist the file. Sorry for the old email reply here. ;) No, it wasn't. I can try that... kevin
signature.asc
Description: PGP signature
------------------------------------------------------------------------------ Live Security Virtual Conference Exclusive live event will cover all the ways today's security and threat landscape has changed and how IT managers can respond. Discussions will include endpoint security, mobile security and the latest in malware threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________ Rkhunter-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/rkhunter-users
