Rocky_Linux_8
Sponsored Link

RKHunter : Install2021/08/26

 
Install RKHunter which is the Rootkit Detection tool.
[1] Install RKHunter.
# install from EPEL

[root@dlp ~]#
dnf --enablerepo=epel -y install rkhunter
[2] Configure and Use RKHunter.
For regular checking, checking script is installed under the [/etc/cron.daily] directory and it is executed everyday by Cron.
[root@dlp ~]#
vi /etc/sysconfig/rkhunter
# recipient address for report

MAILTO=root@localhost
# if specified [yes], scan more detaily

DIAG_SCAN=no
# update database

[root@dlp ~]#
rkhunter --update
# update system file properties

[root@dlp ~]#
rkhunter --propupd
# run checking

# [--sk] means sikpping to push Enter key

# [--rwo] means display only warnings

[root@dlp ~]#
rkhunter --check --sk
[ Rootkit Hunter version 1.4.6 ]

Checking system commands...

  Performing 'strings' command checks
    Checking 'strings' command                               [ OK ]

  Performing 'shared libraries' checks
    Checking for preloading variables                        [ None found ]
    Checking for preloaded libraries                         [ None found ]
    Checking LD_LIBRARY_PATH variable                        [ Not found ]

  Performing file properties checks
    Checking for prerequisites                               [ Warning ]
    /usr/sbin/adduser                                        [ OK ]
    /usr/sbin/chkconfig                                      [ OK ]
    /usr/sbin/chroot                                         [ OK ]
    /usr/sbin/depmod                                         [ OK ]
    /usr/sbin/fsck                                           [ OK ]
    /usr/sbin/fuser                                          [ OK ]
    /usr/sbin/groupadd                                       [ OK ]

.....
.....

System checks summary
=====================

File properties checks...
    Required commands check failed
    Files checked: 136
    Suspect files: 4

Rootkit checks...
    Rootkits checked : 500
    Possible rootkits: 0

Applications checks...
    All checks skipped

The system checks took: 1 minute and 27 seconds

All results have been written to the log file: /var/log/rkhunter/rkhunter.log

One or more warnings have been found while checking the system.
Please check the log file (/var/log/rkhunter/rkhunter.log)
Matched Content