Rkhunter: Difference between revisions

From James's Wiki
No edit summary
No edit summary
Line 15: Line 15:
to edit the config file and get rid of warnings:
to edit the config file and get rid of warnings:
  sudo nano /etc/rkhunter.conf
  sudo nano /etc/rkhunter.conf
to whitelist stuff in the config file add lines like:
SCRIPTWHITELIST=/usr/bin/lwp-request


run this after making changes to the config file
run this after making changes to the config file

Revision as of 14:26, 25 February 2018

download source form site

https://sourceforge.net/projects/rkhunter/files/latest/download?source=typ_redirect

tar zxf rkhunter-1.4.4.tar.gz
cd rkhunter-1.4.4/
sudo ./installer.sh --install

By default, the log file '/var/log/rkhunter.log' will be created. It will contain the results of the checks made by RKH.

to edit the config file and get rid of warnings:

sudo nano /etc/rkhunter.conf

to whitelist stuff in the config file add lines like:

SCRIPTWHITELIST=/usr/bin/lwp-request

run this after making changes to the config file

check if the config file is valid:

sudo rkhunter -C

update so you dont get a warning the the config file was changed:

sudo rkhunter --propupd

run manually from command prompt without all the annoying pauses

sudo rkhunter -c --rwo


references: https://www.digitalocean.com/community/tutorials/how-to-use-rkhunter-to-guard-against-rootkits-on-an-ubuntu-vps the cronjob

#run rkhunter at 1am
00 01 * * * rkhunter --cronjob --update --quiet