Re: [opensuse] rkhunter warning



On Tue, 9 Oct 2007, Carl Hartung wrote:
Hi All,

I've run a manual scan with rkhunter and received the following warning:

- - - - - 8< - - - - -
Scanning for hidden files... [ Warning! ]
---------------
/dev/.tmp-22-64
/dev/.udev /etc/.pwd.lock
---------------
Please inspect: /dev/.tmp-22-64 (block special (22/64))

[Press <ENTER> to continue]
- - - - - 8< - - - - -

I seem to recall seeing this issue addressed some time ago but I'm not getting
any relevant Google hits.

Is this normal or how should I proceed?

You need to edit rkhunter.conf and add the files or directories. There
are some examples in the file. I have added the /dev/.udev and
/etc/pwd.lock. I am not sure waht the /dev/.tmp-22-64 file is. Once they
are added it should be clean when running and will fix the error/warning.


--
Boyd Gerber <gerberb@xxxxxxxxx>
ZENEZ 1042 East Fort Union #135, Midvale Utah 84047
--
To unsubscribe, e-mail: opensuse+unsubscribe@xxxxxxxxxxxx
For additional commands, e-mail: opensuse+help@xxxxxxxxxxxx



Relevant Pages

  • Re: [opensuse] rkhunter warning
    ... On Tuesday 09 October 2007 20:57:15 Boyd Lynn Gerber wrote: ... I've run a manual scan with rkhunter and received the following warning: ... I seem to recall seeing this issue addressed some time ago but I'm not ...
    (SuSE)
  • [opensuse] rkhunter warning
    ... I've run a manual scan with rkhunter and received the following warning: ... I seem to recall seeing this issue addressed some time ago but I'm not getting ... For additional commands, e-mail: opensuse+help@xxxxxxxxxxxx ...
    (SuSE)
  • Re: understanding chkrootkit and rkhunter logs
    ... by the chkrootkit and rkhunter on my Debian Etch home server. ... Searching for suspicious files and dirs, ... Each warning bears investigation (you will also learn about your system in ... adjust your configuration files accordingly. ...
    (Focus-Linux)
  • Re: [OT]: possible spyware?
    ... So taking cue from your message, I ran rkhunter and got two warnings. ... Performing system configuration file checks ... Warning: The SSH and rkhunter configuration options should be the same: ... So this warning also is benign ... ...
    (Debian-User)
  • Re: mondo + rkhunter
    ... Now on that different partition rkhunter spits out all sorts of warnings: ... Current inode: 472355 Stored inode: 944706 ... Warning: The file '/usr/sbin/unhide' exists on the system, but it is not present in the rkhunter.dat file. ...
    (Debian-User)