LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-01-2012, 08:54 AM   #1
LQParsons
Member
 
Registered: Feb 2010
Location: North of Boston, Mass (North Shore/Cape Ann)
Distribution: CentOS 7.0 (and kvm/qemu)
Posts: 91

Rep: Reputation: 22
rkhunter.conf hash value


I have this error, for a while (my attempts to research and fix have been futile):

Quote:
[08:57:01] /etc/rkhunter.conf [ Warning ]
[08:57:01] Warning: Package manager verification has failed:
[08:57:01] File: /etc/rkhunter.conf
[08:57:01] The file hash value has changed
[08:57:01] The file size has changed
[08:57:01] The file modification time has changed
I've done:
Quote:
$ prelink -va
$ rkhunter --propupd
especally after a
Quote:
$ yum update
I have modified the rkhunter.conf, I guess I should have just put my entries into rkhunter.conf.local, I've started doing so.

How do I tell rkhunter, I've done the mal-action, it's not nefarious, please let's reset and sally forth.

-doug
 
Old 08-01-2012, 12:43 PM   #2
honeybadger
Member
 
Registered: Aug 2007
Location: India
Distribution: Slackware (mainly) and then a lot of others...
Posts: 855

Rep: Reputation: Disabled
If this is something that you have done the easiest way seems to be reinstallation. Dowload the latest rkhunter (so you will have the latest virus definations) uninstall the one you have and then install the newest one.
Hope this helps.
 
1 members found this post helpful.
Old 08-02-2012, 06:24 AM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by honeybadger View Post
If this is something that you have done the easiest way seems to be reinstallation.
Linux software rarely requires re-installation.

Due to using the package manager for verification in this case it would be easier to first ensure all local modifications are in /etc/rkhunter.conf.local, then D/L the RPM and extract rkhunter.conf and replace /etc/rkhunter.conf with the pristine one. Just to make sure also check the package with '-q --scripts' for any %post install modifications that would skew hashes.
 
1 members found this post helpful.
Old 08-06-2012, 07:53 PM   #4
LQParsons
Member
 
Registered: Feb 2010
Location: North of Boston, Mass (North Shore/Cape Ann)
Distribution: CentOS 7.0 (and kvm/qemu)
Posts: 91

Original Poster
Rep: Reputation: 22
Thank you, unspawn, you are correct,
Quote:
Linux software rarely requires re-installation.
But who knows what else I've done incorrectly as I've been "learning by doing" with rkhunter, so I printed out my .conf files and will follow honeybadger
Quote:
If this is something that you have done the easiest way seems to be re-installation.
Knowing what I now know, I'll just do it again, paying closer attention, using my efforts thus far for reference.

I actually do a little business supporting Linux for those even less competent than myself (Is that even possible? ) so it'll do me good to go through the process again, so I can understand the mistakes previously made.

thanks to all.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Perl Hashes -- Updating a hash ref via hash value 0.o Programming 5 06-05-2012 12:45 PM
Perl Hash of Hash reference query kdelover Programming 1 02-19-2011 04:47 AM
rkhunter.conf doesn't exists? qwertyjjj Linux - Newbie 19 02-17-2011 10:57 AM
Rkhunter Missing Hash values Golgo13 Linux - Software 2 07-29-2008 08:21 PM
rkhunter 1.2.9 shows bad hash for /usr/bin/file Slackware 11.0 opto Slackware 7 04-05-2007 11:48 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:54 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration