Rkhunter
Rkhunter SSH for SME7
Maintainer
Unnilennium aka Jean-Philippe PIALASSE (Contrib)
Description
- Rkhunter searches for rootkits and other abnormalities.
it needs the packages smeserver-rkhunter and rkhunter
Installation
- Log in (with username root) to the SMEserver console.
- Install smeserver-Rkhunter
/usr/bin/yum install smeserver-rkhunter --enablerepo=smecontribs
You will get a y/N-question, answer y if it looks fine. There is no need to reboot the server. - you should then issue:
signal-event remoteaccess-update
Alternatively you can use the server-manager panel "Software installer" to add a new package and select smeserver-Rkhunter (repo smecontribs must be enabled) then do the reconfiguration and reboot task, instead of steps 1 and 2, then refresh your browser and configure Rkhunter,.
Editing configuration
as root you can check the current configuration :
db configuration show rkhunter rkhunter=service DisableTests=apps,suspscan,system_commands status=enabled
to set a new value just issue ( where you change VALUE and OPTION by the appropriate data):
db configuration setprop rkhunter OPTION VALUE
DIAG_SCAN
set to yes or no, default : no
DisableTests
here you can set a string of disabled tests separated by ","(default is apps,suspscan,system_commands)
as an example you can avoid alert about deleted file by adding ,deleted_files
see rkhunter doc for more informations
allow to set the mail where you want to send daily report, default is blank for "root"
mailWarn
recipient to send a mail in case of warning. Default is empty.
status
active or deactivate rkhunter : activated / deactivated(default)
Uninstall
yum remove smeserver-Rkhunter Rkhunter
or alternatively just remove them from the server-manager "Software installer"
Additional information
you can change the destination email account, instead of the default admin account, for this contribs using :
config setprop Rkhunter AdminEmail youremail@yourdomaine.tld signal-event conf-Rkhunter
Check installed version
yum info installed smeserver-Rkhunter