Rkhunter

From SME Server
Revision as of 19:26, 17 September 2013 by Unnilennium (talk | contribs) (Created page with "{{Languages|Rkhunter}} =Rkhunter SSH for SME7= === Maintainer === [http://smeserver.pialasse.com/ Unnilennium aka Jean-Philippe PIALASSE] (Contrib) === Description === * Rk...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigation Jump to search


Rkhunter SSH for SME7

Maintainer

Unnilennium aka Jean-Philippe PIALASSE (Contrib)

Description

  • Rkhunter searches for rootkits and other abnormalities.


it needs the packages smeserver-rkhunter and rkhunter

Installation

  1. Log in (with username root) to the SMEserver console.
  2. Install smeserver-Rkhunter
    /usr/bin/yum install smeserver-rkhunter --enablerepo=smecontribs
    You will get a y/N-question, answer y if it looks fine. There is no need to reboot the server.
  3. you should then issue:
signal-event remoteaccess-update


Alternatively you can use the server-manager panel "Software installer" to add a new package and select smeserver-Rkhunter (repo smecontribs must be enabled) then do the reconfiguration and reboot task, instead of steps 1 and 2, then refresh your browser and configure Rkhunter,.


Editing configuration

as root you can check the current configuration :

db configuration show rkhunter
rkhunter=service
    DisableTests=apps,suspscan,system_commands
    status=enabled

to set a new value just issue ( where you change VALUE and OPTION by the appropriate data):

db configuration setprop rkhunter OPTION VALUE

DIAG_SCAN

set to yes or no, default : no

DisableTests

here you can set a string of disabled tests separated by ","(default is apps,suspscan,system_commands)

mail

allow to set the mail where you want to send daily report, default is blank for "root"

mailWarn

recipient to send a mail in case of warning. Default is empty.

status

active or deactivate rkhunter : activated / deactivated(default)

Uninstall

yum remove smeserver-Rkhunter Rkhunter

or alternatively just remove them from the server-manager "Software installer"

Additional information

you can change the destination email account, instead of the default admin account, for this contribs using :

config setprop Rkhunter AdminEmail youremail@yourdomaine.tld
signal-event conf-Rkhunter


Check installed version

yum info installed smeserver-Rkhunter