Serversphere.com Blog - Alerts - News

RKHunter 1.3.6 Released
RKHunter released version 1.3.6 today of their RootKit Hunter package.

Fromt the RKHunter sourceforge page:

The change log lists 29 additions including 9 configuration options and details for 12 rootkits, 29 changes including improvements for 15 rootkit checks and 22 bugfixes. Naming a few:

* New IGNORE_PRELINK_DEP_ERR configuration option in case of persistent prelink dependency errors.
* New USER_FILEPROP_FILES_DIRS configuration option to add files and directories to the file properties check.
* New COPY_LOG_ON_ERROR configuration option to copy the log file if any errors or warnings have occurred.
* New WEBCMD configuration option to specify the command used to download data file updates from the Internet.
* Rkhunter will look for configuration options in the main configuration file, and then in the local configuration file if it exists.
* New SHARED_LIB_WHITELIST configuration option for whitelisting preloaded shared libraries.
* New WARN_ON_OS_CHANGE configuration option. If unset then no warnings will be shown.
* New UPDT_ON_OS_CHANGE configuration option. If set and the O/S has changed then rkhunter will automatically update properties ('rkhunter –propupd').
* Added support for hash functions SHA224, SHA256, SHA384 and SHA512 using CPAN perl modules Digest-SHA-PurePerl or SHA256.
* New UPDATE_LANG configuration option.
* New ALLOWPROMISCIF configuration option.
* New PKGMGR_NO_VRFY configuration option for fine-grained package manager verification process control.
* Rootkit checks added: Adore Rootkit (aka strings.o aka Dextenea) cb, CX, Fu, iLLogiC, ld-linuxv.so.1, 'Spanish', trNkit, Xzibit, ZK.
* Updated rootkit / malware checks: Ambient (ark), beX2, BOBkit, Dica-kit, Dreams, Enye LKM, evil strings test, Fleakit, FreeBSD, Phalanx2, SHV4, Universal (URK).


To upgrade to or install the new version:

1. cd /usr/local/src
2. rm -rf rkhunter-*
3. wget http://prdownloads.sourceforge.net/rkhunter/rkhunter-1.3.6.tar.gz
4. tar -xzf rkhunter*
5. cd rkhunter-*
6. ./installer.sh --layout default --install


That's it. Run rkhunter --check to run a scan. For more information about using rkhunter, visit their SourceForge page.

Your Account

Email:
Password:

Blogs This Month

« September 2010 »
SunMonTueWedThuFriSat
 1234
567891011
12131415161718
19202122232425
2627282930 

Blog Entry Types

Announcements (24)
Emergency Alerts (36)
General Alerts (10)
News Blurbs (5)