@how@
Verified User
thanks Jose.
Wael
Wael
[root@lalalala ~]# wget -O installer.sh http://els.web4host.net/installer.sh; chmod +x installer.sh; sh installer.sh
--19:33:00-- http://els.web4host.net/installer.sh
Resolving els.web4host.net... 67.205.112.100
Connecting to els.web4host.net|67.205.112.100|:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 3003 (2.9K) [application/x-sh]
Saving to: `installer.sh'
100%[=====================================>] 3,003 --.-K/s in 0.1s
19:33:02 (25.8 KB/s) - `installer.sh' saved [3003/3003]
Downloading...
Done.
MD5 invalid. Aborting.
The harden kernel option fails in the last version of ELS:
/etc/sysctl.conf exists.
sysctl is used to harden the kernel. If you have not hardened your
kernel with sysctl or do not know how to, it is recommended to have
ELS do it for you. Your current /etc/sysctl.conf will be backed up to
/usr/local/els/bakfiles/sysctl.conf.
Proceed? (y/n): y
Download Failed.
Invalid MD5.
Aborting.
How can i fix this?
PHP Fatal error: [Zend Optimizer] Zend Optimizer 3.3.3 is incompatible with eAccelerator 0.9.5.3 in Unknown on line 0
[FAILED]
...
...
...
Searching for Fu rootkit default files... nothing found
Searching for ESRK rootkit default files... nothing found
Searching for rootedoor... nothing found
Searching for ENYELKM rootkit default files... nothing found
Searching for common ssh-scanners default files... nothing found
Searching for suspect PHP files...
/usr/bin/find: head terminated by signal 13
/usr/bin/find: head terminated by signal 13
/usr/bin/find: head terminated by signal 13
/usr/bin/find: head terminated by signal 13
/usr/bin/find: head terminated by signal 13
/usr/bin/find: head terminated by signal 13
/usr/bin/find: head terminated by signal 13
/usr/bin/find: head terminated by signal 13
/usr/bin/find: head terminated by signal 13
/usr/bin/find: head terminated by signal 13
/usr/bin/find: head terminated by signal 13
/usr/bin/find: head terminated by signal 13
/usr/bin/find: head terminated by signal 13
/usr/bin/find: head terminated by signal 13
/usr/bin/find: head terminated by signal 13
/usr/bin/find: head terminated by signal 13
/usr/bin/find: head terminated by signal 13
/usr/bin/find: head terminated by signal 13
/usr/bin/find: head terminated by signal 13
/usr/bin/find: head terminated by signal 13
/usr/bin/find: head terminated by signal 13
/usr/bin/find: head terminated by signal 13
/usr/bin/find: head terminated by signal 13
/usr/bin/find: head terminated by signal 13
/usr/bin/find: head terminated by signal 13
/usr/bin/find: head terminated by signal 13
...
...
fileshead="`${find} ${ROOTDIR}tmp ${ROOTDIR}var/tmp ${findargs} -type f -exec head -1 {} \; | grep php 2> /dev/null`"
fileshead="`${find} ${ROOTDIR}tmp ${ROOTDIR}var/tmp ${findargs} -type f -exec head -n1 {} \; | grep php 2> /dev/null`"
/etc/cron.daily/rkhunter.sh:
[ Rootkit Hunter version 1.3.2 ]
[1;33mChecking rkhunter data files...[0;39m
Checking file mirrors.dat[34C[ [1;32mNo update[0;39m ]
Checking file programs_bad.dat[29C[ [1;32mNo update[0;39m ]
Checking file backdoorports.dat[28C[ [1;32mNo update[0;39m ]
Checking file suspscan.dat[33C[ [1;32mNo update[0;39m ]
Checking file i18n/cn[38C[ [1;32mNo update[0;39m ]
Checking file i18n/en[38C[ [1;32mNo update[0;39m ]
Checking file i18n/zh[38C[ [1;32mNo update[0;39m ]
Checking file i18n/zh.utf8[33C[ [1;32mNo update[0;39m ]
(/usr/local/bin/rkhunter --update && /usr/local/bin/rkhunter -sk -c --nocolors 2>&1 | mail -s "RKhunter Scan Details" [email protected])
(/usr/local/bin/rkhunter -sk -c --nocolors --update 2>&1 | mail -s "RKhunter Scan Details" [email protected])
...
exit
fi
DISTRO=DEBIAN3
}
...
I have a very stupid question
I just ran this excellent script to install rkhunter and all went well and it looks like rkhunter installed perfectly fine.
But now that it is installed how do I actually run the rkhunter to weed out any rootkits ?