<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Activity for Rootkit Hunter</title><link>https://sourceforge.net/p/rkhunter/activity/</link><description>Recent activity for Rootkit Hunter</description><language>en</language><lastBuildDate>Wed, 08 Oct 2025 15:59:39 -0000</lastBuildDate><item><title>Anton Avramov posted a comment on ticket #190</title><link>https://sourceforge.net/p/rkhunter/bugs/190/?limit=25#f580</link><description>It's actually a security issue since someone can add PermitRootLogin in /etc/ssh/sshd_config and then override it in /etc/ssh/sshd_config.d/ later on.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Anton Avramov</dc:creator><pubDate>Wed, 08 Oct 2025 15:59:39 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/190/?limit=25#f580</guid></item><item><title>&lt;REDACTED&gt; created ticket #47</title><link>https://sourceforge.net/p/rkhunter/patches/47/</link><description>Fixed egrep usage, new modern grep usage</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">&lt;REDACTED&gt;</dc:creator><pubDate>Fri, 29 Aug 2025 21:27:27 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/patches/47/</guid></item><item><title>CaPaCuL created ticket #191</title><link>https://sourceforge.net/p/rkhunter/bugs/191/</link><description>systemd-journald and some warnings</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CaPaCuL</dc:creator><pubDate>Wed, 25 Jun 2025 22:38:12 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/191/</guid></item><item><title>Justin F. Hallett created ticket #190</title><link>https://sourceforge.net/p/rkhunter/bugs/190/</link><description>ALLOW_SSH_ROOT_USER only looks in main sshd_config, add sshd_config.d</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Justin F. Hallett</dc:creator><pubDate>Mon, 23 Dec 2024 18:31:56 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/190/</guid></item><item><title>Martin posted a comment on ticket #74</title><link>https://sourceforge.net/p/rkhunter/support-requests/74/?limit=25#685a</link><description>I'm happy to contribute to this as well. I don't think unspawn will respawn.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Martin</dc:creator><pubDate>Thu, 17 Oct 2024 02:24:25 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/support-requests/74/?limit=25#685a</guid></item><item><title>Martin created ticket #76</title><link>https://sourceforge.net/p/rkhunter/support-requests/76/</link><description>Rkhunter project handover</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Martin</dc:creator><pubDate>Wed, 16 Oct 2024 11:25:33 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/support-requests/76/</guid></item><item><title>Christophe PEREZ created ticket #189</title><link>https://sourceforge.net/p/rkhunter/bugs/189/</link><description>daily output error</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Christophe PEREZ</dc:creator><pubDate>Mon, 23 Sep 2024 03:23:43 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/189/</guid></item><item><title>Christophe PEREZ posted a comment on ticket #169</title><link>https://sourceforge.net/p/rkhunter/bugs/169/?limit=25#6c34/297e/4714/9666</link><description>Thanks !</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Christophe PEREZ</dc:creator><pubDate>Thu, 15 Aug 2024 22:53:22 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/169/?limit=25#6c34/297e/4714/9666</guid></item><item><title>sai-mike posted a comment on ticket #169</title><link>https://sourceforge.net/p/rkhunter/bugs/169/?limit=25#6c34/297e/4714</link><description>Go to the Code tab. Make sure you are in the develop branch. In the banner at the top it will say: Tree [866f69] develop / next to that will be a link to 'Download Snapshot'. Click that. This will give you a .zip file to download. Download it to a directory and unzip. Change to the directory and run ./installer.sh Follow the rest of the installation instructions in the README file.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">sai-mike</dc:creator><pubDate>Thu, 15 Aug 2024 20:42:28 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/169/?limit=25#6c34/297e/4714</guid></item><item><title>Christophe PEREZ posted a comment on ticket #169</title><link>https://sourceforge.net/p/rkhunter/bugs/169/?limit=25#6c34/297e</link><description>Where is that development version please ?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Christophe PEREZ</dc:creator><pubDate>Thu, 15 Aug 2024 19:47:50 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/169/?limit=25#6c34/297e</guid></item><item><title>William Garber created ticket #75</title><link>https://sourceforge.net/p/rkhunter/support-requests/75/</link><description>small bug with fix; gives error message about grep</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">William Garber</dc:creator><pubDate>Mon, 29 Jul 2024 17:13:00 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/support-requests/75/</guid></item><item><title>Abhilash Mandula posted a comment on ticket #31</title><link>https://sourceforge.net/p/rkhunter/feature-requests/31/?limit=25#95fa/546f</link><description>I discovered a script that the hacker is executing using a cron job. Can we integrate this script into the rkhunter toolkit check?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Abhilash Mandula</dc:creator><pubDate>Sat, 13 Jul 2024 03:51:11 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/feature-requests/31/?limit=25#95fa/546f</guid></item><item><title>Abhilash Mandula modified a comment on ticket #31</title><link>https://sourceforge.net/p/rkhunter/feature-requests/31/?limit=25#112d</link><description/><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Abhilash Mandula</dc:creator><pubDate>Sat, 13 Jul 2024 03:50:55 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/feature-requests/31/?limit=25#112d</guid></item><item><title>Abhilash Mandula posted a comment on ticket #31</title><link>https://sourceforge.net/p/rkhunter/feature-requests/31/?limit=25#112d</link><description>I found a script which the hacker is running using a cron job. Is it possible to include this script as well in rkhunter toolkit check?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Abhilash Mandula</dc:creator><pubDate>Fri, 12 Jul 2024 04:25:12 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/feature-requests/31/?limit=25#112d</guid></item><item><title>Lionel Debroux posted a comment on ticket #188</title><link>https://sourceforge.net/p/rkhunter/bugs/188/?limit=25#f157</link><description>There's a drawback to memoizing the output of strings, though: DoS upon huge rcfiles... Here's another take on optimizing the possible_rkt_strings check, which no longer memoizes anything. I split the work between a fast path which tries to find all strings at once in every rcfile, and a slow path if the first check returns at least one match. Core i7-6700 HQ (SMP, SMT disabled), 32 GB DDR4-2133, Debian sid amd64, cache hot: before: \time rkhunter_ --cronjob --report-warnings-only --enable possible_rkt_strings...</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lionel Debroux</dc:creator><pubDate>Sat, 04 May 2024 22:40:47 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/188/?limit=25#f157</guid></item><item><title>Lionel Debroux created ticket #188</title><link>https://sourceforge.net/p/rkhunter/bugs/188/</link><description>Redundant operations: possible rootkit strings check</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lionel Debroux</dc:creator><pubDate>Mon, 29 Apr 2024 18:32:02 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/188/</guid></item><item><title>Lionel Debroux posted a comment on ticket #186</title><link>https://sourceforge.net/p/rkhunter/bugs/186/?limit=25#fa34</link><description>New version: the warnings-only mode works better.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lionel Debroux</dc:creator><pubDate>Mon, 29 Apr 2024 18:04:14 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/186/?limit=25#fa34</guid></item><item><title>Lionel Debroux posted a comment on ticket #186</title><link>https://sourceforge.net/p/rkhunter/bugs/186/?limit=25#d409</link><description>I gave my idea a go, stopping at the point where the /var/log/rkhunter.log file created by rkhunter -c --sk does not contain relevant changes anymore, when LANGUAGE=en. On two computers ~15 years apart, both equipped with SATA SSDs, my changes seem to yield a significant speedup, without significant adverse effect on memory consumption. Core i7-6700 HQ (SMP, SMT disabled), 32 GB DDR4-2133, Debian sid amd64, cache hot (second run): before: 211.88user 153.26system 4:47.00elapsed 127%CPU (0avgtext+0avgdata...</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lionel Debroux</dc:creator><pubDate>Sun, 28 Apr 2024 19:07:01 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/186/?limit=25#d409</guid></item><item><title>Christophe PEREZ created ticket #187</title><link>https://sourceforge.net/p/rkhunter/bugs/187/</link><description>project dead</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Christophe PEREZ</dc:creator><pubDate>Wed, 24 Apr 2024 14:38:02 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/187/</guid></item><item><title>Lionel Debroux created ticket #186</title><link>https://sourceforge.net/p/rkhunter/bugs/186/</link><description>Redundant operations: parsing of the external translations file ?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lionel Debroux</dc:creator><pubDate>Sun, 21 Apr 2024 20:41:03 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/186/</guid></item><item><title>David Waring created ticket #185</title><link>https://sourceforge.net/p/rkhunter/bugs/185/</link><description>ALLOW_SSH_PROT_V1 check should skip on OpenSSH 7.6 or later</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David Waring</dc:creator><pubDate>Sun, 17 Mar 2024 19:00:15 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/185/</guid></item><item><title>Dogsbody posted a comment on ticket #74</title><link>https://sourceforge.net/p/rkhunter/support-requests/74/?limit=25#cfd5</link><description>I would be honoured to carry on the great work. Please add me as an administrator and share anything required. Thank you.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dogsbody</dc:creator><pubDate>Tue, 05 Dec 2023 09:15:16 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/support-requests/74/?limit=25#cfd5</guid></item><item><title>John Horne posted a comment on ticket #74</title><link>https://sourceforge.net/p/rkhunter/support-requests/74/?limit=25#2ce7</link><description>If you want to become the project owner, then let me know and I'll add you as an administrator and provide various passwords.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Mon, 04 Dec 2023 18:50:55 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/support-requests/74/?limit=25#2ce7</guid></item><item><title>mildred ratched created ticket #184</title><link>https://sourceforge.net/p/rkhunter/bugs/184/</link><description>no matter what i try, there are 2 files i'm unsuccesful to exclude from rkhunter</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">mildred ratched</dc:creator><pubDate>Sun, 03 Dec 2023 18:36:39 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/184/</guid></item><item><title>Dogsbody posted a comment on ticket #74</title><link>https://sourceforge.net/p/rkhunter/support-requests/74/?limit=25#9060</link><description>How can I help? I realise you don't know me from Adam :-) I'd be happy to have a chat (e-mail, public, private, phone, zoom) if you like I could pull a group of interested individuals together and make a plan together or I guess you could just hand over the keys ¯_(ツ)_/¯ I personally do not want to shake anything up. The rkhunter project is good &amp; strong, it just needs a few tweaks for more modern operating systems and perhaps the docs a lick of paint. I've just had a look and according to my posts...</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dogsbody</dc:creator><pubDate>Fri, 01 Dec 2023 09:22:05 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/support-requests/74/?limit=25#9060</guid></item><item><title>John Horne posted a comment on ticket #74</title><link>https://sourceforge.net/p/rkhunter/support-requests/74/?limit=25#3f65</link><description>The rkhunter project needs a new owner. I cannot do it. I haven't heard from unspawn in 10 years or more, so it needs someone else.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Fri, 01 Dec 2023 02:11:13 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/support-requests/74/?limit=25#3f65</guid></item><item><title>Dogsbody posted a comment on ticket #74</title><link>https://sourceforge.net/p/rkhunter/support-requests/74/?limit=25#1394</link><description>Hi John, I have just posted in the Rkhunter-users mailing list as I tend to hang out there more than here :-) I would be very interested in helping keep rkhunter going. We still use rkhunter as part of our suite of protection on around 150 servers and run https://rkhmirror.dogsbody.com/ for the times that sourceforge goes down. I'd be very happy to help support it's transition, even if just to keep things ticking over as new distributions are released :-) How can we (all) make this happen? Thank...</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dogsbody</dc:creator><pubDate>Thu, 30 Nov 2023 21:17:49 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/support-requests/74/?limit=25#1394</guid></item><item><title>Adrian posted a comment on ticket #183</title><link>https://sourceforge.net/p/rkhunter/bugs/183/?limit=50#dd51</link><description>This make sense to some degree, of course you cannot test the tool on all the distros, but at the same time it might be better to either improve the detection so we don't see so many false positives (and forget our small distribution, even on straight Debian as long as I remember this tool always gave a lot of false positives), or provide a bit more detailed info about the warning: what it means, why it shows up and what to check. Also, it's a bit weird if there's let's say a virus scanner that reports...</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Adrian</dc:creator><pubDate>Wed, 23 Aug 2023 23:57:21 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/183/?limit=50#dd51</guid></item><item><title>John Horne posted a comment on ticket #183</title><link>https://sourceforge.net/p/rkhunter/bugs/183/?limit=25#a56b</link><description>If you are providing rkhunter as a package for your distro, then modify the rkhunter config file you distribute to whitelist the relevant rootkit files. If you are not providing it as a package, but users are complaining, then tell them to whitelist the files.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Wed, 23 Aug 2023 21:37:18 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/183/?limit=25#a56b</guid></item><item><title>Adrian created ticket #183</title><link>https://sourceforge.net/p/rkhunter/bugs/183/</link><description>false positives on MX Linux</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Adrian</dc:creator><pubDate>Wed, 23 Aug 2023 20:02:20 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/183/</guid></item><item><title>John Horne posted a comment on ticket #74</title><link>https://sourceforge.net/p/rkhunter/support-requests/74/?limit=25#c926</link><description>The development version 1.4.7 has been updated since 2018, but not released as a new version (1.4.8). I have no plans to do that as I can no longer support RKH any more. Version 1.4.7 does seem stable though, so should be usable in production. Are you asking to take over the rkhunter project on sourceforge? If so, then I can provide you with some passwords required, and add you as an administrator. (As far as I remember all I need do then is remove myself as an admin, and you are then the project...</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Thu, 10 Aug 2023 12:12:23 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/support-requests/74/?limit=25#c926</guid></item><item><title>KenUnix created ticket #74</title><link>https://sourceforge.net/p/rkhunter/support-requests/74/</link><description>Updates to rkhunter 1.4.6</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">KenUnix</dc:creator><pubDate>Mon, 07 Aug 2023 23:50:58 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/support-requests/74/</guid></item><item><title>KenUnix posted a comment on a blog post</title><link>https://sourceforge.net/p/rkhunter/news/2018/02/rootkit-hunter-release-146/?limit=25#4c7b</link><description>Is it safe to assume that rkhunter is a dead project sine it has not been updated sine 2018? If it is dead is it possible to get the source code to update it? Thanks</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">KenUnix</dc:creator><pubDate>Mon, 07 Aug 2023 23:48:46 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/news/2018/02/rootkit-hunter-release-146/?limit=25#4c7b</guid></item><item><title>Andrew Ruthven posted a comment on ticket #151</title><link>https://sourceforge.net/p/rkhunter/bugs/151/?limit=25#8e94</link><description>rkhunter on the develop branch uses sshd -T to list the configuration settings, including whatever is set in files within sshd_config.d .</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Andrew Ruthven</dc:creator><pubDate>Tue, 13 Jun 2023 10:27:29 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/151/?limit=25#8e94</guid></item><item><title>Matthew M. Ogilvie posted a comment on ticket #151</title><link>https://sourceforge.net/p/rkhunter/bugs/151/?limit=25#d2eb</link><description>7) More recent versions of sshd support an "Include" directive that allows moving customizations into separate file(s) in a separate directory (likely "sshd_config.d"), which can be useful to preserve those customizations if system updates want to update the main sshd_config file. I don't think rkhunter understands such includes at all - it only considers the main sshd_config file. 8) (maybe OK) I think current versions of sshd have a default "PermitRootLogin prohibit-password", which would probably...</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Matthew M. Ogilvie</dc:creator><pubDate>Sun, 04 Jun 2023 17:08:30 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/151/?limit=25#d2eb</guid></item><item><title>Matthew M. Ogilvie posted a comment on ticket #176</title><link>https://sourceforge.net/p/rkhunter/bugs/176/?limit=25#8040</link><description>Here is the the same thing formatted as an easier to use and more robust unidiff patch and isolated from any distribution-specific patches. It should be easier to combine this with other distribution-specific patches/etc. (For example, on Gentoo, this patch could be applied by simply depositing it at /etc/portage/patches/app-forensics/rkhunter-1.4.6-r1/rkhunter-GNUgrep3.8.patch and re-emerging rkhunter, until a newer version incorporates something like it directly.) I don't know enough about the...</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Matthew M. Ogilvie</dc:creator><pubDate>Fri, 03 Feb 2023 20:57:39 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/176/?limit=25#8040</guid></item><item><title>DKragen posted a comment on ticket #182</title><link>https://sourceforge.net/p/rkhunter/bugs/182/?limit=25#5a28</link><description>Regarding the various unhide options, ignore my comments above. Found that unhide is a separate program. Installing it rid the log of all the missed tests. Looks like the only remaining problem is the missing quote at line 18833</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">DKragen</dc:creator><pubDate>Tue, 31 Jan 2023 23:06:44 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/182/?limit=25#5a28</guid></item><item><title>Christophe PEREZ posted a comment on ticket #181</title><link>https://sourceforge.net/p/rkhunter/bugs/181/?limit=25#8944/8fb2</link><description>You're right. I didn't find this bug. Tried the patch with success. Thanks !</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Christophe PEREZ</dc:creator><pubDate>Tue, 31 Jan 2023 22:35:10 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/181/?limit=25#8944/8fb2</guid></item><item><title>DKragen posted a comment on ticket #182</title><link>https://sourceforge.net/p/rkhunter/bugs/182/?limit=25#31a4</link><description>Similarly, unhide-linux and unhide commands couldn't be found for hidden processes test, per the log</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">DKragen</dc:creator><pubDate>Tue, 31 Jan 2023 22:14:46 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/182/?limit=25#31a4</guid></item><item><title>DKragen posted a comment on ticket #182</title><link>https://sourceforge.net/p/rkhunter/bugs/182/?limit=25#e66c</link><description>In log found that rkhunter couldn't find the unhide-tcp command, shortly after starting to look for hidden ports. Suspect that may be related to the failure to investigate for hidden ports...</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">DKragen</dc:creator><pubDate>Tue, 31 Jan 2023 22:12:31 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/182/?limit=25#e66c</guid></item><item><title>GGGG posted a comment on ticket #181</title><link>https://sourceforge.net/p/rkhunter/bugs/181/?limit=250#8944</link><description>you should have a look a #176 An unofficial patch is provided. As long as i can say still not merged</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">GGGG</dc:creator><pubDate>Tue, 31 Jan 2023 22:00:56 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/181/?limit=250#8944</guid></item><item><title>DKragen posted a comment on ticket #182</title><link>https://sourceforge.net/p/rkhunter/bugs/182/?limit=25#6c8c</link><description>rkhunter v. 1.4.6</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">DKragen</dc:creator><pubDate>Tue, 31 Jan 2023 21:52:41 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/182/?limit=25#6c8c</guid></item><item><title>DKragen created ticket #182</title><link>https://sourceforge.net/p/rkhunter/bugs/182/</link><description>fresh reinstall but still flagging code problem with incomplete quote</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">DKragen</dc:creator><pubDate>Tue, 31 Jan 2023 21:49:18 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/182/</guid></item><item><title>Christophe PEREZ created ticket #181</title><link>https://sourceforge.net/p/rkhunter/bugs/181/</link><description>grep warnings</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Christophe PEREZ</dc:creator><pubDate>Tue, 31 Jan 2023 20:34:06 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/181/</guid></item><item><title>Giorgos posted a comment on ticket #179</title><link>https://sourceforge.net/p/rkhunter/bugs/179/?limit=25#f158</link><description>THANKS Tom!!! ;-) I had the MIRRORS_MODE -&gt; 2, so I changed it -&gt; 0 and now works!!! :-) (Though I don't understand why didn't work at the 1st place, since I don't have any local mirrors). HAPPY NEW YEAR everyone!!! :-)</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Giorgos</dc:creator><pubDate>Thu, 05 Jan 2023 16:51:43 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/179/?limit=25#f158</guid></item><item><title>Tom Hendrikx posted a comment on ticket #179</title><link>https://sourceforge.net/p/rkhunter/bugs/179/?limit=25#5ce7</link><description>I just solved this issue with ubuntu, I guess the same problem exists on debian. The problem is a combination of issues: The default WEB_CMD in rkhunter.conf is set to '/bin/false' you need to change it to your liking, and the primary example for that in the comments is to replace it with 'curl'. Now you can do --versioncheck, but you'll get 'Download failed'. The logfile (/var/log/rkhunter.log) tells you: "Info: The mirrors file has no required mirrors in it: /var/lib/rkhunter/db/mirrors.dat" The...</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Tom Hendrikx</dc:creator><pubDate>Thu, 05 Jan 2023 13:40:12 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/179/?limit=25#5ce7</guid></item><item><title>DKragen posted a comment on ticket #179</title><link>https://sourceforge.net/p/rkhunter/bugs/179/?limit=25#f812</link><description>The rkhunter page (https://rkhunter.sourceforge.net/1.4.6/mirrors.dat)is down: "An error has been encountered in accessing this page. Server: rkhunter.sourceforge.net URL path: /1.4.6/mirrors.dat Error notes: NONE Error type: 404 Request method: GET Request query string: NONE Time: 2023-01-01 23:01:10 UTC (1672614070) Reporting this problem: The problem you have encountered is with a project web site hosted by SourceForge.net. This issue should be reported to the SourceForge.net-hosted project (not...</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">DKragen</dc:creator><pubDate>Sun, 01 Jan 2023 23:35:51 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/179/?limit=25#f812</guid></item><item><title>kiran nettimi posted a comment on ticket #180</title><link>https://sourceforge.net/p/rkhunter/bugs/180/?limit=25#a7b9</link><description>Can anyone take a look into this please</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">kiran nettimi</dc:creator><pubDate>Tue, 22 Nov 2022 06:07:30 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/180/?limit=25#a7b9</guid></item><item><title>kiran nettimi created ticket #180</title><link>https://sourceforge.net/p/rkhunter/bugs/180/</link><description>"rkhunter --propupd" command  execution got hung</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">kiran nettimi</dc:creator><pubDate>Fri, 18 Nov 2022 11:27:51 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/180/</guid></item><item><title>Nong Hoang Tu created ticket #52</title><link>https://sourceforge.net/p/rkhunter/feature-requests/52/</link><description>An alternative way to detect diamorphine rootkit</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Nong Hoang Tu</dc:creator><pubDate>Sat, 12 Nov 2022 05:03:58 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/feature-requests/52/</guid></item><item><title>sbourdette posted a comment on ticket #169</title><link>https://sourceforge.net/p/rkhunter/bugs/169/?limit=25#1904</link><description>Do you know when it would be available in distribution repository like ubuntu ?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">sbourdette</dc:creator><pubDate>Thu, 10 Nov 2022 09:26:20 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/169/?limit=25#1904</guid></item><item><title>John Horne committed [866f69]</title><link>https://sourceforge.net/p/rkhunter/rkh_code/ci/866f69cbf5dba7ec6b6c3948fb3c94cb0b3dd56a/</link><description>Removed redundant comment.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Mon, 24 Oct 2022 16:16:52 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/rkh_code/ci/866f69cbf5dba7ec6b6c3948fb3c94cb0b3dd56a/</guid></item><item><title>John Horne committed [980239]</title><link>https://sourceforge.net/p/rkhunter/rkh_code/ci/980239f7fe662922621dbb0a133e32830a992913/</link><description>Correct regex used with grep/egrep/sed commands. Also correct msg when link hash changed, it it the target that changed not the link itself.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Mon, 24 Oct 2022 15:27:48 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/rkh_code/ci/980239f7fe662922621dbb0a133e32830a992913/</guid></item><item><title>Giorgos created ticket #179</title><link>https://sourceforge.net/p/rkhunter/bugs/179/</link><description>Update failed.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Giorgos</dc:creator><pubDate>Thu, 20 Oct 2022 12:22:12 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/179/</guid></item><item><title>John Horne committed [140b0f]</title><link>https://sourceforge.net/p/rkhunter/rkh_code/ci/140b0fb83f0053999c2b5e84065e36928cb0be3d/</link><description>Renamed the '--versioncheck' option to '--version-check'. Old name still recognized.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Wed, 19 Oct 2022 14:48:32 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/rkh_code/ci/140b0fb83f0053999c2b5e84065e36928cb0be3d/</guid></item><item><title>John Horne committed [138f02]</title><link>https://sourceforge.net/p/rkhunter/rkh_code/ci/138f02802c1e465a4575841004592abe7b43fdf4/</link><description>Cater for grep 3.8 reporting about stray escape characters in regex.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Wed, 19 Oct 2022 14:35:41 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/rkh_code/ci/138f02802c1e465a4575841004592abe7b43fdf4/</guid></item><item><title>John Horne committed [9ab9c3]</title><link>https://sourceforge.net/p/rkhunter/rkh_code/ci/9ab9c360d7a5e19babe293bc85d8490edcc0defc/</link><description>Forgot to set the default for ALLOW_SSH_PROT_V1 to 2.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Tue, 18 Oct 2022 16:24:13 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/rkh_code/ci/9ab9c360d7a5e19babe293bc85d8490edcc0defc/</guid></item><item><title>John Horne committed [3626c5]</title><link>https://sourceforge.net/p/rkhunter/rkh_code/ci/3626c57b0ffc6a6624e33a91b2867f8bd6f711d2/</link><description>Carry out the check for 'grep -a' on all O/S's now.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Tue, 18 Oct 2022 15:38:54 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/rkh_code/ci/3626c57b0ffc6a6624e33a91b2867f8bd6f711d2/</guid></item><item><title>John Horne committed [e25e2a]</title><link>https://sourceforge.net/p/rkhunter/rkh_code/ci/e25e2acd6642ab713702822cdf350e8ecce2b62f/</link><description>Removed egrep as a required command, also changed occurrences of egrep to 'grep -E'.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Tue, 18 Oct 2022 13:04:01 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/rkh_code/ci/e25e2acd6642ab713702822cdf350e8ecce2b62f/</guid></item><item><title>John Horne committed [2b0dd4]</title><link>https://sourceforge.net/p/rkhunter/rkh_code/ci/2b0dd4b31515c0753381d229a95db3cd5ac2315b/</link><description>Reorganized part of the 'filesystem' check so that whitelisted entries are ignored before further testing on them.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Sun, 16 Oct 2022 18:53:40 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/rkh_code/ci/2b0dd4b31515c0753381d229a95db3cd5ac2315b/</guid></item><item><title>Paul Menchini posted a comment on ticket #175</title><link>https://sourceforge.net/p/rkhunter/bugs/175/?limit=25#5bbc/a46e</link><description>I added it, which suppressed the error. But, not sure if that is the proper action. __ I'm phoning this in. Please excuse brevity, autocorrect mishaps, typos and the like. No electrons were harmed in the composition or transmission of this email. On Fri, Oct 14, 2022, 11:48 Justin Pasher jpasher@users.sourceforge.net wrote: Does /etc/rkhunter.conf contain this line? Mine does. SCRIPTWHITELIST=/usr/bin/which.debianutils I see that Ubuntu 20.04 does not have it, but 22.04 does. Maybe your conf file...</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Paul Menchini</dc:creator><pubDate>Fri, 14 Oct 2022 23:18:52 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/175/?limit=25#5bbc/a46e</guid></item><item><title>Justin Pasher posted a comment on ticket #178</title><link>https://sourceforge.net/p/rkhunter/bugs/178/?limit=25#ec85</link><description>I tried running "rkhunter --enable filesystem" using the latest snapshot on Ubuntu 22.04, and I am not seeing the grep warning anymore (it did still give me the suspicious files in /dev warning, as expected for a default config). Looking at the log file, I do see this line, so it looks like it switched shells properly. [14:19:35] Info: Environment shell is /bin/bash; rkhunter is using bash [14:19:35] Info: Unknown shell changed from /usr/bin/dash to bash Somewhat interesting is the log entry for...</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Justin Pasher</dc:creator><pubDate>Fri, 14 Oct 2022 19:37:35 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/178/?limit=25#ec85</guid></item><item><title>John Horne posted a comment on ticket #178</title><link>https://sourceforge.net/p/rkhunter/bugs/178/?limit=25#c1ab</link><description>Ah! Oh sorry, I thought the problem came from the grep command used in the 'file' pipeline. Okay, so it's the 'echo' command used later on with grep. Could you try the development version (1.4.7) of RKH? One of the first changes was to detect the shell better, and switch to bash if possible. I suspect the problem will then disappear. You can obtain the development version from: https://sourceforge.net/p/rkhunter/rkh_code/ci/develop/tree/ Click on the 'Download snapshot' towards the top-right. Unzip...</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Fri, 14 Oct 2022 16:46:12 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/178/?limit=25#c1ab</guid></item><item><title>Justin Pasher posted a comment on ticket #175</title><link>https://sourceforge.net/p/rkhunter/bugs/175/?limit=25#5bbc</link><description>Does /etc/rkhunter.conf contain this line? Mine does. SCRIPTWHITELIST=/usr/bin/which.debianutils I see that Ubuntu 20.04 does not have it, but 22.04 does. Maybe your conf file wasn't merged with upstream changes? I see this changelog entry: rkhunter (1.4.6-10) unstable; urgency=medium * Add /usr/bin/which.debianutils to SCRIPTWHITELIST. * Bump Standards-Version up to 4.6.0. -- Francois Marier &lt;francois@debian.org&gt; Sun, 22 Aug 2021 11:14:44 -0700</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Justin Pasher</dc:creator><pubDate>Fri, 14 Oct 2022 15:48:38 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/175/?limit=25#5bbc</guid></item><item><title>Justin Pasher posted a comment on ticket #178</title><link>https://sourceforge.net/p/rkhunter/bugs/178/?limit=25#cf12</link><description>The command you provided works fine without warnings (it even works fine without the tr). Keep in mind that it's the 'echo' command in dash that is causing the escape sequences to be converted to their actual ASCII characters. If you chain together the 'file' and 'grep' commands, I wouldn't expect any warnings about binary files to display, since 'file' produces "clean" output. However, rkhunter captures the results in FTYPE, then echoes it out to grep because of the special case for MACOSX. If I...</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Justin Pasher</dc:creator><pubDate>Fri, 14 Oct 2022 15:36:07 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/178/?limit=25#cf12</guid></item><item><title>John Horne posted a comment on ticket #178</title><link>https://sourceforge.net/p/rkhunter/bugs/178/?limit=25#dc0f</link><description>Thanks for that, and all the testing. Would you try the following please: file testfile | tr '[:cntrl:]' ' ' | grep abc I just want to see if the 030 (control-X) is the problem, so changing it to a space then makes grep work. (The second part of the 'tr' command is a single space in quotes, but it may not display too well above.) Using Fedora 36 and your testfile, rkhunter/grep showed no problem. It gave a warning about the file, but no grep problem. The file command shows it as a Matlab file. Using...</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Fri, 14 Oct 2022 01:10:27 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/178/?limit=25#dc0f</guid></item><item><title>John Horne modified ticket #178</title><link>https://sourceforge.net/p/rkhunter/bugs/178/</link><description>rkhunter generates "bogus" grep warnings</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Fri, 14 Oct 2022 01:10:27 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/178/</guid></item><item><title>John Horne posted a comment on ticket #178</title><link>https://sourceforge.net/p/rkhunter/bugs/178/?limit=25#3e9e</link><description>Thanks for that, and all the testing. Would you try the following please: file testfile | tr '[:cntrl:]' ' ' | grep abc I just want to see if the 030 (control-X) is the problem, so changing it to a space then makes grep work. (The second part of the 'tr' command is a single space in quotes, but it may not display too well above.) Using Fedora 36 and your testfile, rkhunter/grep showed no problem. It gave a warning about the file, but no grep problem. The file command shows it as a Matlab file. Using...</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Fri, 14 Oct 2022 01:09:57 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/178/?limit=25#3e9e</guid></item><item><title>Justin Pasher posted a comment on ticket #178</title><link>https://sourceforge.net/p/rkhunter/bugs/178/?limit=25#f874</link><description>Okay, I did a little more testing and narrowed down when it's happening, and it's a bash vs dash echo thing (Ubuntu uses dash for /bin/sh). The 'file' command is actually returning regular backslash-escaped text. I was able to create a test file that triggers the false detection that you can use (it should be 22 bytes). $ echo -ne '\x0\x0\x0\x0\xd0\xd0\xd0\xd0\x6\x0\x0\x0\x0\x0\x0\x0\x10\x0\x0\x0\xca\x18' &gt;testfile $ file testfile testfile: Matlab v4 mat-file (little endian) \312\030, numeric, rows...</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Justin Pasher</dc:creator><pubDate>Thu, 13 Oct 2022 23:37:26 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/178/?limit=25#f874</guid></item><item><title>John Horne posted a comment on ticket #178</title><link>https://sourceforge.net/p/rkhunter/bugs/178/?limit=25#5cb6</link><description>Okay, I'm having trouble replicating this. The output from the 'file' command you ran on the command-line should be the same as received by rkhunter. It shouldn't contain any binary/control characters unless the '-r' option is used. So likewise if you run 'file &lt;your matlab="" file=""&gt; | grep abc' then the 'grep' command should not be seeing anything causing it to think it is binary input. Could you run 'rkhunter --enable filesystem --debug'. This should create a file named '/tmp/rkhunter...'. Could...</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Thu, 13 Oct 2022 13:55:09 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/178/?limit=25#5cb6</guid></item><item><title>John Horne posted a comment on ticket #178</title><link>https://sourceforge.net/p/rkhunter/bugs/178/?limit=25#8c3f</link><description>From the CHANGELOG for version 1.4.0: Ensure that the ALLOWDEVFILE, ALLOWHIDDENFILE and ALLOWHIDDENDIR options re-evaluate their whitelisting lists to ensure that any wildcard entries are the most recent. (A time window previously existed which meant that the list was processed, but new files could be created before the test was run. As such they were reported as false-positive warnings, when they should have been whitelisted.) The whitelisting was previously only done before the test, but, as said...</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Thu, 13 Oct 2022 10:13:11 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/178/?limit=25#8c3f</guid></item><item><title>Robert J Dinse posted a comment on ticket #174</title><link>https://sourceforge.net/p/rkhunter/bugs/174/?limit=25#3377</link><description>Ah thank you. Now have 1.4.7 and it appears to be fixed. Thank you very much.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Robert J Dinse</dc:creator><pubDate>Thu, 13 Oct 2022 09:58:33 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/174/?limit=25#3377</guid></item><item><title>John Horne posted a comment on ticket #174</title><link>https://sourceforge.net/p/rkhunter/bugs/174/?limit=25#4beb</link><description>Yes, that just clones the master branch which is version 1.4.6. You need to click on the 'download snapshot' button to get the latest development version.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Thu, 13 Oct 2022 09:42:20 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/174/?limit=25#4beb</guid></item><item><title>Robert J Dinse posted a comment on ticket #174</title><link>https://sourceforge.net/p/rkhunter/bugs/174/?limit=25#a8d6</link><description>Ok, the version I have is 1.4.6 which is same version number as what I was running but I obtained it via: git clone https://git.code.sf.net/p/rkhunter/rkh_code rkhunter-rkh_code, I got this off the website you provided, it had: HTTPS Access: git clone https://git.code.sf.net/p/rkhunter/rkh_code rkhunter-rkh_code So that is what I did and the version I have installed is definitely from that as I wiped the previous and verified that it was all gone with locate.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Robert J Dinse</dc:creator><pubDate>Thu, 13 Oct 2022 01:08:36 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/174/?limit=25#a8d6</guid></item><item><title>John Horne posted a comment on ticket #174</title><link>https://sourceforge.net/p/rkhunter/bugs/174/?limit=25#2f92</link><description>You can't be running the right version. The development version does not contain 'libkeyutils.so.1.9' or 'Spam tool component' anywhere in its code. Run 'rkhunter -V' to see what version you have.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Thu, 13 Oct 2022 00:54:49 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/174/?limit=25#2f92</guid></item><item><title>Robert J Dinse posted a comment on ticket #174</title><link>https://sourceforge.net/p/rkhunter/bugs/174/?limit=25#c66f</link><description>I obtained the development release from the from the git server referenced in the above URL and I still get the following errors: [16:57:22] Checking running processes for suspicious files [ Warning ] [16:57:22] Warning: The following processes are using suspicious files: [16:57:22] Command: cron [16:57:22] UID: 0 PID: 3612284 [16:57:22] Pathname: /usr/lib/x86_64-linux-gnu/libkeyutils.so.1.9 [16:57:22] Possible Rootkit: Spam tool component [16:57:22] Command: dbus-daemon [16:57:22] UID: 105 PID:...</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Robert J Dinse</dc:creator><pubDate>Thu, 13 Oct 2022 00:06:17 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/174/?limit=25#c66f</guid></item><item><title>John Horne committed [1e502b]</title><link>https://sourceforge.net/p/rkhunter/rkh_code/ci/1e502b8854943c3cf041ee12fee07a296b83c25b/</link><description>Add comments about order of config file processing into man page.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Wed, 12 Oct 2022 23:57:44 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/rkh_code/ci/1e502b8854943c3cf041ee12fee07a296b83c25b/</guid></item><item><title>John Horne committed [3deeb2]</title><link>https://sourceforge.net/p/rkhunter/rkh_code/ci/3deeb225cc6e32c5b9564ffb577b276c2c85e3f6/</link><description>If rkhunter.d has no config files, then this should not give an error.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Wed, 12 Oct 2022 22:45:12 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/rkh_code/ci/3deeb225cc6e32c5b9564ffb577b276c2c85e3f6/</guid></item><item><title>John Horne committed [8d1baf]</title><link>https://sourceforge.net/p/rkhunter/rkh_code/ci/8d1baff3b48c7a166cf4cb5c5bc3e631e294f425/</link><description>Added (very) minor tests for BPFDoor, Syslogk, Symbiote, OrBit, Lightning Framework, HiddenWasp and the Bitspin and Shikitega malware.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Wed, 12 Oct 2022 17:50:57 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/rkh_code/ci/8d1baff3b48c7a166cf4cb5c5bc3e631e294f425/</guid></item><item><title>John Horne committed [0ceb4a]</title><link>https://sourceforge.net/p/rkhunter/rkh_code/ci/0ceb4a810d89f2e27dab5e029980750e7f041659/</link><description>Added v minor check for syslogk malware</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Wed, 12 Oct 2022 15:25:06 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/rkh_code/ci/0ceb4a810d89f2e27dab5e029980750e7f041659/</guid></item><item><title>John Horne posted a comment on ticket #174</title><link>https://sourceforge.net/p/rkhunter/bugs/174/?limit=25#658b/7593/077a</link><description>The development release can be found at: https://sourceforge.net/p/rkhunter/rkh_code/ci/develop/tree/ Then click on the 'download snapshot' to the top-right. Unzip the downloaded zip file, and run the installer.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Wed, 12 Oct 2022 15:00:25 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/174/?limit=25#658b/7593/077a</guid></item><item><title>John Horne committed [0a61e1]</title><link>https://sourceforge.net/p/rkhunter/rkh_code/ci/0a61e124b277f1a115629f1bae36b72ad25e3aca/</link><description>Corrected output from IPC memory segments check.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Tue, 11 Oct 2022 23:51:53 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/rkh_code/ci/0a61e124b277f1a115629f1bae36b72ad25e3aca/</guid></item><item><title>John Horne committed [2699b0]</title><link>https://sourceforge.net/p/rkhunter/rkh_code/ci/2699b0519d74fdc34c053c2cf9b246c0195547a0/</link><description>Added v minor check for BPFDoor malware.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Tue, 11 Oct 2022 15:47:29 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/rkh_code/ci/2699b0519d74fdc34c053c2cf9b246c0195547a0/</guid></item><item><title>John Horne committed [2b7a20]</title><link>https://sourceforge.net/p/rkhunter/rkh_code/ci/2b7a208aac849f5cd9126178a994bb367838905a/</link><description>Changed default value of ALLOW_SSH_PROT_V1 option to 2.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Tue, 11 Oct 2022 15:29:24 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/rkh_code/ci/2b7a208aac849f5cd9126178a994bb367838905a/</guid></item><item><title>John Horne committed [efb203]</title><link>https://sourceforge.net/p/rkhunter/rkh_code/ci/efb203b5008a82798f564da32a589de82a7643e3/</link><description>Improved the previous SSH commit: caters for config file sub-directory, and adds the 'With key' test result.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Tue, 11 Oct 2022 15:05:52 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/rkh_code/ci/efb203b5008a82798f564da32a589de82a7643e3/</guid></item><item><title>Robert J Dinse posted a comment on ticket #174</title><link>https://sourceforge.net/p/rkhunter/bugs/174/?limit=25#658b/7593</link><description>Where can I pick up the development release? ---------------------------------------_- Eskimo North Linux Friendly Internet Access, Shell Accounts, and Hosting. Knowledgeable human assistance, not telephone trees or script readers. See our web site: http://www.eskimo.com/ (206) 812-0051 or (800) 246-6874. On Sun, 9 Oct 2022, John Horne wrote: Date: Sun, 09 Oct 2022 21:25:24 -0000 From: John Horne jhorne@users.sourceforge.net Reply-To: "[rkhunter:bugs] " 174@bugs.rkhunter.p.re.sourceforge.net To:...</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Robert J Dinse</dc:creator><pubDate>Sun, 09 Oct 2022 21:46:02 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/174/?limit=25#658b/7593</guid></item><item><title>John Horne posted a comment on ticket #174</title><link>https://sourceforge.net/p/rkhunter/bugs/174/?limit=25#658b</link><description>The output shown is from the 'running_procs' test, not suspscan. If you run something like: grep 'Disabled tests' /var/log/rkhunter.log then it will show you which tests are disabled. The issue with the libkeyutils library, and whitelisting failing (as can be seen by the pathname being a number) are known about and fixed in the development version of rkhunter.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Sun, 09 Oct 2022 21:25:23 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/174/?limit=25#658b</guid></item><item><title>Robert J Dinse posted a comment on ticket #174</title><link>https://sourceforge.net/p/rkhunter/bugs/174/?limit=25#5760</link><description>I have: DISABLE_TESTS=suspscan, and yet: [20:37:04] Warning: The following processes are using suspicious files: [20:37:04] Command: dbus-daemon [20:37:04] UID: 105 PID: 816 [20:37:04] Pathname: /usr/lib/x86_64-linux-gnu/libkeyutils.so.1.9 [20:37:04] Possible Rootkit: Spam tool component [20:37:04] Command: in.ftpd [20:37:04] UID: 14 PID: 1011422 [20:37:04] Pathname: /usr/lib/x86_64-linux-gnu/libkeyutils.so.1.9 [20:37:04] Possible Rootkit: Spam tool component [20:37:04] Command: in.ftpd [20:37:04]...</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Robert J Dinse</dc:creator><pubDate>Sun, 09 Oct 2022 03:43:32 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/174/?limit=25#5760</guid></item><item><title>Justin Pasher created ticket #178</title><link>https://sourceforge.net/p/rkhunter/bugs/178/</link><description>rkhunter generates "bogus" grep warnings</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Justin Pasher</dc:creator><pubDate>Fri, 07 Oct 2022 22:54:02 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/178/</guid></item><item><title>John Horne posted a comment on ticket #174</title><link>https://sourceforge.net/p/rkhunter/bugs/174/?limit=25#1911</link><description>Suspscan is part of the 'malware' test which you have enabled (looking at the above). You haven't said what your DISABLE_TESTS setting is. John.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Fri, 30 Sep 2022 19:48:13 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/174/?limit=25#1911</guid></item><item><title>John Horne posted a comment on ticket #169</title><link>https://sourceforge.net/p/rkhunter/bugs/169/?limit=25#6c34</link><description>Fixed in the development version.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Fri, 30 Sep 2022 19:42:45 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/169/?limit=25#6c34</guid></item><item><title>John Horne modified ticket #169</title><link>https://sourceforge.net/p/rkhunter/bugs/169/</link><description>Changes to sshd config files. Creates bug.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Fri, 30 Sep 2022 19:42:45 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/169/</guid></item><item><title>John Horne committed [f6816f]</title><link>https://sourceforge.net/p/rkhunter/rkh_code/ci/f6816fbf06711191698f4eb4091a1fcd5e0836cc/</link><description>Add in use of sshd -T for SSH options check.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Horne</dc:creator><pubDate>Fri, 30 Sep 2022 14:45:31 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/rkh_code/ci/f6816fbf06711191698f4eb4091a1fcd5e0836cc/</guid></item><item><title>Matthias Fenner created ticket #177</title><link>https://sourceforge.net/p/rkhunter/bugs/177/</link><description>suspscan.dat outdated</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Matthias Fenner</dc:creator><pubDate>Wed, 21 Sep 2022 06:41:21 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/177/</guid></item><item><title>Pantelis Panayiotou posted a comment on ticket #176</title><link>https://sourceforge.net/p/rkhunter/bugs/176/?limit=25#96ce</link><description>OK, I think I've done it. The attached should contain all of GGGG's fixes, and be identical to stock 1.4.6 otherwise. It appears to work fine, for me at least. Let's hope the developers will find it useful, and manage to issue an official patch for this bug as soon as possible.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Pantelis Panayiotou</dc:creator><pubDate>Mon, 12 Sep 2022 15:15:13 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/176/?limit=25#96ce</guid></item><item><title>GGGG modified a comment on ticket #176</title><link>https://sourceforge.net/p/rkhunter/bugs/176/?limit=250#83f3</link><description>Well this patch was part of my distro. As you pointed out, it is related to systemd-journal. So, it should be reverted from mine to get something which should better work on other distros. Regards</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">GGGG</dc:creator><pubDate>Mon, 12 Sep 2022 14:34:32 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/176/?limit=250#83f3</guid></item><item><title>GGGG posted a comment on ticket #176</title><link>https://sourceforge.net/p/rkhunter/bugs/176/?limit=250#83f3</link><description>Well those patches were part of my distro. Included all from the rpm packages. As you pointed out, the relevant one is related to systemd-journal. So those patches should be reverted from mine to get something which should better work on other distros. Regards</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">GGGG</dc:creator><pubDate>Mon, 12 Sep 2022 14:32:11 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/176/?limit=250#83f3</guid></item><item><title>Pantelis Panayiotou modified a comment on ticket #176</title><link>https://sourceforge.net/p/rkhunter/bugs/176/?limit=25#52ef</link><description>Hi GGGG, The offending code seems to be this block at line 17529: RKHTMPVAR=`${PS_CMD} ${PS_ARGS} | grep -E 'systemd-journald( |$)' | grep -v 'grep'` if [ -n "${RKHTMPVAR}" ]; then SYSTEMD_JOURNAL_SEEN=1 display --to SCREEN+LOG --type PLAIN --result FOUND --color GREEN --log-indent 2 --screen-indent 4 SYSTEM_CONFIGS_SYSLOG_SYSTEMD_JOURNAL else display --to SCREEN+LOG --type PLAIN --result NOT_FOUND --color GREEN --log-indent 2 --screen-indent 4 SYSTEM_CONFIGS_SYSLOG_SYSTEMD_JOURNAL fi Removing the...</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Pantelis Panayiotou</dc:creator><pubDate>Mon, 12 Sep 2022 12:32:15 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/176/?limit=25#52ef</guid></item><item><title>Pantelis Panayiotou modified a comment on ticket #176</title><link>https://sourceforge.net/p/rkhunter/bugs/176/?limit=25#52ef</link><description>Hi GGGG, The offending code seems to be this block at line 17529: RKHTMPVAR=`${PS_CMD} ${PS_ARGS} | grep -E 'systemd-journald( |$)' | grep -v 'grep'` if [ -n "${RKHTMPVAR}" ]; then SYSTEMD_JOURNAL_SEEN=1 display --to SCREEN+LOG --type PLAIN --result FOUND --color GREEN --log-indent 2 --screen-indent 4 SYSTEM_CONFIGS_SYSLOG_SYSTEMD_JOURNAL else display --to SCREEN+LOG --type PLAIN --result NOT_FOUND --color GREEN --log-indent 2 --screen-indent 4 SYSTEM_CONFIGS_SYSLOG_SYSTEMD_JOURNAL fi Removing the...</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Pantelis Panayiotou</dc:creator><pubDate>Mon, 12 Sep 2022 12:30:43 -0000</pubDate><guid>https://sourceforge.net/p/rkhunter/bugs/176/?limit=25#52ef</guid></item></channel></rss>