Enviado em 12/09/2015 - 19:18h
Me chamou muita atenção o adduser,egrep e o fgrepsudo rkhunter --update
sudo rkhunter --propupd
cat /var/log/rkhunter.log | grep Warning
[18:50:24] /usr/sbin/adduser [ Warning ]
[18:50:25] Warning: The command '/usr/sbin/adduser' has been replaced by a script: /usr/sbin/adduser: Perl script, ASCII text executable
[18:50:45] /usr/bin/ldd [ Warning ]
[18:50:45] Warning: The command '/usr/bin/ldd' has been replaced by a script: /usr/bin/ldd: Bourne-Again shell script, ASCII text executable
[18:51:33] /bin/egrep [ Warning ]
[18:51:33] Warning: The command '/bin/egrep' has been replaced by a script: /bin/egrep: POSIX shell script, ASCII text executable
[18:51:33] /bin/fgrep [ Warning ]
[18:51:34] Warning: The command '/bin/fgrep' has been replaced by a script: /bin/fgrep: POSIX shell script, ASCII text executable
[18:51:49] /bin/which [ Warning ]
[18:51:49] Warning: The command '/bin/which' has been replaced by a script: /bin/which: POSIX shell script, ASCII text executable
[19:01:12] Checking for enabled inetd services [ Warning ]
[19:01:12] Warning: Found enabled inetd service: tftp
[19:02:25] Checking if SSH root access is allowed [ Warning ]
[19:02:25] Warning: The SSH configuration option 'PermitRootLogin' has not been set.
[19:02:34] Checking /dev for suspicious file types [ Warning ]
[19:02:34] Warning: Suspicious file types found in /dev:
[19:02:35] Checking for hidden files and directories [ Warning ]
[19:02:35] Warning: Hidden directory found: /etc/.java