rkhunter on centos revisited

Discussion in 'Installation/Configuration' started by Doug G, Aug 16, 2009.

  1. Doug G

    Doug G Member HowtoForge Supporter

    I know the abundance of rkhunter warning emails has been discussed previously but I haven't found any posts with a cure. I get an email an hour, and from 11PM to 12AM one every 5 minutes. I think the email may be triggerred in rkhunter because a scan starts with 'warning this os is not fully supported'.

    Anyway, my question: Is there somewhere I can manually hack something to only run rkhunter once a day instead of (apparently) once an hour? I read in another thread this is something being done in svn, but if there is somewhere I can make a hack I'd be happy to do so. I haven't been able to figure out on my own exactly how the ispconfig3 scheduled jobs really get scheduled.

    tia
     
  2. till

    till Super Moderator Staff Member ISPConfig Developer

    Take a look at the code of the monitor module in /usr/local/ispconfig/server/mods-available/
     
  3. Bookworm

    Bookworm Member

    What fixed my problem was running the hashupd.sh script, after removing the two 'warning' hidden file scans from the rkhunter config file.

    Unfortunately, you can't get the hashupd.sh script from sourceforge anymore - you have to get it from elsewhere. If you can't find it online, let me know, and I'll either post it, or email it to you.
     

Share This Page