Posts: 41,665
Thanks: 1,896
Thanked 2,592 Times in 2,443 Posts
Are these warnings new? Did you run an update recently? If you have more than one server with the same OS, do you get these warnings on the other servers as well?
On http://www.debian.org/distrib/packages and http://packages.ubuntu.com/ you can search for packages (if you use Debian/Ubuntu) and also check out the contents of packages. I think they also show the MD5 sum of each file. I guess you can compare this with the MD5 sum of your own files.
Posts: 464
Thanks: 76
Thanked 35 Times in 29 Posts
now I look at the other server yes they also show there - the one i was looking at initially consistently emails me about it! I'm pretty sure they were showing like that from the day I built it.
It's debian lenny. Do you have the same warnings Falko?
4.4) After performing some updates, all, or some, binaries in the
file properties checks are marked with a 'Warning'.
What can I do?
A. The first thing would be to verify that the update is the cause
of the warnings. Checking the system log files should indicate
what has been updated.
It is most likely that the stored rkhunter file property values
need to be recalculated. To do this use the RKH '--propupd'
option. However, the output of the RKH file properties check
should only be seen as an indication that the file has changed.
Updating the stored property values should be done only after
proper verification of the files using a file integrity checker
or your distributions package management tools.
Alternatively, you can use the '--pkgmgr' command-line option, or
the PKGMGR option in the configuration file, to tell RKH to obtain
its file properties information from the package manager database.
See the README file for more information about the package manager
options.
Recent comments
1 day 23 hours ago
2 days 8 hours ago
2 days 11 hours ago
2 days 12 hours ago
2 days 13 hours ago
2 days 15 hours ago
2 days 17 hours ago
2 days 18 hours ago
3 days 10 hours ago
3 days 11 hours ago