Menu

#184 no matter what i try, there are 2 files i'm unsuccesful to exclude from rkhunter

main
open
nobody
None
5
2023-12-03
2023-12-03
No
Warning: Suspicious file types found in /dev:
         /dev/shm/kmotion_ramdisk/02/20231203132749.jpg: 9], baseline, precision 8, 320x240, components 3
Warning: Hidden file found: /usr/share/man/man5/.containerignore.5.gz: symbolic link to containerignore.5.gz
~

Here's my /etc/rkhunter.conf/local:
sudo cat /etc/rkhunter.conf.local

SCRIPTWHITELIST=/usr/bin/fgrep
SCRIPTWHITELIST=/usr/bin/egrep
SCRIPTWHITELIST=/usr/bin/which
SCRIPTWHITELIST=/usr/bin/groups
SCRIPTWHITELIST=/usr/bin/lwp-request

EXISTWHITELIST=/usr/share/man/man5/.containerignore.5.gz
EXISTWHITELIST=/dev/shm/kmotion_ramdisk/*

ALLOWHIDDENDIR=/dev/shm/kmotion_ramdisk
ALLOWHIDDENDIR=/etc/.java

ALLOWHIDDEN=/usr/share/man/man5/.containerignore.5.gz
ALLOWHIDDEN=/dev/shm/kmotion_ramdisk/*
ALLOWHIDDEN=/dev/shm/libpod_lock

ALLOWDEVFILE=/dev/shm/PostgreSQL.*
ALLOWDEVFILE=/dev/shm/kmotion_ramdisk/*
ALLOWDEVFILE=/dev/shm/kmotion_ramdisk/01/2*.jpg
ALLOWDEVFILE=/dev/shm/kmotion_ramdisk/02/2*.jpg
ALLOWDEVFILE=/dev/shm/kmotion_ramdisk/03/2*.jpg
ALLOWDEVFILE=/dev/shm/kmotion_ramdisk/04/2*.jpg
ALLOWDEVFILE=/dev/shm/kmotion_ramdisk/05/2*.jpg
ALLOWDEVFILE=/dev/shm/kmotion_ramdisk/06/2*.jpg
ALLOWDEVFILE=/dev/shm/kmotion_ramdisk/07/2*.jpg
ALLOWDEVFILE=/dev/shm/kmotion_ramdisk/08/2*.jpg
ALLOWDEVFILE=/dev/shm/kmotion_ramdisk/09/2*.jpg
ALLOWDEVFILE=/dev/shm/kmotion_ramdisk/10/2*.jpg
ALLOWDEVFILE=/dev/shm/kmotion_ramdisk/11/2*.jpg
ALLOWDEVFILE=/dev/shm/kmotion_ramdisk/12/2*.jpg
ALLOWDEVFILE=/dev/shm/kmotion_ramdisk/13/2*.jpg
ALLOWDEVFILE=/dev/shm/kmotion_ramdisk/14/2*.jpg
ALLOWDEVFILE=/dev/shm/kmotion_ramdisk/15/2*.jpg
ALLOWDEVFILE=/dev/shm/kmotion_ramdisk/16/2*.jpg
ALLOWDEVFILE=/dev/shm/kmotion_ramdisk/01/last_jpeg
ALLOWDEVFILE=/dev/shm/kmotion_ramdisk/02/last_jpeg
ALLOWDEVFILE=/dev/shm/kmotion_ramdisk/03/last_jpeg
ALLOWDEVFILE=/dev/shm/kmotion_ramdisk/04/last_jpeg
ALLOWDEVFILE=/dev/shm/kmotion_ramdisk/05/last_jpeg
ALLOWDEVFILE=/dev/shm/kmotion_ramdisk/06/last_jpeg
ALLOWDEVFILE=/dev/shm/libpod_lock
ALLOWDEVFILE=/dev/shm/sem.lastpassffsemaphore
ALLOWDEVFILE=/dev/shm/ShM.*

XINETD_CONF_PATH=/etc/xinetd.conf
XINETD_ALLOWED_SVC=/etc/xinetd.conf

ALLOW_SSH_PROT_V1=0

DISABLE_UNHIDE=1

INSTALLDIR=/usr

UPDATE_LANG="fr"
DISABLE_TESTS=suspscan hidden_procs deleted_files packet_cap_apps apps
#EOF

System is Debian12, but this issue is present since at least Debian 8

Version installed:
ii rkhunter 1.4.6-11 all rootkit, backdoor, sniffer and exploit scanner

Discussion


Log in to post a comment.

MongoDB Logo MongoDB