Compare commits

...
Sign in to create a new pull request.

54 commits

Author SHA1 Message Date
Kevin Fenzi
3474090453 Add patch to find systemd-journald config and avoid warning. Fixes rhbz#2361203
Add patch to fix false positive on Li0n from bin/sbin merge. Fixes rhbz#2382304
2026-01-03 10:43:13 -08:00
Fedora Release Engineering
31a16ee1fa Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild 2025-07-25 11:59:42 +00:00
Kevin Fenzi
6292e46ab1 Add fix for additional case of grep warnings with cron. 2025-05-04 11:00:42 -07:00
Kevin Fenzi
5f79b238c2 Add a fix to grep warning about escaping /s. Fixes rhbz#2360502 2025-04-19 10:20:00 -07:00
Fedora Release Engineering
a8142de0d5 Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild 2025-01-18 22:30:53 +00:00
Miroslav Suchý
f8eba31470 convert GPLv2+ license to SPDX
This is part of https://fedoraproject.org/wiki/Changes/SPDX_Licenses_Phase_4
2024-07-26 02:39:10 +02:00
Fedora Release Engineering
d622b8fee1 Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild 2024-07-19 18:38:04 +00:00
Fedora Release Engineering
5cef75540d Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild 2024-01-26 15:28:47 +00:00
Fedora Release Engineering
120f482d92 Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild 2024-01-22 11:39:32 +00:00
Fedora Release Engineering
b5d434e590 Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2023-07-21 16:55:08 +00:00
Kevin Fenzi
0054f1e6a1 More complete fix for egrep changes. 2023-04-29 10:26:27 -07:00
Kevin Fenzi
48e94c27b2 Patch grep/egrep changes to avoid warnings in F38+ 2023-04-20 18:02:26 -07:00
Fedora Release Engineering
7982b85a2a Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2023-01-20 19:48:37 +00:00
Fedora Release Engineering
7793e743e6 Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2022-07-23 00:52:33 +00:00
Kevin Fenzi
44210e0646 Switch to using s-nail instead of mailx. 2022-06-19 15:06:25 -07:00
Kevin Fenzi
dacfb9e4cf Whitelist .dockerignore man page ( rhbz#2050551 ) 2022-06-11 10:06:14 -07:00
Fedora Release Engineering
56adbc656a - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2022-01-21 17:53:33 +00:00
Kevin Fenzi
8723338ace Add exclude for containers-common man page ( rhbz#2020015 ) 2021-11-06 10:41:20 -07:00
Fedora Release Engineering
4845f0667d - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2021-07-23 11:28:44 +00:00
Kevin Fenzi
dde37ecefa Fix bug around ssh protocol detection ( rhbz#1597635 ) 2021-02-07 14:12:26 -08:00
Fedora Release Engineering
a8f5de252c - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2021-01-27 15:20:53 +00:00
Kevin Fenzi
8e522edf60 Drop check on libkeyutils, it's a legit library now. Fixes rhbz#1914662
Look for and use the ssh.d config snippet direction. Thanks John Dodson for patch. Fixes rhbz#1851620
2021-01-16 11:08:05 -08:00
Fedora Release Engineering
63afb91cf5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2020-07-29 05:48:29 +00:00
Kevin Fenzi
4fceddaada Add allow for podman's /dev/shm files (fixes bug #1828698 ) 2020-05-16 14:00:06 -07:00
Fedora Release Engineering
5a71981d2e - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2020-01-30 17:43:43 +00:00
Kevin Fenzi
5857eb61fa Adjust config for PermitRootLogin change in f31+. Fixes bug #1756593 2019-10-06 12:39:20 -07:00
Fedora Release Engineering
36eb0f4abb - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2019-07-26 18:37:38 +00:00
Kevin Fenzi
ce2173f1dc Drop ifup/ifdown since network-scripts is now deprecated. Fixes bug #1698920 2019-04-14 16:35:50 -07:00
Fedora Release Engineering
9114393bb4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2019-02-02 11:26:58 +00:00
Igor Gnatenko
5d155e09e2 Remove obsolete Group tag
References: https://fedoraproject.org/wiki/Changes/Remove_Group_Tag
2019-01-28 20:24:45 +01:00
Fedora Release Engineering
c20f687593 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2018-07-14 03:38:17 +00:00
Jason Tibbitts
c36061be21 Remove needless use of %defattr 2018-07-10 01:33:55 -05:00
Kevin Fenzi
a1f6159937 Also add sources 2018-02-25 15:36:23 -08:00
Kevin Fenzi
545c12f7b7 Update to 1.4.6. Fixes bug #1547315
Allow KRA vault log files. Fixes bug #1541472
ipc_shared_mem warning fixed upstream. Fixes bug #1524456
2018-02-25 15:12:57 -08:00
Igor Gnatenko
a811f64f56
Remove %clean section
None of currently supported distributions need that.
Last one was EL5 which is EOL for a while.

Signed-off-by: Igor Gnatenko <ignatenkobrain@fedoraproject.org>
2018-02-14 09:17:30 +01:00
Igor Gnatenko
72a6e4ea77
Escape macros in %changelog
Reference: https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org/thread/Y2ZUKK2B7T2IKXPMODNF6HB2O5T5TS6H/
Signed-off-by: Igor Gnatenko <ignatenkobrain@fedoraproject.org>
2018-02-09 09:05:57 +01:00
Kevin Fenzi
287a60a4af Add fix for new rpm queryformat and ARCH. Fixes bug #1517387 2017-11-27 18:29:27 -08:00
Kevin Fenzi
f7a7db4c59 Disable ipc_shared_mem test for now due to false positives. Bug #1472299 2017-08-12 12:21:12 -07:00
Fedora Release Engineering
9ce2db8216 - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild 2017-07-27 13:11:28 +00:00
Petr Písař
9213982713 perl dependency renamed to perl-interpreter <https://fedoraproject.org/wiki/Changes/perl_Package_to_Install_Core_Modules> 2017-07-13 10:55:19 +02:00
Kevin Fenzi
6a0737b2c4 - Update to 1.4.4. Fixes bug #1466318
- Fix for logger and spaces. Fixes bug #1284403
2017-06-30 15:06:00 -06:00
Fedora Release Engineering
1abde9b791 - Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild 2017-02-11 11:46:04 +00:00
Mukundan Ragavan
a9f2950493 Add /dev/shm/qb* files to whitelist. Fixes bug #1403602
Add /dev/shm/squid-ssl_session_cache.shm to whitelist. Fixes bug #1411130
2017-01-25 21:11:04 -05:00
Petr Písař
d52773e606 Mandatory Perl build-requires added <https://fedoraproject.org/wiki/Changes/Build_Root_Without_Perl> 2016-06-24 10:20:10 +02:00
Kevin Fenzi
a1a79a3b7e Add /dev/shm/lldpad files to whitelist. Fixes bug #1293059 2016-04-20 09:56:26 -06:00
Fedora Release Engineering
8e4da676d1 - Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild 2016-02-04 22:12:52 +00:00
Kevin Fenzi
54e01c542b Add /dev/shm/squid files to whitelist. Fixes bug #1279632 2015-12-06 11:23:29 -07:00
Mukundan Ragavan
459190292e Change config patch to account for change in default SSH config 2015-10-13 20:17:51 -04:00
Dennis Gilmore
ad2d3480de - Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild 2015-06-18 22:24:48 +00:00
Kevin Fenzi
ccad0c6353 - Add /etc/.updated systemd file to whitelist. Fixes bug #1173481
- Add patch to fix grep -a issue with too many arguments output.·
2014-12-20 09:13:26 -07:00
Kevin Fenzi
eff4162c7d Set /var/lib/rkhunter to be mode 700. fixes bug #1154428 2014-10-27 09:42:30 -06:00
Kevin Fenzi
750e7c26af Fix cron script to work with non bash shells. Fixes bug #1146717 2014-09-26 12:16:45 -06:00
Dennis Gilmore
0396062a2f - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild 2014-06-07 21:36:46 -05:00
Kevin Fenzi
17b3bec112 Add patch to fix ipcs command in non en locales
- Add config to fix freeipa installs. Fixes bug #994567
2014-04-06 11:53:08 -06:00
11 changed files with 415 additions and 48 deletions

2
.gitignore vendored
View file

@ -2,3 +2,5 @@ rkhunter-1.3.6.tar.gz
/rkhunter-1.3.8.tar.gz
/rkhunter-1.4.0.tar.gz
/rkhunter-1.4.2.tar.gz
/rkhunter-1.4.4.tar.gz
/rkhunter-1.4.6.tar.gz

View file

@ -19,7 +19,7 @@ if [ ! -e /var/lock/subsys/rkhunter ]; then
fi
# If a diagnostic mode scan was requested, setup the parameters
if [ "$DIAG_SCAN" == "yes" ]; then
if [ "$DIAG_SCAN" = "yes" ]; then
RKHUNTER_FLAGS="--checkall --skip-keypress --nocolors --quiet --appendlog --display-logfile"
else
RKHUNTER_FLAGS="--cronjob --nocolors --report-warnings-only"

View file

@ -0,0 +1,13 @@
diff --color -Nur rkhunter-1.4.6/files/rkhunter rkhunter-1.4.6-build/rkhunter-1.4.6/files/rkhunter
--- rkhunter-1.4.6/files/rkhunter 2026-01-03 10:15:00.159046977 -0800
+++ rkhunter-1.4.6/files/rkhunter 2026-01-03 10:22:54.440297219 -0800
@@ -8680,8 +8680,7 @@
# Lion Worm
- LION_FILES="/bin/in.telnetd
- /bin/mjy
+ LION_FILES="/bin/mjy
/usr/man/man1/man1/lib/.lib/mjy
/usr/man/man1/man1/lib/.lib/in.telnetd
/usr/man/man1/man1/lib/.lib/.x

View file

@ -0,0 +1,43 @@
diff --color -Nur rkhunter-1.4.6.orig/files/rkhunter rkhunter-1.4.6/files/rkhunter
--- rkhunter-1.4.6.orig/files/rkhunter 2018-02-24 15:08:27.000000000 -0800
+++ rkhunter-1.4.6/files/rkhunter 2021-01-15 12:47:54.399665856 -0800
@@ -8370,9 +8370,7 @@
/lib/libsbr.so
/lib64/libsbr.so
/lib/libslr.so
- /lib64/libslr.so
- /lib/tls/libkeyutils.so.1
- /lib64/tls/libkeyutils.so.1"
+ /lib64/libslr.so"
EBURY_DIRS=
EBURY_KSYMS=
@@ -9762,10 +9760,6 @@
file:/usr/share/sshd.sync:Trojaned SSH daemon
file:/bin/zcut:Trojaned SSH daemon
file:/usr/bin/zmuie:Trojaned SSH daemon
- file:/lib/libkeyutils.so.1.9:Sniffer component
- file:/lib64/libkeyutils.so.1.9:Sniffer component
- file:/usr/lib/libkeyutils.so.1.9:Sniffer component
- file:/usr/lib64/libkeyutils.so.1.9:Sniffer component
file:/IptabLes:malware component
file:/.IptabLex:malware component
file:/boot/.IptabLex:malware component
@@ -9956,7 +9950,6 @@
ssh-scan:Port scanner
atac:Port scanner component
\[pdflush\]:IRC bot
- libkeyutils.so.1.9:Spam tool component
.IptabLex:malware component
.IptabLes:malware component
.flush:malware component
diff --color -Nur rkhunter-1.4.6.orig/files/signatures/RKH_libkeyutils1.ldb rkhunter-1.4.6/files/signatures/RKH_libkeyutils1.ldb
--- rkhunter-1.4.6.orig/files/signatures/RKH_libkeyutils1.ldb 2017-11-29 08:14:02.000000000 -0800
+++ rkhunter-1.4.6/files/signatures/RKH_libkeyutils1.ldb 1969-12-31 16:00:00.000000000 -0800
@@ -1 +0,0 @@
-RKH_libkeyutils.so.1.9-v1;Target:0;(((0&1&2)|(3&4&5))&((6&7&8)|(9&10)));58636174;58766572;58626e64;73686d6174;73686d6474;73686d676574;62696e64;636f6e6e656374;736f636b6574;737973636f6e66;746d7066696c65
diff --color -Nur rkhunter-1.4.6.orig/files/signatures/RKH_libkeyutils.ldb rkhunter-1.4.6/files/signatures/RKH_libkeyutils.ldb
--- rkhunter-1.4.6.orig/files/signatures/RKH_libkeyutils.ldb 2017-11-29 08:14:02.000000000 -0800
+++ rkhunter-1.4.6/files/signatures/RKH_libkeyutils.ldb 1969-12-31 16:00:00.000000000 -0800
@@ -1 +0,0 @@
-RKH_libkeyutils.1.9.so;Target:0;(0&1&2&3&4&5&6&7&8&9&10&11&12&13&14&15&16);737973636f6e66;746d7066696c65;77616974706964;736f636b6574;636f6e6e656374;73686d6174;73686d6474;73686d676574;73656d676574;73656d74696d65646f70;736c656570;737072696e7466;7372616e64;7374646f7574;737472636174;737472637079;5f5f737472647570

View file

@ -1,7 +1,7 @@
diff -Nur rkhunter-1.4.2.orig/files/rkhunter.conf rkhunter-1.4.2/files/rkhunter.conf
--- rkhunter-1.4.2.orig/files/rkhunter.conf 2014-02-23 19:38:01.000000000 -0700
+++ rkhunter-1.4.2/files/rkhunter.conf 2014-03-05 17:23:47.171809385 -0700
@@ -155,6 +155,7 @@
diff --color -Nur rkhunter-1.4.6.orig/files/rkhunter.conf rkhunter-1.4.6/files/rkhunter.conf
--- rkhunter-1.4.6.orig/files/rkhunter.conf 2018-02-19 15:49:06.000000000 -0800
+++ rkhunter-1.4.6/files/rkhunter.conf 2022-06-11 09:58:09.740944517 -0700
@@ -158,6 +158,7 @@
# default directory beneath the installation directory.
#
#TMPDIR=/var/lib/rkhunter/tmp
@ -9,16 +9,15 @@ diff -Nur rkhunter-1.4.2.orig/files/rkhunter.conf rkhunter-1.4.2/files/rkhunter.
#
# This option specifies the database directory to use.
@@ -163,7 +164,7 @@
# subsequently commented out or removed, then the program will assume a
@@ -167,6 +168,7 @@
# default directory beneath the installation directory.
#
-#DBDIR=/var/lib/rkhunter/db
#DBDIR=/var/lib/rkhunter/db
+DBDIR=/var/lib/rkhunter/db
#
# This option specifies the script directory to use.
@@ -172,6 +173,7 @@
@@ -175,6 +177,7 @@
# subsequently commented out or removed, then the program will not run.
#
#SCRIPTDIR=/usr/local/lib/rkhunter/scripts
@ -26,7 +25,7 @@ diff -Nur rkhunter-1.4.2.orig/files/rkhunter.conf rkhunter-1.4.2/files/rkhunter.
#
# This option can be used to modify the command directory list used by rkhunter
@@ -228,7 +230,7 @@
@@ -231,7 +234,7 @@
#
# The default value is '/var/log/rkhunter.log'.
#
@ -35,7 +34,7 @@ diff -Nur rkhunter-1.4.2.orig/files/rkhunter.conf rkhunter-1.4.2/files/rkhunter.
#
# Set this option to '1' if the log file is to be appended to whenever rkhunter
@@ -238,6 +240,7 @@
@@ -241,6 +244,7 @@
# The default value is '0'.
#
#APPEND_LOG=0
@ -43,7 +42,7 @@ diff -Nur rkhunter-1.4.2.orig/files/rkhunter.conf rkhunter-1.4.2/files/rkhunter.
#
# Set the following option to '1' if the log file is to be copied when rkhunter
@@ -304,6 +307,7 @@
@@ -307,6 +311,7 @@
# The default value is 'no'.
#
#ALLOW_SSH_ROOT_USER=no
@ -51,7 +50,7 @@ diff -Nur rkhunter-1.4.2.orig/files/rkhunter.conf rkhunter-1.4.2/files/rkhunter.
#
# Set this option to '1' to allow the use of the SSH-1 protocol, but note
@@ -318,6 +322,7 @@
@@ -321,6 +326,7 @@
# The default value is '0'.
#
#ALLOW_SSH_PROT_V1=0
@ -59,17 +58,17 @@ diff -Nur rkhunter-1.4.2.orig/files/rkhunter.conf rkhunter-1.4.2/files/rkhunter.
#
# This setting tells rkhunter the directory containing the SSH configuration
@@ -350,7 +355,8 @@
@@ -353,7 +359,8 @@
# program defaults.
#
ENABLE_TESTS=ALL
-DISABLE_TESTS=suspscan hidden_ports hidden_procs deleted_files packet_cap_apps
+#DISABLE_TESTS=suspscan hidden_ports hidden_procs deleted_files packet_cap_apps
+DISABLE_TESTS=suspscan hidden_ports deleted_files packet_cap_apps apps
-DISABLE_TESTS=suspscan hidden_ports hidden_procs deleted_files packet_cap_apps apps
+#DISABLE_TESTS=suspscan hidden_ports hidden_procs deleted_files packet_cap_apps apps
+DISABLE_TESTS=suspscan hidden_ports deleted_files packet_cap_apps apps ipc_shared_mem
#
# The HASH_CMD option can be used to specify the command to use for the file
@@ -422,6 +428,7 @@
@@ -435,6 +442,7 @@
# Also see the PKGMGR_NO_VRFY and USE_SUNSUM options.
#
#PKGMGR=NONE
@ -77,17 +76,25 @@ diff -Nur rkhunter-1.4.2.orig/files/rkhunter.conf rkhunter-1.4.2/files/rkhunter.
#
# It is possible that a file, which is part of a package, may have been
@@ -545,6 +552,9 @@
@@ -558,6 +566,17 @@
# The default value is the null string.
#
#EXISTWHITELIST=""
+EXISTWHITELIST=/bin/ad
+# FreeIPA Certificate Authority
+EXISTWHITELIST=/var/log/pki-ca/system
+# FreeIPA Certificate Authority
+EXISTWHITELIST=/var/log/pki/pki-tomcat/ca/system
+# FreeIPA with KRA (Password Vault)
+EXISTWHITELIST=/var/log/pki/pki-tomcat/kra/system
+RTKT_FILE_WHITELIST=/var/log/pki/pki-tomcat/kra/system
+# Some non default installed files we check
+EXISTWHITELIST=/usr/bin/GET
+EXISTWHITELIST=/usr/bin/whatis
#
# Whitelist various attributes of the specified file. The attributes are those
@@ -575,6 +585,12 @@
@@ -588,6 +607,10 @@
# The default value is the null string.
#
#SCRIPTWHITELIST=/usr/bin/groups
@ -95,12 +102,10 @@ diff -Nur rkhunter-1.4.2.orig/files/rkhunter.conf rkhunter-1.4.2/files/rkhunter.
+SCRIPTWHITELIST=/usr/bin/ldd
+SCRIPTWHITELIST=/usr/bin/groups
+SCRIPTWHITELIST=/usr/bin/GET
+SCRIPTWHITELIST=/sbin/ifup
+SCRIPTWHITELIST=/sbin/ifdown
#
# Allow the specified file to have the immutable attribute set.
@@ -605,6 +621,19 @@
@@ -630,6 +653,19 @@
#ALLOWHIDDENDIR=/dev/.udev
#ALLOWHIDDENDIR=/dev/.udevdb
#ALLOWHIDDENDIR=/dev/.mdadm
@ -120,7 +125,7 @@ diff -Nur rkhunter-1.4.2.orig/files/rkhunter.conf rkhunter-1.4.2/files/rkhunter.
#
# Allow the specified hidden file to be whitelisted.
@@ -620,6 +649,30 @@
@@ -645,6 +681,36 @@
#ALLOWHIDDENFILE=/usr/lib/hmaccalc/sha1hmac.hmac
#ALLOWHIDDENFILE=/usr/lib/hmaccalc/sha256hmac.hmac
#ALLOWHIDDENFILE=/usr/sbin/.sshd.hmac
@ -148,10 +153,16 @@ diff -Nur rkhunter-1.4.2.orig/files/rkhunter.conf rkhunter-1.4.2/files/rkhunter.
+ALLOWHIDDENFILE=/etc/.etckeeper
+ALLOWHIDDENFILE=/etc/.gitignore
+ALLOWHIDDENFILE=/etc/.bzrignore
+# systemd
+ALLOWHIDDENFILE=/etc/.updated
+# containers-common
+ALLOWHIDDENFILE=/usr/share/man/man5/.containerignore.5.gz
+# containers-common (older versions)
+ALLOWHIDDENFILE=/usr/share/man/man5/.dockerignore.5.gz
#
# Allow the specified process to use deleted files. The process name may be
@@ -681,6 +734,16 @@
@@ -714,6 +780,37 @@
#
#ALLOWDEVFILE=/dev/shm/pulse-shm-*
#ALLOWDEVFILE=/dev/shm/sem.ADBE_*
@ -165,22 +176,45 @@ diff -Nur rkhunter-1.4.2.orig/files/rkhunter.conf rkhunter-1.4.2/files/rkhunter.
+ALLOWDEVFILE="/dev/shm/spice.*"
+# created by mdadm
+ALLOWDEVFILE="/dev/md/autorebuild.pid"
+# 389 Directory Server
+ALLOWDEVFILE=/dev/shm/sem.slapd-*.stats
+# squid proxy
+ALLOWDEVFILE=/dev/shm/squid-cf*
+# squid ssl cache
+ALLOWDEVFILE=/dev/shm/squid-ssl_session_cache.shm
+# allow lldpad state file
+ALLOWDEVFILE=/dev/shm/lldpad.state
+# Allow PCS/Pacemaker/Corosync
+ALLOWDEVFILE=/dev/shm/qb-attrd-*
+ALLOWDEVFILE=/dev/shm/qb-cfg-*
+ALLOWDEVFILE=/dev/shm/qb-cib_rw-*
+ALLOWDEVFILE=/dev/shm/qb-cib_shm-*
+ALLOWDEVFILE=/dev/shm/qb-corosync-*
+ALLOWDEVFILE=/dev/shm/qb-cpg-*
+ALLOWDEVFILE=/dev/shm/qb-lrmd-*
+ALLOWDEVFILE=/dev/shm/qb-pengine-*
+ALLOWDEVFILE=/dev/shm/qb-quorum-*
+ALLOWDEVFILE=/dev/shm/qb-stonith-*
+# Allow podman
+ALLOWDEVFILE=/dev/shm/libpod*lock*
#
# This option is used to indicate if the Phalanx2 test is to perform a basic
@@ -1004,6 +1067,9 @@
# Allow the specified process pathnames to use shared memory segments.
@@ -1090,6 +1187,11 @@
#
#RTKT_DIR_WHITELIST=""
#RTKT_FILE_WHITELIST=""
+RTKT_FILE_WHITELIST=/bin/ad
+# FreeIPA Certificate Authority
+RTKT_FILE_WHITELIST=/var/log/pki-ca/system
+# FreeIPA Certificate Authority
+RTKT_FILE_WHITELIST=/var/log/pki/pki-tomcat/ca/system
#
# The following option can be used to whitelist shared library files that would
@@ -1222,3 +1288,5 @@
@@ -1329,3 +1431,5 @@
# The default value is '0'.
#
#EMPTY_LOGFILES=""
#MISSING_LOGFILES=""
#GLOBSTAR=0
+
+INSTALLDIR="/usr"

View file

@ -0,0 +1,21 @@
diff --color -Nur rkhunter-1.4.6.orig/files/rkhunter rkhunter-1.4.6/files/rkhunter
--- rkhunter-1.4.6.orig/files/rkhunter 2025-05-04 10:41:26.009520652 -0700
+++ rkhunter-1.4.6/files/rkhunter 2025-05-04 10:37:49.439199695 -0700
@@ -6691,7 +6691,7 @@
#
if [ $ERRCODE -eq 1 -a $BINISLINK -eq 1 ]; then
- if [ -n "`echo \"$FNAME\" | grep '^\/usr\/'`" ]; then
+ if [ -n "`echo \"$FNAME\" | grep '^/usr/'`" ]; then
RKHTMPVAR3=`echo "$FNAMEGREP" | sed -e 's:^/usr::'`
else
RKHTMPVAR3="/usr${FNAMEGREP}"
@@ -11005,7 +11005,7 @@
#
if [ $ERRCODE -eq 1 -a $BINISLINK -eq 1 ]; then
- if [ -n "`echo \"${FNAME}\" | grep '^\/usr\/'`" ]; then
+ if [ -n "`echo \"${FNAME}\" | grep '^/usr/'`" ]; then
RKHTMPVAR3=`echo "${FNAMEGREP}" | sed -e 's:^/usr::'`
else
RKHTMPVAR3="/usr${FNAMEGREP}"

35
rkhunter-1.4.6-grep.patch Normal file
View file

@ -0,0 +1,35 @@
diff --color -Nur rkhunter-1.4.6.orig/files/rkhunter rkhunter-1.4.6/files/rkhunter
--- rkhunter-1.4.6.orig/files/rkhunter 2023-04-29 09:32:39.288709203 -0700
+++ rkhunter-1.4.6/files/rkhunter 2023-04-29 10:00:29.396271053 -0700
@@ -70,7 +70,7 @@
# we exec to log everything to the debug file.
#
-if [ -n "`echo \"$*\" | grep '\-\-debug'`" ]; then
+if [ -n "`echo \"$*\" | grep '\--debug'`" ]; then
RKHDEBUGFILE=""
RKHDEBUGBASE="/tmp/rkhunter-debug"
@@ -181,9 +181,11 @@
# used. If it is, then some typical grep tests will fail.
#
-if [ "`echo \"rkh-grep-test\" | grep '^\+'`" = "rkh-grep-test" ]; then
+# fedora always uses POSIX grep and set an alias here for depreciated egrep too
+#if [ "`echo \"rkh-grep-test\" | grep '^\+'`" = "rkh-grep-test" ]; then
alias grep='grep -E'
-fi
+ alias egrep='grep -E'
+#fi
#
@@ -9585,7 +9587,7 @@
rpc.nfsd:tcp.log:Sniffer installed
sshd:/dev/ptyxx:OpenBSD Rootkit
sshd:/.config:SHV4 Rootkit
- sshd:+\\$.*\\$\!.*\!\!\\$:Backdoored SSH daemon installed
+ sshd:+\\$.*\\$!.*!!\\$:Backdoored SSH daemon installed
sshd:backdoor.h:Trojaned SSH daemon
sshd:backdoor_active:Trojaned SSH daemon
sshd:magic_pass_active:Trojaned SSH daemon

View file

@ -0,0 +1,12 @@
diff --color -Nur rkhunter-1.4.6/files/rkhunter rkhunter-1.4.6-build/rkhunter-1.4.6/files/rkhunter
--- rkhunter-1.4.6/files/rkhunter 2026-01-03 10:15:00.159046977 -0800
+++ rkhunter-1.4.6/files/rkhunter 2026-01-03 10:18:12.190029798 -0800
@@ -17615,7 +17615,7 @@
#
if [ -z "${SYSLOG_CONFIG_FILE}" ]; then
- SYSLOG_CONFIG_FILE="/etc/syslog.conf /etc/rsyslog.conf /etc/syslog-ng/syslog-ng.conf /etc/systemd/journald.conf /etc/systemd/systemd-journald.conf"
+ SYSLOG_CONFIG_FILE="/etc/syslog.conf /etc/rsyslog.conf /etc/syslog-ng/syslog-ng.conf /etc/systemd/journald.conf /etc/systemd/systemd-journald.conf /usr/lib/systemd/journald.conf"
fi
if [ "${SYSLOG_CONFIG_FILE}" = "NONE" ]; then

View file

@ -0,0 +1,43 @@
diff --color -Nur rkhunter-1.4.6.orig/files/rkhunter rkhunter-1.4.6/files/rkhunter
--- rkhunter-1.4.6.orig/files/rkhunter 2021-02-07 13:58:43.355270731 -0800
+++ rkhunter-1.4.6/files/rkhunter 2021-02-07 14:02:41.551554134 -0800
@@ -17379,6 +17379,12 @@
fi
done
+ if [ -d "${SSH_CONFIG_FILE}.d" ];then
+ SSH_CONFIG_FILE="${SSH_CONFIG_FILE} ${SSH_CONFIG_FILE}.d/*"
+ else
+ :
+ fi
+
if [ -n "${SSH_CONFIG_FILE}" ]; then
display --to SCREEN+LOG --type PLAIN --result FOUND --color GREEN --log-indent 2 --screen-indent 4 SYSTEM_CONFIGS_FILE_SSH
@@ -17396,7 +17402,7 @@
# First we check for allowed root access.
#
- RKHTMPVAR=`grep -i '^[ ]*PermitRootLogin[ =]' "${SSH_CONFIG_FILE}" 2>/dev/null | tail ${TAIL_OPT}1`
+ RKHTMPVAR=`grep -ih '^[ ]*PermitRootLogin[ =]' ${SSH_CONFIG_FILE} 2>/dev/null | tail ${TAIL_OPT}1`
if [ -n "${RKHTMPVAR}" ]; then
#
@@ -17427,7 +17433,7 @@
# Next we check to see if protocol version 1 is allowed.
#
- RKHTMPVAR=`grep -i '^[ ]*Protocol[ =]' "${SSH_CONFIG_FILE}" 2>/dev/null | tail ${TAIL_OPT}1`
+ RKHTMPVAR=`grep -i '^[ ]*Protocol[ =]' ${SSH_CONFIG_FILE} 2>/dev/null | tail ${TAIL_OPT}1`
if [ -n "${RKHTMPVAR}" ]; then
#
@@ -17467,7 +17473,7 @@
# First check for the Ebury backdoor.
#
- RKHTMPVAR=`grep -i '^[ ]*AuthorizedKeysFile[ =]' "${SSH_CONFIG_FILE}" 2>/dev/null | tail ${TAIL_OPT}1`
+ RKHTMPVAR=`grep -i '^[ ]*AuthorizedKeysFile[ =]' ${SSH_CONFIG_FILE} 2>/dev/null | tail ${TAIL_OPT}1`
if [ -n "${RKHTMPVAR}" ]; then
RKHTMPVAR2=`echo ${RKHTMPVAR} | sed -e 's/^[^ =]*[ ]*=*[ ]*\([^ #]*\).*$/\1/'`

View file

@ -2,23 +2,35 @@
%{!?_pkgdocdir: %global _pkgdocdir %{_docdir}/%{name}-%{version}}
Name: rkhunter
Version: 1.4.2
Release: 1%{?dist}
Version: 1.4.6
Release: 31%{?dist}
Summary: A host-based tool to scan for rootkits, backdoors and local exploits
Group: Applications/System
License: GPLv2+
# Automatically converted from old format: GPLv2+ - review is highly recommended.
License: GPL-2.0-or-later
URL: http://rkhunter.sourceforge.net/
Source0: http://downloads.sourceforge.net/rkhunter/rkhunter-%{version}.tar.gz
Source2: 01-rkhunter
Source3: rkhunter.sysconfig
Patch0: rkhunter-1.4.2-fedoraconfig.patch
Patch0: rkhunter-1.4.6-fedoraconfig.patch
# libkeyutils is an actual legit library now, so this old check is a false positive.
Patch1: rkhunter-1.4.6-drop-libkeyutils-check.patch
# have ssh checks use the sshd.d directoy config files too.
Patch2: rkhunter-1.4.6-ssh.d.patch
# Fix grep/egrep changes in f38+
Patch3: rkhunter-1.4.6-grep.patch
# Fix grep warning about escaping / in f42+
Patch4: rkhunter-1.4.6-grep-fix.patch
# Fix systemd-journald config path
Patch5: rkhunter-1.4.6-journald-config.patch
# Fix false positive Li0n detection due to bin/sbin merge
Patch6: rkhunter-1.4.6-Li0n-fix.patch
BuildArch: noarch
BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n)
BuildRequires: perl-generators
Requires: coreutils, binutils, kmod, findutils, grep
Requires: e2fsprogs, procps, lsof, iproute, wget
Requires: perl, perl(strict), perl(IO::Socket), mailx, logrotate
Requires: perl-interpreter, perl(strict), perl(IO::Socket), s-nail, logrotate
Requires: crontabs
%description
@ -28,9 +40,7 @@ and other unwanted tools.
%prep
%setup -q
%patch0 -p1
%autosetup -p1
%{__cat} <<'EOF' >%{name}.logrotate
%{_localstatedir}/log/%{name}/%{name}.log {
@ -51,6 +61,7 @@ EOF
%{__mkdir} -m755 -p ${RPM_BUILD_ROOT}%{_datadir}/%{name}/scripts
%{__mkdir} -m755 -p ${RPM_BUILD_ROOT}%{_pkgdocdir}
%{__mkdir} -m755 -p ${RPM_BUILD_ROOT}%{_mandir}/man8
%{__mkdir} -m700 -p ${RPM_BUILD_ROOT}%{_var}/lib/%{name}
%{__mkdir} -m755 -p ${RPM_BUILD_ROOT}%{_var}/lib/%{name}/db
%{__mkdir} -m755 -p ${RPM_BUILD_ROOT}%{_var}/log/%{name}
%{__mkdir} -m755 -p ${RPM_BUILD_ROOT}%{_var}/lib/%{name}/db/i18n
@ -76,11 +87,7 @@ EOF
%{__install} -m640 -p files/%{name}.conf ${RPM_BUILD_ROOT}%{_sysconfdir}/
%{__install} -m640 -p %{SOURCE3} ${RPM_BUILD_ROOT}%{_sysconfdir}/sysconfig/%{name}
%clean
%{__rm} -rf $RPM_BUILD_ROOT
%files
%defattr(-,root,root,-)
%doc %{_pkgdocdir}/*
%{_bindir}/%{name}
%dir %{_datadir}/%{name}
@ -88,9 +95,10 @@ EOF
%{_sysconfdir}/cron.daily/%{name}
%config(noreplace) %{_sysconfdir}/logrotate.d/%{name}
%dir %{_var}/lib/%{name}
%{_var}/lib/%{name}/db
%dir %{_var}/lib/%{name}/db
%ghost %{_var}/lib/%{name}/db/mirrors.dat
%ghost %{_var}/lib/%{name}/db/programs_bad.dat
%ghost %{_var}/lib/%{name}/db/backdoorports.dat
%{_var}/lib/%{name}/db/i18n
%dir %{_var}/log/%{name}
%config(noreplace) %{_sysconfdir}/%{name}.conf
@ -99,6 +107,162 @@ EOF
%{_mandir}/man8/*
%changelog
* Sat Jan 03 2026 Kevin Fenzi <kevin@scrye.com> - 1.4.6-31
- Add patch to find systemd-journald config and avoid warning. Fixes rhbz#2361203
- Add patch to fix false positive on Li0n from bin/sbin merge. Fixes rhbz#2382304
* Fri Jul 25 2025 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.6-30
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Sun May 04 2025 Kevin Fenzi <kevin@scrye.com> - 1.4.6-29
- Add fix for additional case of grep warnings with cron.
* Sat Apr 19 2025 Kevin Fenzi <kevin@scrye.com> - 1.4.6-28
- Add a fix to grep warning about escaping /s. Fixes rhbz#2360502
* Sat Jan 18 2025 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.6-27
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Fri Jul 26 2024 Miroslav Suchý <msuchy@redhat.com> - 1.4.6-26
- convert license to SPDX
* Fri Jul 19 2024 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.6-25
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Fri Jan 26 2024 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.6-24
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Mon Jan 22 2024 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.6-23
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Fri Jul 21 2023 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.6-22
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Sat Apr 29 2023 Kevin Fenzi <kevin@scrye.com> - 1.4.6-21
- More complete fix for egrep changes.
* Mon Apr 10 2023 Kevin Fenzi <kevin@scrye.com> - 1.4.6-20
- Patch grep/egrep changes to avoid warnings in F38+
* Fri Jan 20 2023 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.6-19
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
* Sat Jul 23 2022 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.6-18
- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Sun Jun 19 2022 Kevin Fenzi <kevin@scrye.com> - 1.4.6-17
- Switch to using s-nail instead of mailx.
* Sat Jun 11 2022 Kevin Fenzi <kevin@scrye.com> - 1.4.6-16
- Whitelist .dockerignore man page ( rhbz#2050551 )
* Fri Jan 21 2022 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.6-15
- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
* Sat Nov 06 2021 Kevin Fenzi <kevin@scrye.com> - 1.4.6-14
- Add exclude for containers-common man page ( rhbz#2020015 )
* Fri Jul 23 2021 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.6-13
- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
* Sun Feb 07 2021 Kevin Fenzi <kevin@scrye.com> - 1.4.6-12
- Fix bug around ssh protocol detection ( rhbz#1597635 )
* Wed Jan 27 2021 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.6-11
- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild
* Sat Jan 16 2021 Kevin Fenzi <kevin@scrye.com> - 1.4.6-10
- Drop check on libkeyutils, it's a legit library now. Fixes rhbz#1914662
- Look for and use the ssh.d config snippet direction. Thanks John Dodson for patch. Fixes rhbz#1851620
* Wed Jul 29 2020 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.6-9
- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
* Sat May 16 2020 Kevin Fenzi <kevin@scrye.com> - 1.4.6-8
- Add allow for podman's /dev/shm files (fixes bug #1828698 )
* Thu Jan 30 2020 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.6-7
- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
* Sun Oct 06 2019 Kevin Fenzi <kevin@scrye.com> - 1.4.6-6
- Adjust config for PermitRootLogin change in f31+. Fixes bug #1756593
* Fri Jul 26 2019 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.6-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
* Sun Apr 14 2019 Kevin Fenzi <kevin@scrye.com> - 1.4.6-4
- Drop ifup/ifdown since network-scripts is now deprecated. Fixes bug #1698920
* Sat Feb 02 2019 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.6-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
* Sat Jul 14 2018 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.6-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
* Sun Feb 25 2018 Kevin Fenzi <kevin@scrye.com> - 1.4.6-1
- Update to 1.4.6. Fixes bug #1547315
- Allow KRA vault log files. Fixes bug #1541472
- ipc_shared_mem warning fixed upstream. Fixes bug #1524456
* Fri Feb 09 2018 Igor Gnatenko <ignatenkobrain@fedoraproject.org> - 1.4.4-6
- Escape macros in %%changelog
* Mon Nov 27 2017 Kevin Fenzi <kevin@scrye.com> - 1.4.4-5
- Add fix for new rpm queryformat and ARCH. Fixes bug #1517387
* Sat Aug 12 2017 Kevin Fenzi <kevin@scrye.com> - 1.4.4-4
- Disable ipc_shared_mem test for now due to false positives. Bug #1472299
* Thu Jul 27 2017 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.4-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild
* Thu Jul 13 2017 Petr Pisar <ppisar@redhat.com> - 1.4.4-2
- perl dependency renamed to perl-interpreter
<https://fedoraproject.org/wiki/Changes/perl_Package_to_Install_Core_Modules>
* Thu Jun 29 2017 Kevin Fenzi <kevin@scrye.com> - 1.4.4-1
- Update to 1.4.4. Fixes bug #1466318
- Fix for logger and spaces. Fixes bug #1284403
* Sat Feb 11 2017 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.2-13
- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild
* Wed Jan 25 2017 Mukundan Ragavan <nonamedotc@fedoraproject.org> - 1.4.2-12
- Add /dev/shm/qb* files to whitelist. Fixes bug #1403602
- Add /dev/shm/squid-ssl_session_cache.shm to whitelist. Fixes bug #1411130
* Wed Apr 20 2016 Kevin Fenzi <kevin@scrye.com> - 1.4.2-11
- Add /dev/shm/lldpad files to whitelist. Fixes bug #1293059
* Thu Feb 04 2016 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.2-10
- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild
* Sun Dec 06 2015 Kevin Fenzi <kevin@scrye.com> - 1.4.2-9
- Add /dev/shm/squid files to whitelist. Fixes bug #1279632
* Tue Oct 13 2015 Mukundan Ragavan <nonamedotc@fedoraproject.org> - 1.4.2-8
- Change config patch to account for change in default SSH config
* Thu Jun 18 2015 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.4.2-7
- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild
* Sat Dec 20 2014 Kevin Fenzi <kevin@scrye.com> 1.4.2-6
- Add /etc/.updated systemd file to whitelist. Fixes bug #1173481
- Add patch to fix grep -a issue with too many arguments output.
* Mon Oct 27 2014 Kevin Fenzi <kevin@scrye.com> 1.4.2-5
- Set /var/lib/rkhunter to be mode 700. fixes bug #1154428
* Fri Sep 26 2014 Kevin Fenzi <kevin@scrye.com> 1.4.2-4
- Fix cron script to work with non bash shells. Fixes bug #1146717
* Sun Jun 08 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.4.2-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild
* Sun Apr 06 2014 Kevin Fenzi <kevin@scrye.com> 1.4.2-2
- Add patch to fix ipcs command in non en locales
- Add config to fix freeipa installs. Fixes bug #994567
* Fri Mar 14 2014 Kevin Fenzi <kevin@scrye.com> 1.4.2-1
- Update to 1.4.2
@ -150,7 +314,7 @@ EOF
- Add /usr/share/man/man5/.k5identity.5.gz to whitelisted hidden files.
* Wed Oct 12 2011 Jim Pirzyk <jim+rpm@pirzyk.org> - 1.3.8-10
- Update %files section so that some .dat files are marked %ghost
- Update %%files section so that some .dat files are marked %%ghost
* Fri Aug 05 2011 Kevin Fenzi <kevin@scrye.com> - 1.3.8-9
- Add patch to fix ALLOWPROCDELFILE config option. fixes bug #727524
@ -289,7 +453,7 @@ EOF
- Changed to SHA1 for optional message digest (canary check)
- Added a couple of suggested skip entries to rkhunter.conf
* Mon Jun 11 2005 Greg Houlette <tamaster@pobox.com> - 1.2.7-1
* Sat Jun 11 2005 Greg Houlette <tamaster@pobox.com> - 1.2.7-1
- Added signature auto-updating to CRON scan (new script)
- Removed BOOTSCAN pending rewrite to full SysV Init scan in background
- Added the --append-log command line option

View file

@ -1 +1 @@
85ad366b7f3999eb2a9371e39a1a4df7 rkhunter-1.4.2.tar.gz
SHA512 (rkhunter-1.4.6.tar.gz) = c51a21b6b66ed1f73a19d8ce04eaba35999eefcb666acc824989c3bf53ac56d24a33ac4fec290be942e33fe24674406b371eafff73f7e697b9e03ec031b37216