Revisions of rkhunter

buildservice-autocommit accepted request 1149901 from Robert Frohl's avatar Robert Frohl (rfrohl) (revision 63)
baserev update by copy to link target
buildservice-autocommit accepted request 1035891 from Marcus Meissner's avatar Marcus Meissner (msmeissn) (revision 61)
baserev update by copy to link target
buildservice-autocommit accepted request 982374 from Marcus Meissner's avatar Marcus Meissner (msmeissn) (revision 59)
baserev update by copy to link target
Marcus Meissner's avatar Marcus Meissner (msmeissn) accepted request 978724 from Andreas Schwab's avatar Andreas Schwab (Andreas_Schwab) (revision 58)
- Use correct SCRIPTDIR
buildservice-autocommit accepted request 969501 from Marcus Meissner's avatar Marcus Meissner (msmeissn) (revision 57)
baserev update by copy to link target
Marcus Meissner's avatar Marcus Meissner (msmeissn) committed (revision 56)
- renable gpg verification, change to https urls.
- rkhunter.keyring: changed from keyserver
buildservice-autocommit accepted request 762491 from Marcus Meissner's avatar Marcus Meissner (msmeissn) (revision 55)
baserev update by copy to link target
Marcus Meissner's avatar Marcus Meissner (msmeissn) accepted request 762232 from Johannes Segitz's avatar Johannes Segitz (jsegitz) (revision 54)
- Remove default cron job and install it with the documentation.
  This way the user can decide if he needs rkhunter to run regularly
  (bsc#1150553).
buildservice-autocommit accepted request 725634 from Marcus Meissner's avatar Marcus Meissner (msmeissn) (revision 53)
baserev update by copy to link target
Marcus Meissner's avatar Marcus Meissner (msmeissn) committed (revision 52)
- package the /etc/cron.daily instead of buildrequire cron
Marcus Meissner's avatar Marcus Meissner (msmeissn) accepted request 724765 from Thorsten Kukuk's avatar Thorsten Kukuk (kukuk) (revision 51)
- BuildRequire cron, as this contains now the cron directories
buildservice-autocommit accepted request 693631 from Marcus Meissner's avatar Marcus Meissner (msmeissn) (revision 50)
baserev update by copy to link target
Marcus Meissner's avatar Marcus Meissner (msmeissn) accepted request 693322 from Eric Schirra's avatar Eric Schirra (ecsos) (revision 49)
- Generate rkhunter.conf.local to prevent hash error for 
  rkhunter.conf.
- Remove some rpmlint-erros.
buildservice-autocommit accepted request 640774 from Marcus Meissner's avatar Marcus Meissner (msmeissn) (revision 48)
baserev update by copy to link target
Marcus Meissner's avatar Marcus Meissner (msmeissn) accepted request 637864 from Jan Engelhardt's avatar Jan Engelhardt (jengelh) (revision 47)
- Replace %__-type macro indirections.
- Avoid repeating name in summary.
buildservice-autocommit accepted request 637741 from Lars Vogdt's avatar Lars Vogdt (lrupp) (revision 46)
baserev update by copy to link target
Lars Vogdt's avatar Lars Vogdt (lrupp) accepted request 637335 from Mathias Homann's avatar Mathias Homann (lemmy04) (revision 45)
- upgrade to version 1.4.6 
  * 1.4.6 (20/02/2018)
  * New:
   - Added support for Alpine Linux (busybox).
   - Added the 'Diamorphine LKM' test.
   - Added the ALLOWIPCPID configuration file option. This will allow
   specific PIDs to be whitelisted from the shared memory check.
   - Added the ALLOWIPCUSER configuration file option. This will allow
   specific usernames to be whitelisted from the shared memory check.
   - Added the IPC_SEG_SIZE configuration file option. This can be used
   to set the minimum shared memory segment size to check. The default
   value is 1048576 bytes (1MB).
   - Added the SKIP_INODE_CHECK configuration file option. Setting this
   option will disable the reporting of any changed inode numbers.
   The default is to report inode changes. (This option may be useful
   for filesystems such as Btrfs.)
   - Added Ebury sshd backdoor test.
   - Added a new SSH configuration test to check for various suspicious
   configuration options. Currently there is only one check which
   relates to the Ebury backdoor.
   - Added basic test for Jynx2 rootkit.
   - Added Komplex trojan test.
   - Added basic test for KeRanger running process.
   - Added test for Keydnap backdoor.
   - Added basic test for Eleanor backdoor running process.
   - Added basic tests for Mokes backdoor.
   - Added tests for Proton backdoor.
   - Added the SUSPSCAN_WHITELIST configuration file option. This
   option can be used to whitelist file pathnames from the
   'suspscan' test.
 * Changes:
   - The 'ipc_shared_mem' test will now log the minimum segment size
   that will be checked. It will also log the size of any segments
   which appear suspicious (that is, larger than the configured
   allowed maximum size).
   - If verbose logging is disabled, then generally only the test
   name and the final result for the test will now be logged.
   - Kernel symbol checks will now use the 'System.map' file, if it
   exists, and no other kernel symbol file can be found.
 * Bugfixes:
   - For prelinked systems ensure that the default hash function is
   SHA1 and not SHA256.
   - The result from the 'hidden_procs' test was not being
   calculated correctly.
   - Checking the O/S version number could be missed in some cases.
   - Minor improvement to the *BSD immutable files check.
   - The 'OS_VERSION_FILE' configuration option pathname cannot be
   a link, but this was not checked.
   - Improved checks for the O/S name on Devuan systems.
   - Handling of the '/etc/issue' file during O/S detection has now
   improved. Escape sequences are either replaced or removed.
   - Not all the linux kernel module names were being checked.
   - The logging of detached memory segments tried to show the
   process pathname. This has now been corrected, and where no
   pathname is available, the segment owner and PID will be logged.
   - It was possible for the return code to be lost when running the
   'ipc_shared_mem' test. This has now been corrected.
   - Some configuration options were still not being handled correctly
   when specified more than once.
   - The 'ipc_shared_mem' test did not correctly handle whitelisting
   when a segment pathname was flagged as deleted. This has now
   been corrected.
   - Commands disabled in the configuration file were being logged
   as not found. They are now logged as having been disabled.
   - Disabling verbose logging could hide some warning messages.
   - The 'shared_libs' test now caters for simple filenames, as well
   as pathnames which contain the '$LIB', '$ORIGIN' or '$PLATFORM'
   variables.
 --
buildservice-autocommit accepted request 545264 from Marcus Meissner's avatar Marcus Meissner (msmeissn) (revision 44)
baserev update by copy to link target
Displaying revisions 1 - 20 of 63
openSUSE Build Service is sponsored by