Koozali.org: home of the SME Server

Strange cron alerte

Offline dadoudidon

  • *
  • 84
  • +0/-0
Strange cron alerte
« on: January 16, 2008, 09:04:05 AM »
Since yesterday i have this alert!

Code: [Select]
/etc/cron.daily/01-rkhunter:

Warning: File '/tmp/sess_e01e4ddd948bbc9161fa5b0cf7221dfe' (score: 286) contains some suspicious content and should be checked.
Warning: File '/tmp/hsperfdata_tomcat/4596' (score: 261) contains some suspicious content and should be checked.
Warning: File '/tmp/sess_9fb62bb504fdd88a4ccb6a283ba434c2' (score: 221) contains some suspicious content and should be checked.
Warning: Possible promiscuous interfaces:
         'ifconfig' command output:           UP BROADCAST RUNNING PROMISC ALLMULTI MULTICAST  MTU:1500  Metric:1
         UP BROADCAST RUNNING PROMISC MULTICAST  MTU:1500  Metric:1
         'ip' command output: eth0
         'ip' command output: tap0
Warning: Process '/sbin/pppoe' (PID 8226) is listening on the network.
Warning: Process '/sbin/pppoe' (PID 8226) is listening on the network.
Warning: The SSH and rkhunter configuration options should be the same:
         SSH configuration option 'PermitRootLogin': yes
         Rkhunter configuration option 'ALLOW_SSH_ROOT_USER': no
Warning: Suspicious file types found in /dev:
         /dev/shm/suspscan.1136.strings: ASCII text, with very long lines
         /dev/shm/suspscan.9857.strings: ASCII text, with very long lines
         /dev/shm/suspscan.21927.strings: ASCII text, with very long lines
         /dev/shm/suspscan.20268.strings: ASCII text, with very long lines
         /dev/shm/suspscan.462.strings: ASCII text, with very long lines
Warning: Hidden directory found: /etc/.java

One or more warnings have been found while checking the system.
Please check the log file (/var/log/rkhunter.log)
/etc/cron.daily/sa_update:

'spamassassin' is not a valid service name

Does amyone can help me to solve that?
I did nothing on the server, no install, no remove before this alert came.

I have seen on the Ixus forum that i'm not the only one
http://forums.ixus.fr/viewtopic.php?t=39725

dave

Offline raem

  • *
  • 3,972
  • +4/-0
Re: Strange cron alerte
« Reply #1 on: January 16, 2008, 10:08:44 AM »
dadoudidon

Check bugzilla for similar bug report
...

Offline dadoudidon

  • *
  • 84
  • +0/-0
Re: Strange cron alerte
« Reply #2 on: January 16, 2008, 10:29:27 AM »
dadoudidon

Check bugzilla for similar bug report

Thanks but i understand nothing
http://bugs.contribs.org/show_bug.cgi?id=3700

dave

Offline raem

  • *
  • 3,972
  • +4/-0
Re: Strange cron alerte
« Reply #3 on: January 16, 2008, 10:39:59 AM »
dadoudidon

That's not the bug I was thinking of.
If I recall correctly, "we " are waiting for an upstream release of rkhunter to resolve those messages.
...

Offline dadoudidon

  • *
  • 84
  • +0/-0
Re: Strange cron alerte
« Reply #4 on: January 16, 2008, 11:00:35 AM »
dadoudidon

That's not the bug I was thinking of.
If I recall correctly, "we " are waiting for an upstream release of rkhunter to resolve those messages.


thanks for you answer
dave