Koozali.org: home of the SME Server

rkhunter warning message query

Offline janet

  • *****
  • 4,812
  • +0/-0
rkhunter warning message query
« on: October 17, 2008, 01:16:35 AM »
I received these messages in the daily rkhunter report.
A search of the forums & google did not find a conclusive answer.
Is this a problem, or a system occurrence that can be ignored ?
I have never seen these messages before.

Warning: Process '/usr/sbin/httpd' (PID 24468) is listening on the network.
Warning: Process '/usr/sbin/httpd' (PID 24468) is listening on the network.
Warning: Process '/usr/sbin/httpd' (PID 24468) is listening on the network.
Warning: Process '/usr/sbin/httpd' (PID 24468) is listening on the network.
Warning: Process '/usr/sbin/httpd' (PID 24468) is listening on the network.
Warning: Process '/usr/sbin/httpd' (PID 24468) is listening on the network.
Warning: Process '/usr/sbin/httpd' (PID 24468) is listening on the network.
Warning: Process '/usr/sbin/httpd' (PID 24468) is listening on the network.
Warning: Process '/usr/sbin/httpd' (PID 24468) is listening on the network.

Immediately following this entry was advice that a new user was added.
I checked and the new user was a valid entry made by a local admin user via user-manager.

htop shows that process (PID 24468) no longer running

Thanks
« Last Edit: October 17, 2008, 01:18:34 AM by mary »
Please search before asking, an answer may already exist.
The Search & other links to useful information are at top of Forum.

Offline cactus

  • *
  • 4,880
  • +3/-0
    • http://www.snetram.nl
Re: rkhunter warning message query
« Reply #1 on: October 17, 2008, 01:58:58 PM »
I received these messages in the daily rkhunter report.
A search of the forums & google did not find a conclusive answer.
Is this a problem, or a system occurrence that can be ignored ?
I have never seen these messages before.

Warning: Process '/usr/sbin/httpd' (PID 24468) is listening on the network.
Warning: Process '/usr/sbin/httpd' (PID 24468) is listening on the network.
Warning: Process '/usr/sbin/httpd' (PID 24468) is listening on the network.
Warning: Process '/usr/sbin/httpd' (PID 24468) is listening on the network.
Warning: Process '/usr/sbin/httpd' (PID 24468) is listening on the network.
Warning: Process '/usr/sbin/httpd' (PID 24468) is listening on the network.
Warning: Process '/usr/sbin/httpd' (PID 24468) is listening on the network.
Warning: Process '/usr/sbin/httpd' (PID 24468) is listening on the network.
Warning: Process '/usr/sbin/httpd' (PID 24468) is listening on the network.
This I have not come across before.
Immediately following this entry was advice that a new user was added.
I checked and the new user was a valid entry made by a local admin user via user-manager.
That should be normal behavior, it is even mentioned in the README.txt on the 7.3 ISO.
Be careful whose advice you buy, but be patient with those who supply it. Advice is a form of nostalgia, dispensing it is a way of fishing the past from the disposal, wiping it off, painting over the ugly parts and recycling it for more than its worth ~ Baz Luhrmann - Everybody's Free (To Wear Sunscreen)

Offline CharlieBrady

  • *
  • 6,918
  • +3/-0
Re: rkhunter warning message query
« Reply #2 on: October 17, 2008, 02:58:21 PM »
Warning: Process '/usr/sbin/httpd' (PID 24468) is listening on the network.

It would be surprising to me if /usr/sbin/httpd were not listening on the network.

I have no idea why rkhunter bothers to tell you about this.

google for rkhunter and 'false positive' and I expect you'll find lots of hits.

Offline janet

  • *****
  • 4,812
  • +0/-0
Re: rkhunter warning message query
« Reply #3 on: October 18, 2008, 06:21:40 AM »
cactus

Quote
That should be normal behavior...

Yes I understand that valid system changes will be notified in the next rkhunter report.

Charlie & cactus

It seems that the report about /usr/sbin/httpd is simply a false positive of a valid process.
If Charlie doesn't know why rkhunter generated it, then it's not likely any of us will know.

As it appears to be a "one off", I'll ignore it with safety.
Thanks all.
Please search before asking, an answer may already exist.
The Search & other links to useful information are at top of Forum.