⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 rkhunter.8

📁 在网络安全中经常会遇到rootkit
💻 8
📖 第 1 页 / 共 2 页
字号:
specific \fIcommand\fP may be specified. A value of \fINONE\fP can be usedto indicate that the hash values should not be obtained or used as part of thefile properties check. The default is \fISHA1\fP, or \fIMD5\fP if no SHA1command can be found..IP "\fB\-\-lang, \-\-language <language>\fP"This option specifies which language to use for the displayed tests and results.The currently supported languages can be seen by the \fB\-\-list\fP commandoption. The default is \fIen\fP (English). If a message to be displayed cannotbe found in the language file, then the English version will be used. As such,the English language file must always be present. The \fB\-\-update\fP commandoption will update the language files when new versions are available..IP "\fB\-l, \-\-logfile [file]\fP"By default \fBrkhunter\fP will write out a log file. The default location ofthe file is \fI/var/log/rkhunter.log\fP. However, this location can be changedby using this option. If \fI/dev/null\fP is specified as the log file, then nolog file will be written. If no specific \fIfile\fP is given, then the defaultwill be used. By default \fBrkhunter\fP will create a new log file each timeit is run. Any previously existing logfile is moved out of the way, and has\fI.old\fP appended to it..IP \fB\-\-noappend\-log\fPThis option reverts \fBrkhunter\fP to its default behaviour of creating a newlog file rather than appending to it..IP \fB\-\-nocolors\fPThis option causes the result of each test to not be displayed in a specificcolor. The default color, usually the reverse of the background color, will beused (typically this is just black and white)..IP \fB\-\-nolog\fPThis option tells \fBrkhunter\fP not to write anything to a log file..IP "\fB\-\-nomow, \-\-no\-mail\-on\-warning\fP"The configuration file has an option which will cause a simple email message tobe sent to a user should \fBrkhunter\fP detect any warnings. This command\-lineoption overrides the configuration file option, and prevents an email messagefrom being sent. The configuration file default is not to email a message..IP "\fB\-\-ns, \-\-nosummary\fP"When the \fB\-\-check\fP command option is used, by default a short summary ofresults is displayed at the end. This option prevents the summary from beingdisplayed..IP "\fB\-\-novl, \-\-no\-verbose\-logging\fP"During some tests \fBrkhunter\fP will log a lot of information. Use of thisoption reduces the amount of logging, and so can improve the performance of\fBrkhunter\fP. However, the log file will contain less information should anywarnings occur. By default verbose logging is enabled..IP "\fB\-\-pkgmgr {RPM | DPKG | BSD | NONE}\fP"This option is used during the file properties check or when the\fB\-\-propupd\fP command option is given. It tells \fBrkhunter\fP that thecurrent file property values should be obtained from the relevant package manager.See the README file for more details of this option. The default is \fINONE\fP,which means not to use a package manager..IP "\fB\-q, \-\-quiet\fP"This option tells \fBrkhunter\fP not to display any output. It can be usefulwhen only the exit code is going to be checked. Other options may be used withthis one, to force only specific items to be displayed..IP "\fB\-\-rwo, \-\-report\-warnings\-only\fP"This option causes only warning messages to be displayed. This can beuseful when \fBrkhunter\fP is run via cron. Other options may be used toforce other items of information to be displayed..IP "\fB\-r, \-\-rootdir <directory>\fP"If a suspect system is locally or remotely mounted, it is possible to tell\fBrkhunter\fP to inspect it by using this option. However, it must be usedwith care, as several of the other options specifying configurationdirectories may need to be set as well. There is no default..IP "\fB\-\-sk, \-\-skip\-keypress\fP"When the \fB\-\-check\fP command option is used, after certain sections oftests, the user will be prompted to press the \fIreturn\fP key in order tocontinue. This option disables that feature, and \fBrkhunter\fP will run untilall the tests have completed.If this option has not been given, and the user is prompted to press the\fIreturn\fP key, a single '\fIs\fP' character, in upper\- or lowercase, may begiven followed by the \fIreturn\fP key. \fBrkhunter\fP will then continuethe tests without prompting the user again (as if this option had been given)..IP \fB\-\-summary\fPThis option will cause the summary of test results to be displayed. This isthe default..IP "\fB\-\-syslog [facility.priority]\fP"When the \fB\-\-check\fP command option is used, this option will cause thestart and finish times to be logged to syslog. The default is not to loganything to syslog, but if the option is used, then the default levelis \fIauthpriv.notice\fP..IP "\fB\-\-tmpdir <directory>\fP"The installation process will automatically configure where temporary files areto be created. However, if necessary, this option can be used to specify adifferent directory. The directory must not be a symbolic link, and must besecure (root access only)..IP "\fB\-\-vl, \-\-verbose\-logging\fP"This option tells \fBrkhunter\fP that when it runs some tests, it should logas much information as possible. This can be useful when trying to diagnosewhy a warning has occurred, but it obviously also takes more time. The defaultis to use verbose logging..IP "\fB\-x, \-\-autox\fP"When this option is used, \fBrkhunter\fP will try and detect if the X Windowsystem is in use. If it is in use, then the second color set willautomatically be used (see the \fB\-\-color\-set2\fP option). This allows\fBrkhunter\fP to be run on, for example, a server console (where X is notpresent, so the default color set should be used), and on a users terminal(where X is in use, so the second color set should be used). In both cases\fBrkhunter\fP will use the correct color set. The configuration file defaultis to try and detect X..IP "\fB\-X, \-\-no\-autox\fP"This option prevents \fBrkhunter\fP from automatically detecting if the XWindow system is being used. See the \fB\-\-autox\fP option..SH TESTS.IP "\fBadditional_rkts\fP" This test is for SHORT_EXPLANATION. It works as part of GROUP. Corresponding configuration file entries: ONE=one, TWO=two and for white-listing THREE=three,three. Simple globbing (/dev/shm/file-*) works..IP \fBall\fP.IP \fBapps\fP.IP \fBattributes\fP.IP \fBdeleted_files\fP.IP \fBfilesystem\fP.IP \fBgroup_accounts\fP.IP \fBgroup_changes\fP.IP \fBhashes\fP.IP \fBhidden_procs\fP.IP \fBimmutable known_rkts\fP.IP \fBlocal_host\fP.IP \fBmalware\fP.IP \fBnetwork\fP.IP \fBnone\fP.IP \fBos_specific\fP.IP \fBother_malware\fP.IP \fBpacket_cap_apps\fP.IP \fBpasswd_changes\fP.IP \fBports\fP.IP \fBpossible_rkt_files\fP.IP \fBpossible_rkts\fP.IP \fBpossible_rkt_strings\fP.IP \fBpromisc\fP.IP \fBproperties\fP.IP \fBrootkits\fP.IP \fBrunning_procs\fP.IP \fBscripts\fP.IP \fBshared_libs\fP.IP \fBshared_libs_path\fP.IP \fBstartup_files\fP.IP \fBstartup_malware\fP.IP \fBstrings\fP.IP \fBsuspscan\fP.IP \fBsystem_commands\fP.IP \fBsystem_configs trojans\fP.SH FILES(For a default installation)/etc/rkhunter.conf.SH SEE ALSOSee the CHANGELOG file for recent changes..brThe README file has information about installing \fBrkhunter\fP, as well asspecific sections on test names and using package managers..brThe FAQ file should also answer some questions..SH LICENSINGRootKit Hunter is licensed under the GPL, copyright Michael Boelen.See the LICENSE file for details of GPL licensing..SH CONTACT INFORMATIONRootKit Hunter is under active development by the RootKit Hunter project team. For reporting bugs, updates, patches, comments and questions, please go to http://rkhunter.sourceforge.net/.fi

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -