<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="https://dev1galaxy.org/extern.php?action=feed&amp;tid=5358&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Dev1 Galaxy Forum / [SOLVED] System check/audit/rootkit tools]]></title>
		<link>https://dev1galaxy.org/viewtopic.php?id=5358</link>
		<description><![CDATA[The most recent posts in [SOLVED] System check/audit/rootkit tools.]]></description>
		<lastBuildDate>Sat, 19 Nov 2022 19:01:20 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Re: [SOLVED] System check/audit/rootkit tools]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=38798#p38798</link>
			<description><![CDATA[<p>Hello:</p><div class="quotebox"><cite>steve_v wrote:</cite><blockquote><div><p>... appears to have very few dependencies ...<br />... less likely to make a mess than trying to install the chimarea binary package ...</p></div></blockquote></div><p>I marked this thread as solved as I was able to update <span class="bbc">lynis</span> without much ado or issues.<br />It runs properly as far as I can see, at least for the time being.</p><p>The solution is <a href="https://packages.cisofy.com/community/#debian-ubuntu" rel="nofollow">here</a>.<br />Basically it involves importing a key and adding the <span class="bbc">CISOfy</span> software repository to <span class="bbc">/etc/apt/sources.list</span>. </p><p>Will eventually look into <span class="bbc">chkrootkit</span> to see it the same thing can be done.<br />It looks like <span class="bbc">rkhunter</span> has probably been abandoned so I will remove it.</p><p>Best,</p><p>A.</p>]]></description>
			<author><![CDATA[dummy@example.com (Altoid)]]></author>
			<pubDate>Sat, 19 Nov 2022 19:01:20 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=38798#p38798</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SOLVED] System check/audit/rootkit tools]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=38789#p38789</link>
			<description><![CDATA[<p>Hello:</p><div class="quotebox"><cite>steve_v wrote:</cite><blockquote><div><p>...lynis appears to have very few dependencies ...<br />... amenable to a simple local backport</p></div></blockquote></div><p>Thanks for the heads up.<br />I&#039;ll check it out.</p><div class="quotebox"><cite>steve_v wrote:</cite><blockquote><div><p>... some change that you need ...</p></div></blockquote></div><p>I really don&#039;t know if I need it.<br />Because I don&#039;t know how much the threat scenario has evolved.</p><p>If it <strong>has</strong> evolved (high probability), goes to reason that newer version would address it.</p><div class="quotebox"><cite>steve_v wrote:</cite><blockquote><div><p>... just &quot;newer must be better&quot;?</p></div></blockquote></div><p>Me?&#160; 8^D<br />Been in this far too long for that.</p><div class="quotebox"><cite>steve_v wrote:</cite><blockquote><div><p>... could just dist-upgrade to stable.</p></div></blockquote></div><p>Yes, I could.</p><p>But first I have to make 100% sure my nvidia cards will work properly and I will still be able to use <span class="bbc">slim</span> and <span class="bbc">wicd</span>, among other old stuff I have installed and then comfortably get rid of the POS that Xfce is slowly turning into to get myself a set up like what Phillip Newborough&#039;s <span class="bbc">#! Waldorf</span>* was.</p><p>* which I think should be the default template for both Devuan <span class="bbc">desktop-live</span> and <span class="bbc">installer-iso</span> versions.</p><div class="quotebox"><cite>steve_v wrote:</cite><blockquote><div><p>... going to sooner or later ...</p></div></blockquote></div><p>Yes, I know. 8^° </p><p>Thanks a lot for your input.</p><p>Best,</p><p>A.</p>]]></description>
			<author><![CDATA[dummy@example.com (Altoid)]]></author>
			<pubDate>Sat, 19 Nov 2022 16:39:38 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=38789#p38789</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SOLVED] System check/audit/rootkit tools]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=38786#p38786</link>
			<description><![CDATA[<p>I don&#039;t have a beowulf install to play with right now... But lynis appears to have very few dependencies, so it should be amenable to a <a href="https://wiki.debian.org/SimpleBackportCreation" rel="nofollow">simple local backport</a>. That&#039;s far less likely to make a mess than trying to install the chimarea binary package anyway.</p><p>The real question is why... Is there actually some change that you need, or is it just &quot;newer must be better&quot;?</p><p>OTOH, you could just dist-upgrade to stable. You&#039;re going to sooner or later, and this might be a suitable excuse to get on with it.</p>]]></description>
			<author><![CDATA[dummy@example.com (steve_v)]]></author>
			<pubDate>Sat, 19 Nov 2022 16:07:28 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=38786#p38786</guid>
		</item>
		<item>
			<title><![CDATA[[SOLVED] System check/audit/rootkit tools]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=38785#p38785</link>
			<description><![CDATA[<p>Hello:</p><p>Every so often and maybe not as regularly as I should, I run <span class="bbc">chkrootkit</span>, <span class="bbc">rkhunter</span>and <span class="bbc">lynis</span>.<br />Always come up clean, or so it seems.</p><p>This is what I have installed: </p><div class="codebox"><pre><code>~$ apt-cache policy chkrootkit &amp;&amp; apt-cache policy rkhunter &amp;&amp; apt-cache policy lynis
chkrootkit:
  Installed: 0.52-3+b10
  Candidate: 0.52-3+b10
  Version table:
 *** 0.52-3+b10 500
        500 http://deb.devuan.org/merged beowulf/main amd64 Packages
        100 /var/lib/dpkg/status
rkhunter:
  Installed: 1.4.6-5
  Candidate: 1.4.6-5
  Version table:
 *** 1.4.6-5 500
        500 http://deb.devuan.org/merged beowulf/main amd64 Packages
        500 http://deb.devuan.org/merged beowulf/main i386 Packages
        100 /var/lib/dpkg/status
lynis:
  Installed: 2.6.2-1
  Candidate: 2.6.2-1
  Version table:
 *** 2.6.2-1 500
        500 http://deb.devuan.org/merged beowulf/main amd64 Packages
        500 http://deb.devuan.org/merged beowulf/main i386 Packages
        100 /var/lib/dpkg/status
~$ </code></pre></div><p>Now, when I check available versions on-line I find that <span class="bbc">lynis</span> seems to be the one with most active development, the latest version being 3.0.8 from last June while <span class="bbc">chkrootkit</span> latest is at version 0.55 from June last year.</p><p>See <a href="https://cisofy.com/downloads/lynis/" rel="nofollow">https://cisofy.com/downloads/lynis/</a> and <a href="http://www.chkrootkit.org/" rel="nofollow">http://www.chkrootkit.org/</a></p><p>By comparison, <span class="bbc">rkhunter</span> version 1.4.6 does not seem to have had <em>any</em> work done since 1.4.6 (2018).</p><p>See <a href="https://rkhunter.sourceforge.net/" rel="nofollow">https://rkhunter.sourceforge.net/</a></p><p>My Beowulf installation runs on a backported kernel:</p><div class="codebox"><pre><code>~$ uname -a
Linux devuan 5.10.0-0.deb10.16-amd64 #1 SMP Debian 5.10.127-2~bpo10+1 (2022-07-28) x86_64 GNU/Linux
~$ </code></pre></div><p>But there are no Beowulf backports to any of these tools, not even for <span class="bbc">lynis</span> but the Chimaera repository has version 3.0.2-1 available.</p><p>Would it work on my backported system?<br />If so, how can I install it without making a mess?</p><p>Thanks in advance.</p><p>Best,</p><p>A.</p>]]></description>
			<author><![CDATA[dummy@example.com (Altoid)]]></author>
			<pubDate>Sat, 19 Nov 2022 15:37:59 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=38785#p38785</guid>
		</item>
	</channel>
</rss>
