rkhunter

Alexander Dalloz alexander.dalloz at uni-bielefeld.de
Fri Oct 15 18:03:25 UTC 2004


Am Fr, den 15.10.2004 schrieb François Patte um 19:46:

> > > * Application version scan
> > >    - GnuPG 1.2.3                                              [ Vulnerable
> > ]
> > >    - Apache 2.0.47                                            [ Vulnerable
> > ]
> > >    - OpenSSL 0.9.7a                                           [ Vulnerable
> > ]
> > >    - PHP 4.3.3                                                [ Vulnerable
> > ]
> > >    - OpenSSH 3.6.1p2                                          [ Vulnerable
> > ]

> http://mirrors.ircam.fr/pub/fedoralegacy/legacy/fedora/1/updates/i386/gnupg-1.2.3-2.i386.rpm
> >
> http://mirrors.ircam.fr/pub/fedoralegacy/legacy/fedora/1/updates/i386/httpd-2.0.51-1.4.legacy.i386.rpm
> >
> http://mirrors.ircam.fr/pub/fedoralegacy/legacy/fedora/1/updates/i386/openssl-0.9.7a-33.10.i386.rpm
> >
> http://mirrors.ircam.fr/pub/fedoralegacy/legacy/fedora/1/updates/i386/php-4.3.8-1.1.i386.rpm

> Something is wrong in rkhunter:
> 
> rpm -q gnupg
> gnupg-1.2.3-2
> 
> rpm -q httpd
> le paquetage httpd n'est pas installé
> 
> rpm -q openssl
> openssl-0.9.7a-33.10
> 
> rpm -q php
> le paquetage php n'est pas installé
> 
> rpm -q openssh
> openssh-3.6.1p2-19

> François Patte

Yes, that is indeed curious. You really checked the same system? How
should rkhunter detect the initial Apache2 version of FC1

http://mirrors.ircam.fr/pub/fedoralegacy/legacy/fedora/1/os/i386/httpd-2.0.47-10.i386.rpm

if this package isn't even installed. Along with the the detected PHP
version

http://mirrors.ircam.fr/pub/fedoralegacy/legacy/fedora/1/os/i386/php-4.3.3-6.i386.rpm

Alexander


-- 
Alexander Dalloz | Enger, Germany | GPG key 1024D/ED695653 1999-07-13
Fedora GNU/Linux Core 2 (Tettnang) kernel 2.6.8-1.521smp 
Serendipity 19:58:22 up 1 day, 15:09, load average: 0.02, 0.19, 0.16 
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 189 bytes
Desc: Dies ist ein digital signierter Nachrichtenteil
URL: <http://listman.redhat.com/archives/fedora-list/attachments/20041015/c2d29ff1/attachment-0001.sig>


More information about the fedora-list mailing list