From owner-freebsd-ports@FreeBSD.ORG Tue Jan 4 23:42:16 2011 Return-Path: Delivered-To: freebsd-ports@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id D4A46106564A for ; Tue, 4 Jan 2011 23:42:16 +0000 (UTC) (envelope-from tingox@gmail.com) Received: from mail-qw0-f54.google.com (mail-qw0-f54.google.com [209.85.216.54]) by mx1.freebsd.org (Postfix) with ESMTP id 860C58FC14 for ; Tue, 4 Jan 2011 23:42:16 +0000 (UTC) Received: by qwj9 with SMTP id 9so14519820qwj.13 for ; Tue, 04 Jan 2011 15:42:15 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:received:received:in-reply-to :references:date:message-id:subject:from:to:content-type :content-transfer-encoding; bh=FVb3H9fjPFhJL5PPQwHxErmcokTHvFNIkuInW8Xa3jw=; b=Evk9nko0AP8kKaZ/rlR1Hg4pdW+WrXTwFZRpb/oL7E5Bvx9KMkCyHP+RvebIyDlqpP oc2i2Hukm5w9ddG62Knm/xcC0ZO0UhDre1/Oa28QRbtgsWJOoXYAjYHHxWi+HOE/4U6m quwJ7nDD+CMQA+2w0mDFYVQkdCbMxxCIln1Xc= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :content-type:content-transfer-encoding; b=NUFyNa0UM3Ru82a1Qv9wHlV9EIjtAvPRjN7a5NVU7vXLBFaFpVSLBtyYnYOIwRsnUT ISTVFHWvF749qsLEzXLHUTOjeBIz55UJP/98oxD9cBhtY/zS07U23EAbb4QJznomPhzx a9xw9IDIQ3mYnB2lrB2VbRJV95s+9Pdro3mnQ= MIME-Version: 1.0 Received: by 10.224.188.140 with SMTP id da12mr20931598qab.130.1294184535823; Tue, 04 Jan 2011 15:42:15 -0800 (PST) Received: by 10.220.191.132 with HTTP; Tue, 4 Jan 2011 15:42:15 -0800 (PST) In-Reply-To: <35113D20-59B2-4924-823B-DF5F97BE1F7A@mac.com> References: <35113D20-59B2-4924-823B-DF5F97BE1F7A@mac.com> Date: Wed, 5 Jan 2011 00:42:15 +0100 Message-ID: From: Torfinn Ingolfsen To: FreeBSD Ports ML Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Subject: Re: security/rkhunter 1.3.8 - false warning? X-BeenThere: freebsd-ports@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Porting software to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 04 Jan 2011 23:42:16 -0000 Hi, On Tue, Jan 4, 2011 at 7:52 PM, Chuck Swiger wrote: > On Jan 4, 2011, at 9:38 AM, Torfinn Ingolfsen wrote: >> rkhunter 1.3.8 from ports complains about the /etc/passwd file. =A0Why d= oes it do that? > > It's buggy? > > RKHunter is better known for generating vast numbers of obscure false pos= itives than it is for actually providing a security benefit. =A0Something l= ike > tripwire or a functioning backup system which can provide a comparison of= changes against current filesystem state is much more likely to be useful. Well, rkhunter hasn't generated any false warnings for me in a few years now. YMMV, and you are of course entitled to your own opinion. If anyone has anything useful in answer to the question I asked, feel free to provide it. --=20 Regards, Torfinn Ingolfsen