mumbo719 wrote:Greetings and thank you for the tip.
Do you run rkhunter daily on start up or just once in a while?
Do you have a good way to run it daily?
I never used rkhunter before and I dont know how it works in auto mode.
There are some things that I dont understand:
In /etc/default/rkhunter it's mentionned that it runs once a day and it makes updates once a week. But if you search the package in synaptic and click Package->Configure, the options Run Daily and Update Weekly are not checked.
Another point is that rkhunter depends on a MTA (mail transfer agent). In its dependancies exim4 is prioritary and synaptic installs it, but in the /etc/cron.daily/rkhunter , sendmail is mentionned instead.
Warning reports are mentionned in two config files: /etc/rkhunter.conf and /etc/default/rkhunter and are a little confusing. For example, if I replace "root" by my_account_name, will I be warned in case of problem?
Well, I fixed these problems using the common sense, because I didnt find responses on their site. However, I am not sure that the auto mode works as I can't verify it. So I run rkhunter manually for sure.