# yum --enablerepo=epel install rkhunter
# cp /etc/rkhunter.conf{,.default}
# vi /etc/rkhunter.conf
MAIL-ON-WARNING=xxxx@example.jp aaaa@example.com
MAIL_CMD=mail -s "[rkhunter] Warnings found for ${HOST_NAME}"
LANGUAGE=ja
警告: SSHおよびrkhunter設定オプションを同じにする必要があります: SSH設定オプション「PermitRootLogin」: without-password Rkhunter設定オプション「ALLOW_SSH_ROOT_USER」: unset |
ALLOW_SSH_ROOT_USER=without-password
# rkhunter --update
# rkhunter --propupd
# rkhunter --check --skip-keypress
# rkhunter -c -sk
# rkhunter --check --skip-keypress --report-warnings-only