Skip to main content

Rkhunter Set Up in systemd : Revisited

I made a post about setting up rkhunter using systemd. And little did I know it's going to be a work in progress for weeks. But I have finally set up the service and timer units just right.

[donato@archdesktop ~]$ systemctl list-timers
NEXT                         LEFT        LAST                         PASSED       UNIT                         ACTIVATES
Fri 2017-10-06 00:00:00 +08  16h left    Thu 2017-10-05 00:00:20 +08  7h ago       logrotate.timer              logrotate.service
Fri 2017-10-06 00:00:00 +08  16h left    Thu 2017-10-05 00:00:20 +08  7h ago       man-db.timer                 man-db.service
Fri 2017-10-06 00:00:00 +08  16h left    Thu 2017-10-05 00:00:20 +08  7h ago       shadow.timer                 shadow.service
Fri 2017-10-06 00:00:00 +08  16h left    Thu 2017-10-05 00:00:20 +08  7h ago       updatedb.timer               updatedb.service
Fri 2017-10-06 00:08:16 +08  16h left    Thu 2017-10-05 04:28:45 +08  3h 15min ago rkhunter.timer               rkhunter.service
Fri 2017-10-06 01:38:57 +08  17h left    Wed 2017-10-04 19:12:48 +08  12h ago      systemd-tmpfiles-clean.timer systemd-tmpfiles-clean.service
Mon 2017-10-09 08:46:49 +08  4 days left Mon 2017-10-02 19:37:22 +08  2 days ago   reflector.timer              reflector.service

7 timers listed.
Pass --all to see loaded but inactive timers, too.
[donato@archdesktop ~]$ systemctl status rkhunter.service
donato@archdesktop ~]$ systemctl status rkhunter.service
● rkhunter.service - rkhunter rootkit scan and malware detection
   Loaded: loaded (/etc/systemd/system/rkhunter.service; static; vendor preset: disabled)
   Active: inactive (dead)
     Docs: man:rkhunter
           man:systemd.service
[donato@archdesktop ~]$

If I want rkhunter to start scanning at boot, I should enable the service with:

$ systemctl enable rkhunter.service

Since I don't want that behavior I'm disabling the service. It won't start at boot but will start when its timer elapse. 

rkhunter update process fails in this instance, but the main process goes on at the elapse time set in the timer file. My tip with creating service and timer files in systemd is letting the default behavior take you where you want to go. So it's a given that you know what those defaults are.


My current rkhunter.service file is:
[donato@archdesktop ~]$ systemctl cat rkhunter.service
# /etc/systemd/system/rkhunter.service
[Unit]
Description=rkhunter rootkit scan and malware detection
Documentation=man:rkhunter man:systemd.service


[Service]
ExecStartPre=-/usr/bin/rkhunter --update
ExecStartPre=-/usr/bin/rkhunter --propupd
ExecStart=/usr/bin/rkhunter --check -sk
SuccessExitStatus=1 2 8 SIGKILL TERM


[Install]
WantedBy=multi-user.target

My current rkhunter.timer file is:
[donato@archdesktop ~]$ systemctl cat rkhunter.timer
# /etc/systemd/system/rkhunter.timer
[Unit]
Description=Run rkhunter daily
Documentation=man:rkhunter man:systemd.timer


[Timer]
OnCalendar=*-*-* 00:00:00
RandomizedDelaySec=5h
WakeSystem=true
Persistent=true


[Install]
WantedBy=timers.target

Comments

Popular posts from this blog

ZFS Unable to System Snapshot, bpool is Full?

I first encountered the problem after a routine update / upgrade of the system. Well there was a kernel upgrade and I have not checked how many old kernels are still left for backups in /boot. Apparently, there was a few and the partition is 85% full. Every software update included a warning because of the restriction in disk space. Also, zfs could not create snapshots. It is also full. This is not very clear to me. Snapshots were suppose to be diff copies so why would it take up a large space. Most of the snapshots are less than 2MB. Or 0MB. Another problem that popped up is the constant freezing of Rhythmbox. I don't know if the config files are corrupted. The CPU cycles from one to the next. Peaks for 5-6 seconds then on to the next CPU. This forced me to download Clementine and Audacious. But both applications do not find the zfs pool or don't show the zfs structure. Why not? My final solution is to reinstall Rhythmbox via snaps. I re-scanned the music libr

Renter's ID and Business Licensing 2023

Last year's business permit application involved an undertaking of submitting lessee list to the Barangay in order to get them ID's including one for the lessor himself. I received a letter of notification just before New Year's Day. It informed me that I might be denied renewal of permits because I did not comply with this undertaking. So the Renter's ID is a serious thing now. When I went ahead and applied for a business permit renewal at the local government office everything went well except they want my list of lessee. So I had to backtrack and go to the Barangay and submit the list. They produced the ID's and I provided the photo ID's and of course have it signed by the lessee. After that, they pointed me to the cashier to pay the taxes and permit fees which totaled php15,305.00 ($280.33) During the payment of Fire and Safety department, they reminded me to bring my fire extinguisher official receipts of payment. I can pick up my new pe

Check rkhunter warnings For Deleted Files

logfile- /var/log/rkhunter.log starts [partial starts] [19:18:58] Info: Starting test name 'malware' [19:18:58] Performing malware checks [19:18:58] [19:18:58] Info: Starting test name 'deleted_files' [19:19:35]   Checking running processes for deleted files    [ Warning ] [19:19:35] Warning: The following processes are using deleted files: [19:19:35]          Process: /usr/bin/pulseaudio    PID: 784    File: /memfd:pulseaudio [19:19:35]          Process: /usr/bin/gnome-shell    PID: 1151    File: /tmp/mutter-shared-67ER4Y [19:19:35]          Process: /usr/bin/pulseaudio    PID: 1173    File: /memfd:pulseaudio [19:19:35]          Process: /usr/lib/evolution-data-server/evolution-source-registry    PID: 1194    File: /home/donato/.local/share/gvfs-metadata/home [19:19:35]          Process: /usr/bin/python2.7    PID: 1472    File: /tmp/vteZY4V4Y [19:19:35]          Process: /usr/bin/megasync    PID: 1484    File: /run/user/1000/wayland-cursor-shared-t6KVCM [19:19:35]