{"id":419,"date":"2021-03-21T22:32:56","date_gmt":"2021-03-21T22:32:56","guid":{"rendered":"https:\/\/www.virtono.ro\/blog\/?p=419"},"modified":"2021-03-22T01:02:08","modified_gmt":"2021-03-22T01:02:08","slug":"cum-sa-instalez-rkhunter-pe-ubuntu-20","status":"publish","type":"post","link":"https:\/\/www.virtono.ro\/blog\/cum-sa-instalez-rkhunter-pe-ubuntu-20\/","title":{"rendered":"Cum s\u0103 instalez RKHunter pe Ubuntu 20"},"content":{"rendered":"<p>Ne \u00eendrept\u0103m acum aten\u021bia asupra instrumentelor specifice de detectare a rootkit-urilor \u0219i a altor vulnerabilit\u0103\u021bi ale sistemului de operare. \u00cen acest tutorial o s\u0103 vorbim despre RKHunter, un instrument care poate scana sistemul local pentru a g\u0103si rootkit-uri, backdoor-uri \u0219i posibilele vulnerabilit\u0103\u021bi.<\/p>\n<p>Scanarea o face compar\u00e2nd hashurile SHA-1 ale fi\u0219ierelor locale cu hashurile bune cunoscute \u00eentr-o baz\u0103 de date online. Acest pachet face parte din depozitele standard Ubuntu \u0219i este u\u0219or de instalat.<\/p>\n<p>Acest tutorial a fost f\u0103cut pentru un <a href=\"https:\/\/www.virtono.com\/cloud-vps\" target=\"_blank\" rel=\"noopener\">VPS<\/a> comandat de pe <a href=\"https:\/\/www.virtono.ro\" title=\"Hosting siteuri\">www.virtono.ro<\/a> pe care a fost o imagine ubuntu-20.04-x86_64 proasp\u0103t instalat\u0103.<\/p>\n<h6 style=\"text-align: center;\">Update \u0219i upgrade la pachete<\/h6>\n<p>Imediat dup\u0103 conectarea la server ne asigur\u0103m c\u0103 toate pachetele sunt la zi introduc\u00e2nd urm\u0103toarele comenzi:<\/p>\n<blockquote><p>apt update -y; apt upgrade\u00a0 -y<\/p>\n<p><a href=\"https:\/\/www.virtono.ro\/blog\/cum-sa-instalez-rkhunter-pe-ubuntu-20\/upgrade\/\" rel=\"attachment wp-att-423\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.virtono.ro\/blog\/wp-content\/uploads\/2021\/03\/upgrade-300x166.png\" alt=\"apt update -y; apt upgrade -y\" width=\"300\" height=\"166\" class=\"alignnone size-medium wp-image-423\" srcset=\"https:\/\/www.virtono.ro\/blog\/wp-content\/uploads\/2021\/03\/upgrade-300x166.png 300w, https:\/\/www.virtono.ro\/blog\/wp-content\/uploads\/2021\/03\/upgrade-1024x566.png 1024w, https:\/\/www.virtono.ro\/blog\/wp-content\/uploads\/2021\/03\/upgrade-768x425.png 768w, https:\/\/www.virtono.ro\/blog\/wp-content\/uploads\/2021\/03\/upgrade-1536x850.png 1536w, https:\/\/www.virtono.ro\/blog\/wp-content\/uploads\/2021\/03\/upgrade.png 1636w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p><\/blockquote>\n<p>Prin -y(es) ne asigur\u0103m c\u0103 nu o s\u0103 trebuiasc\u0103 s\u0103 confirm\u0103m fiecare upgrade sau upgrade.<\/p>\n<p><a href=\"https:\/\/www.virtono.ro\/blog\/cum-sa-instalez-rkhunter-pe-ubuntu-20\/package\/\" rel=\"attachment wp-att-424\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.virtono.ro\/blog\/wp-content\/uploads\/2021\/03\/package-300x161.png\" alt=\"\" width=\"300\" height=\"161\" class=\"alignnone size-medium wp-image-424\" srcset=\"https:\/\/www.virtono.ro\/blog\/wp-content\/uploads\/2021\/03\/package-300x161.png 300w, https:\/\/www.virtono.ro\/blog\/wp-content\/uploads\/2021\/03\/package-1024x550.png 1024w, https:\/\/www.virtono.ro\/blog\/wp-content\/uploads\/2021\/03\/package-768x412.png 768w, https:\/\/www.virtono.ro\/blog\/wp-content\/uploads\/2021\/03\/package-1536x825.png 1536w, https:\/\/www.virtono.ro\/blog\/wp-content\/uploads\/2021\/03\/package.png 1654w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Pe la jum\u0103tatea instal\u0103rii suntem \u00eentreba\u021bi ce versiune de openssh-server dorim s\u0103 p\u0103str\u0103m, pur \u0219i simplu ap\u0103s\u0103m Ok, apoi a\u0219tept\u0103m mai a\u0219tept\u0103m pu\u021bin.<\/p>\n<h6 style=\"text-align: center;\">Instalare RKHunter<\/h6>\n<p>La sf\u00e2r\u0219itul ambelor de mai sus opera\u021biuni putem instala RKHunter, iar comanda pentru acest lucru este:<\/p>\n<blockquote><p>apt install -y rkhunter<\/p><\/blockquote>\n<p>Deoarece acest VPS este proasp\u0103t instalat, RKHunter o s\u0103 i\u0219i instaleze \u0219i alte pachete pe care le mai folose\u0219te, unul dintre acestea fiind postfix (postfix este necesar pentru notificarea pe email).<\/p>\n<p><a href=\"https:\/\/www.virtono.ro\/blog\/cum-sa-instalez-rkhunter-pe-ubuntu-20\/postfix\/\" rel=\"attachment wp-att-425\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.virtono.ro\/blog\/wp-content\/uploads\/2021\/03\/postfix-300x189.png\" alt=\"\" width=\"300\" height=\"189\" class=\"alignnone size-medium wp-image-425\" srcset=\"https:\/\/www.virtono.ro\/blog\/wp-content\/uploads\/2021\/03\/postfix-300x189.png 300w, https:\/\/www.virtono.ro\/blog\/wp-content\/uploads\/2021\/03\/postfix.png 657w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Ap\u0103s\u0103m enter, apoi suntem \u00eentreba\u021bi numele serverului de email, \u00eel l\u0103s\u0103m pe acela introdus implicit (teoretic este hostname-ul VPS-ului).<\/p>\n<p>La sf\u00e2r\u0219itul instal\u0103rii RKHunter o s\u0103 vedem:<\/p>\n<blockquote><p>[ Rootkit Hunter version 1.4.6 ]<br \/>\nFile updated: searched for 180 files, found 144<\/p><\/blockquote>\n<h6 style=\"text-align: center;\">Configurarea RKHunter<\/h6>\n<p>Dup\u0103 instalare putem s\u0103 ne \u00eendrept\u0103m aten\u021bia asupra configura\u021biei RKHunter, configura\u021bia sa fiind \u00een folderul <strong>\/etc<\/strong>, fi\u0219ierul <strong>rkhunter.conf<\/strong>.<\/p>\n<p>Pentru a asigura o scanare complet\u0103 avem de modificat valoarea a trei caracteristicii, scriem comanda <strong>nano \/etc\/rkhunter.conf<\/strong> pentru a edita urm\u0103toarele valori astfel:<\/p>\n<blockquote><p>UPDATE_MIRRORS=1<\/p>\n<p>MIRRORS_MODE=0<\/p>\n<p>WEB_CMD=&#8221;&#8221;<\/p><\/blockquote>\n<p>Rkhunter poate fi configurat pentru a trimite un e-mail atunci c\u00e2nd este g\u0103sit\u0103 o amenin\u021bare. Pentru a configura aceast\u0103 caracteristic\u0103 c\u0103uta\u021bi caracteristica <span><strong>MAIL-ON-WARNING<\/strong>, apoi adaug\u0103 adresa ta de email. Nu uita s\u0103 \u0219tergi # care se afl\u0103 \u00eenaintea caracteristicii. Acel caracter dezactiveaz\u0103 alerta pe email.<\/span><\/p>\n<p>Op\u021bional, pute\u021bi parcurge configura\u021bia pentru mai multe op\u021biuni, cu toate acestea, \u00een mod implicit, ar trebui s\u0103 func\u021bioneze bine. Pute\u021bi verifica fi\u0219ierul de configurare:<\/p>\n<blockquote><p>rkhunter -C<\/p><\/blockquote>\n<p>Dac\u0103 nu r\u0103spuns, fi\u0219ierul dvs. de configurare este valid.<\/p>\n<p>De asemenea, vom activa actualiz\u0103rile automate modific\u00e2nd fi\u0219ierul <strong>\/etc\/default\/rkhunter<\/strong> cu urm\u0103toarele valori:<\/p>\n<blockquote><p>CRON_DAILY_RUN=&#8221;true&#8221;<\/p>\n<p>CRON_DB_UPDATE=true&#8221;<\/p>\n<p>APT_AUTOGEN=&#8221;true&#8221;<\/p><\/blockquote>\n<p>Op\u021bional, pute\u021bi parcurge configura\u021bia pentru mai multe op\u021biuni, cu toate acestea, \u00een mod implicit, ar trebui s\u0103 func\u021bioneze bine. Pute\u021bi verifica fi\u0219ierul de configurare:<\/p>\n<h6 style=\"text-align: center;\">Update RKHunter<\/h6>\n<p>Urmeaz\u0103 updateul la RKHunter folosind comanda:<\/p>\n<blockquote><p>rkhunter &#8211;update<\/p>\n<p><a href=\"https:\/\/www.virtono.ro\/blog\/cum-sa-instalez-rkhunter-pe-ubuntu-20\/rkupdate\/\" rel=\"attachment wp-att-426\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.virtono.ro\/blog\/wp-content\/uploads\/2021\/03\/rkupdate-300x97.png\" alt=\"rkhunter --update\" width=\"300\" height=\"97\" class=\"alignnone size-medium wp-image-426\" srcset=\"https:\/\/www.virtono.ro\/blog\/wp-content\/uploads\/2021\/03\/rkupdate-300x97.png 300w, https:\/\/www.virtono.ro\/blog\/wp-content\/uploads\/2021\/03\/rkupdate-768x248.png 768w, https:\/\/www.virtono.ro\/blog\/wp-content\/uploads\/2021\/03\/rkupdate.png 793w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p><\/blockquote>\n<p>Aceasta va afi\u0219a o list\u0103 cu fi\u0219iere de date care au fost actualizate \u0219i celor care nu au fost actualizate:<\/p>\n<h6 style=\"text-align: center;\">Prima scanare cu RKHunter<\/h6>\n<p>Acum suntem gata s\u0103 efectu\u0103m primul nostru test. Testul va c\u0103uta rootkit-uri cunoscute \u0219i probleme de securitate generice (cum ar fi accesul root prin SSH) \u0219i va \u00eenregistra constat\u0103rile sale.<\/p>\n<p>. Pentru a face acest lucru pur \u0219i simplu introducem:<\/p>\n<blockquote><p>rkhunter &#8211;check<\/p><\/blockquote>\n<p>\u00cen timpul scan\u0103rii va trebui s\u0103 ap\u0103sa\u021bi manual \u201eEnter\u201d pentru a continua dup\u0103 verific\u0103ri, dar ]n timpul scan\u0103rii o s\u0103 primim o avertizare deoarece este permis\u0103 autentificarea folosind utilizatorul root. La sf\u00e2r\u0219itul auditului o s\u0103 vede\u021bi un scurt raport precum:<\/p>\n<p><a href=\"https:\/\/www.virtono.ro\/blog\/cum-sa-instalez-rkhunter-pe-ubuntu-20\/rkhunter\/\" rel=\"attachment wp-att-427\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.virtono.ro\/blog\/wp-content\/uploads\/2021\/03\/rkhunter-300x166.png\" alt=\"\" width=\"300\" height=\"166\" class=\"alignnone size-medium wp-image-427\" srcset=\"https:\/\/www.virtono.ro\/blog\/wp-content\/uploads\/2021\/03\/rkhunter-300x166.png 300w, https:\/\/www.virtono.ro\/blog\/wp-content\/uploads\/2021\/03\/rkhunter-1024x567.png 1024w, https:\/\/www.virtono.ro\/blog\/wp-content\/uploads\/2021\/03\/rkhunter-768x425.png 768w, https:\/\/www.virtono.ro\/blog\/wp-content\/uploads\/2021\/03\/rkhunter-1536x851.png 1536w, https:\/\/www.virtono.ro\/blog\/wp-content\/uploads\/2021\/03\/rkhunter.png 1612w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.virtono.ro\/blog\/cum-sa-instalez-rkhunter-pe-ubuntu-20\/raport\/\" rel=\"attachment wp-att-428\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.virtono.ro\/blog\/wp-content\/uploads\/2021\/03\/raport-300x174.png\" alt=\"\" width=\"300\" height=\"174\" class=\"alignnone size-medium wp-image-428\" srcset=\"https:\/\/www.virtono.ro\/blog\/wp-content\/uploads\/2021\/03\/raport-300x174.png 300w, https:\/\/www.virtono.ro\/blog\/wp-content\/uploads\/2021\/03\/raport-1024x593.png 1024w, https:\/\/www.virtono.ro\/blog\/wp-content\/uploads\/2021\/03\/raport-768x445.png 768w, https:\/\/www.virtono.ro\/blog\/wp-content\/uploads\/2021\/03\/raport-1536x889.png 1536w, https:\/\/www.virtono.ro\/blog\/wp-content\/uploads\/2021\/03\/raport.png 1565w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Dar avem avertizarea:<\/p>\n<blockquote><p>Checking if SSH root access is allowed [ Warning ]<\/p><\/blockquote>\n<p>De ce s\u0103 nu rezolv\u0103m asta? Putem \u0219i ar trebui s\u0103 interzicem acest lucru \u00een fi\u0219ierul <strong>\/etc\/ssh\/sshd_config<\/strong>, schimb\u00e2nd valoarea din Yes \u00een No pentru PermitRootLogin<\/p>\n<blockquote><p>PermitRootLogin=no<\/p><\/blockquote>\n<p>Restart\u0103m serverul ssh folosind:<\/p>\n<blockquote><p>systemctl restart sshd<\/p><\/blockquote>\n<p>Dac\u0103 refacem testul, totul este \u00een regul\u0103.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ne \u00eendrept\u0103m acum aten\u021bia asupra instrumentelor specifice de detectare a rootkit-urilor \u0219i a altor vulnerabilit\u0103\u021bi ale sistemului de operare. \u00cen acest tutorial o s\u0103 vorbim despre RKHunter, un instrument care poate scana sistemul local pentru a g\u0103si rootkit-uri, backdoor-uri \u0219i posibilele vulnerabilit\u0103\u021bi. Scanarea o face compar\u00e2nd hashurile SHA-1 ale fi\u0219ierelor<\/p>\n","protected":false},"author":1,"featured_media":427,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,21],"tags":[24,22,23,25],"class_list":["post-419","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-vps","category-ubuntu","tag-backdoor-ubuntu","tag-rkhunter","tag-rootkit-hunter","tag-rootkit-uri"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.virtono.ro\/blog\/wp-json\/wp\/v2\/posts\/419","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.virtono.ro\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.virtono.ro\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.virtono.ro\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.virtono.ro\/blog\/wp-json\/wp\/v2\/comments?post=419"}],"version-history":[{"count":6,"href":"https:\/\/www.virtono.ro\/blog\/wp-json\/wp\/v2\/posts\/419\/revisions"}],"predecessor-version":[{"id":441,"href":"https:\/\/www.virtono.ro\/blog\/wp-json\/wp\/v2\/posts\/419\/revisions\/441"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.virtono.ro\/blog\/wp-json\/wp\/v2\/media\/427"}],"wp:attachment":[{"href":"https:\/\/www.virtono.ro\/blog\/wp-json\/wp\/v2\/media?parent=419"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.virtono.ro\/blog\/wp-json\/wp\/v2\/categories?post=419"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.virtono.ro\/blog\/wp-json\/wp\/v2\/tags?post=419"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}