1 |
slords |
1.2 |
# No debuginfo: |
2 |
|
|
%define debug_package %{nil} |
3 |
|
|
|
4 |
|
|
# If you want to debug, uncomment the next line and remove |
5 |
|
|
# the duplicate percent sign (due to macro expansion) |
6 |
|
|
#%%dump |
7 |
|
|
|
8 |
|
|
%define name rkhunter |
9 |
slords |
1.9 |
%define ver 1.3.2 |
10 |
|
|
%define rel 1 |
11 |
slords |
1.2 |
%define epoch 0 |
12 |
|
|
|
13 |
|
|
# Don't change this define or also: |
14 |
|
|
# 1. installer.sh --layout custom /temporary/dir/usr --striproot /temporary/dir --install |
15 |
|
|
# 2. rewrite the files section below. |
16 |
|
|
%define _prefix /usr |
17 |
|
|
|
18 |
slords |
1.1 |
# We can't let RPM do the dependencies automatic because it'll then pick up |
19 |
|
|
# a correct but undesirable perl dependency, which rkhunter does not require |
20 |
|
|
# in order to function properly. |
21 |
|
|
AutoReqProv: no |
22 |
|
|
|
23 |
slords |
1.2 |
Name: %{name} |
24 |
|
|
Summary: %{name} scans for rootkits, backdoors and local exploits |
25 |
|
|
Version: %{ver} |
26 |
|
|
Release: %{rel}%{dist} |
27 |
|
|
Epoch: %{epoch} |
28 |
|
|
License: GPL |
29 |
|
|
Group: Applications/System |
30 |
|
|
Source0: %{name}-%{version}.tar.gz |
31 |
|
|
Patch0: rkhunter-installer.patch |
32 |
bytegw |
1.5 |
Patch1: rkhunter-nolib.patch |
33 |
slords |
1.2 |
BuildArch: noarch |
34 |
|
|
Requires: filesystem, bash, grep, findutils, net-tools, coreutils, e2fsprogs, modutils, procps, binutils, wget, perl |
35 |
|
|
Provides: %{name} |
36 |
|
|
URL: http://rkhunter.sourceforge.net/ |
37 |
|
|
BuildRoot: %{_tmppath}/%{name}-%{version} |
38 |
slords |
1.1 |
|
39 |
|
|
%description |
40 |
slords |
1.2 |
Rootkit Hunter is a scanning tool to ensure you are about 99.9%% |
41 |
|
|
clean of nasty tools. It scans for rootkits, backdoors and local |
42 |
slords |
1.1 |
exploits by running tests like: |
43 |
slords |
1.2 |
- File hash check |
44 |
slords |
1.1 |
- Look for default files used by rootkits |
45 |
|
|
- Wrong file permissions for binaries |
46 |
|
|
- Look for suspected strings in LKM and KLD modules |
47 |
|
|
- Look for hidden files |
48 |
|
|
- Optional scan within plaintext and binary files |
49 |
|
|
- Software version checks |
50 |
|
|
- Application tests |
51 |
|
|
|
52 |
|
|
Rootkit Hunter is released as a GPL licensed project and free for everyone to use. |
53 |
|
|
|
54 |
|
|
|
55 |
|
|
%prep |
56 |
slords |
1.2 |
%setup -q |
57 |
|
|
%patch0 -p1 |
58 |
bytegw |
1.5 |
%patch1 -p1 |
59 |
slords |
1.1 |
|
60 |
|
|
%build |
61 |
|
|
|
62 |
|
|
%install |
63 |
slords |
1.9 |
MANPATH="" |
64 |
|
|
export MANPATH |
65 |
|
|
|
66 |
slords |
1.2 |
sh ./installer.sh --layout RPM --install |
67 |
slords |
1.1 |
|
68 |
slords |
1.3 |
sed -i 's_#ALLOWPROCLISTEN=/sbin/dhclient_ALLOWPROCLISTEN=/sbin/dhclient_' ${RPM_BUILD_ROOT}%{_sysconfdir}/%{name}.conf |
69 |
bytegw |
1.7 |
sed -i 's_#ALLOWPROCLISTEN=/usr/sbin/pppoe_ALLOWPROCLISTEN=/sbin/pppoe_' ${RPM_BUILD_ROOT}%{_sysconfdir}/%{name}.conf |
70 |
slords |
1.3 |
sed -i 's_#ALLOWHIDDENFILE=/usr/share/man/man1/..1.gz_ALLOWHIDDENFILE=/usr/share/man/man1/..1.gz_' ${RPM_BUILD_ROOT}%{_sysconfdir}/%{name}.conf |
71 |
bytegw |
1.4 |
sed -i '/#ALLOWPROCLISTEN=\/usr\/bin\/dhcpcd/iALLOWPROCLISTEN=\/usr\/sbin\/dhcpd' ${RPM_BUILD_ROOT}%{_sysconfdir}/%{name}.conf |
72 |
slords |
1.3 |
sed -i '/#ALLOWPROCDELFILE=\/usr\/sbin\/mysqld/aALLOWPROCDELFILE=\/usr\/sbin\/httpd' ${RPM_BUILD_ROOT}%{_sysconfdir}/%{name}.conf |
73 |
slords |
1.8 |
sed -i '/ALLOWPROCDELFILE=\/usr\/sbin\/httpd/aALLOWPROCDELFILE=\/usr\/sbin\/asterisk' ${RPM_BUILD_ROOT}%{_sysconfdir}/%{name}.conf |
74 |
slords |
1.1 |
|
75 |
slords |
1.2 |
# Make a cron.daily file to mail us the reports |
76 |
slords |
1.1 |
%{__mkdir} -p "${RPM_BUILD_ROOT}/%{_sysconfdir}/cron.daily" |
77 |
|
|
%{__cat} > "${RPM_BUILD_ROOT}/%{_sysconfdir}/cron.daily/01-rkhunter" <<EOF |
78 |
|
|
#!/bin/sh |
79 |
slords |
1.6 |
%{_bindir}/rkhunter --cronjob --update --disable apps,suspscan,system_commands --rwo |
80 |
slords |
1.2 |
exit 0 |
81 |
slords |
1.1 |
EOF |
82 |
|
|
%{__chmod} a+rwx,g-w,o-rwx ${RPM_BUILD_ROOT}%{_sysconfdir}/cron.daily/01-rkhunter |
83 |
|
|
|
84 |
|
|
|
85 |
slords |
1.2 |
%post |
86 |
|
|
# Only do this on an initial install |
87 |
|
|
if [ $1 -eq 1 ]; then |
88 |
bytegw |
1.5 |
%{__cp} -p /etc/passwd /var/rkhunter/tmp >/dev/null 2>&1 || : |
89 |
|
|
%{__cp} -p /etc/group /var/rkhunter/tmp >/dev/null 2>&1 || : |
90 |
slords |
1.2 |
fi |
91 |
slords |
1.1 |
|
92 |
|
|
|
93 |
slords |
1.2 |
%preun |
94 |
|
|
# Only do this when removing the RPM |
95 |
|
|
if [ $1 -eq 0 ]; then |
96 |
|
|
%{__rm} -f /var/log/rkhunter.log /var/log/rkhunter.log.old >/dev/null 2>&1 |
97 |
bytegw |
1.5 |
%{__rm} -rf /var/rkhunter/* >/dev/null 2>&1 |
98 |
slords |
1.2 |
fi |
99 |
slords |
1.1 |
|
100 |
|
|
|
101 |
slords |
1.2 |
%clean |
102 |
|
|
if [ "$RPM_BUILD_ROOT" = "/" ]; then |
103 |
|
|
echo Invalid Build root \'"$RPM_BUILD_ROOT"\' |
104 |
|
|
exit 1 |
105 |
|
|
else |
106 |
|
|
rm -rf $RPM_BUILD_ROOT |
107 |
|
|
fi |
108 |
slords |
1.1 |
|
109 |
|
|
|
110 |
slords |
1.2 |
%define docdir %{_prefix}/share/doc/%{name}-%{version} |
111 |
|
|
%files |
112 |
|
|
%defattr(-,root,root) |
113 |
|
|
%attr(640,root,root) %config(noreplace) %{_sysconfdir}/%{name}.conf |
114 |
|
|
%attr(750,root,root) %{_prefix}/bin/%{name} |
115 |
|
|
%attr(750,root,root) %dir %{_libdir}/%{name} |
116 |
|
|
%attr(750,root,root) %dir %{_libdir}/%{name}/scripts |
117 |
|
|
%attr(750,root,root) %{_libdir}/%{name}/scripts/*.pl |
118 |
|
|
%attr(750,root,root) %{_libdir}/%{name}/scripts/*.sh |
119 |
|
|
%attr(644,root,root) %doc %{_prefix}/share/man/man8/%{name}.8.gz |
120 |
|
|
%attr(755,root,root) %dir %{docdir} |
121 |
|
|
%attr(644,root,root) %doc %{docdir}/* |
122 |
bytegw |
1.5 |
%attr(750,root,root) %dir %{_var}/%{name} |
123 |
|
|
%attr(750,root,root) %dir %{_var}/%{name}/db |
124 |
|
|
%attr(640,root,root) %{_var}/%{name}/db/*.dat |
125 |
|
|
%attr(750,root,root) %dir %{_var}/%{name}/db/i18n |
126 |
|
|
%attr(640,root,root) %{_var}/%{name}/db/i18n/* |
127 |
|
|
%attr(750,root,root) %dir %{_var}/%{name}/tmp |
128 |
slords |
1.2 |
%{_sysconfdir}/cron.daily/01-rkhunter |
129 |
slords |
1.1 |
|
130 |
|
|
|
131 |
slords |
1.2 |
%changelog |
132 |
slords |
1.9 |
* Fri Feb 29 2008 Shad L. Lords <slords@mail.com> 1.3.2-1 |
133 |
|
|
- Update to rkhunter v1.3.2 |
134 |
|
|
|
135 |
slords |
1.8 |
* Wed Jan 30 2008 Shad L. Lords <slords@mail.com> 1.3.0-6 |
136 |
|
|
- Fix asterisk to allow deleted files. [SME: 3795] |
137 |
|
|
|
138 |
bytegw |
1.7 |
* Tue Jan 29 2008 Shad L. Lords <slords@mail.com> 1.3.0-5 |
139 |
|
|
- Correct pppoe binary location. |
140 |
|
|
- Add asterisk binary to allow deleted files. [SME: 3795] |
141 |
|
|
|
142 |
slords |
1.6 |
* Mon Jan 7 2008 Shad L. Lords <slords@mail.com> 1.3.0-4 |
143 |
|
|
- Disable scan for suspicious files until fixed [SME: 3713] |
144 |
|
|
|
145 |
bytegw |
1.5 |
* Mon Dec 17 2007 Shad L. Lords <slords@mail.com> 1.3.0-3 |
146 |
|
|
- Change /var/lib to /var to be consistent with previous versions |
147 |
|
|
|
148 |
bytegw |
1.4 |
* Mon Dec 17 2007 Shad L. Lords <slords@mail.com> 1.3.0-2 |
149 |
|
|
- Add a few more services for sme tests |
150 |
|
|
|
151 |
slords |
1.2 |
* Mon Dec 17 2007 Shad L. Lords <slords@mail.com> 1.3.0-1 |
152 |
|
|
- Fix installer to not install in local |
153 |
slords |
1.3 |
- Set parameters for sme specific tests |
154 |
slords |
1.1 |
|
155 |
slords |
1.2 |
* Sun Feb 11 2007 unSpawn - pre-1.3.0 |
156 |
|
|
- Sync spec with fixes, installer and CVS |
157 |
slords |
1.1 |
|
158 |
slords |
1.2 |
* Sun Nov 12 2006 unSpawn - 1.2.9 |
159 |
|
|
- Re-spec, new installer |
160 |
slords |
1.1 |
|
161 |
slords |
1.2 |
* Fri Sep 29 2006 unSpawn - 1.2.9 |
162 |
|
|
- Updated for release 1.2.9 |
163 |
slords |
1.1 |
|
164 |
|
|
* Tue Aug 10 2004 Michael Boelen - 1.1.5 |
165 |
|
|
- Added update script |
166 |
|
|
- Extended description |
167 |
|
|
|
168 |
|
|
* Sun Aug 08 2004 Greg Houlette - 1.1.5 |
169 |
|
|
- Changed the install procedure eliminating the specification of |
170 |
|
|
destination filenames (only needed if you are renaming during install) |
171 |
|
|
- Changed the permissions for documentation files (root only overkill) |
172 |
|
|
- Added the installation of the rkhunter Man Page |
173 |
|
|
- Added the installation of the programs_{bad, good}.dat database files |
174 |
|
|
- Added the installation of the LICENSE documentation file |
175 |
|
|
- Added the chmod for root only to the /var/rkhunter/db directory |
176 |
|
|
|
177 |
|
|
* Sun May 23 2004 Craig Orsinger (cjo) <cjorsinger@earthlink.net> |
178 |
|
|
- version 1.1.0-1.cjo |
179 |
|
|
- changed installation in accordance with new rootkit installation |
180 |
|
|
procedure |
181 |
|
|
- changed installation root to conform to LSB. Use standard macros. |
182 |
|
|
- added recursive remove of old build root as prep for install phase |
183 |
|
|
|
184 |
|
|
* Wed Apr 28 2004 Doncho N. Gunchev - 1.0.9-0.mr700 |
185 |
|
|
- dropped Requires: perl - rkhunter works without it |
186 |
|
|
- dropped the bash alignpatch (check the source or contact me) |
187 |
|
|
- various file mode fixes (.../tmp/, *.db) |
188 |
|
|
- optimized the %%files section - any new files in the |
189 |
|
|
current dirs will be fine - just %%{__install} them. |
190 |
|
|
|
191 |
|
|
* Mon Apr 26 2004 Michael Boelen - 1.0.8-0 |
192 |
|
|
- Fixed missing md5blacklist.dat |
193 |
|
|
|
194 |
|
|
* Mon Apr 19 2004 Doncho N. Gunchev - 1.0.6-1.mr700 |
195 |
|
|
- added missing /usr/local/rkhunter/db/md5blacklist.dat |
196 |
|
|
- patched to align results in --cronjob, I think rpm based |
197 |
|
|
distros have symlink /bin/sh -> /bin/bash |
198 |
|
|
- added --with/--without alignpatch for conditional builds |
199 |
|
|
(in case previous patch breaks something) |
200 |
|
|
|
201 |
|
|
* Sat Apr 03 2004 Michael Boelen / Joe Klemmer - 1.0.6-0 |
202 |
|
|
- Update to 1.0.6 |
203 |
|
|
|
204 |
|
|
* Mon Mar 29 2004 Doncho N. Gunchev - 1.0.0-0 |
205 |
|
|
- initial .spec file |
206 |
|
|
|
207 |
slords |
1.2 |
|