Advertisement
mjb

rkhunter-1.4.2_2 debug output, FreeBSD 10.2-STABLE armv6

mjb
Oct 4th, 2015
111
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 407.64 KB | None | 0 0
  1. + test 1 -eq 1
  2. + alias print=false
  3. + false rkh-ksh-string-test
  4. + [ '' = rkh-ksh-string-test ]
  5. + [ 0 -eq 1 ]
  6. + MYSHELL=/bin/sh
  7. + test -h /bin/sh
  8. + basename /bin/sh
  9. + MYSHELL=sh
  10. + test -z sh
  11. + echo -e 'rkh-ksh\tstring-test'
  12. + [ 'rkh-ksh string-test' = 'rkh-ksh string-test' ]
  13. + ECHOOPT=-e
  14. + echo -n -e rkh-ksh-string-test
  15. + [ '-e rkh-ksh-string-test' = rkh-ksh-string-test ]
  16. + echo -e 'rkh-ksh-string-test\c'
  17. + [ rkh-ksh-string-test = rkh-ksh-string-test ]
  18. + ECHON=c
  19. + head -n 1
  20. + HEAD_OPT='-n '
  21. + tail -n 1
  22. + TAIL_OPT='-n '
  23. + [ 1 -eq 1 -a sh = ksh ]
  24. + trap - 13
  25. + PROGRAM_NAME='Rootkit Hunter'
  26. + PROGRAM_version=1.4.2
  27. + PROGRAM_copyright_owner='Michael Boelen'
  28. + PROGRAM_copyright='Copyright (c) 2003-2014, Michael Boelen'
  29. + PROGRAM_blurb='
  30. Currently under active development by the Rootkit Hunter project team.
  31. Please review your rkhunter.conf before using.
  32. Please review the documentation before posting bug reports or questions.
  33. To report bugs, obtain updates, or provide patches or comments, please go to:
  34. http://rkhunter.sourceforge.net
  35.  
  36. To ask questions about rkhunter, please use the rkhunter-users mailing list.
  37. Note this is a moderated list: please subscribe before posting.
  38.  
  39. Rootkit Hunter comes with ABSOLUTELY NO WARRANTY.
  40. This is free software, and you are welcome to redistribute it under the
  41. terms of the GNU General Public License. See the LICENSE file for details.
  42. '
  43. + PROGRAM_license='
  44. Rootkit Hunter 1.4.2, Copyright (c) 2003-2014, Michael Boelen
  45.  
  46. Currently under active development by the Rootkit Hunter project team.
  47. Please review your rkhunter.conf before using.
  48. Please review the documentation before posting bug reports or questions.
  49. To report bugs, obtain updates, or provide patches or comments, please go to:
  50. http://rkhunter.sourceforge.net
  51.  
  52. To ask questions about rkhunter, please use the rkhunter-users mailing list.
  53. Note this is a moderated list: please subscribe before posting.
  54.  
  55. Rootkit Hunter comes with ABSOLUTELY NO WARRANTY.
  56. This is free software, and you are welcome to redistribute it under the
  57. terms of the GNU General Public License. See the LICENSE file for details.
  58.  
  59. '
  60. + LEAVE=0
  61. + ERRCODE=0
  62. + CRONJOB=0
  63. + CHECK=0
  64. + CATLOGFILE=0
  65. + NOLOG=0
  66. + RKHLOGFILE=''
  67. + DFLT_LOGFILE=/var/log/rkhunter.log
  68. + APPEND_LOG=0
  69. + APPEND_OPT=0
  70. + COPY_LOG_ON_ERROR=0
  71. + USE_SYSLOG=''
  72. + SYSLOG_DFLT_PRIO=authpriv.notice
  73. + NOMOW=0
  74. + MAILONWARNING=''
  75. + HASH_FUNC=''
  76. + OLD_HASH_FUNC=''
  77. + PKGMGR=''
  78. + OLD_PKGMGR=''
  79. + OLD_ATTRUPD=''
  80. + HASH_OPT=0
  81. + SHA_SIZE=0
  82. + HASH_FLD_IDX=1
  83. + PROP_DIR_LIST=''
  84. + PROP_FILE_LIST=''
  85. + PROP_FILE_LIST_COUNT=0
  86. + PROP_FILE_LIST_TOTAL=0
  87. + PRELINKED=0
  88. + PRELINK_CMD=''
  89. + PRELINK_HASH=''
  90. + PKGMGR_MD5_HASH=''
  91. + MD5_CMD=''
  92. + EPOCH_DATE_CMD=''
  93. + PKGMGRNOVRFY=''
  94. + UPDATE=0
  95. + PROP_UPDATE=0
  96. + PROPUPD_OPT=''
  97. + VERSIONCHECK=0
  98. + COLORS=1
  99. + CLRSET2=0
  100. + WLIST_IS_WHITE=0
  101. + AUTO_X_DTCT=0
  102. + AUTO_X_OPT=0
  103. + QUIET=0
  104. + SHOWWARNINGSONLY=0
  105. + HASH_CHECK_ENABLED=0
  106. + SKIP_HASH_MSG=0
  107. + RKHTMPDIR=''
  108. + DB_PATH=''
  109. + CONFIGFILE=''
  110. + LOCALCONFIGFILE=''
  111. + LOCALCONFIGDIR=''
  112. + LOCALCONFDIRCOUNT=0
  113. + LOCALCONFDIRFILES=''
  114. + BINPATHS=''
  115. + DFLT_BINPATHS='/bin /usr/bin /sbin /usr/sbin /usr/local/bin /usr/local/sbin /usr/libexec /usr/local/libexec'
  116. + BINDIR_OPT=0
  117. + BINISLINK=0
  118. + ID_CMD=id
  119. + SKIP_KEY_PRESS=0
  120. + GREP_OPT=''
  121. + BSDOS=0
  122. + SUNOS=0
  123. + IRIXOS=0
  124. + MACOSX=0
  125. + LINUXOS=0
  126. + BSDOS=1
  127. + HASH_FLD_IDX=4
  128. + GREP_OPT=-a
  129. + OS_CHANGED=0
  130. + WARN_ON_OS_CHANGE=1
  131. + UPDT_ON_OS_CHANGE=0
  132. + ALLOW_SSH_PROT_V1=0
  133. + ALLOW_SSH_ROOT_USER=''
  134. + SSH_CONFIG_DIR=''
  135. + ALLOW_SYSLOG_REMOTE_LOGGING=0
  136. + SYSLOG_CONFIG_FILE=''
  137. + ROOTKIT_COUNT=0
  138. + ROOTKIT_FAILED_COUNT=0
  139. + ROOTKIT_FAILED_NAMES=''
  140. + PROP_FAILED_COUNT=0
  141. + SUMMARY_PROP_REQCMDS=0
  142. + APPS_COUNT=0
  143. + APPS_TOTAL_COUNT=0
  144. + APPS_FAILED_COUNT=0
  145. + BEGINTIME=0
  146. + TOTAL_SCANTIME=''
  147. + WARNING_COUNT=0
  148. + KSYMS_FILE=''
  149. + CMD_LINE='/usr/local/bin/rkhunter --enable filesystem --check --debug'
  150. + tr : ' '
  151. + echo /sbin:/bin:/usr/sbin:/usr/bin:/usr/games:/usr/local/sbin:/usr/local/bin:/home/mike/bin
  152. + RKHROOTPATH='/sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin /home/mike/bin'
  153. + CMDLIST='basename diff dirname file find ifconfig ip ipcs ldd lsattr lsmod lsof mktemp netstat perl pgrep ps pwd readlink stat strings'
  154. + ABSOLUTELY_REQUIRED_CMDS='cut egrep grep sed tail tr'
  155. + REQCMDS='awk cat chmod chown cp cut date egrep grep head ls mv sed sort tail touch tr uname uniq wc'
  156. + WEBCMDLIST='wget curl elinks links lynx bget GET'
  157. + RKHWEBCMD=''
  158. + RKHWEBCMD_OPTS=''
  159. + RKHWEBCMD_BASE=''
  160. + HOST_NAME=''
  161. + RET_CODE=0
  162. + LANGUAGE=''
  163. + UPDATE_LANG=''
  164. + LOCALE_CMD=''
  165. + ICONV_CMD=''
  166. + RKHCHRMAP=''
  167. + RKHCHKLOCALE=0
  168. + KNOWN_TESTS='strings properties hashes scripts immutable attributes
  169. deleted_files packet_cap_apps apps rootkits known_rkts
  170. additional_rkts malware local_host network passwd_changes
  171. group_changes possible_rkt_files possible_rkt_strings
  172. system_commands shared_libs shared_libs_path running_procs
  173. hidden_procs trojans other_malware os_specific startup_malware
  174. startup_files group_accounts system_configs filesystem suspscan
  175. ports hidden_ports promisc loaded_modules avail_modules'
  176. + GROUPED_TESTS='system_commands:properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes
  177. properties:hashes:scripts:immutable:attributes
  178. shared_libs:shared_libs_path
  179. rootkits:known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules
  180. additional_rkts:possible_rkt_files:possible_rkt_strings
  181. network:packet_cap_apps:ports:hidden_ports:promisc
  182. malware:running_procs:hidden_procs:deleted_files:suspscan:other_malware
  183. local_host:startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem
  184. startup_files:startup_malware
  185. os_specific:loaded_modules:avail_modules
  186. group_accounts:passwd_changes:group_changes'
  187. + KNOWN_ROOTKITS='55808 Trojan - Variant A, AjaKit, aPa Kit, Adore, Apache Worm, Ambient (ark),
  188. Balaur, BeastKit, beX2, BOBKit, Boonana (Koobface.A), cb, CiNIK Worm (Slapper.B variant), CX,
  189. Danny-Boy'\''s Abuse Kit, Devil, Dica, Dreams, Duarawkz, Enye LKM, Flea Linux, FreeBSD, Fu,
  190. Fuck`it, GasKit, Heroin LKM, HjC Kit, ignoKit, iLLogiC, Inqtana-A, Inqtana-B, Inqtana-C,
  191. IntoXonia-NG, Irix, Jynx, KBeast, Kitko, Knark, ld-linuxv.so, Li0n Worm, Lockit/LJK2, Mood-NT, MRK, Ni0,
  192. Ohhara, Optic Kit (Tux), OSXRK, Oz, Phalanx, Phalanx2, Portacelo, R3dstorm Toolkit,
  193. RH-Sharpe'\''s, RSHA'\''s, Scalper Worm, Shutdown, SHV4, SHV5, Sin, SInAR, Slapper,
  194. Sneakin, Solaris Wanuk, Spanish, Suckit, SunOS / NSDAP, SunOS Rootkit, Superkit, TBD (Telnet BackDoor),
  195. TeLeKiT, Togroot, T0rn, trNkit, Trojanit Kit, Turtle2, Tuxtendo, URK, Vampire, VcKit, Volc, w00tkit,
  196. weaponX, Xzibit, X-Org SunOS, zaRwT.KiT, ZK'
  197. + LIST_MODULES='File::stat Getopt::Long Crypt::RIPEMD160 Digest::MD5 Digest::SHA Digest::SHA1 Digest::SHA256
  198. Digest::SHA::PurePerl Digest::Whirlpool LWP URI HTTP::Status HTTP::Date Socket Carp'
  199. + SPACE_LIST_OPTS='ALLOWPROMISCIF APP_WHITELIST BINDIR DISABLE_TESTS EMPTY_LOGFILES ENABLE_TESTS
  200. IGNORE_PRELINK_DEP_ERR INETD_ALLOWED_SVC MAIL-ON-WARNING MISSING_LOGFILES
  201. PORT_WHITELIST PWDLESS_ACCOUNTS SHARED_LIB_WHITELIST STARTUP_PATHS SUSPSCAN_DIRS
  202. SYSLOG_CONFIG_FILE UID0_ACCOUNTS UNHIDE_TESTS UNHIDETCP_OPTS UPDATE_LANG
  203. XINETD_ALLOWED_SVC'
  204. + echo ALLOWPROMISCIF APP_WHITELIST BINDIR DISABLE_TESTS EMPTY_LOGFILES ENABLE_TESTS IGNORE_PRELINK_DEP_ERR INETD_ALLOWED_SVC MAIL-ON-WARNING MISSING_LOGFILES PORT_WHITELIST PWDLESS_ACCOUNTS SHARED_LIB_WHITELIST STARTUP_PATHS SUSPSCAN_DIRS SYSLOG_CONFIG_FILE UID0_ACCOUNTS UNHIDE_TESTS UNHIDETCP_OPTS UPDATE_LANG XINETD_ALLOWED_SVC
  205. + SPACE_LIST_OPTS=' ALLOWPROMISCIF APP_WHITELIST BINDIR DISABLE_TESTS EMPTY_LOGFILES ENABLE_TESTS IGNORE_PRELINK_DEP_ERR INETD_ALLOWED_SVC MAIL-ON-WARNING MISSING_LOGFILES PORT_WHITELIST PWDLESS_ACCOUNTS SHARED_LIB_WHITELIST STARTUP_PATHS SUSPSCAN_DIRS SYSLOG_CONFIG_FILE UID0_ACCOUNTS UNHIDE_TESTS UNHIDETCP_OPTS UPDATE_LANG XINETD_ALLOWED_SVC '
  206. + NEWLINE_LIST_OPTS='ALLOWDEVFILE ALLOWHIDDENDIR ALLOWHIDDENFILE ALLOWPROCDELFILE ALLOWPROCLISTEN
  207. ATTRWHITELIST EXCLUDE_USER_FILEPROP_FILES_DIRS EXISTWHITELIST IMMUTWHITELIST
  208. PKGMGR_NO_VRFY PORT_PATH_WHITELIST RTKT_DIR_WHITELIST RTKT_FILE_WHITELIST
  209. SCRIPTWHITELIST USER_FILEPROP_FILES_DIRS WRITEWHITELIST'
  210. + echo ALLOWDEVFILE ALLOWHIDDENDIR ALLOWHIDDENFILE ALLOWPROCDELFILE ALLOWPROCLISTEN ATTRWHITELIST EXCLUDE_USER_FILEPROP_FILES_DIRS EXISTWHITELIST IMMUTWHITELIST PKGMGR_NO_VRFY PORT_PATH_WHITELIST RTKT_DIR_WHITELIST RTKT_FILE_WHITELIST SCRIPTWHITELIST USER_FILEPROP_FILES_DIRS WRITEWHITELIST
  211. + NEWLINE_LIST_OPTS=' ALLOWDEVFILE ALLOWHIDDENDIR ALLOWHIDDENFILE ALLOWPROCDELFILE ALLOWPROCLISTEN ATTRWHITELIST EXCLUDE_USER_FILEPROP_FILES_DIRS EXISTWHITELIST IMMUTWHITELIST PKGMGR_NO_VRFY PORT_PATH_WHITELIST RTKT_DIR_WHITELIST RTKT_FILE_WHITELIST SCRIPTWHITELIST USER_FILEPROP_FILES_DIRS WRITEWHITELIST '
  212. + ENABLE_TESTS=''
  213. + DISABLE_TESTS=''
  214. + CL_ENABLE_TESTS=''
  215. + CL_DISABLE_TESTS=''
  216. + CONFIG_DISABLE_TESTS=''
  217. + ENDIS_OPT=0
  218. + ENABLE_OPT=0
  219. + USECF=1
  220. + LIST_OPT=''
  221. + BLANK_LINE=' '
  222. + NOTTY=0
  223. + SHOW_SUMMARY=1
  224. + SHOW_SUMMARY_OPT=0
  225. + SHOW_SUMMARY_TIME=3
  226. + SHOW_SUMMARY_WARNINGS_NUMBER=0
  227. + VERBOSE_LOGGING=1
  228. + ORIGIFS='
  229. '
  230. + RKHIFS='
  231. '
  232. + IFSNL='
  233. '
  234. + IFS='
  235. '
  236. + STARTUP_PATHS=''
  237. + STARTUP_PATHS_LOGGED=0
  238. + INETD_CONF_PATH=/etc/inetd.conf
  239. + INETDALLOWEDSVCS=''
  240. + XINETD_CONF_PATH=/etc/xinetd.conf
  241. + XINETDALLOWEDSVCS=''
  242. + UPDATE_ONLY=0
  243. + RKHLANGUPDT=0
  244. + ROTATE_MIRRORS=1
  245. + UPDATE_MIRRORS=1
  246. + MIRRORS_MODE=0
  247. + SUSPSCAN_DEBUG=0
  248. + USE_RUNCON=0
  249. + SELINUX_ENABLED=0
  250. + PORT_WHITELIST=''
  251. + PORT_PATH_WHITELIST=''
  252. + PORT_WHITELIST_ALL_TRUSTED=0
  253. + SHADOW_FILE=''
  254. + HAVE_TCB_SHADOW=0
  255. + OS_VERSION_FILE=''
  256. + RTKT_DIR_WHITELIST=''
  257. + RTKT_FILE_WHITELIST=''
  258. + RKHDAT_FILE=''
  259. + RKH_FILEPROP_LIST=''
  260. + HAVE_READLINK=0
  261. + PRELINK_DEP_ERR_CMDS=''
  262. + USER_FILE_LIST=''
  263. + USER_SIMPLE_FILE_LIST=''
  264. + USER_DIR_LIST=''
  265. + USER_EXCLUDE_PROP=''
  266. + SHARED_LIB_WHITELIST=''
  267. + USE_LOCKING=0
  268. + LOCK_TIMEOUT=0
  269. + SHOW_LOCK_MSGS=1
  270. + UNLOCK=0
  271. + EXISTWHITELIST=''
  272. + CONFIG_CHECK=0
  273. + IFWLIST=''
  274. + ALLOWPROCLIST_OPT=''
  275. + [ 4 -eq 0 ]
  276. + [ 4 -ge 1 ]
  277. + RKHTMPVAR=filesystem
  278. + shift
  279. + CHECK=1
  280. + ENDIS_OPT=1
  281. + ENABLE_OPT=1
  282. + CL_ENABLE_TESTS=' filesystem'
  283. + [ -z filesystem ]
  284. + shift
  285. + [ 2 -ge 1 ]
  286. + CHECK=1
  287. + shift
  288. + [ 1 -ge 1 ]
  289. + SKIP_KEY_PRESS=1
  290. + shift
  291. + [ 0 -ge 1 ]
  292. + [ 0 -eq 1 ]
  293. + id -u
  294. + RKHTMPVAR=0
  295. + [ -z 0 ]
  296. + [ -z 0 ]
  297. + [ 0 != 0 -a 0 != root ]
  298. + [ 1 -eq 1 ]
  299. + echo filesystem
  300. + CL_ENABLE_TESTS=filesystem
  301. + echo
  302. + CL_DISABLE_TESTS=''
  303. + test -z ''
  304. + USECF=1
  305. + test 0 -eq 1 -a 1 -eq 0 -a 0 -eq 0 -a 0 -eq 0
  306. + check_required_commands 1
  307. + LEAVE=0
  308. + [ 1 -eq 1 ]
  309. + CMDDIR='/sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin /home/mike/bin'
  310. + CMDNAMES='cut egrep grep sed tail tr'
  311. + SEEN=0
  312. + [ -f /sbin/cut -a -x /sbin/cut ]
  313. + [ -f /bin/cut -a -x /bin/cut ]
  314. + [ -f /usr/sbin/cut -a -x /usr/sbin/cut ]
  315. + [ -f /usr/bin/cut -a -x /usr/bin/cut ]
  316. + SEEN=1
  317. + break
  318. + [ 1 -eq 0 ]
  319. + SEEN=0
  320. + [ -f /sbin/egrep -a -x /sbin/egrep ]
  321. + [ -f /bin/egrep -a -x /bin/egrep ]
  322. + [ -f /usr/sbin/egrep -a -x /usr/sbin/egrep ]
  323. + [ -f /usr/bin/egrep -a -x /usr/bin/egrep ]
  324. + SEEN=1
  325. + break
  326. + [ 1 -eq 0 ]
  327. + SEEN=0
  328. + [ -f /sbin/grep -a -x /sbin/grep ]
  329. + [ -f /bin/grep -a -x /bin/grep ]
  330. + [ -f /usr/sbin/grep -a -x /usr/sbin/grep ]
  331. + [ -f /usr/bin/grep -a -x /usr/bin/grep ]
  332. + SEEN=1
  333. + break
  334. + [ 1 -eq 0 ]
  335. + SEEN=0
  336. + [ -f /sbin/sed -a -x /sbin/sed ]
  337. + [ -f /bin/sed -a -x /bin/sed ]
  338. + [ -f /usr/sbin/sed -a -x /usr/sbin/sed ]
  339. + [ -f /usr/bin/sed -a -x /usr/bin/sed ]
  340. + SEEN=1
  341. + break
  342. + [ 1 -eq 0 ]
  343. + SEEN=0
  344. + [ -f /sbin/tail -a -x /sbin/tail ]
  345. + [ -f /bin/tail -a -x /bin/tail ]
  346. + [ -f /usr/sbin/tail -a -x /usr/sbin/tail ]
  347. + [ -f /usr/bin/tail -a -x /usr/bin/tail ]
  348. + SEEN=1
  349. + break
  350. + [ 1 -eq 0 ]
  351. + SEEN=0
  352. + [ -f /sbin/tr -a -x /sbin/tr ]
  353. + [ -f /bin/tr -a -x /bin/tr ]
  354. + [ -f /usr/sbin/tr -a -x /usr/sbin/tr ]
  355. + [ -f /usr/bin/tr -a -x /usr/bin/tr ]
  356. + SEEN=1
  357. + break
  358. + [ 1 -eq 0 ]
  359. + [ 0 -eq 1 ]
  360. + return
  361. + [ -z '' ]
  362. + [ -f /usr/local/etc/rkhunter.conf ]
  363. + CONFIGFILE=/usr/local/etc/rkhunter.conf
  364. + [ ! -f /usr/local/etc/rkhunter.conf ]
  365. + [ ! -r /usr/local/etc/rkhunter.conf ]
  366. + [ ! -s /usr/local/etc/rkhunter.conf ]
  367. + echo /usr/local/etc/rkhunter.conf
  368. + sed -e 's:/[^/]*$::'
  369. + RKHTMPVAR=/usr/local/etc
  370. + test -f /usr/local/etc/rkhunter.conf.local -a ! -h /usr/local/etc/rkhunter.conf.local -a -r /usr/local/etc/rkhunter.conf.local
  371. + [ -d /usr/local/etc/rkhunter.d ]
  372. + get_configfile_options
  373. + get_bindir_option
  374. + LEAVE=0
  375. + [ 0 -eq 1 ]
  376. + get_option space-list BINDIR
  377. + OPTMULTI=space-list
  378. + OPTNAME=BINDIR
  379. + ERRCODE=0
  380. + [ -z space-list -o -z BINDIR ]
  381. + grep -h ^BINDIR= /usr/local/etc/rkhunter.conf
  382. + RKHTMPVAR2=''
  383. + [ -z '' ]
  384. + echo ''
  385. + return 0
  386. + BINPATHS=''
  387. + [ 0 -eq 0 ]
  388. + [ -z '' ]
  389. + BINPATHS='/bin /usr/bin /sbin /usr/sbin /usr/local/bin /usr/local/sbin /usr/libexec /usr/local/libexec'
  390. + [ 0 -eq 1 -o 0 -eq 1 -o FreeBSD = AIX ]
  391. + add_extra_dirs
  392. + EXTRA_DIRS=''
  393. + [ 0 -eq 1 ]
  394. + [ 1 -eq 1 ]
  395. + test -d /usr/pkg
  396. + test -d /opt
  397. + test -d /usr/opt
  398. + return
  399. + BINPATHS='/bin /usr/bin /sbin /usr/sbin /usr/local/bin /usr/local/sbin /usr/libexec /usr/local/libexec'
  400. + [ 0 -eq 0 ]
  401. + RKHTMPVAR=''
  402. + PREPEND_PATHS=''
  403. + echo /bin
  404. + grep '^\+'
  405. + [ -n '' ]
  406. + echo /usr/bin
  407. + grep '^\+'
  408. + [ -n '' ]
  409. + echo /sbin
  410. + grep '^\+'
  411. + [ -n '' ]
  412. + grep '^\+'
  413. + echo /usr/sbin
  414. + [ -n '' ]
  415. + grep '^\+'
  416. + echo /usr/local/bin
  417. + [ -n '' ]
  418. + echo /usr/local/sbin
  419. + grep '^\+'
  420. + [ -n '' ]
  421. + echo /usr/libexec
  422. + grep '^\+'
  423. + [ -n '' ]
  424. + echo /usr/local/libexec
  425. + grep '^\+'
  426. + [ -n '' ]
  427. + echo
  428. + PREPEND_PATHS=''
  429. + grep '^\+'
  430. + echo /sbin
  431. + [ -n '' ]
  432. + grep ^/
  433. + echo /sbin
  434. + [ -z /sbin ]
  435. + [ -e /sbin ]
  436. + [ -d /sbin ]
  437. + test -h /sbin
  438. + echo /sbin
  439. + sed -e 's:/$::'
  440. + tr -s /
  441. + DIR=/sbin
  442. + echo ' '
  443. + grep ' /sbin '
  444. + [ -z '' ]
  445. + RKHTMPVAR=' /sbin'
  446. + grep '^\+'
  447. + echo /bin
  448. + [ -n '' ]
  449. + grep ^/
  450. + echo /bin
  451. + [ -z /bin ]
  452. + [ -e /bin ]
  453. + [ -d /bin ]
  454. + test -h /bin
  455. + echo /bin
  456. + sed -e 's:/$::'
  457. + tr -s /
  458. + DIR=/bin
  459. + echo ' /sbin '
  460. + grep ' /bin '
  461. + [ -z '' ]
  462. + RKHTMPVAR=' /sbin /bin'
  463. + grep '^\+'
  464. + echo /usr/sbin
  465. + [ -n '' ]
  466. + grep ^/
  467. + echo /usr/sbin
  468. + [ -z /usr/sbin ]
  469. + [ -e /usr/sbin ]
  470. + [ -d /usr/sbin ]
  471. + test -h /usr/sbin
  472. + echo /usr/sbin
  473. + tr -s /
  474. + sed -e 's:/$::'
  475. + DIR=/usr/sbin
  476. + echo ' /sbin /bin '
  477. + grep ' /usr/sbin '
  478. + [ -z '' ]
  479. + RKHTMPVAR=' /sbin /bin /usr/sbin'
  480. + grep '^\+'
  481. + echo /usr/bin
  482. + [ -n '' ]
  483. + echo /usr/bin
  484. + grep ^/
  485. + [ -z /usr/bin ]
  486. + [ -e /usr/bin ]
  487. + [ -d /usr/bin ]
  488. + test -h /usr/bin
  489. + echo /usr/bin
  490. + sed -e 's:/$::'
  491. + tr -s /
  492. + DIR=/usr/bin
  493. + echo ' /sbin /bin /usr/sbin '
  494. + grep ' /usr/bin '
  495. + [ -z '' ]
  496. + RKHTMPVAR=' /sbin /bin /usr/sbin /usr/bin'
  497. + echo /usr/games
  498. + grep '^\+'
  499. + [ -n '' ]
  500. + echo /usr/games
  501. + grep ^/
  502. + [ -z /usr/games ]
  503. + [ -e /usr/games ]
  504. + [ -d /usr/games ]
  505. + test -h /usr/games
  506. + tr -s /
  507. + sed -e 's:/$::'
  508. + echo /usr/games
  509. + DIR=/usr/games
  510. + grep ' /usr/games '
  511. + echo ' /sbin /bin /usr/sbin /usr/bin '
  512. + [ -z '' ]
  513. + RKHTMPVAR=' /sbin /bin /usr/sbin /usr/bin /usr/games'
  514. + echo /usr/local/sbin
  515. + grep '^\+'
  516. + [ -n '' ]
  517. + echo /usr/local/sbin
  518. + grep ^/
  519. + [ -z /usr/local/sbin ]
  520. + [ -e /usr/local/sbin ]
  521. + [ -d /usr/local/sbin ]
  522. + test -h /usr/local/sbin
  523. + tr -s /
  524. + sed -e 's:/$::'
  525. + echo /usr/local/sbin
  526. + DIR=/usr/local/sbin
  527. + echo ' /sbin /bin /usr/sbin /usr/bin /usr/games '
  528. + grep ' /usr/local/sbin '
  529. + [ -z '' ]
  530. + RKHTMPVAR=' /sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin'
  531. + echo /usr/local/bin
  532. + grep '^\+'
  533. + [ -n '' ]
  534. + echo /usr/local/bin
  535. + grep ^/
  536. + [ -z /usr/local/bin ]
  537. + [ -e /usr/local/bin ]
  538. + [ -d /usr/local/bin ]
  539. + test -h /usr/local/bin
  540. + tr -s /
  541. + sed -e 's:/$::'
  542. + echo /usr/local/bin
  543. + DIR=/usr/local/bin
  544. + echo ' /sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin '
  545. + grep ' /usr/local/bin '
  546. + [ -z '' ]
  547. + RKHTMPVAR=' /sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin'
  548. + echo /home/mike/bin
  549. + grep '^\+'
  550. + [ -n '' ]
  551. + echo /home/mike/bin
  552. + grep ^/
  553. + [ -z /home/mike/bin ]
  554. + [ -e /home/mike/bin ]
  555. + grep '^\+'
  556. + echo /bin
  557. + [ -n '' ]
  558. + echo /bin
  559. + grep ^/
  560. + [ -z /bin ]
  561. + [ -e /bin ]
  562. + [ -d /bin ]
  563. + test -h /bin
  564. + echo /bin
  565. + sed -e 's:/$::'
  566. + tr -s /
  567. + DIR=/bin
  568. + grep ' /bin '
  569. + echo ' /sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin '
  570. + [ -z ' /sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin ' ]
  571. + grep '^\+'
  572. + echo /usr/bin
  573. + [ -n '' ]
  574. + echo /usr/bin
  575. + grep ^/
  576. + [ -z /usr/bin ]
  577. + [ -e /usr/bin ]
  578. + [ -d /usr/bin ]
  579. + test -h /usr/bin
  580. + echo /usr/bin
  581. + sed -e 's:/$::'
  582. + tr -s /
  583. + DIR=/usr/bin
  584. + grep ' /usr/bin '
  585. + echo ' /sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin '
  586. + [ -z ' /sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin ' ]
  587. + echo /sbin
  588. + grep '^\+'
  589. + [ -n '' ]
  590. + echo /sbin
  591. + grep ^/
  592. + [ -z /sbin ]
  593. + [ -e /sbin ]
  594. + [ -d /sbin ]
  595. + test -h /sbin
  596. + tr -s /
  597. + sed -e 's:/$::'
  598. + echo /sbin
  599. + DIR=/sbin
  600. + grep ' /sbin '
  601. + echo ' /sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin '
  602. + [ -z ' /sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin ' ]
  603. + echo /usr/sbin
  604. + grep '^\+'
  605. + [ -n '' ]
  606. + echo /usr/sbin
  607. + grep ^/
  608. + [ -z /usr/sbin ]
  609. + [ -e /usr/sbin ]
  610. + [ -d /usr/sbin ]
  611. + test -h /usr/sbin
  612. + tr -s /
  613. + sed -e 's:/$::'
  614. + echo /usr/sbin
  615. + DIR=/usr/sbin
  616. + echo ' /sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin '
  617. + grep ' /usr/sbin '
  618. + [ -z ' /sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin ' ]
  619. + echo /usr/local/bin
  620. + grep '^\+'
  621. + [ -n '' ]
  622. + echo /usr/local/bin
  623. + grep ^/
  624. + [ -z /usr/local/bin ]
  625. + [ -e /usr/local/bin ]
  626. + [ -d /usr/local/bin ]
  627. + test -h /usr/local/bin
  628. + tr -s /
  629. + sed -e 's:/$::'
  630. + echo /usr/local/bin
  631. + DIR=/usr/local/bin
  632. + echo ' /sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin '
  633. + grep ' /usr/local/bin '
  634. + [ -z ' /sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin ' ]
  635. + echo /usr/local/sbin
  636. + grep '^\+'
  637. + [ -n '' ]
  638. + grep ^/
  639. + echo /usr/local/sbin
  640. + [ -z /usr/local/sbin ]
  641. + [ -e /usr/local/sbin ]
  642. + [ -d /usr/local/sbin ]
  643. + test -h /usr/local/sbin
  644. + echo /usr/local/sbin
  645. + tr -s /
  646. + sed -e 's:/$::'
  647. + DIR=/usr/local/sbin
  648. + echo ' /sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin '
  649. + grep ' /usr/local/sbin '
  650. + [ -z ' /sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin ' ]
  651. + echo /usr/libexec
  652. + grep '^\+'
  653. + [ -n '' ]
  654. + echo /usr/libexec
  655. + grep ^/
  656. + [ -z /usr/libexec ]
  657. + [ -e /usr/libexec ]
  658. + [ -d /usr/libexec ]
  659. + test -h /usr/libexec
  660. + echo /usr/libexec
  661. + tr -s /
  662. + sed -e 's:/$::'
  663. + DIR=/usr/libexec
  664. + echo ' /sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin '
  665. + grep ' /usr/libexec '
  666. + [ -z '' ]
  667. + RKHTMPVAR=' /sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin /usr/libexec'
  668. + echo /usr/local/libexec
  669. + grep '^\+'
  670. + [ -n '' ]
  671. + grep ^/
  672. + echo /usr/local/libexec
  673. + [ -z /usr/local/libexec ]
  674. + [ -e /usr/local/libexec ]
  675. + [ -d /usr/local/libexec ]
  676. + test -h /usr/local/libexec
  677. + echo /usr/local/libexec
  678. + tr -s /
  679. + sed -e 's:/$::'
  680. + DIR=/usr/local/libexec
  681. + echo ' /sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin /usr/libexec '
  682. + grep ' /usr/local/libexec '
  683. + [ -z '' ]
  684. + RKHTMPVAR=' /sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin /usr/libexec /usr/local/libexec'
  685. + [ 0 -eq 0 ]
  686. + echo /sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin /usr/libexec /usr/local/libexec
  687. + BINPATHS='/sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin /usr/libexec /usr/local/libexec'
  688. + test 0 -eq 1
  689. + RKHTMPVAR=BINDIR
  690. + check_paths BINPATHS BINDIR NOWILD
  691. + OPT_VALUE_OPT=BINPATHS
  692. + OPT_NAME=BINDIR
  693. + STRICT=NOWILD
  694. + test -z BINDIR
  695. + eval echo '"$BINPATHS"'
  696. + echo '/sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin /usr/libexec /usr/local/libexec'
  697. + OPT_VALUE='/sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin /usr/libexec /usr/local/libexec'
  698. + ERRCODE=0
  699. + test -z '/sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin /usr/libexec /usr/local/libexec'
  700. + MUSTEXIST=0
  701. + NOWILD=0
  702. + NOLINK=0
  703. + NOWILD=1
  704. + grep ^-
  705. + echo '/sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin /usr/libexec /usr/local/libexec '
  706. + RKHTMPVAR=''
  707. + [ -n '' ]
  708. + [ 1 -eq 1 ]
  709. + egrep '(^|[^\])[][?*{}]'
  710. + echo '/sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin /usr/libexec /usr/local/libexec'
  711. + RKHTMPVAR=''
  712. + [ -n '' ]
  713. + echo ' ALLOWDEVFILE ALLOWHIDDENDIR ALLOWHIDDENFILE ALLOWPROCDELFILE ALLOWPROCLISTEN ATTRWHITELIST EXCLUDE_USER_FILEPROP_FILES_DIRS EXISTWHITELIST IMMUTWHITELIST PKGMGR_NO_VRFY PORT_PATH_WHITELIST RTKT_DIR_WHITELIST RTKT_FILE_WHITELIST SCRIPTWHITELIST USER_FILEPROP_FILES_DIRS WRITEWHITELIST '
  714. + grep ' BINDIR '
  715. + [ -n '' ]
  716. + test -z /sbin
  717. + echo /sbin
  718. + egrep '(^[./]*$)|[;&]|/\.\./'
  719. + [ -n '' ]
  720. + grep '^[^/].*/'
  721. + echo /sbin
  722. + [ -n '' ]
  723. + grep ^/
  724. + echo /sbin
  725. + [ -z /sbin ]
  726. + [ -f /sbin ]
  727. + [ -d /sbin ]
  728. + test BINDIR = ALLOWHIDDENFILE -a -h /sbin
  729. + test -z /bin
  730. + echo /bin
  731. + egrep '(^[./]*$)|[;&]|/\.\./'
  732. + [ -n '' ]
  733. + echo /bin
  734. + grep '^[^/].*/'
  735. + [ -n '' ]
  736. + grep ^/
  737. + echo /bin
  738. + [ -z /bin ]
  739. + [ -f /bin ]
  740. + [ -d /bin ]
  741. + test BINDIR = ALLOWHIDDENFILE -a -h /bin
  742. + test -z /usr/sbin
  743. + egrep '(^[./]*$)|[;&]|/\.\./'
  744. + echo /usr/sbin
  745. + [ -n '' ]
  746. + echo /usr/sbin
  747. + grep '^[^/].*/'
  748. + [ -n '' ]
  749. + echo /usr/sbin
  750. + grep ^/
  751. + [ -z /usr/sbin ]
  752. + [ -f /usr/sbin ]
  753. + [ -d /usr/sbin ]
  754. + test BINDIR = ALLOWHIDDENFILE -a -h /usr/sbin
  755. + test -z /usr/bin
  756. + egrep '(^[./]*$)|[;&]|/\.\./'
  757. + echo /usr/bin
  758. + [ -n '' ]
  759. + echo /usr/bin
  760. + grep '^[^/].*/'
  761. + [ -n '' ]
  762. + echo /usr/bin
  763. + grep ^/
  764. + [ -z /usr/bin ]
  765. + [ -f /usr/bin ]
  766. + [ -d /usr/bin ]
  767. + test BINDIR = ALLOWHIDDENFILE -a -h /usr/bin
  768. + test -z /usr/games
  769. + echo /usr/games
  770. + egrep '(^[./]*$)|[;&]|/\.\./'
  771. + [ -n '' ]
  772. + grep '^[^/].*/'
  773. + echo /usr/games
  774. + [ -n '' ]
  775. + echo /usr/games
  776. + grep ^/
  777. + [ -z /usr/games ]
  778. + [ -f /usr/games ]
  779. + [ -d /usr/games ]
  780. + test BINDIR = ALLOWHIDDENFILE -a -h /usr/games
  781. + test -z /usr/local/sbin
  782. + echo /usr/local/sbin
  783. + egrep '(^[./]*$)|[;&]|/\.\./'
  784. + [ -n '' ]
  785. + grep '^[^/].*/'
  786. + echo /usr/local/sbin
  787. + [ -n '' ]
  788. + grep ^/
  789. + echo /usr/local/sbin
  790. + [ -z /usr/local/sbin ]
  791. + [ -f /usr/local/sbin ]
  792. + [ -d /usr/local/sbin ]
  793. + test BINDIR = ALLOWHIDDENFILE -a -h /usr/local/sbin
  794. + test -z /usr/local/bin
  795. + echo /usr/local/bin
  796. + egrep '(^[./]*$)|[;&]|/\.\./'
  797. + [ -n '' ]
  798. + echo /usr/local/bin
  799. + grep '^[^/].*/'
  800. + [ -n '' ]
  801. + grep ^/
  802. + echo /usr/local/bin
  803. + [ -z /usr/local/bin ]
  804. + [ -f /usr/local/bin ]
  805. + [ -d /usr/local/bin ]
  806. + test BINDIR = ALLOWHIDDENFILE -a -h /usr/local/bin
  807. + test -z /usr/libexec
  808. + egrep '(^[./]*$)|[;&]|/\.\./'
  809. + echo /usr/libexec
  810. + [ -n '' ]
  811. + echo /usr/libexec
  812. + grep '^[^/].*/'
  813. + [ -n '' ]
  814. + echo /usr/libexec
  815. + grep ^/
  816. + [ -z /usr/libexec ]
  817. + [ -f /usr/libexec ]
  818. + [ -d /usr/libexec ]
  819. + test BINDIR = ALLOWHIDDENFILE -a -h /usr/libexec
  820. + test -z /usr/local/libexec
  821. + egrep '(^[./]*$)|[;&]|/\.\./'
  822. + echo /usr/local/libexec
  823. + [ -n '' ]
  824. + echo /usr/local/libexec
  825. + grep '^[^/].*/'
  826. + [ -n '' ]
  827. + echo /usr/local/libexec
  828. + grep ^/
  829. + [ -z /usr/local/libexec ]
  830. + [ -f /usr/local/libexec ]
  831. + [ -d /usr/local/libexec ]
  832. + test BINDIR = ALLOWHIDDENFILE -a -h /usr/local/libexec
  833. + IFS='
  834. '
  835. + return
  836. + test 0 -eq 1
  837. + [ 0 -eq 1 ]
  838. + return
  839. + get_scriptdir_option
  840. + LEAVE=0
  841. + get_option single SCRIPTDIR
  842. + OPTMULTI=single
  843. + OPTNAME=SCRIPTDIR
  844. + ERRCODE=0
  845. + [ -z single -o -z SCRIPTDIR ]
  846. + grep -h ^SCRIPTDIR= /usr/local/etc/rkhunter.conf
  847. + RKHTMPVAR2=SCRIPTDIR=/usr/local/lib/rkhunter/scripts
  848. + [ -z SCRIPTDIR=/usr/local/lib/rkhunter/scripts ]
  849. + tail -n 1
  850. + sed -e s/SCRIPTDIR=//
  851. + echo SCRIPTDIR=/usr/local/lib/rkhunter/scripts
  852. + OPTVAR=/usr/local/lib/rkhunter/scripts
  853. + [ -z /usr/local/lib/rkhunter/scripts -o /usr/local/lib/rkhunter/scripts = '""' -o /usr/local/lib/rkhunter/scripts = \'\' ]
  854. + echo /usr/local/lib/rkhunter/scripts
  855. + tr -d \'
  856. + tr -d '" '
  857. + OPTVAR=/usr/local/lib/rkhunter/scripts
  858. + echo /usr/local/lib/rkhunter/scripts
  859. + return 0
  860. + SCRIPT_PATH=/usr/local/lib/rkhunter/scripts
  861. + [ 0 -eq 0 ]
  862. + check_paths SCRIPT_PATH SCRIPTDIR 'NOWILD EXIST NOBROKENLINK'
  863. + OPT_VALUE_OPT=SCRIPT_PATH
  864. + OPT_NAME=SCRIPTDIR
  865. + STRICT='NOWILD EXIST NOBROKENLINK'
  866. + test -z SCRIPTDIR
  867. + eval echo '"$SCRIPT_PATH"'
  868. + echo /usr/local/lib/rkhunter/scripts
  869. + OPT_VALUE=/usr/local/lib/rkhunter/scripts
  870. + ERRCODE=0
  871. + test -z /usr/local/lib/rkhunter/scripts
  872. + MUSTEXIST=0
  873. + NOWILD=0
  874. + NOLINK=0
  875. + NOWILD=1
  876. + MUSTEXIST=1
  877. + NOLINK=1
  878. + grep ^-
  879. + echo '/usr/local/lib/rkhunter/scripts '
  880. + RKHTMPVAR=''
  881. + [ -n '' ]
  882. + [ 1 -eq 1 ]
  883. + echo /usr/local/lib/rkhunter/scripts
  884. + egrep '(^|[^\])[][?*{}]'
  885. + RKHTMPVAR=''
  886. + [ -n '' ]
  887. + echo ' ALLOWDEVFILE ALLOWHIDDENDIR ALLOWHIDDENFILE ALLOWPROCDELFILE ALLOWPROCLISTEN ATTRWHITELIST EXCLUDE_USER_FILEPROP_FILES_DIRS EXISTWHITELIST IMMUTWHITELIST PKGMGR_NO_VRFY PORT_PATH_WHITELIST RTKT_DIR_WHITELIST RTKT_FILE_WHITELIST SCRIPTWHITELIST USER_FILEPROP_FILES_DIRS WRITEWHITELIST '
  888. + grep ' SCRIPTDIR '
  889. + [ -n '' ]
  890. + test -z /usr/local/lib/rkhunter/scripts
  891. + egrep '(^[./]*$)|[;&]|/\.\./'
  892. + echo /usr/local/lib/rkhunter/scripts
  893. + [ -n '' ]
  894. + grep '^[^/].*/'
  895. + echo /usr/local/lib/rkhunter/scripts
  896. + [ -n '' ]
  897. + echo /usr/local/lib/rkhunter/scripts
  898. + grep ^/
  899. + [ -z /usr/local/lib/rkhunter/scripts ]
  900. + [ -f /usr/local/lib/rkhunter/scripts ]
  901. + [ -d /usr/local/lib/rkhunter/scripts ]
  902. + test SCRIPTDIR = ALLOWHIDDENFILE -a -h /usr/local/lib/rkhunter/scripts
  903. + IFS='
  904. '
  905. + return
  906. + [ 0 -eq 0 ]
  907. + [ -z /usr/local/lib/rkhunter/scripts ]
  908. + [ 0 -eq 1 ]
  909. + [ ! -r /usr/local/lib/rkhunter/scripts ]
  910. + [ 0 -eq 1 ]
  911. + return
  912. + check_required_commands 2
  913. + LEAVE=0
  914. + [ 2 -eq 1 ]
  915. + CMDDIR='/sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin /usr/libexec /usr/local/libexec'
  916. + CMDNAMES='awk cat chmod chown cp cut date egrep grep head ls mv sed sort tail touch tr uname uniq wc'
  917. + SEEN=0
  918. + [ -f /sbin/awk -a -x /sbin/awk ]
  919. + [ -f /bin/awk -a -x /bin/awk ]
  920. + [ -f /usr/sbin/awk -a -x /usr/sbin/awk ]
  921. + [ -f /usr/bin/awk -a -x /usr/bin/awk ]
  922. + SEEN=1
  923. + break
  924. + [ 1 -eq 0 ]
  925. + SEEN=0
  926. + [ -f /sbin/cat -a -x /sbin/cat ]
  927. + [ -f /bin/cat -a -x /bin/cat ]
  928. + SEEN=1
  929. + break
  930. + [ 1 -eq 0 ]
  931. + SEEN=0
  932. + [ -f /sbin/chmod -a -x /sbin/chmod ]
  933. + [ -f /bin/chmod -a -x /bin/chmod ]
  934. + SEEN=1
  935. + break
  936. + [ 1 -eq 0 ]
  937. + SEEN=0
  938. + [ -f /sbin/chown -a -x /sbin/chown ]
  939. + [ -f /bin/chown -a -x /bin/chown ]
  940. + [ -f /usr/sbin/chown -a -x /usr/sbin/chown ]
  941. + SEEN=1
  942. + break
  943. + [ 1 -eq 0 ]
  944. + SEEN=0
  945. + [ -f /sbin/cp -a -x /sbin/cp ]
  946. + [ -f /bin/cp -a -x /bin/cp ]
  947. + SEEN=1
  948. + break
  949. + [ 1 -eq 0 ]
  950. + SEEN=0
  951. + [ -f /sbin/cut -a -x /sbin/cut ]
  952. + [ -f /bin/cut -a -x /bin/cut ]
  953. + [ -f /usr/sbin/cut -a -x /usr/sbin/cut ]
  954. + [ -f /usr/bin/cut -a -x /usr/bin/cut ]
  955. + SEEN=1
  956. + break
  957. + [ 1 -eq 0 ]
  958. + SEEN=0
  959. + [ -f /sbin/date -a -x /sbin/date ]
  960. + [ -f /bin/date -a -x /bin/date ]
  961. + SEEN=1
  962. + break
  963. + [ 1 -eq 0 ]
  964. + SEEN=0
  965. + [ -f /sbin/egrep -a -x /sbin/egrep ]
  966. + [ -f /bin/egrep -a -x /bin/egrep ]
  967. + [ -f /usr/sbin/egrep -a -x /usr/sbin/egrep ]
  968. + [ -f /usr/bin/egrep -a -x /usr/bin/egrep ]
  969. + SEEN=1
  970. + break
  971. + [ 1 -eq 0 ]
  972. + SEEN=0
  973. + [ -f /sbin/grep -a -x /sbin/grep ]
  974. + [ -f /bin/grep -a -x /bin/grep ]
  975. + [ -f /usr/sbin/grep -a -x /usr/sbin/grep ]
  976. + [ -f /usr/bin/grep -a -x /usr/bin/grep ]
  977. + SEEN=1
  978. + break
  979. + [ 1 -eq 0 ]
  980. + SEEN=0
  981. + [ -f /sbin/head -a -x /sbin/head ]
  982. + [ -f /bin/head -a -x /bin/head ]
  983. + [ -f /usr/sbin/head -a -x /usr/sbin/head ]
  984. + [ -f /usr/bin/head -a -x /usr/bin/head ]
  985. + SEEN=1
  986. + break
  987. + [ 1 -eq 0 ]
  988. + SEEN=0
  989. + [ -f /sbin/ls -a -x /sbin/ls ]
  990. + [ -f /bin/ls -a -x /bin/ls ]
  991. + SEEN=1
  992. + break
  993. + [ 1 -eq 0 ]
  994. + SEEN=0
  995. + [ -f /sbin/mv -a -x /sbin/mv ]
  996. + [ -f /bin/mv -a -x /bin/mv ]
  997. + SEEN=1
  998. + break
  999. + [ 1 -eq 0 ]
  1000. + SEEN=0
  1001. + [ -f /sbin/sed -a -x /sbin/sed ]
  1002. + [ -f /bin/sed -a -x /bin/sed ]
  1003. + [ -f /usr/sbin/sed -a -x /usr/sbin/sed ]
  1004. + [ -f /usr/bin/sed -a -x /usr/bin/sed ]
  1005. + SEEN=1
  1006. + break
  1007. + [ 1 -eq 0 ]
  1008. + SEEN=0
  1009. + [ -f /sbin/sort -a -x /sbin/sort ]
  1010. + [ -f /bin/sort -a -x /bin/sort ]
  1011. + [ -f /usr/sbin/sort -a -x /usr/sbin/sort ]
  1012. + [ -f /usr/bin/sort -a -x /usr/bin/sort ]
  1013. + SEEN=1
  1014. + break
  1015. + [ 1 -eq 0 ]
  1016. + SEEN=0
  1017. + [ -f /sbin/tail -a -x /sbin/tail ]
  1018. + [ -f /bin/tail -a -x /bin/tail ]
  1019. + [ -f /usr/sbin/tail -a -x /usr/sbin/tail ]
  1020. + [ -f /usr/bin/tail -a -x /usr/bin/tail ]
  1021. + SEEN=1
  1022. + break
  1023. + [ 1 -eq 0 ]
  1024. + SEEN=0
  1025. + [ -f /sbin/touch -a -x /sbin/touch ]
  1026. + [ -f /bin/touch -a -x /bin/touch ]
  1027. + [ -f /usr/sbin/touch -a -x /usr/sbin/touch ]
  1028. + [ -f /usr/bin/touch -a -x /usr/bin/touch ]
  1029. + SEEN=1
  1030. + break
  1031. + [ 1 -eq 0 ]
  1032. + SEEN=0
  1033. + [ -f /sbin/tr -a -x /sbin/tr ]
  1034. + [ -f /bin/tr -a -x /bin/tr ]
  1035. + [ -f /usr/sbin/tr -a -x /usr/sbin/tr ]
  1036. + [ -f /usr/bin/tr -a -x /usr/bin/tr ]
  1037. + SEEN=1
  1038. + break
  1039. + [ 1 -eq 0 ]
  1040. + SEEN=0
  1041. + [ -f /sbin/uname -a -x /sbin/uname ]
  1042. + [ -f /bin/uname -a -x /bin/uname ]
  1043. + [ -f /usr/sbin/uname -a -x /usr/sbin/uname ]
  1044. + [ -f /usr/bin/uname -a -x /usr/bin/uname ]
  1045. + SEEN=1
  1046. + break
  1047. + [ 1 -eq 0 ]
  1048. + SEEN=0
  1049. + [ -f /sbin/uniq -a -x /sbin/uniq ]
  1050. + [ -f /bin/uniq -a -x /bin/uniq ]
  1051. + [ -f /usr/sbin/uniq -a -x /usr/sbin/uniq ]
  1052. + [ -f /usr/bin/uniq -a -x /usr/bin/uniq ]
  1053. + SEEN=1
  1054. + break
  1055. + [ 1 -eq 0 ]
  1056. + SEEN=0
  1057. + [ -f /sbin/wc -a -x /sbin/wc ]
  1058. + [ -f /bin/wc -a -x /bin/wc ]
  1059. + [ -f /usr/sbin/wc -a -x /usr/sbin/wc ]
  1060. + [ -f /usr/bin/wc -a -x /usr/bin/wc ]
  1061. + SEEN=1
  1062. + break
  1063. + [ 1 -eq 0 ]
  1064. + [ 0 -eq 1 ]
  1065. + return
  1066. + check_commands
  1067. + LEAVE=0
  1068. + echo basename
  1069. + tr '[:lower:]' '[:upper:]'
  1070. + CMDNAME=BASENAME
  1071. + CMDNAME=BASENAME_CMD
  1072. + get_option single BASENAME_CMD
  1073. + OPTMULTI=single
  1074. + OPTNAME=BASENAME_CMD
  1075. + ERRCODE=0
  1076. + [ -z single -o -z BASENAME_CMD ]
  1077. + grep -h ^BASENAME_CMD= /usr/local/etc/rkhunter.conf
  1078. + RKHTMPVAR2=''
  1079. + [ -z '' ]
  1080. + echo ''
  1081. + return 0
  1082. + CFG_CMD=''
  1083. + [ 0 -eq 0 ]
  1084. + [ -n '' ]
  1085. + test -z ''
  1086. + find_cmd basename
  1087. + CMD=basename
  1088. + test -z basename
  1089. + grep /
  1090. + echo basename
  1091. + [ -n '' ]
  1092. + [ -f /sbin/basename -a -x /sbin/basename ]
  1093. + [ -f /bin/basename -a -x /bin/basename ]
  1094. + [ -f /usr/sbin/basename -a -x /usr/sbin/basename ]
  1095. + [ -f /usr/bin/basename -a -x /usr/bin/basename ]
  1096. + echo /usr/bin/basename
  1097. + return
  1098. + eval BASENAME_CMD=/usr/bin/basename
  1099. + BASENAME_CMD=/usr/bin/basename
  1100. + echo diff
  1101. + tr '[:lower:]' '[:upper:]'
  1102. + CMDNAME=DIFF
  1103. + CMDNAME=DIFF_CMD
  1104. + get_option single DIFF_CMD
  1105. + OPTMULTI=single
  1106. + OPTNAME=DIFF_CMD
  1107. + ERRCODE=0
  1108. + [ -z single -o -z DIFF_CMD ]
  1109. + grep -h ^DIFF_CMD= /usr/local/etc/rkhunter.conf
  1110. + RKHTMPVAR2=''
  1111. + [ -z '' ]
  1112. + echo ''
  1113. + return 0
  1114. + CFG_CMD=''
  1115. + [ 0 -eq 0 ]
  1116. + [ -n '' ]
  1117. + test -z ''
  1118. + find_cmd diff
  1119. + CMD=diff
  1120. + test -z diff
  1121. + echo diff
  1122. + grep /
  1123. + [ -n '' ]
  1124. + [ -f /sbin/diff -a -x /sbin/diff ]
  1125. + [ -f /bin/diff -a -x /bin/diff ]
  1126. + [ -f /usr/sbin/diff -a -x /usr/sbin/diff ]
  1127. + [ -f /usr/bin/diff -a -x /usr/bin/diff ]
  1128. + echo /usr/bin/diff
  1129. + return
  1130. + eval DIFF_CMD=/usr/bin/diff
  1131. + DIFF_CMD=/usr/bin/diff
  1132. + echo dirname
  1133. + tr '[:lower:]' '[:upper:]'
  1134. + CMDNAME=DIRNAME
  1135. + CMDNAME=DIRNAME_CMD
  1136. + get_option single DIRNAME_CMD
  1137. + OPTMULTI=single
  1138. + OPTNAME=DIRNAME_CMD
  1139. + ERRCODE=0
  1140. + [ -z single -o -z DIRNAME_CMD ]
  1141. + grep -h ^DIRNAME_CMD= /usr/local/etc/rkhunter.conf
  1142. + RKHTMPVAR2=''
  1143. + [ -z '' ]
  1144. + echo ''
  1145. + return 0
  1146. + CFG_CMD=''
  1147. + [ 0 -eq 0 ]
  1148. + [ -n '' ]
  1149. + test -z ''
  1150. + find_cmd dirname
  1151. + CMD=dirname
  1152. + test -z dirname
  1153. + grep /
  1154. + echo dirname
  1155. + [ -n '' ]
  1156. + [ -f /sbin/dirname -a -x /sbin/dirname ]
  1157. + [ -f /bin/dirname -a -x /bin/dirname ]
  1158. + [ -f /usr/sbin/dirname -a -x /usr/sbin/dirname ]
  1159. + [ -f /usr/bin/dirname -a -x /usr/bin/dirname ]
  1160. + echo /usr/bin/dirname
  1161. + return
  1162. + eval DIRNAME_CMD=/usr/bin/dirname
  1163. + DIRNAME_CMD=/usr/bin/dirname
  1164. + echo file
  1165. + tr '[:lower:]' '[:upper:]'
  1166. + CMDNAME=FILE
  1167. + CMDNAME=FILE_CMD
  1168. + get_option single FILE_CMD
  1169. + OPTMULTI=single
  1170. + OPTNAME=FILE_CMD
  1171. + ERRCODE=0
  1172. + [ -z single -o -z FILE_CMD ]
  1173. + grep -h ^FILE_CMD= /usr/local/etc/rkhunter.conf
  1174. + RKHTMPVAR2=''
  1175. + [ -z '' ]
  1176. + echo ''
  1177. + return 0
  1178. + CFG_CMD=''
  1179. + [ 0 -eq 0 ]
  1180. + [ -n '' ]
  1181. + test -z ''
  1182. + find_cmd file
  1183. + CMD=file
  1184. + test -z file
  1185. + grep /
  1186. + echo file
  1187. + [ -n '' ]
  1188. + [ -f /sbin/file -a -x /sbin/file ]
  1189. + [ -f /bin/file -a -x /bin/file ]
  1190. + [ -f /usr/sbin/file -a -x /usr/sbin/file ]
  1191. + [ -f /usr/bin/file -a -x /usr/bin/file ]
  1192. + echo /usr/bin/file
  1193. + return
  1194. + eval FILE_CMD=/usr/bin/file
  1195. + FILE_CMD=/usr/bin/file
  1196. + echo find
  1197. + tr '[:lower:]' '[:upper:]'
  1198. + CMDNAME=FIND
  1199. + CMDNAME=FIND_CMD
  1200. + get_option single FIND_CMD
  1201. + OPTMULTI=single
  1202. + OPTNAME=FIND_CMD
  1203. + ERRCODE=0
  1204. + [ -z single -o -z FIND_CMD ]
  1205. + grep -h ^FIND_CMD= /usr/local/etc/rkhunter.conf
  1206. + RKHTMPVAR2=''
  1207. + [ -z '' ]
  1208. + echo ''
  1209. + return 0
  1210. + CFG_CMD=''
  1211. + [ 0 -eq 0 ]
  1212. + [ -n '' ]
  1213. + test -z ''
  1214. + find_cmd find
  1215. + CMD=find
  1216. + test -z find
  1217. + grep /
  1218. + echo find
  1219. + [ -n '' ]
  1220. + [ -f /sbin/find -a -x /sbin/find ]
  1221. + [ -f /bin/find -a -x /bin/find ]
  1222. + [ -f /usr/sbin/find -a -x /usr/sbin/find ]
  1223. + [ -f /usr/bin/find -a -x /usr/bin/find ]
  1224. + echo /usr/bin/find
  1225. + return
  1226. + eval FIND_CMD=/usr/bin/find
  1227. + FIND_CMD=/usr/bin/find
  1228. + echo ifconfig
  1229. + tr '[:lower:]' '[:upper:]'
  1230. + CMDNAME=IFCONFIG
  1231. + CMDNAME=IFCONFIG_CMD
  1232. + get_option single IFCONFIG_CMD
  1233. + OPTMULTI=single
  1234. + OPTNAME=IFCONFIG_CMD
  1235. + ERRCODE=0
  1236. + [ -z single -o -z IFCONFIG_CMD ]
  1237. + grep -h ^IFCONFIG_CMD= /usr/local/etc/rkhunter.conf
  1238. + RKHTMPVAR2=''
  1239. + [ -z '' ]
  1240. + echo ''
  1241. + return 0
  1242. + CFG_CMD=''
  1243. + [ 0 -eq 0 ]
  1244. + [ -n '' ]
  1245. + test -z ''
  1246. + find_cmd ifconfig
  1247. + CMD=ifconfig
  1248. + test -z ifconfig
  1249. + echo ifconfig
  1250. + grep /
  1251. + [ -n '' ]
  1252. + [ -f /sbin/ifconfig -a -x /sbin/ifconfig ]
  1253. + echo /sbin/ifconfig
  1254. + return
  1255. + eval IFCONFIG_CMD=/sbin/ifconfig
  1256. + IFCONFIG_CMD=/sbin/ifconfig
  1257. + echo ip
  1258. + tr '[:lower:]' '[:upper:]'
  1259. + CMDNAME=IP
  1260. + CMDNAME=IP_CMD
  1261. + get_option single IP_CMD
  1262. + OPTMULTI=single
  1263. + OPTNAME=IP_CMD
  1264. + ERRCODE=0
  1265. + [ -z single -o -z IP_CMD ]
  1266. + grep -h ^IP_CMD= /usr/local/etc/rkhunter.conf
  1267. + RKHTMPVAR2=''
  1268. + [ -z '' ]
  1269. + echo ''
  1270. + return 0
  1271. + CFG_CMD=''
  1272. + [ 0 -eq 0 ]
  1273. + [ -n '' ]
  1274. + test -z ''
  1275. + find_cmd ip
  1276. + CMD=ip
  1277. + test -z ip
  1278. + echo ip
  1279. + grep /
  1280. + [ -n '' ]
  1281. + [ -f /sbin/ip -a -x /sbin/ip ]
  1282. + [ -f /bin/ip -a -x /bin/ip ]
  1283. + [ -f /usr/sbin/ip -a -x /usr/sbin/ip ]
  1284. + [ -f /usr/bin/ip -a -x /usr/bin/ip ]
  1285. + [ -f /usr/games/ip -a -x /usr/games/ip ]
  1286. + [ -f /usr/local/sbin/ip -a -x /usr/local/sbin/ip ]
  1287. + [ -f /usr/local/bin/ip -a -x /usr/local/bin/ip ]
  1288. + [ -f /usr/libexec/ip -a -x /usr/libexec/ip ]
  1289. + [ -f /usr/local/libexec/ip -a -x /usr/local/libexec/ip ]
  1290. + return
  1291. + eval IP_CMD=
  1292. + IP_CMD=''
  1293. + echo ipcs
  1294. + tr '[:lower:]' '[:upper:]'
  1295. + CMDNAME=IPCS
  1296. + CMDNAME=IPCS_CMD
  1297. + get_option single IPCS_CMD
  1298. + OPTMULTI=single
  1299. + OPTNAME=IPCS_CMD
  1300. + ERRCODE=0
  1301. + [ -z single -o -z IPCS_CMD ]
  1302. + grep -h ^IPCS_CMD= /usr/local/etc/rkhunter.conf
  1303. + RKHTMPVAR2=''
  1304. + [ -z '' ]
  1305. + echo ''
  1306. + return 0
  1307. + CFG_CMD=''
  1308. + [ 0 -eq 0 ]
  1309. + [ -n '' ]
  1310. + test -z ''
  1311. + find_cmd ipcs
  1312. + CMD=ipcs
  1313. + test -z ipcs
  1314. + echo ipcs
  1315. + grep /
  1316. + [ -n '' ]
  1317. + [ -f /sbin/ipcs -a -x /sbin/ipcs ]
  1318. + [ -f /bin/ipcs -a -x /bin/ipcs ]
  1319. + [ -f /usr/sbin/ipcs -a -x /usr/sbin/ipcs ]
  1320. + [ -f /usr/bin/ipcs -a -x /usr/bin/ipcs ]
  1321. + echo /usr/bin/ipcs
  1322. + return
  1323. + eval IPCS_CMD=/usr/bin/ipcs
  1324. + IPCS_CMD=/usr/bin/ipcs
  1325. + echo ldd
  1326. + tr '[:lower:]' '[:upper:]'
  1327. + CMDNAME=LDD
  1328. + CMDNAME=LDD_CMD
  1329. + get_option single LDD_CMD
  1330. + OPTMULTI=single
  1331. + OPTNAME=LDD_CMD
  1332. + ERRCODE=0
  1333. + [ -z single -o -z LDD_CMD ]
  1334. + grep -h ^LDD_CMD= /usr/local/etc/rkhunter.conf
  1335. + RKHTMPVAR2=''
  1336. + [ -z '' ]
  1337. + echo ''
  1338. + return 0
  1339. + CFG_CMD=''
  1340. + [ 0 -eq 0 ]
  1341. + [ -n '' ]
  1342. + test -z ''
  1343. + find_cmd ldd
  1344. + CMD=ldd
  1345. + test -z ldd
  1346. + echo ldd
  1347. + grep /
  1348. + [ -n '' ]
  1349. + [ -f /sbin/ldd -a -x /sbin/ldd ]
  1350. + [ -f /bin/ldd -a -x /bin/ldd ]
  1351. + [ -f /usr/sbin/ldd -a -x /usr/sbin/ldd ]
  1352. + [ -f /usr/bin/ldd -a -x /usr/bin/ldd ]
  1353. + echo /usr/bin/ldd
  1354. + return
  1355. + eval LDD_CMD=/usr/bin/ldd
  1356. + LDD_CMD=/usr/bin/ldd
  1357. + echo lsattr
  1358. + tr '[:lower:]' '[:upper:]'
  1359. + CMDNAME=LSATTR
  1360. + CMDNAME=LSATTR_CMD
  1361. + get_option single LSATTR_CMD
  1362. + OPTMULTI=single
  1363. + OPTNAME=LSATTR_CMD
  1364. + ERRCODE=0
  1365. + [ -z single -o -z LSATTR_CMD ]
  1366. + grep -h ^LSATTR_CMD= /usr/local/etc/rkhunter.conf
  1367. + RKHTMPVAR2=''
  1368. + [ -z '' ]
  1369. + echo ''
  1370. + return 0
  1371. + CFG_CMD=''
  1372. + [ 0 -eq 0 ]
  1373. + [ -n '' ]
  1374. + test -z ''
  1375. + find_cmd lsattr
  1376. + CMD=lsattr
  1377. + test -z lsattr
  1378. + echo lsattr
  1379. + grep /
  1380. + [ -n '' ]
  1381. + [ -f /sbin/lsattr -a -x /sbin/lsattr ]
  1382. + [ -f /bin/lsattr -a -x /bin/lsattr ]
  1383. + [ -f /usr/sbin/lsattr -a -x /usr/sbin/lsattr ]
  1384. + [ -f /usr/bin/lsattr -a -x /usr/bin/lsattr ]
  1385. + [ -f /usr/games/lsattr -a -x /usr/games/lsattr ]
  1386. + [ -f /usr/local/sbin/lsattr -a -x /usr/local/sbin/lsattr ]
  1387. + [ -f /usr/local/bin/lsattr -a -x /usr/local/bin/lsattr ]
  1388. + [ -f /usr/libexec/lsattr -a -x /usr/libexec/lsattr ]
  1389. + [ -f /usr/local/libexec/lsattr -a -x /usr/local/libexec/lsattr ]
  1390. + return
  1391. + eval LSATTR_CMD=
  1392. + LSATTR_CMD=''
  1393. + echo lsmod
  1394. + tr '[:lower:]' '[:upper:]'
  1395. + CMDNAME=LSMOD
  1396. + CMDNAME=LSMOD_CMD
  1397. + get_option single LSMOD_CMD
  1398. + OPTMULTI=single
  1399. + OPTNAME=LSMOD_CMD
  1400. + ERRCODE=0
  1401. + [ -z single -o -z LSMOD_CMD ]
  1402. + grep -h ^LSMOD_CMD= /usr/local/etc/rkhunter.conf
  1403. + RKHTMPVAR2=''
  1404. + [ -z '' ]
  1405. + echo ''
  1406. + return 0
  1407. + CFG_CMD=''
  1408. + [ 0 -eq 0 ]
  1409. + [ -n '' ]
  1410. + test -z ''
  1411. + find_cmd lsmod
  1412. + CMD=lsmod
  1413. + test -z lsmod
  1414. + echo lsmod
  1415. + grep /
  1416. + [ -n '' ]
  1417. + [ -f /sbin/lsmod -a -x /sbin/lsmod ]
  1418. + [ -f /bin/lsmod -a -x /bin/lsmod ]
  1419. + [ -f /usr/sbin/lsmod -a -x /usr/sbin/lsmod ]
  1420. + [ -f /usr/bin/lsmod -a -x /usr/bin/lsmod ]
  1421. + [ -f /usr/games/lsmod -a -x /usr/games/lsmod ]
  1422. + [ -f /usr/local/sbin/lsmod -a -x /usr/local/sbin/lsmod ]
  1423. + [ -f /usr/local/bin/lsmod -a -x /usr/local/bin/lsmod ]
  1424. + [ -f /usr/libexec/lsmod -a -x /usr/libexec/lsmod ]
  1425. + [ -f /usr/local/libexec/lsmod -a -x /usr/local/libexec/lsmod ]
  1426. + return
  1427. + eval LSMOD_CMD=
  1428. + LSMOD_CMD=''
  1429. + echo lsof
  1430. + tr '[:lower:]' '[:upper:]'
  1431. + CMDNAME=LSOF
  1432. + CMDNAME=LSOF_CMD
  1433. + get_option single LSOF_CMD
  1434. + OPTMULTI=single
  1435. + OPTNAME=LSOF_CMD
  1436. + ERRCODE=0
  1437. + [ -z single -o -z LSOF_CMD ]
  1438. + grep -h ^LSOF_CMD= /usr/local/etc/rkhunter.conf
  1439. + RKHTMPVAR2=''
  1440. + [ -z '' ]
  1441. + echo ''
  1442. + return 0
  1443. + CFG_CMD=''
  1444. + [ 0 -eq 0 ]
  1445. + [ -n '' ]
  1446. + test -z ''
  1447. + find_cmd lsof
  1448. + CMD=lsof
  1449. + test -z lsof
  1450. + echo lsof
  1451. + grep /
  1452. + [ -n '' ]
  1453. + [ -f /sbin/lsof -a -x /sbin/lsof ]
  1454. + [ -f /bin/lsof -a -x /bin/lsof ]
  1455. + [ -f /usr/sbin/lsof -a -x /usr/sbin/lsof ]
  1456. + [ -f /usr/bin/lsof -a -x /usr/bin/lsof ]
  1457. + [ -f /usr/games/lsof -a -x /usr/games/lsof ]
  1458. + [ -f /usr/local/sbin/lsof -a -x /usr/local/sbin/lsof ]
  1459. + echo /usr/local/sbin/lsof
  1460. + return
  1461. + eval LSOF_CMD=/usr/local/sbin/lsof
  1462. + LSOF_CMD=/usr/local/sbin/lsof
  1463. + echo mktemp
  1464. + tr '[:lower:]' '[:upper:]'
  1465. + CMDNAME=MKTEMP
  1466. + CMDNAME=MKTEMP_CMD
  1467. + get_option single MKTEMP_CMD
  1468. + OPTMULTI=single
  1469. + OPTNAME=MKTEMP_CMD
  1470. + ERRCODE=0
  1471. + [ -z single -o -z MKTEMP_CMD ]
  1472. + grep -h ^MKTEMP_CMD= /usr/local/etc/rkhunter.conf
  1473. + RKHTMPVAR2=''
  1474. + [ -z '' ]
  1475. + echo ''
  1476. + return 0
  1477. + CFG_CMD=''
  1478. + [ 0 -eq 0 ]
  1479. + [ -n '' ]
  1480. + test -z ''
  1481. + find_cmd mktemp
  1482. + CMD=mktemp
  1483. + test -z mktemp
  1484. + echo mktemp
  1485. + grep /
  1486. + [ -n '' ]
  1487. + [ -f /sbin/mktemp -a -x /sbin/mktemp ]
  1488. + [ -f /bin/mktemp -a -x /bin/mktemp ]
  1489. + [ -f /usr/sbin/mktemp -a -x /usr/sbin/mktemp ]
  1490. + [ -f /usr/bin/mktemp -a -x /usr/bin/mktemp ]
  1491. + echo /usr/bin/mktemp
  1492. + return
  1493. + eval MKTEMP_CMD=/usr/bin/mktemp
  1494. + MKTEMP_CMD=/usr/bin/mktemp
  1495. + echo netstat
  1496. + tr '[:lower:]' '[:upper:]'
  1497. + CMDNAME=NETSTAT
  1498. + CMDNAME=NETSTAT_CMD
  1499. + get_option single NETSTAT_CMD
  1500. + OPTMULTI=single
  1501. + OPTNAME=NETSTAT_CMD
  1502. + ERRCODE=0
  1503. + [ -z single -o -z NETSTAT_CMD ]
  1504. + grep -h ^NETSTAT_CMD= /usr/local/etc/rkhunter.conf
  1505. + RKHTMPVAR2=''
  1506. + [ -z '' ]
  1507. + echo ''
  1508. + return 0
  1509. + CFG_CMD=''
  1510. + [ 0 -eq 0 ]
  1511. + [ -n '' ]
  1512. + test -z ''
  1513. + find_cmd netstat
  1514. + CMD=netstat
  1515. + test -z netstat
  1516. + echo netstat
  1517. + grep /
  1518. + [ -n '' ]
  1519. + [ -f /sbin/netstat -a -x /sbin/netstat ]
  1520. + [ -f /bin/netstat -a -x /bin/netstat ]
  1521. + [ -f /usr/sbin/netstat -a -x /usr/sbin/netstat ]
  1522. + [ -f /usr/bin/netstat -a -x /usr/bin/netstat ]
  1523. + echo /usr/bin/netstat
  1524. + return
  1525. + eval NETSTAT_CMD=/usr/bin/netstat
  1526. + NETSTAT_CMD=/usr/bin/netstat
  1527. + echo perl
  1528. + tr '[:lower:]' '[:upper:]'
  1529. + CMDNAME=PERL
  1530. + CMDNAME=PERL_CMD
  1531. + get_option single PERL_CMD
  1532. + OPTMULTI=single
  1533. + OPTNAME=PERL_CMD
  1534. + ERRCODE=0
  1535. + [ -z single -o -z PERL_CMD ]
  1536. + grep -h ^PERL_CMD= /usr/local/etc/rkhunter.conf
  1537. + RKHTMPVAR2=''
  1538. + [ -z '' ]
  1539. + echo ''
  1540. + return 0
  1541. + CFG_CMD=''
  1542. + [ 0 -eq 0 ]
  1543. + [ -n '' ]
  1544. + test -z ''
  1545. + find_cmd perl
  1546. + CMD=perl
  1547. + test -z perl
  1548. + grep /
  1549. + echo perl
  1550. + [ -n '' ]
  1551. + [ -f /sbin/perl -a -x /sbin/perl ]
  1552. + [ -f /bin/perl -a -x /bin/perl ]
  1553. + [ -f /usr/sbin/perl -a -x /usr/sbin/perl ]
  1554. + [ -f /usr/bin/perl -a -x /usr/bin/perl ]
  1555. + [ -f /usr/games/perl -a -x /usr/games/perl ]
  1556. + [ -f /usr/local/sbin/perl -a -x /usr/local/sbin/perl ]
  1557. + [ -f /usr/local/bin/perl -a -x /usr/local/bin/perl ]
  1558. + echo /usr/local/bin/perl
  1559. + return
  1560. + eval PERL_CMD=/usr/local/bin/perl
  1561. + PERL_CMD=/usr/local/bin/perl
  1562. + echo pgrep
  1563. + tr '[:lower:]' '[:upper:]'
  1564. + CMDNAME=PGREP
  1565. + CMDNAME=PGREP_CMD
  1566. + get_option single PGREP_CMD
  1567. + OPTMULTI=single
  1568. + OPTNAME=PGREP_CMD
  1569. + ERRCODE=0
  1570. + [ -z single -o -z PGREP_CMD ]
  1571. + grep -h ^PGREP_CMD= /usr/local/etc/rkhunter.conf
  1572. + RKHTMPVAR2=''
  1573. + [ -z '' ]
  1574. + echo ''
  1575. + return 0
  1576. + CFG_CMD=''
  1577. + [ 0 -eq 0 ]
  1578. + [ -n '' ]
  1579. + test -z ''
  1580. + find_cmd pgrep
  1581. + CMD=pgrep
  1582. + test -z pgrep
  1583. + grep /
  1584. + echo pgrep
  1585. + [ -n '' ]
  1586. + [ -f /sbin/pgrep -a -x /sbin/pgrep ]
  1587. + [ -f /bin/pgrep -a -x /bin/pgrep ]
  1588. + echo /bin/pgrep
  1589. + return
  1590. + eval PGREP_CMD=/bin/pgrep
  1591. + PGREP_CMD=/bin/pgrep
  1592. + echo ps
  1593. + tr '[:lower:]' '[:upper:]'
  1594. + CMDNAME=PS
  1595. + CMDNAME=PS_CMD
  1596. + get_option single PS_CMD
  1597. + OPTMULTI=single
  1598. + OPTNAME=PS_CMD
  1599. + ERRCODE=0
  1600. + [ -z single -o -z PS_CMD ]
  1601. + grep -h ^PS_CMD= /usr/local/etc/rkhunter.conf
  1602. + RKHTMPVAR2=''
  1603. + [ -z '' ]
  1604. + echo ''
  1605. + return 0
  1606. + CFG_CMD=''
  1607. + [ 0 -eq 0 ]
  1608. + [ -n '' ]
  1609. + test -z ''
  1610. + find_cmd ps
  1611. + CMD=ps
  1612. + test -z ps
  1613. + grep /
  1614. + echo ps
  1615. + [ -n '' ]
  1616. + [ -f /sbin/ps -a -x /sbin/ps ]
  1617. + [ -f /bin/ps -a -x /bin/ps ]
  1618. + echo /bin/ps
  1619. + return
  1620. + eval PS_CMD=/bin/ps
  1621. + PS_CMD=/bin/ps
  1622. + echo pwd
  1623. + tr '[:lower:]' '[:upper:]'
  1624. + CMDNAME=PWD
  1625. + CMDNAME=PWD_CMD
  1626. + get_option single PWD_CMD
  1627. + OPTMULTI=single
  1628. + OPTNAME=PWD_CMD
  1629. + ERRCODE=0
  1630. + [ -z single -o -z PWD_CMD ]
  1631. + grep -h ^PWD_CMD= /usr/local/etc/rkhunter.conf
  1632. + RKHTMPVAR2=''
  1633. + [ -z '' ]
  1634. + echo ''
  1635. + return 0
  1636. + CFG_CMD=''
  1637. + [ 0 -eq 0 ]
  1638. + [ -n '' ]
  1639. + test -z ''
  1640. + find_cmd pwd
  1641. + CMD=pwd
  1642. + test -z pwd
  1643. + grep /
  1644. + echo pwd
  1645. + [ -n '' ]
  1646. + [ -f /sbin/pwd -a -x /sbin/pwd ]
  1647. + [ -f /bin/pwd -a -x /bin/pwd ]
  1648. + echo /bin/pwd
  1649. + return
  1650. + eval PWD_CMD=/bin/pwd
  1651. + PWD_CMD=/bin/pwd
  1652. + echo readlink
  1653. + tr '[:lower:]' '[:upper:]'
  1654. + CMDNAME=READLINK
  1655. + CMDNAME=READLINK_CMD
  1656. + get_option single READLINK_CMD
  1657. + OPTMULTI=single
  1658. + OPTNAME=READLINK_CMD
  1659. + ERRCODE=0
  1660. + [ -z single -o -z READLINK_CMD ]
  1661. + grep -h ^READLINK_CMD= /usr/local/etc/rkhunter.conf
  1662. + RKHTMPVAR2=''
  1663. + [ -z '' ]
  1664. + echo ''
  1665. + return 0
  1666. + CFG_CMD=''
  1667. + [ 0 -eq 0 ]
  1668. + [ -n '' ]
  1669. + test -z ''
  1670. + find_cmd readlink
  1671. + CMD=readlink
  1672. + test -z readlink
  1673. + grep /
  1674. + echo readlink
  1675. + [ -n '' ]
  1676. + [ -f /sbin/readlink -a -x /sbin/readlink ]
  1677. + [ -f /bin/readlink -a -x /bin/readlink ]
  1678. + [ -f /usr/sbin/readlink -a -x /usr/sbin/readlink ]
  1679. + [ -f /usr/bin/readlink -a -x /usr/bin/readlink ]
  1680. + echo /usr/bin/readlink
  1681. + return
  1682. + eval READLINK_CMD=/usr/bin/readlink
  1683. + READLINK_CMD=/usr/bin/readlink
  1684. + echo stat
  1685. + tr '[:lower:]' '[:upper:]'
  1686. + CMDNAME=STAT
  1687. + CMDNAME=STAT_CMD
  1688. + get_option single STAT_CMD
  1689. + OPTMULTI=single
  1690. + OPTNAME=STAT_CMD
  1691. + ERRCODE=0
  1692. + [ -z single -o -z STAT_CMD ]
  1693. + grep -h ^STAT_CMD= /usr/local/etc/rkhunter.conf
  1694. + RKHTMPVAR2=''
  1695. + [ -z '' ]
  1696. + echo ''
  1697. + return 0
  1698. + CFG_CMD=''
  1699. + [ 0 -eq 0 ]
  1700. + [ -n '' ]
  1701. + test -z ''
  1702. + find_cmd stat
  1703. + CMD=stat
  1704. + test -z stat
  1705. + grep /
  1706. + echo stat
  1707. + [ -n '' ]
  1708. + [ -f /sbin/stat -a -x /sbin/stat ]
  1709. + [ -f /bin/stat -a -x /bin/stat ]
  1710. + [ -f /usr/sbin/stat -a -x /usr/sbin/stat ]
  1711. + [ -f /usr/bin/stat -a -x /usr/bin/stat ]
  1712. + echo /usr/bin/stat
  1713. + return
  1714. + eval STAT_CMD=/usr/bin/stat
  1715. + STAT_CMD=/usr/bin/stat
  1716. + echo strings
  1717. + tr '[:lower:]' '[:upper:]'
  1718. + CMDNAME=STRINGS
  1719. + CMDNAME=STRINGS_CMD
  1720. + get_option single STRINGS_CMD
  1721. + OPTMULTI=single
  1722. + OPTNAME=STRINGS_CMD
  1723. + ERRCODE=0
  1724. + [ -z single -o -z STRINGS_CMD ]
  1725. + grep -h ^STRINGS_CMD= /usr/local/etc/rkhunter.conf
  1726. + RKHTMPVAR2=''
  1727. + [ -z '' ]
  1728. + echo ''
  1729. + return 0
  1730. + CFG_CMD=''
  1731. + [ 0 -eq 0 ]
  1732. + [ -n '' ]
  1733. + test -z ''
  1734. + find_cmd strings
  1735. + CMD=strings
  1736. + test -z strings
  1737. + grep /
  1738. + echo strings
  1739. + [ -n '' ]
  1740. + [ -f /sbin/strings -a -x /sbin/strings ]
  1741. + [ -f /bin/strings -a -x /bin/strings ]
  1742. + [ -f /usr/sbin/strings -a -x /usr/sbin/strings ]
  1743. + [ -f /usr/bin/strings -a -x /usr/bin/strings ]
  1744. + echo /usr/bin/strings
  1745. + return
  1746. + eval STRINGS_CMD=/usr/bin/strings
  1747. + STRINGS_CMD=/usr/bin/strings
  1748. + [ 0 -eq 1 ]
  1749. + [ -n /usr/local/bin/perl -a /usr/local/bin/perl != DISABLED ]
  1750. + [ -z /usr/bin/stat -o /usr/bin/stat = BUILTIN ]
  1751. + [ -z /usr/bin/readlink -o /usr/bin/readlink = BUILTIN ]
  1752. + /usr/bin/readlink -f /usr/local/lib/rkhunter/scripts/readlink.sh
  1753. + [ -n '' ]
  1754. + test -n /usr/bin/readlink
  1755. + HAVE_READLINK=1
  1756. + [ 0 -eq 1 ]
  1757. + AWK_CMD=awk
  1758. + echo basename
  1759. + tr '[:lower:]' '[:upper:]'
  1760. + RKHTMPVAR=BASENAME
  1761. + RKHTMPVAR=BASENAME_CMD
  1762. + eval echo '$BASENAME_CMD'
  1763. + echo /usr/bin/basename
  1764. + RKHTMPVAR2=/usr/bin/basename
  1765. + test /usr/bin/basename = DISABLED -o /usr/bin/basename = BUILTIN
  1766. + echo diff
  1767. + tr '[:lower:]' '[:upper:]'
  1768. + RKHTMPVAR=DIFF
  1769. + RKHTMPVAR=DIFF_CMD
  1770. + eval echo '$DIFF_CMD'
  1771. + echo /usr/bin/diff
  1772. + RKHTMPVAR2=/usr/bin/diff
  1773. + test /usr/bin/diff = DISABLED -o /usr/bin/diff = BUILTIN
  1774. + tr '[:lower:]' '[:upper:]'
  1775. + echo dirname
  1776. + RKHTMPVAR=DIRNAME
  1777. + RKHTMPVAR=DIRNAME_CMD
  1778. + eval echo '$DIRNAME_CMD'
  1779. + echo /usr/bin/dirname
  1780. + RKHTMPVAR2=/usr/bin/dirname
  1781. + test /usr/bin/dirname = DISABLED -o /usr/bin/dirname = BUILTIN
  1782. + echo file
  1783. + tr '[:lower:]' '[:upper:]'
  1784. + RKHTMPVAR=FILE
  1785. + RKHTMPVAR=FILE_CMD
  1786. + eval echo '$FILE_CMD'
  1787. + echo /usr/bin/file
  1788. + RKHTMPVAR2=/usr/bin/file
  1789. + test /usr/bin/file = DISABLED -o /usr/bin/file = BUILTIN
  1790. + tr '[:lower:]' '[:upper:]'
  1791. + echo find
  1792. + RKHTMPVAR=FIND
  1793. + RKHTMPVAR=FIND_CMD
  1794. + eval echo '$FIND_CMD'
  1795. + echo /usr/bin/find
  1796. + RKHTMPVAR2=/usr/bin/find
  1797. + test /usr/bin/find = DISABLED -o /usr/bin/find = BUILTIN
  1798. + echo ifconfig
  1799. + tr '[:lower:]' '[:upper:]'
  1800. + RKHTMPVAR=IFCONFIG
  1801. + RKHTMPVAR=IFCONFIG_CMD
  1802. + eval echo '$IFCONFIG_CMD'
  1803. + echo /sbin/ifconfig
  1804. + RKHTMPVAR2=/sbin/ifconfig
  1805. + test /sbin/ifconfig = DISABLED -o /sbin/ifconfig = BUILTIN
  1806. + tr '[:lower:]' '[:upper:]'
  1807. + echo ip
  1808. + RKHTMPVAR=IP
  1809. + RKHTMPVAR=IP_CMD
  1810. + eval echo '$IP_CMD'
  1811. + echo
  1812. + RKHTMPVAR2=''
  1813. + test '' = DISABLED -o '' = BUILTIN
  1814. + tr '[:lower:]' '[:upper:]'
  1815. + echo ipcs
  1816. + RKHTMPVAR=IPCS
  1817. + RKHTMPVAR=IPCS_CMD
  1818. + eval echo '$IPCS_CMD'
  1819. + echo /usr/bin/ipcs
  1820. + RKHTMPVAR2=/usr/bin/ipcs
  1821. + test /usr/bin/ipcs = DISABLED -o /usr/bin/ipcs = BUILTIN
  1822. + tr '[:lower:]' '[:upper:]'
  1823. + echo ldd
  1824. + RKHTMPVAR=LDD
  1825. + RKHTMPVAR=LDD_CMD
  1826. + eval echo '$LDD_CMD'
  1827. + echo /usr/bin/ldd
  1828. + RKHTMPVAR2=/usr/bin/ldd
  1829. + test /usr/bin/ldd = DISABLED -o /usr/bin/ldd = BUILTIN
  1830. + tr '[:lower:]' '[:upper:]'
  1831. + echo lsattr
  1832. + RKHTMPVAR=LSATTR
  1833. + RKHTMPVAR=LSATTR_CMD
  1834. + eval echo '$LSATTR_CMD'
  1835. + echo
  1836. + RKHTMPVAR2=''
  1837. + test '' = DISABLED -o '' = BUILTIN
  1838. + echo lsmod
  1839. + tr '[:lower:]' '[:upper:]'
  1840. + RKHTMPVAR=LSMOD
  1841. + RKHTMPVAR=LSMOD_CMD
  1842. + eval echo '$LSMOD_CMD'
  1843. + echo
  1844. + RKHTMPVAR2=''
  1845. + test '' = DISABLED -o '' = BUILTIN
  1846. + echo lsof
  1847. + tr '[:lower:]' '[:upper:]'
  1848. + RKHTMPVAR=LSOF
  1849. + RKHTMPVAR=LSOF_CMD
  1850. + eval echo '$LSOF_CMD'
  1851. + echo /usr/local/sbin/lsof
  1852. + RKHTMPVAR2=/usr/local/sbin/lsof
  1853. + test /usr/local/sbin/lsof = DISABLED -o /usr/local/sbin/lsof = BUILTIN
  1854. + echo mktemp
  1855. + tr '[:lower:]' '[:upper:]'
  1856. + RKHTMPVAR=MKTEMP
  1857. + RKHTMPVAR=MKTEMP_CMD
  1858. + eval echo '$MKTEMP_CMD'
  1859. + echo /usr/bin/mktemp
  1860. + RKHTMPVAR2=/usr/bin/mktemp
  1861. + test /usr/bin/mktemp = DISABLED -o /usr/bin/mktemp = BUILTIN
  1862. + echo netstat
  1863. + tr '[:lower:]' '[:upper:]'
  1864. + RKHTMPVAR=NETSTAT
  1865. + RKHTMPVAR=NETSTAT_CMD
  1866. + eval echo '$NETSTAT_CMD'
  1867. + echo /usr/bin/netstat
  1868. + RKHTMPVAR2=/usr/bin/netstat
  1869. + test /usr/bin/netstat = DISABLED -o /usr/bin/netstat = BUILTIN
  1870. + echo perl
  1871. + tr '[:lower:]' '[:upper:]'
  1872. + RKHTMPVAR=PERL
  1873. + RKHTMPVAR=PERL_CMD
  1874. + eval echo '$PERL_CMD'
  1875. + echo /usr/local/bin/perl
  1876. + RKHTMPVAR2=/usr/local/bin/perl
  1877. + test /usr/local/bin/perl = DISABLED -o /usr/local/bin/perl = BUILTIN
  1878. + echo pgrep
  1879. + tr '[:lower:]' '[:upper:]'
  1880. + RKHTMPVAR=PGREP
  1881. + RKHTMPVAR=PGREP_CMD
  1882. + eval echo '$PGREP_CMD'
  1883. + echo /bin/pgrep
  1884. + RKHTMPVAR2=/bin/pgrep
  1885. + test /bin/pgrep = DISABLED -o /bin/pgrep = BUILTIN
  1886. + echo ps
  1887. + tr '[:lower:]' '[:upper:]'
  1888. + RKHTMPVAR=PS
  1889. + RKHTMPVAR=PS_CMD
  1890. + eval echo '$PS_CMD'
  1891. + echo /bin/ps
  1892. + RKHTMPVAR2=/bin/ps
  1893. + test /bin/ps = DISABLED -o /bin/ps = BUILTIN
  1894. + echo pwd
  1895. + tr '[:lower:]' '[:upper:]'
  1896. + RKHTMPVAR=PWD
  1897. + RKHTMPVAR=PWD_CMD
  1898. + eval echo '$PWD_CMD'
  1899. + echo /bin/pwd
  1900. + RKHTMPVAR2=/bin/pwd
  1901. + test /bin/pwd = DISABLED -o /bin/pwd = BUILTIN
  1902. + tr '[:lower:]' '[:upper:]'
  1903. + echo readlink
  1904. + RKHTMPVAR=READLINK
  1905. + RKHTMPVAR=READLINK_CMD
  1906. + eval echo '$READLINK_CMD'
  1907. + echo /usr/bin/readlink
  1908. + RKHTMPVAR2=/usr/bin/readlink
  1909. + test /usr/bin/readlink = DISABLED -o /usr/bin/readlink = BUILTIN
  1910. + tr '[:lower:]' '[:upper:]'
  1911. + echo stat
  1912. + RKHTMPVAR=STAT
  1913. + RKHTMPVAR=STAT_CMD
  1914. + eval echo '$STAT_CMD'
  1915. + echo /usr/bin/stat
  1916. + RKHTMPVAR2=/usr/bin/stat
  1917. + test /usr/bin/stat = DISABLED -o /usr/bin/stat = BUILTIN
  1918. + tr '[:lower:]' '[:upper:]'
  1919. + echo strings
  1920. + RKHTMPVAR=STRINGS
  1921. + RKHTMPVAR=STRINGS_CMD
  1922. + eval echo '$STRINGS_CMD'
  1923. + echo /usr/bin/strings
  1924. + RKHTMPVAR2=/usr/bin/strings
  1925. + test /usr/bin/strings = DISABLED -o /usr/bin/strings = BUILTIN
  1926. + return
  1927. + get_installdir_option
  1928. + LEAVE=0
  1929. + get_option single INSTALLDIR
  1930. + OPTMULTI=single
  1931. + OPTNAME=INSTALLDIR
  1932. + ERRCODE=0
  1933. + [ -z single -o -z INSTALLDIR ]
  1934. + grep -h ^INSTALLDIR= /usr/local/etc/rkhunter.conf
  1935. + RKHTMPVAR2=INSTALLDIR=/usr/local
  1936. + [ -z INSTALLDIR=/usr/local ]
  1937. + echo INSTALLDIR=/usr/local
  1938. + tail -n 1
  1939. + sed -e s/INSTALLDIR=//
  1940. + OPTVAR=/usr/local
  1941. + [ -z /usr/local -o /usr/local = '""' -o /usr/local = \'\' ]
  1942. + echo /usr/local
  1943. + tr -d '" '
  1944. + tr -d \'
  1945. + OPTVAR=/usr/local
  1946. + echo /usr/local
  1947. + return 0
  1948. + RKHINSTALLDIR=/usr/local
  1949. + [ 0 -eq 0 ]
  1950. + [ -z /usr/local ]
  1951. + [ ! -d /usr/local ]
  1952. + [ ! -r /usr/local ]
  1953. + [ 0 -eq 1 ]
  1954. + return
  1955. + get_rootdir_option
  1956. + get_option single ROOTDIR
  1957. + OPTMULTI=single
  1958. + OPTNAME=ROOTDIR
  1959. + ERRCODE=0
  1960. + [ -z single -o -z ROOTDIR ]
  1961. + grep -h ^ROOTDIR= /usr/local/etc/rkhunter.conf
  1962. + RKHTMPVAR2=''
  1963. + [ -z '' ]
  1964. + echo ''
  1965. + return 0
  1966. + RKHTMPVAR=''
  1967. + [ -n '' ]
  1968. + return
  1969. + get_logfile_option
  1970. + LEAVE=0
  1971. + [ -n '' ]
  1972. + get_option single LOGFILE
  1973. + OPTMULTI=single
  1974. + OPTNAME=LOGFILE
  1975. + ERRCODE=0
  1976. + [ -z single -o -z LOGFILE ]
  1977. + grep -h ^LOGFILE= /usr/local/etc/rkhunter.conf
  1978. + RKHTMPVAR2=LOGFILE=/var/log/rkhunter.log
  1979. + [ -z LOGFILE=/var/log/rkhunter.log ]
  1980. + echo LOGFILE=/var/log/rkhunter.log
  1981. + sed -e s/LOGFILE=//
  1982. + tail -n 1
  1983. + OPTVAR=/var/log/rkhunter.log
  1984. + [ -z /var/log/rkhunter.log -o /var/log/rkhunter.log = '""' -o /var/log/rkhunter.log = \'\' ]
  1985. + tr -d '" '
  1986. + tr -d \'
  1987. + echo /var/log/rkhunter.log
  1988. + OPTVAR=/var/log/rkhunter.log
  1989. + echo /var/log/rkhunter.log
  1990. + return 0
  1991. + RKHLOGFILE=/var/log/rkhunter.log
  1992. + [ 0 -eq 0 ]
  1993. + check_paths RKHLOGFILE LOGFILE 'NOWILD NOBROKENLINK'
  1994. + OPT_VALUE_OPT=RKHLOGFILE
  1995. + OPT_NAME=LOGFILE
  1996. + STRICT='NOWILD NOBROKENLINK'
  1997. + test -z LOGFILE
  1998. + eval echo '"$RKHLOGFILE"'
  1999. + echo /var/log/rkhunter.log
  2000. + OPT_VALUE=/var/log/rkhunter.log
  2001. + ERRCODE=0
  2002. + test -z /var/log/rkhunter.log
  2003. + MUSTEXIST=0
  2004. + NOWILD=0
  2005. + NOLINK=0
  2006. + NOWILD=1
  2007. + NOLINK=1
  2008. + echo '/var/log/rkhunter.log '
  2009. + grep ^-
  2010. + RKHTMPVAR=''
  2011. + [ -n '' ]
  2012. + [ 1 -eq 1 ]
  2013. + egrep '(^|[^\])[][?*{}]'
  2014. + echo /var/log/rkhunter.log
  2015. + RKHTMPVAR=''
  2016. + [ -n '' ]
  2017. + grep ' LOGFILE '
  2018. + echo ' ALLOWDEVFILE ALLOWHIDDENDIR ALLOWHIDDENFILE ALLOWPROCDELFILE ALLOWPROCLISTEN ATTRWHITELIST EXCLUDE_USER_FILEPROP_FILES_DIRS EXISTWHITELIST IMMUTWHITELIST PKGMGR_NO_VRFY PORT_PATH_WHITELIST RTKT_DIR_WHITELIST RTKT_FILE_WHITELIST SCRIPTWHITELIST USER_FILEPROP_FILES_DIRS WRITEWHITELIST '
  2019. + [ -n '' ]
  2020. + test -z /var/log/rkhunter.log
  2021. + echo /var/log/rkhunter.log
  2022. + egrep '(^[./]*$)|[;&]|/\.\./'
  2023. + [ -n '' ]
  2024. + echo /var/log/rkhunter.log
  2025. + grep '^[^/].*/'
  2026. + [ -n '' ]
  2027. + grep ^/
  2028. + echo /var/log/rkhunter.log
  2029. + [ -z /var/log/rkhunter.log ]
  2030. + [ -f /var/log/rkhunter.log ]
  2031. + IFS='
  2032. '
  2033. + return
  2034. + [ 0 -eq 0 ]
  2035. + [ -z /var/log/rkhunter.log ]
  2036. + [ 0 -eq 1 ]
  2037. + [ /var/log/rkhunter.log = /dev/null ]
  2038. + echo /var/log/rkhunter.log
  2039. + sed -e 's:/[^/][^/]*$::'
  2040. + LOGDIR=/var/log
  2041. + echo /var/log
  2042. + grep /
  2043. + [ -z /var/log ]
  2044. + [ /var/log = /var/log/rkhunter.log ]
  2045. + [ ! -e /var/log ]
  2046. + [ ! -d /var/log ]
  2047. + [ ! -w /var/log ]
  2048. + [ ! -r /var/log ]
  2049. + [ -h /var/log/rkhunter.log ]
  2050. + [ -e /var/log/rkhunter.log -a ! -f /var/log/rkhunter.log ]
  2051. + [ 0 -eq 0 ]
  2052. + get_option single APPEND_LOG
  2053. + OPTMULTI=single
  2054. + OPTNAME=APPEND_LOG
  2055. + ERRCODE=0
  2056. + [ -z single -o -z APPEND_LOG ]
  2057. + grep -h ^APPEND_LOG= /usr/local/etc/rkhunter.conf
  2058. + RKHTMPVAR2=''
  2059. + [ -z '' ]
  2060. + echo ''
  2061. + return 0
  2062. + APPEND_LOG=''
  2063. + [ 0 -eq 0 ]
  2064. + [ -n '' ]
  2065. + APPEND_LOG=0
  2066. + get_option single COPY_LOG_ON_ERROR
  2067. + OPTMULTI=single
  2068. + OPTNAME=COPY_LOG_ON_ERROR
  2069. + ERRCODE=0
  2070. + [ -z single -o -z COPY_LOG_ON_ERROR ]
  2071. + grep -h ^COPY_LOG_ON_ERROR= /usr/local/etc/rkhunter.conf
  2072. + RKHTMPVAR2=''
  2073. + [ -z '' ]
  2074. + echo ''
  2075. + return 0
  2076. + RKHTMPVAR=''
  2077. + [ 0 -eq 0 ]
  2078. + [ -n '' ]
  2079. + COPY_LOG_ON_ERROR=0
  2080. + [ 0 -eq 1 ]
  2081. + return
  2082. + get_tmpdir_option
  2083. + LEAVE=0
  2084. + [ -n '' ]
  2085. + get_option single TMPDIR
  2086. + OPTMULTI=single
  2087. + OPTNAME=TMPDIR
  2088. + ERRCODE=0
  2089. + [ -z single -o -z TMPDIR ]
  2090. + grep -h ^TMPDIR= /usr/local/etc/rkhunter.conf
  2091. + RKHTMPVAR2=TMPDIR=/usr/local/var/lib/rkhunter/tmp
  2092. + [ -z TMPDIR=/usr/local/var/lib/rkhunter/tmp ]
  2093. + tail -n 1
  2094. + echo TMPDIR=/usr/local/var/lib/rkhunter/tmp
  2095. + sed -e s/TMPDIR=//
  2096. + OPTVAR=/usr/local/var/lib/rkhunter/tmp
  2097. + [ -z /usr/local/var/lib/rkhunter/tmp -o /usr/local/var/lib/rkhunter/tmp = '""' -o /usr/local/var/lib/rkhunter/tmp = \'\' ]
  2098. + tr -d '" '
  2099. + tr -d \'
  2100. + echo /usr/local/var/lib/rkhunter/tmp
  2101. + OPTVAR=/usr/local/var/lib/rkhunter/tmp
  2102. + echo /usr/local/var/lib/rkhunter/tmp
  2103. + return 0
  2104. + RKHTMPDIR=/usr/local/var/lib/rkhunter/tmp
  2105. + [ 0 -eq 0 ]
  2106. + check_paths RKHTMPDIR TMPDIR 'NOWILD NOBROKENLINK EXIST'
  2107. + OPT_VALUE_OPT=RKHTMPDIR
  2108. + OPT_NAME=TMPDIR
  2109. + STRICT='NOWILD NOBROKENLINK EXIST'
  2110. + test -z TMPDIR
  2111. + eval echo '"$RKHTMPDIR"'
  2112. + echo /usr/local/var/lib/rkhunter/tmp
  2113. + OPT_VALUE=/usr/local/var/lib/rkhunter/tmp
  2114. + ERRCODE=0
  2115. + test -z /usr/local/var/lib/rkhunter/tmp
  2116. + MUSTEXIST=0
  2117. + NOWILD=0
  2118. + NOLINK=0
  2119. + NOWILD=1
  2120. + NOLINK=1
  2121. + MUSTEXIST=1
  2122. + echo '/usr/local/var/lib/rkhunter/tmp '
  2123. + grep ^-
  2124. + RKHTMPVAR=''
  2125. + [ -n '' ]
  2126. + [ 1 -eq 1 ]
  2127. + echo /usr/local/var/lib/rkhunter/tmp
  2128. + egrep '(^|[^\])[][?*{}]'
  2129. + RKHTMPVAR=''
  2130. + [ -n '' ]
  2131. + grep ' TMPDIR '
  2132. + echo ' ALLOWDEVFILE ALLOWHIDDENDIR ALLOWHIDDENFILE ALLOWPROCDELFILE ALLOWPROCLISTEN ATTRWHITELIST EXCLUDE_USER_FILEPROP_FILES_DIRS EXISTWHITELIST IMMUTWHITELIST PKGMGR_NO_VRFY PORT_PATH_WHITELIST RTKT_DIR_WHITELIST RTKT_FILE_WHITELIST SCRIPTWHITELIST USER_FILEPROP_FILES_DIRS WRITEWHITELIST '
  2133. + [ -n '' ]
  2134. + test -z /usr/local/var/lib/rkhunter/tmp
  2135. + echo /usr/local/var/lib/rkhunter/tmp
  2136. + egrep '(^[./]*$)|[;&]|/\.\./'
  2137. + [ -n '' ]
  2138. + echo /usr/local/var/lib/rkhunter/tmp
  2139. + grep '^[^/].*/'
  2140. + [ -n '' ]
  2141. + echo /usr/local/var/lib/rkhunter/tmp
  2142. + grep ^/
  2143. + [ -z /usr/local/var/lib/rkhunter/tmp ]
  2144. + [ -f /usr/local/var/lib/rkhunter/tmp ]
  2145. + [ -d /usr/local/var/lib/rkhunter/tmp ]
  2146. + test TMPDIR = ALLOWHIDDENFILE -a -h /usr/local/var/lib/rkhunter/tmp
  2147. + IFS='
  2148. '
  2149. + return
  2150. + [ 0 -eq 0 ]
  2151. + [ -z /usr/local/var/lib/rkhunter/tmp ]
  2152. + [ 0 -eq 1 ]
  2153. + [ ! -e /usr/local/var/lib/rkhunter/tmp ]
  2154. + [ ! -d /usr/local/var/lib/rkhunter/tmp ]
  2155. + [ ! -w /usr/local/var/lib/rkhunter/tmp ]
  2156. + [ ! -r /usr/local/var/lib/rkhunter/tmp ]
  2157. + [ /usr/local/var/lib/rkhunter/tmp = /tmp -o /usr/local/var/lib/rkhunter/tmp = /var/tmp ]
  2158. + [ /usr/local/var/lib/rkhunter/tmp = /etc ]
  2159. + [ 0 -eq 1 ]
  2160. + return
  2161. + get_dbdir_option
  2162. + LEAVE=0
  2163. + [ -n '' ]
  2164. + get_option single DBDIR
  2165. + OPTMULTI=single
  2166. + OPTNAME=DBDIR
  2167. + ERRCODE=0
  2168. + [ -z single -o -z DBDIR ]
  2169. + grep -h ^DBDIR= /usr/local/etc/rkhunter.conf
  2170. + RKHTMPVAR2=DBDIR=/usr/local/var/lib/rkhunter/db
  2171. + [ -z DBDIR=/usr/local/var/lib/rkhunter/db ]
  2172. + echo DBDIR=/usr/local/var/lib/rkhunter/db
  2173. + sed -e s/DBDIR=//
  2174. + tail -n 1
  2175. + OPTVAR=/usr/local/var/lib/rkhunter/db
  2176. + [ -z /usr/local/var/lib/rkhunter/db -o /usr/local/var/lib/rkhunter/db = '""' -o /usr/local/var/lib/rkhunter/db = \'\' ]
  2177. + echo /usr/local/var/lib/rkhunter/db
  2178. + tr -d \'
  2179. + tr -d '" '
  2180. + OPTVAR=/usr/local/var/lib/rkhunter/db
  2181. + echo /usr/local/var/lib/rkhunter/db
  2182. + return 0
  2183. + DB_PATH=/usr/local/var/lib/rkhunter/db
  2184. + [ 0 -eq 0 ]
  2185. + check_paths DB_PATH DBDIR 'NOWILD EXIST NOBROKENLINK'
  2186. + OPT_VALUE_OPT=DB_PATH
  2187. + OPT_NAME=DBDIR
  2188. + STRICT='NOWILD EXIST NOBROKENLINK'
  2189. + test -z DBDIR
  2190. + eval echo '"$DB_PATH"'
  2191. + echo /usr/local/var/lib/rkhunter/db
  2192. + OPT_VALUE=/usr/local/var/lib/rkhunter/db
  2193. + ERRCODE=0
  2194. + test -z /usr/local/var/lib/rkhunter/db
  2195. + MUSTEXIST=0
  2196. + NOWILD=0
  2197. + NOLINK=0
  2198. + NOWILD=1
  2199. + MUSTEXIST=1
  2200. + NOLINK=1
  2201. + echo '/usr/local/var/lib/rkhunter/db '
  2202. + grep ^-
  2203. + RKHTMPVAR=''
  2204. + [ -n '' ]
  2205. + [ 1 -eq 1 ]
  2206. + egrep '(^|[^\])[][?*{}]'
  2207. + echo /usr/local/var/lib/rkhunter/db
  2208. + RKHTMPVAR=''
  2209. + [ -n '' ]
  2210. + echo ' ALLOWDEVFILE ALLOWHIDDENDIR ALLOWHIDDENFILE ALLOWPROCDELFILE ALLOWPROCLISTEN ATTRWHITELIST EXCLUDE_USER_FILEPROP_FILES_DIRS EXISTWHITELIST IMMUTWHITELIST PKGMGR_NO_VRFY PORT_PATH_WHITELIST RTKT_DIR_WHITELIST RTKT_FILE_WHITELIST SCRIPTWHITELIST USER_FILEPROP_FILES_DIRS WRITEWHITELIST '
  2211. + grep ' DBDIR '
  2212. + [ -n '' ]
  2213. + test -z /usr/local/var/lib/rkhunter/db
  2214. + echo /usr/local/var/lib/rkhunter/db
  2215. + egrep '(^[./]*$)|[;&]|/\.\./'
  2216. + [ -n '' ]
  2217. + grep '^[^/].*/'
  2218. + echo /usr/local/var/lib/rkhunter/db
  2219. + [ -n '' ]
  2220. + echo /usr/local/var/lib/rkhunter/db
  2221. + grep ^/
  2222. + [ -z /usr/local/var/lib/rkhunter/db ]
  2223. + [ -f /usr/local/var/lib/rkhunter/db ]
  2224. + [ -d /usr/local/var/lib/rkhunter/db ]
  2225. + test DBDIR = ALLOWHIDDENFILE -a -h /usr/local/var/lib/rkhunter/db
  2226. + IFS='
  2227. '
  2228. + return
  2229. + [ 0 -eq 0 ]
  2230. + [ -z /usr/local/var/lib/rkhunter/db ]
  2231. + [ 0 -eq 1 ]
  2232. + [ ! -e /usr/local/var/lib/rkhunter/db ]
  2233. + [ ! -d /usr/local/var/lib/rkhunter/db ]
  2234. + [ ! -r /usr/local/var/lib/rkhunter/db ]
  2235. + [ 0 -eq 1 -o 0 -eq 1 -o 0 -eq 1 ]
  2236. + [ 0 -eq 0 ]
  2237. + RKHDAT_FILE=/usr/local/var/lib/rkhunter/db/rkhunter.dat
  2238. + RKH_FILEPROP_LIST=/usr/local/var/lib/rkhunter/db/rkhunter_prop_list.dat
  2239. + return
  2240. + get_language_option
  2241. + LEAVE=0
  2242. + [ -n '' ]
  2243. + get_option single LANGUAGE
  2244. + OPTMULTI=single
  2245. + OPTNAME=LANGUAGE
  2246. + ERRCODE=0
  2247. + [ -z single -o -z LANGUAGE ]
  2248. + grep -h ^LANGUAGE= /usr/local/etc/rkhunter.conf
  2249. + RKHTMPVAR2=''
  2250. + [ -z '' ]
  2251. + echo ''
  2252. + return 0
  2253. + LANGUAGE=''
  2254. + test 0 -eq 1
  2255. + test -z ''
  2256. + LANGUAGE=en
  2257. + [ ! -d /usr/local/var/lib/rkhunter/db/i18n ]
  2258. + [ 0 -eq 0 ]
  2259. + [ ! -s /usr/local/var/lib/rkhunter/db/i18n/en -a en != en ]
  2260. + [ ! -s /usr/local/var/lib/rkhunter/db/i18n/en ]
  2261. + [ en = de ]
  2262. + [ 0 -eq 1 ]
  2263. + [ 0 -eq 1 ]
  2264. + return
  2265. + get_auto_x_option
  2266. + LEAVE=0
  2267. + [ 0 -eq 0 ]
  2268. + get_option single AUTO_X_DETECT
  2269. + OPTMULTI=single
  2270. + OPTNAME=AUTO_X_DETECT
  2271. + ERRCODE=0
  2272. + [ -z single -o -z AUTO_X_DETECT ]
  2273. + grep -h ^AUTO_X_DETECT= /usr/local/etc/rkhunter.conf
  2274. + RKHTMPVAR2=AUTO_X_DETECT=1
  2275. + [ -z AUTO_X_DETECT=1 ]
  2276. + tail -n 1
  2277. + sed -e s/AUTO_X_DETECT=//
  2278. + echo AUTO_X_DETECT=1
  2279. + OPTVAR=1
  2280. + [ -z 1 -o 1 = '""' -o 1 = \'\' ]
  2281. + echo 1
  2282. + tr -d \'
  2283. + tr -d '" '
  2284. + OPTVAR=1
  2285. + echo 1
  2286. + return 0
  2287. + AUTO_X_DTCT=1
  2288. + [ 0 -eq 0 ]
  2289. + [ -n 1 ]
  2290. + check_is_digit AUTO_X_DTCT AUTO_X_DETECT
  2291. + OPT_VALUE=AUTO_X_DTCT
  2292. + OPT_NAME=AUTO_X_DETECT
  2293. + OTHERS=''
  2294. + test -z AUTO_X_DETECT
  2295. + test -z ''
  2296. + OTHERS=0
  2297. + eval echo '"$AUTO_X_DTCT"'
  2298. + echo 1
  2299. + RKHTMPVAR=1
  2300. + ERRCODE=0
  2301. + test -z 1
  2302. + [ 1 = 0 -a 0 = ANY1 ]
  2303. + [ 1 != 0 -a 1 != 1 ]
  2304. + return
  2305. + test 0 -eq 1
  2306. + [ 1 -eq 1 -a -n '' ]
  2307. + [ 0 -eq 0 ]
  2308. + get_option single COLOR_SET2
  2309. + OPTMULTI=single
  2310. + OPTNAME=COLOR_SET2
  2311. + ERRCODE=0
  2312. + [ -z single -o -z COLOR_SET2 ]
  2313. + grep -h ^COLOR_SET2= /usr/local/etc/rkhunter.conf
  2314. + RKHTMPVAR2=''
  2315. + [ -z '' ]
  2316. + echo ''
  2317. + return 0
  2318. + CLRSET2=''
  2319. + [ 0 -eq 0 ]
  2320. + [ -n '' ]
  2321. + CLRSET2=0
  2322. + get_option single WHITELISTED_IS_WHITE
  2323. + OPTMULTI=single
  2324. + OPTNAME=WHITELISTED_IS_WHITE
  2325. + ERRCODE=0
  2326. + [ -z single -o -z WHITELISTED_IS_WHITE ]
  2327. + grep -h ^WHITELISTED_IS_WHITE= /usr/local/etc/rkhunter.conf
  2328. + RKHTMPVAR2=''
  2329. + [ -z '' ]
  2330. + echo ''
  2331. + return 0
  2332. + WLIST_IS_WHITE=''
  2333. + [ 0 -eq 0 ]
  2334. + [ -n '' ]
  2335. + WLIST_IS_WHITE=0
  2336. + [ 0 -eq 1 ]
  2337. + return
  2338. + get_locking_options
  2339. + LEAVE=0
  2340. + get_option single USE_LOCKING
  2341. + OPTMULTI=single
  2342. + OPTNAME=USE_LOCKING
  2343. + ERRCODE=0
  2344. + [ -z single -o -z USE_LOCKING ]
  2345. + grep -h ^USE_LOCKING= /usr/local/etc/rkhunter.conf
  2346. + RKHTMPVAR2=''
  2347. + [ -z '' ]
  2348. + echo ''
  2349. + return 0
  2350. + USE_LOCKING=''
  2351. + [ 0 -eq 0 ]
  2352. + [ -n '' ]
  2353. + USE_LOCKING=0
  2354. + get_option single LOCK_TIMEOUT
  2355. + OPTMULTI=single
  2356. + OPTNAME=LOCK_TIMEOUT
  2357. + ERRCODE=0
  2358. + [ -z single -o -z LOCK_TIMEOUT ]
  2359. + grep -h ^LOCK_TIMEOUT= /usr/local/etc/rkhunter.conf
  2360. + RKHTMPVAR2=''
  2361. + [ -z '' ]
  2362. + echo ''
  2363. + return 0
  2364. + LOCK_TIMEOUT=''
  2365. + [ 0 -eq 0 ]
  2366. + [ -n '' ]
  2367. + LOCK_TIMEOUT=300
  2368. + [ 0 -eq 0 ]
  2369. + get_option single SHOW_LOCK_MSGS
  2370. + OPTMULTI=single
  2371. + OPTNAME=SHOW_LOCK_MSGS
  2372. + ERRCODE=0
  2373. + [ -z single -o -z SHOW_LOCK_MSGS ]
  2374. + grep -h ^SHOW_LOCK_MSGS= /usr/local/etc/rkhunter.conf
  2375. + RKHTMPVAR2=''
  2376. + [ -z '' ]
  2377. + echo ''
  2378. + return 0
  2379. + SHOW_LOCK_MSGS=''
  2380. + [ 0 -eq 0 ]
  2381. + [ -n '' ]
  2382. + SHOW_LOCK_MSGS=1
  2383. + [ 0 -eq 1 ]
  2384. + return
  2385. + [ 1 -eq 1 -o 0 -eq 1 -o 0 -eq 1 ]
  2386. + get_enable_option
  2387. + LEAVE=0
  2388. + [ 1 -eq 1 ]
  2389. + tr -d '"'
  2390. + tr -d \'
  2391. + echo filesystem
  2392. + tr , ' '
  2393. + ENABLE_TESTS=filesystem
  2394. + echo filesystem
  2395. + ENABLE_TESTS=filesystem
  2396. + [ -z filesystem ]
  2397. + echo filesystem
  2398. + tr '[:upper:]' '[:lower:]'
  2399. + ENABLE_TESTS=filesystem
  2400. + grep ' '
  2401. + echo filesystem
  2402. + [ filesystem != all -a -z '' ]
  2403. + SKIP_KEY_PRESS=1
  2404. + [ 0 -eq 1 ]
  2405. + return
  2406. + get_disable_option
  2407. + LEAVE=0
  2408. + [ -n '' ]
  2409. + [ 1 -eq 1 ]
  2410. + get_option space-list DISABLE_TESTS
  2411. + OPTMULTI=space-list
  2412. + OPTNAME=DISABLE_TESTS
  2413. + ERRCODE=0
  2414. + [ -z space-list -o -z DISABLE_TESTS ]
  2415. + grep -h ^DISABLE_TESTS= /usr/local/etc/rkhunter.conf
  2416. + RKHTMPVAR2='DISABLE_TESTS=suspscan hidden_ports hidden_procs deleted_files packet_cap_apps'
  2417. + [ -z 'DISABLE_TESTS=suspscan hidden_ports hidden_procs deleted_files packet_cap_apps' ]
  2418. + echo 'DISABLE_TESTS=suspscan hidden_ports hidden_procs deleted_files packet_cap_apps'
  2419. + sed -e s/DISABLE_TESTS=//
  2420. + tail -n 1
  2421. + RKHTMPVAR3='suspscan hidden_ports hidden_procs deleted_files packet_cap_apps'
  2422. + [ -z 'suspscan hidden_ports hidden_procs deleted_files packet_cap_apps' -o 'suspscan hidden_ports hidden_procs deleted_files packet_cap_apps' = '""' -o 'suspscan hidden_ports hidden_procs deleted_files packet_cap_apps' = \'\' ]
  2423. + sed -e s/DISABLE_TESTS=//
  2424. + echo 'DISABLE_TESTS=suspscan hidden_ports hidden_procs deleted_files packet_cap_apps'
  2425. + OPTVAR='suspscan hidden_ports hidden_procs deleted_files packet_cap_apps'
  2426. + grep ^-
  2427. + echo 'suspscan hidden_ports hidden_procs deleted_files packet_cap_apps '
  2428. + test -n ''
  2429. + [ space-list = space-list ]
  2430. + tr -s ' ' ' '
  2431. + echo 'suspscan hidden_ports hidden_procs deleted_files packet_cap_apps'
  2432. + OPTVAR='suspscan hidden_ports hidden_procs deleted_files packet_cap_apps'
  2433. + sed -e 's/^ *"* *//; s/ *"* *$//'
  2434. + sed -e 's/^ *'\''* *//; s/ *'\''* *$//'
  2435. + echo 'suspscan hidden_ports hidden_procs deleted_files packet_cap_apps'
  2436. + OPTVAR='suspscan hidden_ports hidden_procs deleted_files packet_cap_apps'
  2437. + grep ^-
  2438. + echo 'suspscan hidden_ports hidden_procs deleted_files packet_cap_apps '
  2439. + test -n ''
  2440. + [ -n 'suspscan hidden_ports hidden_procs deleted_files packet_cap_apps' ]
  2441. + echo 'suspscan hidden_ports hidden_procs deleted_files packet_cap_apps'
  2442. + wc -l
  2443. + tr -d ' '
  2444. + RKHLINES=1
  2445. + echo 'suspscan hidden_ports hidden_procs deleted_files packet_cap_apps'
  2446. + echo 1
  2447. + awk -v l=1 '/./ { if (a) { a = a "\n" $0 } else a = $0 }; /^$/ { a = "" }; NR == l { print a }'
  2448. + OPTVAR='suspscan hidden_ports hidden_procs deleted_files packet_cap_apps'
  2449. + echo 'suspscan hidden_ports hidden_procs deleted_files packet_cap_apps '
  2450. + grep ^-
  2451. + test -n ''
  2452. + echo 'suspscan hidden_ports hidden_procs deleted_files packet_cap_apps'
  2453. + return 0
  2454. + CONFIG_DISABLE_TESTS='suspscan hidden_ports hidden_procs deleted_files packet_cap_apps'
  2455. + test 0 -eq 1
  2456. + [ 0 -eq 0 ]
  2457. + DISABLE_TESTS=' suspscan hidden_ports hidden_procs deleted_files packet_cap_apps'
  2458. + echo suspscan hidden_ports hidden_procs deleted_files packet_cap_apps
  2459. + DISABLE_TESTS='suspscan hidden_ports hidden_procs deleted_files packet_cap_apps'
  2460. + [ -z 'suspscan hidden_ports hidden_procs deleted_files packet_cap_apps' ]
  2461. + tr '[:upper:]' '[:lower:]'
  2462. + echo 'suspscan hidden_ports hidden_procs deleted_files packet_cap_apps'
  2463. + DISABLE_TESTS='suspscan hidden_ports hidden_procs deleted_files packet_cap_apps'
  2464. + return
  2465. + check_test_options
  2466. + SEEN=0
  2467. + LEAVE=0
  2468. + echo strings properties hashes scripts immutable attributes deleted_files packet_cap_apps apps rootkits known_rkts additional_rkts malware local_host network passwd_changes group_changes possible_rkt_files possible_rkt_strings system_commands shared_libs shared_libs_path running_procs hidden_procs trojans other_malware os_specific startup_malware startup_files group_accounts system_configs filesystem suspscan ports hidden_ports promisc loaded_modules avail_modules
  2469. + RKHTMPVAR=' strings properties hashes scripts immutable attributes deleted_files packet_cap_apps apps rootkits known_rkts additional_rkts malware local_host network passwd_changes group_changes possible_rkt_files possible_rkt_strings system_commands shared_libs shared_libs_path running_procs hidden_procs trojans other_malware os_specific startup_malware startup_files group_accounts system_configs filesystem suspscan ports hidden_ports promisc loaded_modules avail_modules '
  2470. + [ filesystem = all ]
  2471. + [ filesystem = none ]
  2472. + echo ' strings properties hashes scripts immutable attributes deleted_files packet_cap_apps apps rootkits known_rkts additional_rkts malware local_host network passwd_changes group_changes possible_rkt_files possible_rkt_strings system_commands shared_libs shared_libs_path running_procs hidden_procs trojans other_malware os_specific startup_malware startup_files group_accounts system_configs filesystem suspscan ports hidden_ports promisc loaded_modules avail_modules '
  2473. + grep ' filesystem '
  2474. + [ -z ' strings properties hashes scripts immutable attributes deleted_files packet_cap_apps apps rootkits known_rkts additional_rkts malware local_host network passwd_changes group_changes possible_rkt_files possible_rkt_strings system_commands shared_libs shared_libs_path running_procs hidden_procs trojans other_malware os_specific startup_malware startup_files group_accounts system_configs filesystem suspscan ports hidden_ports promisc loaded_modules avail_modules ' ]
  2475. + test 0 -eq 1
  2476. + SEEN=0
  2477. + [ 1 -eq 1 ]
  2478. + [ suspscan = none ]
  2479. + [ suspscan = all ]
  2480. + echo ' strings properties hashes scripts immutable attributes deleted_files packet_cap_apps apps rootkits known_rkts additional_rkts malware local_host network passwd_changes group_changes possible_rkt_files possible_rkt_strings system_commands shared_libs shared_libs_path running_procs hidden_procs trojans other_malware os_specific startup_malware startup_files group_accounts system_configs filesystem suspscan ports hidden_ports promisc loaded_modules avail_modules '
  2481. + grep ' suspscan '
  2482. + [ -z ' strings properties hashes scripts immutable attributes deleted_files packet_cap_apps apps rootkits known_rkts additional_rkts malware local_host network passwd_changes group_changes possible_rkt_files possible_rkt_strings system_commands shared_libs shared_libs_path running_procs hidden_procs trojans other_malware os_specific startup_malware startup_files group_accounts system_configs filesystem suspscan ports hidden_ports promisc loaded_modules avail_modules ' ]
  2483. + [ hidden_ports = none ]
  2484. + [ hidden_ports = all ]
  2485. + grep ' hidden_ports '
  2486. + echo ' strings properties hashes scripts immutable attributes deleted_files packet_cap_apps apps rootkits known_rkts additional_rkts malware local_host network passwd_changes group_changes possible_rkt_files possible_rkt_strings system_commands shared_libs shared_libs_path running_procs hidden_procs trojans other_malware os_specific startup_malware startup_files group_accounts system_configs filesystem suspscan ports hidden_ports promisc loaded_modules avail_modules '
  2487. + [ -z ' strings properties hashes scripts immutable attributes deleted_files packet_cap_apps apps rootkits known_rkts additional_rkts malware local_host network passwd_changes group_changes possible_rkt_files possible_rkt_strings system_commands shared_libs shared_libs_path running_procs hidden_procs trojans other_malware os_specific startup_malware startup_files group_accounts system_configs filesystem suspscan ports hidden_ports promisc loaded_modules avail_modules ' ]
  2488. + [ hidden_procs = none ]
  2489. + [ hidden_procs = all ]
  2490. + echo ' strings properties hashes scripts immutable attributes deleted_files packet_cap_apps apps rootkits known_rkts additional_rkts malware local_host network passwd_changes group_changes possible_rkt_files possible_rkt_strings system_commands shared_libs shared_libs_path running_procs hidden_procs trojans other_malware os_specific startup_malware startup_files group_accounts system_configs filesystem suspscan ports hidden_ports promisc loaded_modules avail_modules '
  2491. + grep ' hidden_procs '
  2492. + [ -z ' strings properties hashes scripts immutable attributes deleted_files packet_cap_apps apps rootkits known_rkts additional_rkts malware local_host network passwd_changes group_changes possible_rkt_files possible_rkt_strings system_commands shared_libs shared_libs_path running_procs hidden_procs trojans other_malware os_specific startup_malware startup_files group_accounts system_configs filesystem suspscan ports hidden_ports promisc loaded_modules avail_modules ' ]
  2493. + [ deleted_files = none ]
  2494. + [ deleted_files = all ]
  2495. + grep ' deleted_files '
  2496. + echo ' strings properties hashes scripts immutable attributes deleted_files packet_cap_apps apps rootkits known_rkts additional_rkts malware local_host network passwd_changes group_changes possible_rkt_files possible_rkt_strings system_commands shared_libs shared_libs_path running_procs hidden_procs trojans other_malware os_specific startup_malware startup_files group_accounts system_configs filesystem suspscan ports hidden_ports promisc loaded_modules avail_modules '
  2497. + [ -z ' strings properties hashes scripts immutable attributes deleted_files packet_cap_apps apps rootkits known_rkts additional_rkts malware local_host network passwd_changes group_changes possible_rkt_files possible_rkt_strings system_commands shared_libs shared_libs_path running_procs hidden_procs trojans other_malware os_specific startup_malware startup_files group_accounts system_configs filesystem suspscan ports hidden_ports promisc loaded_modules avail_modules ' ]
  2498. + [ packet_cap_apps = none ]
  2499. + [ packet_cap_apps = all ]
  2500. + echo ' strings properties hashes scripts immutable attributes deleted_files packet_cap_apps apps rootkits known_rkts additional_rkts malware local_host network passwd_changes group_changes possible_rkt_files possible_rkt_strings system_commands shared_libs shared_libs_path running_procs hidden_procs trojans other_malware os_specific startup_malware startup_files group_accounts system_configs filesystem suspscan ports hidden_ports promisc loaded_modules avail_modules '
  2501. + grep ' packet_cap_apps '
  2502. + [ -z ' strings properties hashes scripts immutable attributes deleted_files packet_cap_apps apps rootkits known_rkts additional_rkts malware local_host network passwd_changes group_changes possible_rkt_files possible_rkt_strings system_commands shared_libs shared_libs_path running_procs hidden_procs trojans other_malware os_specific startup_malware startup_files group_accounts system_configs filesystem suspscan ports hidden_ports promisc loaded_modules avail_modules ' ]
  2503. + [ 0 -eq 1 ]
  2504. + test 0 -eq 1
  2505. + test filesystem = all
  2506. + [ 1 -eq 1 -a 'suspscan hidden_ports hidden_procs deleted_files packet_cap_apps' != none ]
  2507. + GROUP_TEST_NAMES=''
  2508. + echo system_commands:properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes
  2509. + cut -d: -f1
  2510. + GROUP_TEST_NAMES=' system_commands'
  2511. + echo properties:hashes:scripts:immutable:attributes
  2512. + cut -d: -f1
  2513. + GROUP_TEST_NAMES=' system_commands properties'
  2514. + echo shared_libs:shared_libs_path
  2515. + cut -d: -f1
  2516. + GROUP_TEST_NAMES=' system_commands properties shared_libs'
  2517. + echo rootkits:known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules
  2518. + cut -d: -f1
  2519. + GROUP_TEST_NAMES=' system_commands properties shared_libs rootkits'
  2520. + echo additional_rkts:possible_rkt_files:possible_rkt_strings
  2521. + cut -d: -f1
  2522. + GROUP_TEST_NAMES=' system_commands properties shared_libs rootkits additional_rkts'
  2523. + echo network:packet_cap_apps:ports:hidden_ports:promisc
  2524. + cut -d: -f1
  2525. + GROUP_TEST_NAMES=' system_commands properties shared_libs rootkits additional_rkts network'
  2526. + echo malware:running_procs:hidden_procs:deleted_files:suspscan:other_malware
  2527. + cut -d: -f1
  2528. + GROUP_TEST_NAMES=' system_commands properties shared_libs rootkits additional_rkts network malware'
  2529. + echo local_host:startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem
  2530. + cut -d: -f1
  2531. + GROUP_TEST_NAMES=' system_commands properties shared_libs rootkits additional_rkts network malware local_host'
  2532. + echo startup_files:startup_malware
  2533. + cut -d: -f1
  2534. + GROUP_TEST_NAMES=' system_commands properties shared_libs rootkits additional_rkts network malware local_host startup_files'
  2535. + cut -d: -f1
  2536. + echo os_specific:loaded_modules:avail_modules
  2537. + GROUP_TEST_NAMES=' system_commands properties shared_libs rootkits additional_rkts network malware local_host startup_files os_specific'
  2538. + cut -d: -f1
  2539. + echo group_accounts:passwd_changes:group_changes
  2540. + GROUP_TEST_NAMES=' system_commands properties shared_libs rootkits additional_rkts network malware local_host startup_files os_specific group_accounts'
  2541. + echo system_commands properties shared_libs rootkits additional_rkts network malware local_host startup_files os_specific group_accounts
  2542. + GROUP_TEST_NAMES=' system_commands properties shared_libs rootkits additional_rkts network malware local_host startup_files os_specific group_accounts '
  2543. + DISABLE_TESTS=' suspscan hidden_ports hidden_procs deleted_files packet_cap_apps '
  2544. + grep ' filesystem '
  2545. + echo ' system_commands properties shared_libs rootkits additional_rkts network malware local_host startup_files os_specific group_accounts '
  2546. + [ -z '' ]
  2547. + echo ' suspscan hidden_ports hidden_procs deleted_files packet_cap_apps '
  2548. + grep ' filesystem '
  2549. + [ -n '' ]
  2550. + echo suspscan hidden_ports hidden_procs deleted_files packet_cap_apps
  2551. + DISABLE_TESTS='suspscan hidden_ports hidden_procs deleted_files packet_cap_apps'
  2552. + [ -z 'suspscan hidden_ports hidden_procs deleted_files packet_cap_apps' ]
  2553. + sort_test_lists 2
  2554. + RKHTMPVAR=2
  2555. + test 2 -eq 1
  2556. + test 2 -eq 2
  2557. + tr ' ' '\n'
  2558. + sort
  2559. + echo suspscan hidden_ports hidden_procs deleted_files packet_cap_apps
  2560. + uniq
  2561. + DISABLE_TESTS='deleted_files
  2562. hidden_ports
  2563. hidden_procs
  2564. packet_cap_apps
  2565. suspscan'
  2566. + echo filesystem
  2567. + ENABLE_TESTS=filesystem
  2568. + echo deleted_files hidden_ports hidden_procs packet_cap_apps suspscan
  2569. + DISABLE_TESTS='deleted_files hidden_ports hidden_procs packet_cap_apps suspscan'
  2570. + [ filesystem = 'deleted_files hidden_ports hidden_procs packet_cap_apps suspscan' ]
  2571. + return
  2572. + cut -d: -f1
  2573. + echo system_commands:properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes
  2574. + GROUP_NAME=system_commands
  2575. + echo system_commands:properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes
  2576. + grep :
  2577. + [ -n system_commands:properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes ]
  2578. + cut -d: -f2-
  2579. + echo system_commands:properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes
  2580. + GROUP_TESTS=properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes
  2581. + [ filesystem = system_commands ]
  2582. + [ -z properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes ]
  2583. + grep :filesystem:
  2584. + echo :properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes:
  2585. + [ -n '' ]
  2586. + echo properties:hashes:scripts:immutable:attributes
  2587. + cut -d: -f1
  2588. + GROUP_NAME=properties
  2589. + grep :
  2590. + echo properties:hashes:scripts:immutable:attributes
  2591. + [ -n properties:hashes:scripts:immutable:attributes ]
  2592. + echo properties:hashes:scripts:immutable:attributes
  2593. + cut -d: -f2-
  2594. + GROUP_TESTS=hashes:scripts:immutable:attributes
  2595. + [ filesystem = properties ]
  2596. + [ -z hashes:scripts:immutable:attributes ]
  2597. + echo :hashes:scripts:immutable:attributes:
  2598. + grep :filesystem:
  2599. + [ -n '' ]
  2600. + echo shared_libs:shared_libs_path
  2601. + cut -d: -f1
  2602. + GROUP_NAME=shared_libs
  2603. + echo shared_libs:shared_libs_path
  2604. + grep :
  2605. + [ -n shared_libs:shared_libs_path ]
  2606. + echo shared_libs:shared_libs_path
  2607. + cut -d: -f2-
  2608. + GROUP_TESTS=shared_libs_path
  2609. + [ filesystem = shared_libs ]
  2610. + [ -z shared_libs_path ]
  2611. + echo :shared_libs_path:
  2612. + grep :filesystem:
  2613. + [ -n '' ]
  2614. + cut -d: -f1
  2615. + echo rootkits:known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules
  2616. + GROUP_NAME=rootkits
  2617. + grep :
  2618. + echo rootkits:known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules
  2619. + [ -n rootkits:known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules ]
  2620. + cut -d: -f2-
  2621. + echo rootkits:known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules
  2622. + GROUP_TESTS=known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules
  2623. + [ filesystem = rootkits ]
  2624. + [ -z known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules ]
  2625. + grep :filesystem:
  2626. + echo :known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules:
  2627. + [ -n '' ]
  2628. + echo additional_rkts:possible_rkt_files:possible_rkt_strings
  2629. + cut -d: -f1
  2630. + GROUP_NAME=additional_rkts
  2631. + echo additional_rkts:possible_rkt_files:possible_rkt_strings
  2632. + grep :
  2633. + [ -n additional_rkts:possible_rkt_files:possible_rkt_strings ]
  2634. + echo additional_rkts:possible_rkt_files:possible_rkt_strings
  2635. + cut -d: -f2-
  2636. + GROUP_TESTS=possible_rkt_files:possible_rkt_strings
  2637. + [ filesystem = additional_rkts ]
  2638. + [ -z possible_rkt_files:possible_rkt_strings ]
  2639. + echo :possible_rkt_files:possible_rkt_strings:
  2640. + grep :filesystem:
  2641. + [ -n '' ]
  2642. + echo network:packet_cap_apps:ports:hidden_ports:promisc
  2643. + cut -d: -f1
  2644. + GROUP_NAME=network
  2645. + echo network:packet_cap_apps:ports:hidden_ports:promisc
  2646. + grep :
  2647. + [ -n network:packet_cap_apps:ports:hidden_ports:promisc ]
  2648. + cut -d: -f2-
  2649. + echo network:packet_cap_apps:ports:hidden_ports:promisc
  2650. + GROUP_TESTS=packet_cap_apps:ports:hidden_ports:promisc
  2651. + [ filesystem = network ]
  2652. + [ -z packet_cap_apps:ports:hidden_ports:promisc ]
  2653. + grep :filesystem:
  2654. + echo :packet_cap_apps:ports:hidden_ports:promisc:
  2655. + [ -n '' ]
  2656. + cut -d: -f1
  2657. + echo malware:running_procs:hidden_procs:deleted_files:suspscan:other_malware
  2658. + GROUP_NAME=malware
  2659. + grep :
  2660. + echo malware:running_procs:hidden_procs:deleted_files:suspscan:other_malware
  2661. + [ -n malware:running_procs:hidden_procs:deleted_files:suspscan:other_malware ]
  2662. + echo malware:running_procs:hidden_procs:deleted_files:suspscan:other_malware
  2663. + cut -d: -f2-
  2664. + GROUP_TESTS=running_procs:hidden_procs:deleted_files:suspscan:other_malware
  2665. + [ filesystem = malware ]
  2666. + [ -z running_procs:hidden_procs:deleted_files:suspscan:other_malware ]
  2667. + echo :running_procs:hidden_procs:deleted_files:suspscan:other_malware:
  2668. + grep :filesystem:
  2669. + [ -n '' ]
  2670. + echo local_host:startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem
  2671. + cut -d: -f1
  2672. + GROUP_NAME=local_host
  2673. + echo local_host:startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem
  2674. + grep :
  2675. + [ -n local_host:startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem ]
  2676. + echo local_host:startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem
  2677. + cut -d: -f2-
  2678. + GROUP_TESTS=startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem
  2679. + [ filesystem = local_host ]
  2680. + [ -z startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem ]
  2681. + echo :startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem:
  2682. + grep :filesystem:
  2683. + [ -n :startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem: ]
  2684. + ENABLE_TESTS='filesystem local_host'
  2685. + cut -d: -f1
  2686. + echo startup_files:startup_malware
  2687. + GROUP_NAME=startup_files
  2688. + grep :
  2689. + echo startup_files:startup_malware
  2690. + [ -n startup_files:startup_malware ]
  2691. + cut -d: -f2-
  2692. + echo startup_files:startup_malware
  2693. + GROUP_TESTS=startup_malware
  2694. + [ filesystem = startup_files ]
  2695. + [ -z startup_malware ]
  2696. + grep :filesystem:
  2697. + echo :startup_malware:
  2698. + [ -n '' ]
  2699. + echo os_specific:loaded_modules:avail_modules
  2700. + cut -d: -f1
  2701. + GROUP_NAME=os_specific
  2702. + echo os_specific:loaded_modules:avail_modules
  2703. + grep :
  2704. + [ -n os_specific:loaded_modules:avail_modules ]
  2705. + echo os_specific:loaded_modules:avail_modules
  2706. + cut -d: -f2-
  2707. + GROUP_TESTS=loaded_modules:avail_modules
  2708. + [ filesystem = os_specific ]
  2709. + [ -z loaded_modules:avail_modules ]
  2710. + echo :loaded_modules:avail_modules:
  2711. + grep :filesystem:
  2712. + [ -n '' ]
  2713. + echo group_accounts:passwd_changes:group_changes
  2714. + cut -d: -f1
  2715. + GROUP_NAME=group_accounts
  2716. + echo group_accounts:passwd_changes:group_changes
  2717. + grep :
  2718. + [ -n group_accounts:passwd_changes:group_changes ]
  2719. + cut -d: -f2-
  2720. + echo group_accounts:passwd_changes:group_changes
  2721. + GROUP_TESTS=passwd_changes:group_changes
  2722. + [ filesystem = group_accounts ]
  2723. + [ -z passwd_changes:group_changes ]
  2724. + echo :passwd_changes:group_changes:
  2725. + grep :filesystem:
  2726. + [ -n '' ]
  2727. + echo filesystem local_host
  2728. + ENABLE_TESTS='filesystem local_host'
  2729. + sort_test_lists 1
  2730. + RKHTMPVAR=1
  2731. + test 1 -eq 1
  2732. + echo filesystem local_host
  2733. + tr ' ' '\n'
  2734. + sort
  2735. + uniq
  2736. + ENABLE_TESTS='filesystem
  2737. local_host'
  2738. + test 1 -eq 2
  2739. + echo filesystem local_host
  2740. + ENABLE_TESTS='filesystem local_host'
  2741. + echo deleted_files hidden_ports hidden_procs packet_cap_apps suspscan
  2742. + DISABLE_TESTS='deleted_files hidden_ports hidden_procs packet_cap_apps suspscan'
  2743. + [ 'filesystem local_host' = 'deleted_files hidden_ports hidden_procs packet_cap_apps suspscan' ]
  2744. + return
  2745. + [ 'deleted_files hidden_ports hidden_procs packet_cap_apps suspscan' != none ]
  2746. + TEMP_EN_TESTS='filesystem local_host'
  2747. + TEMP_DIS_TESTS='deleted_files hidden_ports hidden_procs packet_cap_apps suspscan'
  2748. + echo system_commands:properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes
  2749. + cut -d: -f1
  2750. + GROUP_NAME=system_commands
  2751. + echo system_commands:properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes
  2752. + grep :
  2753. + [ -n system_commands:properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes ]
  2754. + echo system_commands:properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes
  2755. + cut -d: -f2-
  2756. + GROUP_TESTS=properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes
  2757. + [ deleted_files = system_commands ]
  2758. + [ -z properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes ]
  2759. + echo :properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes:
  2760. + grep :deleted_files:
  2761. + [ -n '' ]
  2762. + echo properties:hashes:scripts:immutable:attributes
  2763. + cut -d: -f1
  2764. + GROUP_NAME=properties
  2765. + echo properties:hashes:scripts:immutable:attributes
  2766. + grep :
  2767. + [ -n properties:hashes:scripts:immutable:attributes ]
  2768. + cut -d: -f2-
  2769. + echo properties:hashes:scripts:immutable:attributes
  2770. + GROUP_TESTS=hashes:scripts:immutable:attributes
  2771. + [ deleted_files = properties ]
  2772. + [ -z hashes:scripts:immutable:attributes ]
  2773. + grep :deleted_files:
  2774. + echo :hashes:scripts:immutable:attributes:
  2775. + [ -n '' ]
  2776. + cut -d: -f1
  2777. + echo shared_libs:shared_libs_path
  2778. + GROUP_NAME=shared_libs
  2779. + grep :
  2780. + echo shared_libs:shared_libs_path
  2781. + [ -n shared_libs:shared_libs_path ]
  2782. + echo shared_libs:shared_libs_path
  2783. + cut -d: -f2-
  2784. + GROUP_TESTS=shared_libs_path
  2785. + [ deleted_files = shared_libs ]
  2786. + [ -z shared_libs_path ]
  2787. + grep :deleted_files:
  2788. + echo :shared_libs_path:
  2789. + [ -n '' ]
  2790. + echo rootkits:known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules
  2791. + cut -d: -f1
  2792. + GROUP_NAME=rootkits
  2793. + echo rootkits:known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules
  2794. + grep :
  2795. + [ -n rootkits:known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules ]
  2796. + echo rootkits:known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules
  2797. + cut -d: -f2-
  2798. + GROUP_TESTS=known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules
  2799. + [ deleted_files = rootkits ]
  2800. + [ -z known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules ]
  2801. + echo :known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules:
  2802. + grep :deleted_files:
  2803. + [ -n :known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules: ]
  2804. + TEMP_DIS_TESTS='deleted_files hidden_ports hidden_procs packet_cap_apps suspscan rootkits'
  2805. + cut -d: -f1
  2806. + echo additional_rkts:possible_rkt_files:possible_rkt_strings
  2807. + GROUP_NAME=additional_rkts
  2808. + grep :
  2809. + echo additional_rkts:possible_rkt_files:possible_rkt_strings
  2810. + [ -n additional_rkts:possible_rkt_files:possible_rkt_strings ]
  2811. + cut -d: -f2-
  2812. + echo additional_rkts:possible_rkt_files:possible_rkt_strings
  2813. + GROUP_TESTS=possible_rkt_files:possible_rkt_strings
  2814. + [ deleted_files = additional_rkts ]
  2815. + [ -z possible_rkt_files:possible_rkt_strings ]
  2816. + grep :deleted_files:
  2817. + echo :possible_rkt_files:possible_rkt_strings:
  2818. + [ -n '' ]
  2819. + cut -d: -f1
  2820. + echo network:packet_cap_apps:ports:hidden_ports:promisc
  2821. + GROUP_NAME=network
  2822. + grep :
  2823. + echo network:packet_cap_apps:ports:hidden_ports:promisc
  2824. + [ -n network:packet_cap_apps:ports:hidden_ports:promisc ]
  2825. + echo network:packet_cap_apps:ports:hidden_ports:promisc
  2826. + cut -d: -f2-
  2827. + GROUP_TESTS=packet_cap_apps:ports:hidden_ports:promisc
  2828. + [ deleted_files = network ]
  2829. + [ -z packet_cap_apps:ports:hidden_ports:promisc ]
  2830. + echo :packet_cap_apps:ports:hidden_ports:promisc:
  2831. + grep :deleted_files:
  2832. + [ -n '' ]
  2833. + echo malware:running_procs:hidden_procs:deleted_files:suspscan:other_malware
  2834. + cut -d: -f1
  2835. + GROUP_NAME=malware
  2836. + echo malware:running_procs:hidden_procs:deleted_files:suspscan:other_malware
  2837. + grep :
  2838. + [ -n malware:running_procs:hidden_procs:deleted_files:suspscan:other_malware ]
  2839. + cut -d: -f2-
  2840. + echo malware:running_procs:hidden_procs:deleted_files:suspscan:other_malware
  2841. + GROUP_TESTS=running_procs:hidden_procs:deleted_files:suspscan:other_malware
  2842. + [ deleted_files = malware ]
  2843. + [ -z running_procs:hidden_procs:deleted_files:suspscan:other_malware ]
  2844. + echo :running_procs:hidden_procs:deleted_files:suspscan:other_malware:
  2845. + grep :deleted_files:
  2846. + [ -n :running_procs:hidden_procs:deleted_files:suspscan:other_malware: ]
  2847. + TEMP_DIS_TESTS='deleted_files hidden_ports hidden_procs packet_cap_apps suspscan rootkits malware'
  2848. + cut -d: -f1
  2849. + echo local_host:startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem
  2850. + GROUP_NAME=local_host
  2851. + echo local_host:startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem
  2852. + grep :
  2853. + [ -n local_host:startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem ]
  2854. + echo local_host:startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem
  2855. + cut -d: -f2-
  2856. + GROUP_TESTS=startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem
  2857. + [ deleted_files = local_host ]
  2858. + [ -z startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem ]
  2859. + echo :startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem:
  2860. + grep :deleted_files:
  2861. + [ -n '' ]
  2862. + echo startup_files:startup_malware
  2863. + cut -d: -f1
  2864. + GROUP_NAME=startup_files
  2865. + echo startup_files:startup_malware
  2866. + grep :
  2867. + [ -n startup_files:startup_malware ]
  2868. + echo startup_files:startup_malware
  2869. + cut -d: -f2-
  2870. + GROUP_TESTS=startup_malware
  2871. + [ deleted_files = startup_files ]
  2872. + [ -z startup_malware ]
  2873. + echo :startup_malware:
  2874. + grep :deleted_files:
  2875. + [ -n '' ]
  2876. + cut -d: -f1
  2877. + echo os_specific:loaded_modules:avail_modules
  2878. + GROUP_NAME=os_specific
  2879. + echo os_specific:loaded_modules:avail_modules
  2880. + grep :
  2881. + [ -n os_specific:loaded_modules:avail_modules ]
  2882. + cut -d: -f2-
  2883. + echo os_specific:loaded_modules:avail_modules
  2884. + GROUP_TESTS=loaded_modules:avail_modules
  2885. + [ deleted_files = os_specific ]
  2886. + [ -z loaded_modules:avail_modules ]
  2887. + grep :deleted_files:
  2888. + echo :loaded_modules:avail_modules:
  2889. + [ -n '' ]
  2890. + cut -d: -f1
  2891. + echo group_accounts:passwd_changes:group_changes
  2892. + GROUP_NAME=group_accounts
  2893. + grep :
  2894. + echo group_accounts:passwd_changes:group_changes
  2895. + [ -n group_accounts:passwd_changes:group_changes ]
  2896. + echo group_accounts:passwd_changes:group_changes
  2897. + cut -d: -f2-
  2898. + GROUP_TESTS=passwd_changes:group_changes
  2899. + [ deleted_files = group_accounts ]
  2900. + [ -z passwd_changes:group_changes ]
  2901. + grep :deleted_files:
  2902. + echo :passwd_changes:group_changes:
  2903. + [ -n '' ]
  2904. + echo system_commands:properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes
  2905. + cut -d: -f1
  2906. + GROUP_NAME=system_commands
  2907. + echo system_commands:properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes
  2908. + grep :
  2909. + [ -n system_commands:properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes ]
  2910. + echo system_commands:properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes
  2911. + cut -d: -f2-
  2912. + GROUP_TESTS=properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes
  2913. + [ hidden_ports = system_commands ]
  2914. + [ -z properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes ]
  2915. + echo :properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes:
  2916. + grep :hidden_ports:
  2917. + [ -n '' ]
  2918. + cut -d: -f1
  2919. + echo properties:hashes:scripts:immutable:attributes
  2920. + GROUP_NAME=properties
  2921. + echo properties:hashes:scripts:immutable:attributes
  2922. + grep :
  2923. + [ -n properties:hashes:scripts:immutable:attributes ]
  2924. + cut -d: -f2-
  2925. + echo properties:hashes:scripts:immutable:attributes
  2926. + GROUP_TESTS=hashes:scripts:immutable:attributes
  2927. + [ hidden_ports = properties ]
  2928. + [ -z hashes:scripts:immutable:attributes ]
  2929. + grep :hidden_ports:
  2930. + echo :hashes:scripts:immutable:attributes:
  2931. + [ -n '' ]
  2932. + cut -d: -f1
  2933. + echo shared_libs:shared_libs_path
  2934. + GROUP_NAME=shared_libs
  2935. + grep :
  2936. + echo shared_libs:shared_libs_path
  2937. + [ -n shared_libs:shared_libs_path ]
  2938. + echo shared_libs:shared_libs_path
  2939. + cut -d: -f2-
  2940. + GROUP_TESTS=shared_libs_path
  2941. + [ hidden_ports = shared_libs ]
  2942. + [ -z shared_libs_path ]
  2943. + grep :hidden_ports:
  2944. + echo :shared_libs_path:
  2945. + [ -n '' ]
  2946. + echo rootkits:known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules
  2947. + cut -d: -f1
  2948. + GROUP_NAME=rootkits
  2949. + echo rootkits:known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules
  2950. + grep :
  2951. + [ -n rootkits:known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules ]
  2952. + echo rootkits:known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules
  2953. + cut -d: -f2-
  2954. + GROUP_TESTS=known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules
  2955. + [ hidden_ports = rootkits ]
  2956. + [ -z known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules ]
  2957. + echo :known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules:
  2958. + grep :hidden_ports:
  2959. + [ -n '' ]
  2960. + cut -d: -f1
  2961. + echo additional_rkts:possible_rkt_files:possible_rkt_strings
  2962. + GROUP_NAME=additional_rkts
  2963. + echo additional_rkts:possible_rkt_files:possible_rkt_strings
  2964. + grep :
  2965. + [ -n additional_rkts:possible_rkt_files:possible_rkt_strings ]
  2966. + cut -d: -f2-
  2967. + echo additional_rkts:possible_rkt_files:possible_rkt_strings
  2968. + GROUP_TESTS=possible_rkt_files:possible_rkt_strings
  2969. + [ hidden_ports = additional_rkts ]
  2970. + [ -z possible_rkt_files:possible_rkt_strings ]
  2971. + grep :hidden_ports:
  2972. + echo :possible_rkt_files:possible_rkt_strings:
  2973. + [ -n '' ]
  2974. + cut -d: -f1
  2975. + echo network:packet_cap_apps:ports:hidden_ports:promisc
  2976. + GROUP_NAME=network
  2977. + grep :
  2978. + echo network:packet_cap_apps:ports:hidden_ports:promisc
  2979. + [ -n network:packet_cap_apps:ports:hidden_ports:promisc ]
  2980. + echo network:packet_cap_apps:ports:hidden_ports:promisc
  2981. + cut -d: -f2-
  2982. + GROUP_TESTS=packet_cap_apps:ports:hidden_ports:promisc
  2983. + [ hidden_ports = network ]
  2984. + [ -z packet_cap_apps:ports:hidden_ports:promisc ]
  2985. + echo :packet_cap_apps:ports:hidden_ports:promisc:
  2986. + grep :hidden_ports:
  2987. + [ -n :packet_cap_apps:ports:hidden_ports:promisc: ]
  2988. + TEMP_DIS_TESTS='deleted_files hidden_ports hidden_procs packet_cap_apps suspscan rootkits malware network'
  2989. + echo malware:running_procs:hidden_procs:deleted_files:suspscan:other_malware
  2990. + cut -d: -f1
  2991. + GROUP_NAME=malware
  2992. + echo malware:running_procs:hidden_procs:deleted_files:suspscan:other_malware
  2993. + grep :
  2994. + [ -n malware:running_procs:hidden_procs:deleted_files:suspscan:other_malware ]
  2995. + cut -d: -f2-
  2996. + echo malware:running_procs:hidden_procs:deleted_files:suspscan:other_malware
  2997. + GROUP_TESTS=running_procs:hidden_procs:deleted_files:suspscan:other_malware
  2998. + [ hidden_ports = malware ]
  2999. + [ -z running_procs:hidden_procs:deleted_files:suspscan:other_malware ]
  3000. + echo :running_procs:hidden_procs:deleted_files:suspscan:other_malware:
  3001. + grep :hidden_ports:
  3002. + [ -n '' ]
  3003. + cut -d: -f1
  3004. + echo local_host:startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem
  3005. + GROUP_NAME=local_host
  3006. + grep :
  3007. + echo local_host:startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem
  3008. + [ -n local_host:startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem ]
  3009. + cut -d: -f2-
  3010. + echo local_host:startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem
  3011. + GROUP_TESTS=startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem
  3012. + [ hidden_ports = local_host ]
  3013. + [ -z startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem ]
  3014. + grep :hidden_ports:
  3015. + echo :startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem:
  3016. + [ -n '' ]
  3017. + echo startup_files:startup_malware
  3018. + cut -d: -f1
  3019. + GROUP_NAME=startup_files
  3020. + echo startup_files:startup_malware
  3021. + grep :
  3022. + [ -n startup_files:startup_malware ]
  3023. + echo startup_files:startup_malware
  3024. + cut -d: -f2-
  3025. + GROUP_TESTS=startup_malware
  3026. + [ hidden_ports = startup_files ]
  3027. + [ -z startup_malware ]
  3028. + echo :startup_malware:
  3029. + grep :hidden_ports:
  3030. + [ -n '' ]
  3031. + echo os_specific:loaded_modules:avail_modules
  3032. + cut -d: -f1
  3033. + GROUP_NAME=os_specific
  3034. + echo os_specific:loaded_modules:avail_modules
  3035. + grep :
  3036. + [ -n os_specific:loaded_modules:avail_modules ]
  3037. + echo os_specific:loaded_modules:avail_modules
  3038. + cut -d: -f2-
  3039. + GROUP_TESTS=loaded_modules:avail_modules
  3040. + [ hidden_ports = os_specific ]
  3041. + [ -z loaded_modules:avail_modules ]
  3042. + grep :hidden_ports:
  3043. + echo :loaded_modules:avail_modules:
  3044. + [ -n '' ]
  3045. + cut -d: -f1
  3046. + echo group_accounts:passwd_changes:group_changes
  3047. + GROUP_NAME=group_accounts
  3048. + grep :
  3049. + echo group_accounts:passwd_changes:group_changes
  3050. + [ -n group_accounts:passwd_changes:group_changes ]
  3051. + cut -d: -f2-
  3052. + echo group_accounts:passwd_changes:group_changes
  3053. + GROUP_TESTS=passwd_changes:group_changes
  3054. + [ hidden_ports = group_accounts ]
  3055. + [ -z passwd_changes:group_changes ]
  3056. + grep :hidden_ports:
  3057. + echo :passwd_changes:group_changes:
  3058. + [ -n '' ]
  3059. + echo system_commands:properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes
  3060. + cut -d: -f1
  3061. + GROUP_NAME=system_commands
  3062. + echo system_commands:properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes
  3063. + grep :
  3064. + [ -n system_commands:properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes ]
  3065. + echo system_commands:properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes
  3066. + cut -d: -f2-
  3067. + GROUP_TESTS=properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes
  3068. + [ hidden_procs = system_commands ]
  3069. + [ -z properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes ]
  3070. + echo :properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes:
  3071. + grep :hidden_procs:
  3072. + [ -n '' ]
  3073. + cut -d: -f1
  3074. + echo properties:hashes:scripts:immutable:attributes
  3075. + GROUP_NAME=properties
  3076. + echo properties:hashes:scripts:immutable:attributes
  3077. + grep :
  3078. + [ -n properties:hashes:scripts:immutable:attributes ]
  3079. + cut -d: -f2-
  3080. + echo properties:hashes:scripts:immutable:attributes
  3081. + GROUP_TESTS=hashes:scripts:immutable:attributes
  3082. + [ hidden_procs = properties ]
  3083. + [ -z hashes:scripts:immutable:attributes ]
  3084. + grep :hidden_procs:
  3085. + echo :hashes:scripts:immutable:attributes:
  3086. + [ -n '' ]
  3087. + cut -d: -f1
  3088. + echo shared_libs:shared_libs_path
  3089. + GROUP_NAME=shared_libs
  3090. + echo shared_libs:shared_libs_path
  3091. + grep :
  3092. + [ -n shared_libs:shared_libs_path ]
  3093. + echo shared_libs:shared_libs_path
  3094. + cut -d: -f2-
  3095. + GROUP_TESTS=shared_libs_path
  3096. + [ hidden_procs = shared_libs ]
  3097. + [ -z shared_libs_path ]
  3098. + echo :shared_libs_path:
  3099. + grep :hidden_procs:
  3100. + [ -n '' ]
  3101. + echo rootkits:known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules
  3102. + cut -d: -f1
  3103. + GROUP_NAME=rootkits
  3104. + echo rootkits:known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules
  3105. + grep :
  3106. + [ -n rootkits:known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules ]
  3107. + echo rootkits:known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules
  3108. + cut -d: -f2-
  3109. + GROUP_TESTS=known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules
  3110. + [ hidden_procs = rootkits ]
  3111. + [ -z known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules ]
  3112. + echo :known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules:
  3113. + grep :hidden_procs:
  3114. + [ -n :known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules: ]
  3115. + TEMP_DIS_TESTS='deleted_files hidden_ports hidden_procs packet_cap_apps suspscan rootkits malware network rootkits'
  3116. + cut -d: -f1
  3117. + echo additional_rkts:possible_rkt_files:possible_rkt_strings
  3118. + GROUP_NAME=additional_rkts
  3119. + grep :
  3120. + echo additional_rkts:possible_rkt_files:possible_rkt_strings
  3121. + [ -n additional_rkts:possible_rkt_files:possible_rkt_strings ]
  3122. + cut -d: -f2-
  3123. + echo additional_rkts:possible_rkt_files:possible_rkt_strings
  3124. + GROUP_TESTS=possible_rkt_files:possible_rkt_strings
  3125. + [ hidden_procs = additional_rkts ]
  3126. + [ -z possible_rkt_files:possible_rkt_strings ]
  3127. + grep :hidden_procs:
  3128. + echo :possible_rkt_files:possible_rkt_strings:
  3129. + [ -n '' ]
  3130. + echo network:packet_cap_apps:ports:hidden_ports:promisc
  3131. + cut -d: -f1
  3132. + GROUP_NAME=network
  3133. + echo network:packet_cap_apps:ports:hidden_ports:promisc
  3134. + grep :
  3135. + [ -n network:packet_cap_apps:ports:hidden_ports:promisc ]
  3136. + echo network:packet_cap_apps:ports:hidden_ports:promisc
  3137. + cut -d: -f2-
  3138. + GROUP_TESTS=packet_cap_apps:ports:hidden_ports:promisc
  3139. + [ hidden_procs = network ]
  3140. + [ -z packet_cap_apps:ports:hidden_ports:promisc ]
  3141. + echo :packet_cap_apps:ports:hidden_ports:promisc:
  3142. + grep :hidden_procs:
  3143. + [ -n '' ]
  3144. + echo malware:running_procs:hidden_procs:deleted_files:suspscan:other_malware
  3145. + cut -d: -f1
  3146. + GROUP_NAME=malware
  3147. + echo malware:running_procs:hidden_procs:deleted_files:suspscan:other_malware
  3148. + grep :
  3149. + [ -n malware:running_procs:hidden_procs:deleted_files:suspscan:other_malware ]
  3150. + cut -d: -f2-
  3151. + echo malware:running_procs:hidden_procs:deleted_files:suspscan:other_malware
  3152. + GROUP_TESTS=running_procs:hidden_procs:deleted_files:suspscan:other_malware
  3153. + [ hidden_procs = malware ]
  3154. + [ -z running_procs:hidden_procs:deleted_files:suspscan:other_malware ]
  3155. + echo :running_procs:hidden_procs:deleted_files:suspscan:other_malware:
  3156. + grep :hidden_procs:
  3157. + [ -n :running_procs:hidden_procs:deleted_files:suspscan:other_malware: ]
  3158. + TEMP_DIS_TESTS='deleted_files hidden_ports hidden_procs packet_cap_apps suspscan rootkits malware network rootkits malware'
  3159. + echo local_host:startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem
  3160. + cut -d: -f1
  3161. + GROUP_NAME=local_host
  3162. + grep :
  3163. + echo local_host:startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem
  3164. + [ -n local_host:startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem ]
  3165. + echo local_host:startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem
  3166. + cut -d: -f2-
  3167. + GROUP_TESTS=startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem
  3168. + [ hidden_procs = local_host ]
  3169. + [ -z startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem ]
  3170. + echo :startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem:
  3171. + grep :hidden_procs:
  3172. + [ -n '' ]
  3173. + echo startup_files:startup_malware
  3174. + cut -d: -f1
  3175. + GROUP_NAME=startup_files
  3176. + echo startup_files:startup_malware
  3177. + grep :
  3178. + [ -n startup_files:startup_malware ]
  3179. + echo startup_files:startup_malware
  3180. + cut -d: -f2-
  3181. + GROUP_TESTS=startup_malware
  3182. + [ hidden_procs = startup_files ]
  3183. + [ -z startup_malware ]
  3184. + echo :startup_malware:
  3185. + grep :hidden_procs:
  3186. + [ -n '' ]
  3187. + cut -d: -f1
  3188. + echo os_specific:loaded_modules:avail_modules
  3189. + GROUP_NAME=os_specific
  3190. + grep :
  3191. + echo os_specific:loaded_modules:avail_modules
  3192. + [ -n os_specific:loaded_modules:avail_modules ]
  3193. + cut -d: -f2-
  3194. + echo os_specific:loaded_modules:avail_modules
  3195. + GROUP_TESTS=loaded_modules:avail_modules
  3196. + [ hidden_procs = os_specific ]
  3197. + [ -z loaded_modules:avail_modules ]
  3198. + grep :hidden_procs:
  3199. + echo :loaded_modules:avail_modules:
  3200. + [ -n '' ]
  3201. + echo group_accounts:passwd_changes:group_changes
  3202. + cut -d: -f1
  3203. + GROUP_NAME=group_accounts
  3204. + grep :
  3205. + echo group_accounts:passwd_changes:group_changes
  3206. + [ -n group_accounts:passwd_changes:group_changes ]
  3207. + echo group_accounts:passwd_changes:group_changes
  3208. + cut -d: -f2-
  3209. + GROUP_TESTS=passwd_changes:group_changes
  3210. + [ hidden_procs = group_accounts ]
  3211. + [ -z passwd_changes:group_changes ]
  3212. + echo :passwd_changes:group_changes:
  3213. + grep :hidden_procs:
  3214. + [ -n '' ]
  3215. + echo system_commands:properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes
  3216. + cut -d: -f1
  3217. + GROUP_NAME=system_commands
  3218. + echo system_commands:properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes
  3219. + grep :
  3220. + [ -n system_commands:properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes ]
  3221. + echo system_commands:properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes
  3222. + cut -d: -f2-
  3223. + GROUP_TESTS=properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes
  3224. + [ packet_cap_apps = system_commands ]
  3225. + [ -z properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes ]
  3226. + echo :properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes:
  3227. + grep :packet_cap_apps:
  3228. + [ -n '' ]
  3229. + cut -d: -f1
  3230. + echo properties:hashes:scripts:immutable:attributes
  3231. + GROUP_NAME=properties
  3232. + grep :
  3233. + echo properties:hashes:scripts:immutable:attributes
  3234. + [ -n properties:hashes:scripts:immutable:attributes ]
  3235. + echo properties:hashes:scripts:immutable:attributes
  3236. + cut -d: -f2-
  3237. + GROUP_TESTS=hashes:scripts:immutable:attributes
  3238. + [ packet_cap_apps = properties ]
  3239. + [ -z hashes:scripts:immutable:attributes ]
  3240. + grep :packet_cap_apps:
  3241. + echo :hashes:scripts:immutable:attributes:
  3242. + [ -n '' ]
  3243. + echo shared_libs:shared_libs_path
  3244. + cut -d: -f1
  3245. + GROUP_NAME=shared_libs
  3246. + echo shared_libs:shared_libs_path
  3247. + grep :
  3248. + [ -n shared_libs:shared_libs_path ]
  3249. + echo shared_libs:shared_libs_path
  3250. + cut -d: -f2-
  3251. + GROUP_TESTS=shared_libs_path
  3252. + [ packet_cap_apps = shared_libs ]
  3253. + [ -z shared_libs_path ]
  3254. + echo :shared_libs_path:
  3255. + grep :packet_cap_apps:
  3256. + [ -n '' ]
  3257. + echo rootkits:known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules
  3258. + cut -d: -f1
  3259. + GROUP_NAME=rootkits
  3260. + echo rootkits:known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules
  3261. + grep :
  3262. + [ -n rootkits:known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules ]
  3263. + cut -d: -f2-
  3264. + echo rootkits:known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules
  3265. + GROUP_TESTS=known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules
  3266. + [ packet_cap_apps = rootkits ]
  3267. + [ -z known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules ]
  3268. + echo :known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules:
  3269. + grep :packet_cap_apps:
  3270. + [ -n '' ]
  3271. + echo additional_rkts:possible_rkt_files:possible_rkt_strings
  3272. + cut -d: -f1
  3273. + GROUP_NAME=additional_rkts
  3274. + grep :
  3275. + echo additional_rkts:possible_rkt_files:possible_rkt_strings
  3276. + [ -n additional_rkts:possible_rkt_files:possible_rkt_strings ]
  3277. + echo additional_rkts:possible_rkt_files:possible_rkt_strings
  3278. + cut -d: -f2-
  3279. + GROUP_TESTS=possible_rkt_files:possible_rkt_strings
  3280. + [ packet_cap_apps = additional_rkts ]
  3281. + [ -z possible_rkt_files:possible_rkt_strings ]
  3282. + echo :possible_rkt_files:possible_rkt_strings:
  3283. + grep :packet_cap_apps:
  3284. + [ -n '' ]
  3285. + echo network:packet_cap_apps:ports:hidden_ports:promisc
  3286. + cut -d: -f1
  3287. + GROUP_NAME=network
  3288. + echo network:packet_cap_apps:ports:hidden_ports:promisc
  3289. + grep :
  3290. + [ -n network:packet_cap_apps:ports:hidden_ports:promisc ]
  3291. + cut -d: -f2-
  3292. + echo network:packet_cap_apps:ports:hidden_ports:promisc
  3293. + GROUP_TESTS=packet_cap_apps:ports:hidden_ports:promisc
  3294. + [ packet_cap_apps = network ]
  3295. + [ -z packet_cap_apps:ports:hidden_ports:promisc ]
  3296. + echo :packet_cap_apps:ports:hidden_ports:promisc:
  3297. + grep :packet_cap_apps:
  3298. + [ -n :packet_cap_apps:ports:hidden_ports:promisc: ]
  3299. + TEMP_DIS_TESTS='deleted_files hidden_ports hidden_procs packet_cap_apps suspscan rootkits malware network rootkits malware network'
  3300. + cut -d: -f1
  3301. + echo malware:running_procs:hidden_procs:deleted_files:suspscan:other_malware
  3302. + GROUP_NAME=malware
  3303. + grep :
  3304. + echo malware:running_procs:hidden_procs:deleted_files:suspscan:other_malware
  3305. + [ -n malware:running_procs:hidden_procs:deleted_files:suspscan:other_malware ]
  3306. + echo malware:running_procs:hidden_procs:deleted_files:suspscan:other_malware
  3307. + cut -d: -f2-
  3308. + GROUP_TESTS=running_procs:hidden_procs:deleted_files:suspscan:other_malware
  3309. + [ packet_cap_apps = malware ]
  3310. + [ -z running_procs:hidden_procs:deleted_files:suspscan:other_malware ]
  3311. + echo :running_procs:hidden_procs:deleted_files:suspscan:other_malware:
  3312. + grep :packet_cap_apps:
  3313. + [ -n '' ]
  3314. + echo local_host:startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem
  3315. + cut -d: -f1
  3316. + GROUP_NAME=local_host
  3317. + echo local_host:startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem
  3318. + grep :
  3319. + [ -n local_host:startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem ]
  3320. + echo local_host:startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem
  3321. + cut -d: -f2-
  3322. + GROUP_TESTS=startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem
  3323. + [ packet_cap_apps = local_host ]
  3324. + [ -z startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem ]
  3325. + echo :startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem:
  3326. + grep :packet_cap_apps:
  3327. + [ -n '' ]
  3328. + cut -d: -f1
  3329. + echo startup_files:startup_malware
  3330. + GROUP_NAME=startup_files
  3331. + grep :
  3332. + echo startup_files:startup_malware
  3333. + [ -n startup_files:startup_malware ]
  3334. + cut -d: -f2-
  3335. + echo startup_files:startup_malware
  3336. + GROUP_TESTS=startup_malware
  3337. + [ packet_cap_apps = startup_files ]
  3338. + [ -z startup_malware ]
  3339. + grep :packet_cap_apps:
  3340. + echo :startup_malware:
  3341. + [ -n '' ]
  3342. + echo os_specific:loaded_modules:avail_modules
  3343. + cut -d: -f1
  3344. + GROUP_NAME=os_specific
  3345. + grep :
  3346. + echo os_specific:loaded_modules:avail_modules
  3347. + [ -n os_specific:loaded_modules:avail_modules ]
  3348. + echo os_specific:loaded_modules:avail_modules
  3349. + cut -d: -f2-
  3350. + GROUP_TESTS=loaded_modules:avail_modules
  3351. + [ packet_cap_apps = os_specific ]
  3352. + [ -z loaded_modules:avail_modules ]
  3353. + echo :loaded_modules:avail_modules:
  3354. + grep :packet_cap_apps:
  3355. + [ -n '' ]
  3356. + echo group_accounts:passwd_changes:group_changes
  3357. + cut -d: -f1
  3358. + GROUP_NAME=group_accounts
  3359. + echo group_accounts:passwd_changes:group_changes
  3360. + grep :
  3361. + [ -n group_accounts:passwd_changes:group_changes ]
  3362. + echo group_accounts:passwd_changes:group_changes
  3363. + cut -d: -f2-
  3364. + GROUP_TESTS=passwd_changes:group_changes
  3365. + [ packet_cap_apps = group_accounts ]
  3366. + [ -z passwd_changes:group_changes ]
  3367. + echo :passwd_changes:group_changes:
  3368. + grep :packet_cap_apps:
  3369. + [ -n '' ]
  3370. + cut -d: -f1
  3371. + echo system_commands:properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes
  3372. + GROUP_NAME=system_commands
  3373. + grep :
  3374. + echo system_commands:properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes
  3375. + [ -n system_commands:properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes ]
  3376. + cut -d: -f2-
  3377. + echo system_commands:properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes
  3378. + GROUP_TESTS=properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes
  3379. + [ suspscan = system_commands ]
  3380. + [ -z properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes ]
  3381. + echo :properties:strings:hashes:scripts:shared_libs:shared_libs_path:immutable:attributes:
  3382. + grep :suspscan:
  3383. + [ -n '' ]
  3384. + echo properties:hashes:scripts:immutable:attributes
  3385. + cut -d: -f1
  3386. + GROUP_NAME=properties
  3387. + echo properties:hashes:scripts:immutable:attributes
  3388. + grep :
  3389. + [ -n properties:hashes:scripts:immutable:attributes ]
  3390. + echo properties:hashes:scripts:immutable:attributes
  3391. + cut -d: -f2-
  3392. + GROUP_TESTS=hashes:scripts:immutable:attributes
  3393. + [ suspscan = properties ]
  3394. + [ -z hashes:scripts:immutable:attributes ]
  3395. + echo :hashes:scripts:immutable:attributes:
  3396. + grep :suspscan:
  3397. + [ -n '' ]
  3398. + cut -d: -f1
  3399. + echo shared_libs:shared_libs_path
  3400. + GROUP_NAME=shared_libs
  3401. + echo shared_libs:shared_libs_path
  3402. + grep :
  3403. + [ -n shared_libs:shared_libs_path ]
  3404. + cut -d: -f2-
  3405. + echo shared_libs:shared_libs_path
  3406. + GROUP_TESTS=shared_libs_path
  3407. + [ suspscan = shared_libs ]
  3408. + [ -z shared_libs_path ]
  3409. + grep :suspscan:
  3410. + echo :shared_libs_path:
  3411. + [ -n '' ]
  3412. + cut -d: -f1
  3413. + echo rootkits:known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules
  3414. + GROUP_NAME=rootkits
  3415. + grep :
  3416. + echo rootkits:known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules
  3417. + [ -n rootkits:known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules ]
  3418. + echo rootkits:known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules
  3419. + cut -d: -f2-
  3420. + GROUP_TESTS=known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules
  3421. + [ suspscan = rootkits ]
  3422. + [ -z known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules ]
  3423. + grep :suspscan:
  3424. + echo :known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules:
  3425. + [ -n :known_rkts:additional_rkts:possible_rkt_files:possible_rkt_strings:malware:running_procs:hidden_procs:deleted_files:trojans:other_malware:os_specific:suspscan:loaded_modules:avail_modules: ]
  3426. + TEMP_DIS_TESTS='deleted_files hidden_ports hidden_procs packet_cap_apps suspscan rootkits malware network rootkits malware network rootkits'
  3427. + echo additional_rkts:possible_rkt_files:possible_rkt_strings
  3428. + cut -d: -f1
  3429. + GROUP_NAME=additional_rkts
  3430. + echo additional_rkts:possible_rkt_files:possible_rkt_strings
  3431. + grep :
  3432. + [ -n additional_rkts:possible_rkt_files:possible_rkt_strings ]
  3433. + echo additional_rkts:possible_rkt_files:possible_rkt_strings
  3434. + cut -d: -f2-
  3435. + GROUP_TESTS=possible_rkt_files:possible_rkt_strings
  3436. + [ suspscan = additional_rkts ]
  3437. + [ -z possible_rkt_files:possible_rkt_strings ]
  3438. + echo :possible_rkt_files:possible_rkt_strings:
  3439. + grep :suspscan:
  3440. + [ -n '' ]
  3441. + cut -d: -f1
  3442. + echo network:packet_cap_apps:ports:hidden_ports:promisc
  3443. + GROUP_NAME=network
  3444. + grep :
  3445. + echo network:packet_cap_apps:ports:hidden_ports:promisc
  3446. + [ -n network:packet_cap_apps:ports:hidden_ports:promisc ]
  3447. + cut -d: -f2-
  3448. + echo network:packet_cap_apps:ports:hidden_ports:promisc
  3449. + GROUP_TESTS=packet_cap_apps:ports:hidden_ports:promisc
  3450. + [ suspscan = network ]
  3451. + [ -z packet_cap_apps:ports:hidden_ports:promisc ]
  3452. + echo :packet_cap_apps:ports:hidden_ports:promisc:
  3453. + grep :suspscan:
  3454. + [ -n '' ]
  3455. + echo malware:running_procs:hidden_procs:deleted_files:suspscan:other_malware
  3456. + cut -d: -f1
  3457. + GROUP_NAME=malware
  3458. + grep :
  3459. + echo malware:running_procs:hidden_procs:deleted_files:suspscan:other_malware
  3460. + [ -n malware:running_procs:hidden_procs:deleted_files:suspscan:other_malware ]
  3461. + echo malware:running_procs:hidden_procs:deleted_files:suspscan:other_malware
  3462. + cut -d: -f2-
  3463. + GROUP_TESTS=running_procs:hidden_procs:deleted_files:suspscan:other_malware
  3464. + [ suspscan = malware ]
  3465. + [ -z running_procs:hidden_procs:deleted_files:suspscan:other_malware ]
  3466. + echo :running_procs:hidden_procs:deleted_files:suspscan:other_malware:
  3467. + grep :suspscan:
  3468. + [ -n :running_procs:hidden_procs:deleted_files:suspscan:other_malware: ]
  3469. + TEMP_DIS_TESTS='deleted_files hidden_ports hidden_procs packet_cap_apps suspscan rootkits malware network rootkits malware network rootkits malware'
  3470. + echo local_host:startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem
  3471. + cut -d: -f1
  3472. + GROUP_NAME=local_host
  3473. + echo local_host:startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem
  3474. + grep :
  3475. + [ -n local_host:startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem ]
  3476. + cut -d: -f2-
  3477. + echo local_host:startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem
  3478. + GROUP_TESTS=startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem
  3479. + [ suspscan = local_host ]
  3480. + [ -z startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem ]
  3481. + echo :startup_files:passwd_changes:group_changes:startup_malware:group_accounts:system_configs:filesystem:
  3482. + grep :suspscan:
  3483. + [ -n '' ]
  3484. + cut -d: -f1
  3485. + echo startup_files:startup_malware
  3486. + GROUP_NAME=startup_files
  3487. + grep :
  3488. + echo startup_files:startup_malware
  3489. + [ -n startup_files:startup_malware ]
  3490. + echo startup_files:startup_malware
  3491. + cut -d: -f2-
  3492. + GROUP_TESTS=startup_malware
  3493. + [ suspscan = startup_files ]
  3494. + [ -z startup_malware ]
  3495. + grep :suspscan:
  3496. + echo :startup_malware:
  3497. + [ -n '' ]
  3498. + echo os_specific:loaded_modules:avail_modules
  3499. + cut -d: -f1
  3500. + GROUP_NAME=os_specific
  3501. + echo os_specific:loaded_modules:avail_modules
  3502. + grep :
  3503. + [ -n os_specific:loaded_modules:avail_modules ]
  3504. + echo os_specific:loaded_modules:avail_modules
  3505. + cut -d: -f2-
  3506. + GROUP_TESTS=loaded_modules:avail_modules
  3507. + [ suspscan = os_specific ]
  3508. + [ -z loaded_modules:avail_modules ]
  3509. + echo :loaded_modules:avail_modules:
  3510. + grep :suspscan:
  3511. + [ -n '' ]
  3512. + echo group_accounts:passwd_changes:group_changes
  3513. + cut -d: -f1
  3514. + GROUP_NAME=group_accounts
  3515. + echo group_accounts:passwd_changes:group_changes
  3516. + grep :
  3517. + [ -n group_accounts:passwd_changes:group_changes ]
  3518. + cut -d: -f2-
  3519. + echo group_accounts:passwd_changes:group_changes
  3520. + GROUP_TESTS=passwd_changes:group_changes
  3521. + [ suspscan = group_accounts ]
  3522. + [ -z passwd_changes:group_changes ]
  3523. + grep :suspscan:
  3524. + echo :passwd_changes:group_changes:
  3525. + [ -n '' ]
  3526. + echo deleted_files hidden_ports hidden_procs packet_cap_apps suspscan rootkits malware network rootkits malware network rootkits malware
  3527. + TEMP_DIS_TESTS=' deleted_files hidden_ports hidden_procs packet_cap_apps suspscan rootkits malware network rootkits malware network rootkits malware '
  3528. + echo ' deleted_files hidden_ports hidden_procs packet_cap_apps suspscan rootkits malware network rootkits malware network rootkits malware '
  3529. + grep ' filesystem '
  3530. + [ -n '' ]
  3531. + echo ' deleted_files hidden_ports hidden_procs packet_cap_apps suspscan rootkits malware network rootkits malware network rootkits malware '
  3532. + grep ' local_host '
  3533. + [ -n '' ]
  3534. + echo filesystem local_host
  3535. + TEMP_EN_TESTS='filesystem local_host'
  3536. + [ -z 'filesystem local_host' ]
  3537. + return
  3538. + get_existwl_option
  3539. + LEAVE=0
  3540. + get_option newline-list EXISTWHITELIST
  3541. + OPTMULTI=newline-list
  3542. + OPTNAME=EXISTWHITELIST
  3543. + ERRCODE=0
  3544. + [ -z newline-list -o -z EXISTWHITELIST ]
  3545. + grep -h ^EXISTWHITELIST= /usr/local/etc/rkhunter.conf
  3546. + RKHTMPVAR2=''
  3547. + [ -z '' ]
  3548. + echo ''
  3549. + return 0
  3550. + EXISTWL_OPT=''
  3551. + [ 0 -eq 0 ]
  3552. + [ -n '' ]
  3553. + [ 0 -eq 1 ]
  3554. + return
  3555. + [ 1 -eq 1 -o 0 -eq 1 ]
  3556. + get_syslog_option
  3557. + LEAVE=0
  3558. + [ -n '' ]
  3559. + get_option single USE_SYSLOG
  3560. + OPTMULTI=single
  3561. + OPTNAME=USE_SYSLOG
  3562. + ERRCODE=0
  3563. + [ -z single -o -z USE_SYSLOG ]
  3564. + grep -h ^USE_SYSLOG= /usr/local/etc/rkhunter.conf
  3565. + RKHTMPVAR2=''
  3566. + [ -z '' ]
  3567. + echo ''
  3568. + return 0
  3569. + USE_SYSLOG=''
  3570. + test 0 -eq 1
  3571. + [ 0 -eq 0 ]
  3572. + [ -n '' ]
  3573. + [ 0 -eq 1 ]
  3574. + return
  3575. + get_startup_paths_option
  3576. + LEAVE=0
  3577. + get_option space-list STARTUP_PATHS
  3578. + OPTMULTI=space-list
  3579. + OPTNAME=STARTUP_PATHS
  3580. + ERRCODE=0
  3581. + [ -z space-list -o -z STARTUP_PATHS ]
  3582. + grep -h ^STARTUP_PATHS= /usr/local/etc/rkhunter.conf
  3583. + RKHTMPVAR2=''
  3584. + [ -z '' ]
  3585. + echo ''
  3586. + return 0
  3587. + STARTUP_PATHS=''
  3588. + [ 0 -eq 0 ]
  3589. + [ -n '' ]
  3590. + [ 0 -eq 1 ]
  3591. + return
  3592. + get_rtkt_whitelist_options
  3593. + LEAVE=0
  3594. + get_option newline-list RTKT_FILE_WHITELIST
  3595. + OPTMULTI=newline-list
  3596. + OPTNAME=RTKT_FILE_WHITELIST
  3597. + ERRCODE=0
  3598. + [ -z newline-list -o -z RTKT_FILE_WHITELIST ]
  3599. + grep -h ^RTKT_FILE_WHITELIST= /usr/local/etc/rkhunter.conf
  3600. + RKHTMPVAR2=''
  3601. + [ -z '' ]
  3602. + echo ''
  3603. + return 0
  3604. + RTKT_FILE_WHITELIST=''
  3605. + [ 0 -eq 0 ]
  3606. + [ -n '' ]
  3607. + get_option newline-list RTKT_DIR_WHITELIST
  3608. + OPTMULTI=newline-list
  3609. + OPTNAME=RTKT_DIR_WHITELIST
  3610. + ERRCODE=0
  3611. + [ -z newline-list -o -z RTKT_DIR_WHITELIST ]
  3612. + grep -h ^RTKT_DIR_WHITELIST= /usr/local/etc/rkhunter.conf
  3613. + RKHTMPVAR2=''
  3614. + [ -z '' ]
  3615. + echo ''
  3616. + return 0
  3617. + RTKT_DIR_WHITELIST=''
  3618. + [ 0 -eq 0 ]
  3619. + [ -n '' ]
  3620. + [ 0 -eq 1 ]
  3621. + return
  3622. + get_epoch_date_cmd_option
  3623. + LEAVE=0
  3624. + get_option single EPOCH_DATE_CMD
  3625. + OPTMULTI=single
  3626. + OPTNAME=EPOCH_DATE_CMD
  3627. + ERRCODE=0
  3628. + [ -z single -o -z EPOCH_DATE_CMD ]
  3629. + grep -h ^EPOCH_DATE_CMD= /usr/local/etc/rkhunter.conf
  3630. + RKHTMPVAR2=''
  3631. + [ -z '' ]
  3632. + echo ''
  3633. + return 0
  3634. + EPOCH_DATE_CMD=''
  3635. + [ 0 -eq 0 ]
  3636. + [ '' = PERL ]
  3637. + [ '' = NONE ]
  3638. + [ -n '' ]
  3639. + [ 0 -eq 0 ]
  3640. + test_epoch_cmd date
  3641. + RKHTMPVAR=date
  3642. + date --date '5 seconds ago' +%s
  3643. + grep '^[0-9][0-9]*$'
  3644. + [ -n '' ]
  3645. + return
  3646. + test -n ''
  3647. + [ 0 -eq 1 ]
  3648. + return
  3649. + get_phalanx2_option
  3650. + test 0 -eq 0
  3651. + return
  3652. + get_summary_options
  3653. + LEAVE=0
  3654. + get_option single SHOW_SUMMARY_WARNINGS_NUMBER
  3655. + OPTMULTI=single
  3656. + OPTNAME=SHOW_SUMMARY_WARNINGS_NUMBER
  3657. + ERRCODE=0
  3658. + [ -z single -o -z SHOW_SUMMARY_WARNINGS_NUMBER ]
  3659. + grep -h ^SHOW_SUMMARY_WARNINGS_NUMBER= /usr/local/etc/rkhunter.conf
  3660. + RKHTMPVAR2=''
  3661. + [ -z '' ]
  3662. + echo ''
  3663. + return 0
  3664. + SHOW_SUMMARY_WARNINGS_NUMBER=''
  3665. + [ 0 -eq 0 ]
  3666. + [ -n '' ]
  3667. + SHOW_SUMMARY_WARNINGS_NUMBER=0
  3668. + get_option single SHOW_SUMMARY_TIME
  3669. + OPTMULTI=single
  3670. + OPTNAME=SHOW_SUMMARY_TIME
  3671. + ERRCODE=0
  3672. + [ -z single -o -z SHOW_SUMMARY_TIME ]
  3673. + grep -h ^SHOW_SUMMARY_TIME= /usr/local/etc/rkhunter.conf
  3674. + RKHTMPVAR2=''
  3675. + [ -z '' ]
  3676. + echo ''
  3677. + return 0
  3678. + SHOW_SUMMARY_TIME=''
  3679. + [ 0 -eq 0 ]
  3680. + [ -n '' ]
  3681. + SHOW_SUMMARY_TIME=3
  3682. + [ 0 -eq 1 ]
  3683. + return
  3684. + test 0 -eq 0
  3685. + get_mailonwarn_option
  3686. + LEAVE=0
  3687. + get_option space-list MAIL-ON-WARNING
  3688. + OPTMULTI=space-list
  3689. + OPTNAME=MAIL-ON-WARNING
  3690. + ERRCODE=0
  3691. + [ -z space-list -o -z MAIL-ON-WARNING ]
  3692. + grep -h ^MAIL-ON-WARNING= /usr/local/etc/rkhunter.conf
  3693. + RKHTMPVAR2=''
  3694. + [ -z '' ]
  3695. + echo ''
  3696. + return 0
  3697. + MAILONWARNING=''
  3698. + [ 0 -eq 0 ]
  3699. + [ -n '' ]
  3700. + [ 0 -eq 1 ]
  3701. + return
  3702. + check_test system_configs
  3703. + echo ' filesystem local_host '
  3704. + grep ' system_configs '
  3705. + [ 'filesystem local_host' = all -o -n '' ]
  3706. + return 1
  3707. +
  3708. + check_test filesystem
  3709. + echo ' filesystem local_host '
  3710. + grep ' filesystem '
  3711. + [ 'filesystem local_host' = all -o -n ' filesystem local_host ' ]
  3712. + echo ' deleted_files hidden_ports hidden_procs packet_cap_apps suspscan '
  3713. + grep ' filesystem '
  3714. + [ 'deleted_files hidden_ports hidden_procs packet_cap_apps suspscan' = none -o -z '' ]
  3715. + return 0
  3716. +
  3717. + get_scan_mode_dev_option
  3718. + LEAVE=0
  3719. + get_option single SCAN_MODE_DEV
  3720. + OPTMULTI=single
  3721. + OPTNAME=SCAN_MODE_DEV
  3722. + ERRCODE=0
  3723. + [ -z single -o -z SCAN_MODE_DEV ]
  3724. + grep -h ^SCAN_MODE_DEV= /usr/local/etc/rkhunter.conf
  3725. + RKHTMPVAR2=''
  3726. + [ -z '' ]
  3727. + echo ''
  3728. + return 0
  3729. + SCAN_MODE_DEV=''
  3730. + [ 0 -eq 0 ]
  3731. + [ -n '' ]
  3732. + SCAN_MODE_DEV=THOROUGH
  3733. + [ 0 -eq 1 ]
  3734. + return
  3735. + get_missing_file_options
  3736. + LEAVE=0
  3737. + get_option space-list MISSING_LOGFILES
  3738. + OPTMULTI=space-list
  3739. + OPTNAME=MISSING_LOGFILES
  3740. + ERRCODE=0
  3741. + [ -z space-list -o -z MISSING_LOGFILES ]
  3742. + grep -h ^MISSING_LOGFILES= /usr/local/etc/rkhunter.conf
  3743. + RKHTMPVAR2=''
  3744. + [ -z '' ]
  3745. + echo ''
  3746. + return 0
  3747. + LOGFILE_MISSING=''
  3748. + [ 0 -eq 0 ]
  3749. + [ -n '' ]
  3750. + get_option space-list EMPTY_LOGFILES
  3751. + OPTMULTI=space-list
  3752. + OPTNAME=EMPTY_LOGFILES
  3753. + ERRCODE=0
  3754. + [ -z space-list -o -z EMPTY_LOGFILES ]
  3755. + grep -h ^EMPTY_LOGFILES= /usr/local/etc/rkhunter.conf
  3756. + RKHTMPVAR2=''
  3757. + [ -z '' ]
  3758. + echo ''
  3759. + return 0
  3760. + LOGFILE_EMPTY=''
  3761. + [ 0 -eq 0 ]
  3762. + [ -n '' ]
  3763. + [ 0 -eq 1 ]
  3764. + return
  3765. + get_hidden_options
  3766. + LEAVE=0
  3767. + ALLOWHIDDENFILES=''
  3768. + get_option newline-list ALLOWHIDDENFILE
  3769. + OPTMULTI=newline-list
  3770. + OPTNAME=ALLOWHIDDENFILE
  3771. + ERRCODE=0
  3772. + [ -z newline-list -o -z ALLOWHIDDENFILE ]
  3773. + grep -h ^ALLOWHIDDENFILE= /usr/local/etc/rkhunter.conf
  3774. + RKHTMPVAR2=''
  3775. + [ -z '' ]
  3776. + echo ''
  3777. + return 0
  3778. + ALLOWHIDDENFILE_OPT=''
  3779. + [ 0 -eq 0 ]
  3780. + [ -n '' ]
  3781. + ALLOWHIDDENDIRS=''
  3782. + get_option newline-list ALLOWHIDDENDIR
  3783. + OPTMULTI=newline-list
  3784. + OPTNAME=ALLOWHIDDENDIR
  3785. + ERRCODE=0
  3786. + [ -z newline-list -o -z ALLOWHIDDENDIR ]
  3787. + grep -h ^ALLOWHIDDENDIR= /usr/local/etc/rkhunter.conf
  3788. + RKHTMPVAR2=''
  3789. + [ -z '' ]
  3790. + echo ''
  3791. + return 0
  3792. + ALLOWHIDDENDIR_OPT=''
  3793. + [ 0 -eq 0 ]
  3794. + [ -n '' ]
  3795. + [ 0 -eq 1 ]
  3796. + return
  3797. + get_dev_options
  3798. + LEAVE=0
  3799. + ALLOWDEVFILES=''
  3800. + get_option newline-list ALLOWDEVFILE
  3801. + OPTMULTI=newline-list
  3802. + OPTNAME=ALLOWDEVFILE
  3803. + ERRCODE=0
  3804. + [ -z newline-list -o -z ALLOWDEVFILE ]
  3805. + grep -h ^ALLOWDEVFILE= /usr/local/etc/rkhunter.conf
  3806. + RKHTMPVAR2=''
  3807. + [ -z '' ]
  3808. + echo ''
  3809. + return 0
  3810. + ALLOWDEVFILE_OPT=''
  3811. + [ 0 -eq 0 ]
  3812. + [ -n '' ]
  3813. + [ 0 -eq 1 ]
  3814. + return
  3815. + check_test trojans
  3816. + grep ' trojans '
  3817. + echo ' filesystem local_host '
  3818. + [ 'filesystem local_host' = all -o -n '' ]
  3819. + return 1
  3820. + check_test ports
  3821. + echo ' filesystem local_host '
  3822. + grep ' ports '
  3823. + [ 'filesystem local_host' = all -o -n '' ]
  3824. + return 1
  3825. + check_test hidden_ports
  3826. + echo ' filesystem local_host '
  3827. + grep ' hidden_ports '
  3828. + [ 'filesystem local_host' = all -o -n '' ]
  3829. + return 1
  3830. + check_test group_accounts
  3831. + echo ' filesystem local_host '
  3832. + grep ' group_accounts '
  3833. + [ 'filesystem local_host' = all -o -n '' ]
  3834. + return 1
  3835. + check_test shared_libs
  3836. + grep ' shared_libs '
  3837. + echo ' filesystem local_host '
  3838. + [ 'filesystem local_host' = all -o -n '' ]
  3839. + return 1
  3840. + check_test hidden_procs
  3841. + echo ' filesystem local_host '
  3842. + grep ' hidden_procs '
  3843. + [ 'filesystem local_host' = all -o -n '' ]
  3844. + return 1
  3845. + check_test hidden_ports
  3846. + echo ' filesystem local_host '
  3847. + grep ' hidden_ports '
  3848. + [ 'filesystem local_host' = all -o -n '' ]
  3849. + return 1
  3850. + check_test deleted_files
  3851. + grep ' deleted_files '
  3852. + echo ' filesystem local_host '
  3853. + [ 'filesystem local_host' = all -o -n '' ]
  3854. + return 1
  3855. + check_test suspscan
  3856. + echo ' filesystem local_host '
  3857. + grep ' suspscan '
  3858. + [ 'filesystem local_host' = all -o -n '' ]
  3859. + return 1
  3860. + check_test network
  3861. + echo ' filesystem local_host '
  3862. + grep ' network '
  3863. + [ 'filesystem local_host' = all -o -n '' ]
  3864. + return 1
  3865. + check_test os_specific
  3866. + echo ' filesystem local_host '
  3867. + grep ' os_specific '
  3868. + [ 'filesystem local_host' = all -o -n '' ]
  3869. + return 1
  3870. + check_test apps
  3871. + grep ' apps '
  3872. + echo ' filesystem local_host '
  3873. + [ 'filesystem local_host' = all -o -n '' ]
  3874. + return 1
  3875. + check_test properties
  3876. + echo ' filesystem local_host '
  3877. + grep ' properties '
  3878. + [ 'filesystem local_host' = all -o -n '' ]
  3879. + return 1
  3880. +
  3881. + test 0 -eq 1
  3882. + test 0 -eq 1
  3883. + [ 0 -eq 1 -o 0 -eq 1 ]
  3884. + [ 0 -eq 1 -o 0 -eq 1 -o 0 -eq 1 ]
  3885. + return
  3886. + [ 0 -eq 1 ]
  3887. + [ -n '' ]
  3888. + [ 0 -eq 1 ]
  3889. + [ /var/log/rkhunter.log = /dev/null ]
  3890. + [ 1 -eq 1 ]
  3891. + NORMAL=''
  3892. + [ 0 -eq 0 ]
  3893. + RED=''
  3894. + GREEN=''
  3895. + YELLOW=''
  3896. + WHITE=''
  3897. + [ 1 -eq 1 ]
  3898. + [ -f /proc/ksyms ]
  3899. + [ -f /proc/kallsyms ]
  3900. + head -n 1 /proc/kallsyms
  3901. + [ -z '' ]
  3902. + KSYMS_FILE=''
  3903. + [ 1 -eq 1 -o 0 -eq 1 ]
  3904. + [ -e /usr/local/var/lib/rkhunter/db/rkhunter.dat ]
  3905. + [ -h /usr/local/var/lib/rkhunter/db/rkhunter.dat ]
  3906. + [ ! -f /usr/local/var/lib/rkhunter/db/rkhunter.dat ]
  3907. + [ -e /usr/local/var/lib/rkhunter/db/rkhunter_prop_list.dat ]
  3908. + [ -h /usr/local/var/lib/rkhunter/db/rkhunter_prop_list.dat ]
  3909. + [ ! -f /usr/local/var/lib/rkhunter/db/rkhunter_prop_list.dat ]
  3910. + [ -n '' ]
  3911. + check_test properties
  3912. + grep ' properties '
  3913. + echo ' filesystem local_host '
  3914. + [ 'filesystem local_host' = all -o -n '' ]
  3915. + return 1
  3916. +
  3917. + test 0 -eq 1
  3918. + get_old_prop_attrs /usr/local/var/lib/rkhunter/db/rkhunter.dat
  3919. + FNAME=/usr/local/var/lib/rkhunter/db/rkhunter.dat
  3920. + test -z /usr/local/var/lib/rkhunter/db/rkhunter.dat -o ! -f /usr/local/var/lib/rkhunter/db/rkhunter.dat
  3921. + [ -s /usr/local/var/lib/rkhunter/db/rkhunter.dat ]
  3922. + grep ^Hash: /usr/local/var/lib/rkhunter/db/rkhunter.dat
  3923. + cut -d: -f2-
  3924. + OLD_HASH_FUNC=/sbin/sha1
  3925. + cut -d: -f2
  3926. + grep ^Pkgmgr: /usr/local/var/lib/rkhunter/db/rkhunter.dat
  3927. + OLD_PKGMGR=''
  3928. + cut -d: -f2
  3929. + grep ^Attributes: /usr/local/var/lib/rkhunter/db/rkhunter.dat
  3930. + OLD_ATTRUPD=Stored
  3931. + return
  3932. + [ 0 -eq 1 -a 0 -eq 1 -a -z '' -a '' != NONE ]
  3933. + [ 0 -eq 1 -o 0 -eq 1 ]
  3934. + [ 1 -eq 0 -a 0 -eq 0 -a 0 -eq 0 -a 0 -eq 0 -a 0 -eq 0 ]
  3935. + [ 0 -eq 1 ]
  3936. + test 0 -eq 1 -o 0 -eq 1
  3937. + IFS='
  3938. '
  3939. + egrep '^MSG_(TYPE|RESULT)_' /usr/local/var/lib/rkhunter/db/i18n/en
  3940. + echo MSG_TYPE_PLAIN:
  3941. + cut -d: -f1
  3942. + TYPE=MSG_TYPE_PLAIN
  3943. + [ en != en ]
  3944. + echo MSG_TYPE_PLAIN:
  3945. + cut -d: -f2-
  3946. + RKHTMPVAR=''
  3947. + eval 'MSG_TYPE_PLAIN=""'
  3948. + MSG_TYPE_PLAIN=''
  3949. + echo MSG_TYPE_INFO:Info
  3950. + cut -d: -f1
  3951. + TYPE=MSG_TYPE_INFO
  3952. + [ en != en ]
  3953. + echo MSG_TYPE_INFO:Info
  3954. + cut -d: -f2-
  3955. + RKHTMPVAR=Info
  3956. + eval 'MSG_TYPE_INFO="Info"'
  3957. + MSG_TYPE_INFO=Info
  3958. + echo MSG_TYPE_WARNING:Warning
  3959. + cut -d: -f1
  3960. + TYPE=MSG_TYPE_WARNING
  3961. + [ en != en ]
  3962. + echo MSG_TYPE_WARNING:Warning
  3963. + cut -d: -f2-
  3964. + RKHTMPVAR=Warning
  3965. + eval 'MSG_TYPE_WARNING="Warning"'
  3966. + MSG_TYPE_WARNING=Warning
  3967. + echo MSG_RESULT_OK:OK
  3968. + cut -d: -f1
  3969. + TYPE=MSG_RESULT_OK
  3970. + [ en != en ]
  3971. + cut -d: -f2-
  3972. + echo MSG_RESULT_OK:OK
  3973. + RKHTMPVAR=OK
  3974. + eval 'MSG_RESULT_OK="OK"'
  3975. + MSG_RESULT_OK=OK
  3976. + cut -d: -f1
  3977. + echo MSG_RESULT_SKIPPED:Skipped
  3978. + TYPE=MSG_RESULT_SKIPPED
  3979. + [ en != en ]
  3980. + echo MSG_RESULT_SKIPPED:Skipped
  3981. + cut -d: -f2-
  3982. + RKHTMPVAR=Skipped
  3983. + eval 'MSG_RESULT_SKIPPED="Skipped"'
  3984. + MSG_RESULT_SKIPPED=Skipped
  3985. + echo MSG_RESULT_WARNING:Warning
  3986. + cut -d: -f1
  3987. + TYPE=MSG_RESULT_WARNING
  3988. + [ en != en ]
  3989. + echo MSG_RESULT_WARNING:Warning
  3990. + cut -d: -f2-
  3991. + RKHTMPVAR=Warning
  3992. + eval 'MSG_RESULT_WARNING="Warning"'
  3993. + MSG_RESULT_WARNING=Warning
  3994. + echo MSG_RESULT_FOUND:Found
  3995. + cut -d: -f1
  3996. + TYPE=MSG_RESULT_FOUND
  3997. + [ en != en ]
  3998. + echo MSG_RESULT_FOUND:Found
  3999. + cut -d: -f2-
  4000. + RKHTMPVAR=Found
  4001. + eval 'MSG_RESULT_FOUND="Found"'
  4002. + MSG_RESULT_FOUND=Found
  4003. + cut -d: -f1
  4004. + echo 'MSG_RESULT_NOT_FOUND:Not found'
  4005. + TYPE=MSG_RESULT_NOT_FOUND
  4006. + [ en != en ]
  4007. + cut -d: -f2-
  4008. + echo 'MSG_RESULT_NOT_FOUND:Not found'
  4009. + RKHTMPVAR='Not found'
  4010. + eval 'MSG_RESULT_NOT_FOUND="Not found"'
  4011. + MSG_RESULT_NOT_FOUND='Not found'
  4012. + echo 'MSG_RESULT_NONE_FOUND:None found'
  4013. + cut -d: -f1
  4014. + TYPE=MSG_RESULT_NONE_FOUND
  4015. + [ en != en ]
  4016. + echo 'MSG_RESULT_NONE_FOUND:None found'
  4017. + cut -d: -f2-
  4018. + RKHTMPVAR='None found'
  4019. + eval 'MSG_RESULT_NONE_FOUND="None found"'
  4020. + MSG_RESULT_NONE_FOUND='None found'
  4021. + echo MSG_RESULT_ALLOWED:Allowed
  4022. + cut -d: -f1
  4023. + TYPE=MSG_RESULT_ALLOWED
  4024. + [ en != en ]
  4025. + echo MSG_RESULT_ALLOWED:Allowed
  4026. + cut -d: -f2-
  4027. + RKHTMPVAR=Allowed
  4028. + eval 'MSG_RESULT_ALLOWED="Allowed"'
  4029. + MSG_RESULT_ALLOWED=Allowed
  4030. + echo 'MSG_RESULT_NOT_ALLOWED:Not allowed'
  4031. + cut -d: -f1
  4032. + TYPE=MSG_RESULT_NOT_ALLOWED
  4033. + [ en != en ]
  4034. + echo 'MSG_RESULT_NOT_ALLOWED:Not allowed'
  4035. + cut -d: -f2-
  4036. + RKHTMPVAR='Not allowed'
  4037. + eval 'MSG_RESULT_NOT_ALLOWED="Not allowed"'
  4038. + MSG_RESULT_NOT_ALLOWED='Not allowed'
  4039. + cut -d: -f1
  4040. + echo 'MSG_RESULT_UNSET:Not set'
  4041. + TYPE=MSG_RESULT_UNSET
  4042. + [ en != en ]
  4043. + cut -d: -f2-
  4044. + echo 'MSG_RESULT_UNSET:Not set'
  4045. + RKHTMPVAR='Not set'
  4046. + eval 'MSG_RESULT_UNSET="Not set"'
  4047. + MSG_RESULT_UNSET='Not set'
  4048. + echo MSG_RESULT_WHITELISTED:Whitelisted
  4049. + cut -d: -f1
  4050. + TYPE=MSG_RESULT_WHITELISTED
  4051. + [ en != en ]
  4052. + echo MSG_RESULT_WHITELISTED:Whitelisted
  4053. + cut -d: -f2-
  4054. + RKHTMPVAR=Whitelisted
  4055. + eval 'MSG_RESULT_WHITELISTED="Whitelisted"'
  4056. + MSG_RESULT_WHITELISTED=Whitelisted
  4057. + echo 'MSG_RESULT_NONE_MISSING:None missing'
  4058. + cut -d: -f1
  4059. + TYPE=MSG_RESULT_NONE_MISSING
  4060. + [ en != en ]
  4061. + echo 'MSG_RESULT_NONE_MISSING:None missing'
  4062. + cut -d: -f2-
  4063. + RKHTMPVAR='None missing'
  4064. + eval 'MSG_RESULT_NONE_MISSING="None missing"'
  4065. + MSG_RESULT_NONE_MISSING='None missing'
  4066. + echo MSG_RESULT_UPD:Updated
  4067. + cut -d: -f1
  4068. + TYPE=MSG_RESULT_UPD
  4069. + [ en != en ]
  4070. + echo MSG_RESULT_UPD:Updated
  4071. + cut -d: -f2-
  4072. + RKHTMPVAR=Updated
  4073. + eval 'MSG_RESULT_UPD="Updated"'
  4074. + MSG_RESULT_UPD=Updated
  4075. + cut -d: -f1
  4076. + echo 'MSG_RESULT_NO_UPD:No update'
  4077. + TYPE=MSG_RESULT_NO_UPD
  4078. + [ en != en ]
  4079. + cut -d: -f2-
  4080. + echo 'MSG_RESULT_NO_UPD:No update'
  4081. + RKHTMPVAR='No update'
  4082. + eval 'MSG_RESULT_NO_UPD="No update"'
  4083. + MSG_RESULT_NO_UPD='No update'
  4084. + cut -d: -f1
  4085. + echo 'MSG_RESULT_UPD_FAILED:Update failed'
  4086. + TYPE=MSG_RESULT_UPD_FAILED
  4087. + [ en != en ]
  4088. + echo 'MSG_RESULT_UPD_FAILED:Update failed'
  4089. + cut -d: -f2-
  4090. + RKHTMPVAR='Update failed'
  4091. + eval 'MSG_RESULT_UPD_FAILED="Update failed"'
  4092. + MSG_RESULT_UPD_FAILED='Update failed'
  4093. + echo 'MSG_RESULT_VCHK_FAILED:Version check failed'
  4094. + cut -d: -f1
  4095. + TYPE=MSG_RESULT_VCHK_FAILED
  4096. + [ en != en ]
  4097. + echo 'MSG_RESULT_VCHK_FAILED:Version check failed'
  4098. + cut -d: -f2-
  4099. + RKHTMPVAR='Version check failed'
  4100. + eval 'MSG_RESULT_VCHK_FAILED="Version check failed"'
  4101. + MSG_RESULT_VCHK_FAILED='Version check failed'
  4102. + IFS='
  4103. '
  4104. + [ 0 -eq 1 ]
  4105. + [ 0 -eq 0 ]
  4106. + [ 0 -eq 0 ]
  4107. + [ -f /var/log/rkhunter.log ]
  4108. + cp -f -p /var/log/rkhunter.log /var/log/rkhunter.log.old
  4109. + [ c = c ]
  4110. + echo -e '\c'
  4111. + hostname
  4112. + HOST_NAME=beaglebone
  4113. + test -z beaglebone
  4114. + test -z beaglebone
  4115. + echo beaglebone
  4116. + cut -d. -f1
  4117. + HOST_NAME=beaglebone
  4118. + display --to SCREEN --type PLAIN VERSIONLINE 'Rootkit Hunter' 1.4.2
  4119. + WARN_MSG=0
  4120. + NL=0
  4121. + NLAFTER=0
  4122. + LOGINDENT=0
  4123. + SCREENINDENT=0
  4124. + LOGNL=0
  4125. + SCREENNL=0
  4126. + WRITETO=''
  4127. + TYPE=''
  4128. + RESULT=''
  4129. + COLOR=''
  4130. + MSG=''
  4131. + LINE1=''
  4132. + LOGLINE1=''
  4133. + SPACES=''
  4134. + NONL=''
  4135. + DISPLAY_LINE='display --to SCREEN --type PLAIN VERSIONLINE Rootkit Hunter 1.4.2'
  4136. + [ 7 -le 0 ]
  4137. + [ 7 -ge 1 ]
  4138. + WRITETO=SCREEN
  4139. + shift
  4140. + shift
  4141. + [ 5 -ge 1 ]
  4142. + eval echo '$MSG_TYPE_PLAIN'
  4143. + echo
  4144. + TYPE=''
  4145. + [ -z '' -a PLAIN != PLAIN ]
  4146. + test PLAIN = WARNING
  4147. + shift
  4148. + shift
  4149. + [ 3 -ge 1 ]
  4150. + MSG=VERSIONLINE
  4151. + shift
  4152. + break
  4153. + test 0 -eq 1
  4154. + [ 0 -eq 1 ]
  4155. + [ 0 -eq 1 ]
  4156. + test SCREEN = SCREEN -o SCREEN = SCREEN+LOG
  4157. + WRITETOTTY=1
  4158. + test SCREEN = LOG -o SCREEN = SCREEN+LOG
  4159. + WRITETOLOG=0
  4160. + [ 1 -eq 0 -a 0 -eq 0 ]
  4161. + [ 1 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  4162. + test -n ''
  4163. + [ 0 -eq 1 -a 1 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  4164. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  4165. + [ -n VERSIONLINE ]
  4166. + grep -a ^VERSIONLINE: /usr/local/var/lib/rkhunter/db/i18n/en
  4167. + cut -d: -f2-
  4168. + head -n 1
  4169. + LINE1='[ $1 version $2 ]'
  4170. + [ 0 -eq 1 ]
  4171. + [ -z '[ $1 version $2 ]' ]
  4172. + echo '[ $1 version $2 ]'
  4173. + sed -e 's/`/\\`/g'
  4174. + LINE1='[ $1 version $2 ]'
  4175. + test -n '[ $1 version $2 ]'
  4176. + eval 'echo "[ $1 version $2 ]" | sed -e '\''s/;/\;/g'\'
  4177. + echo '[ Rootkit Hunter version 1.4.2 ]'
  4178. + sed -e 's/;/\;/g'
  4179. + LINE1='[ Rootkit Hunter version 1.4.2 ]'
  4180. + [ 0 -eq 1 ]
  4181. + [ 1 -eq 1 -a 0 -gt 0 ]
  4182. + [ -n '' ]
  4183. + [ 1 -eq 1 -a -n '' ]
  4184. + [ 0 -eq 1 ]
  4185. + [ 1 -eq 1 ]
  4186. + NLLOOP=0
  4187. + test 0 -gt 0
  4188. + [ '' = c ]
  4189. + echo -e '[ Rootkit Hunter version 1.4.2 ]'
  4190. [ Rootkit Hunter version 1.4.2 ]
  4191. + [ 0 -eq 1 ]
  4192. + test 1 -eq 1 -a 0 -eq 1
  4193. + return
  4194. + [ 0 -eq 0 ]
  4195. + [ -n beaglebone ]
  4196. + display --to LOG --type PLAIN VERSIONLINE2 'Rootkit Hunter' 1.4.2 beaglebone
  4197. + WARN_MSG=0
  4198. + NL=0
  4199. + NLAFTER=0
  4200. + LOGINDENT=0
  4201. + SCREENINDENT=0
  4202. + LOGNL=0
  4203. + SCREENNL=0
  4204. + WRITETO=''
  4205. + TYPE=''
  4206. + RESULT=''
  4207. + COLOR=''
  4208. + MSG=''
  4209. + LINE1=''
  4210. + LOGLINE1=''
  4211. + SPACES=''
  4212. + NONL=''
  4213. + DISPLAY_LINE='display --to LOG --type PLAIN VERSIONLINE2 Rootkit Hunter 1.4.2 beaglebone'
  4214. + [ 8 -le 0 ]
  4215. + [ 8 -ge 1 ]
  4216. + WRITETO=LOG
  4217. + shift
  4218. + shift
  4219. + [ 6 -ge 1 ]
  4220. + eval echo '$MSG_TYPE_PLAIN'
  4221. + echo
  4222. + TYPE=''
  4223. + [ -z '' -a PLAIN != PLAIN ]
  4224. + test PLAIN = WARNING
  4225. + shift
  4226. + shift
  4227. + [ 4 -ge 1 ]
  4228. + MSG=VERSIONLINE2
  4229. + shift
  4230. + break
  4231. + test 0 -eq 1
  4232. + [ 0 -eq 1 ]
  4233. + [ 0 -eq 1 ]
  4234. + test LOG = SCREEN -o LOG = SCREEN+LOG
  4235. + WRITETOTTY=0
  4236. + test LOG = LOG -o LOG = SCREEN+LOG
  4237. + WRITETOLOG=1
  4238. + [ 0 -eq 0 -a 1 -eq 0 ]
  4239. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  4240. + test -n ''
  4241. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  4242. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  4243. + [ -n VERSIONLINE2 ]
  4244. + grep -a ^VERSIONLINE2: /usr/local/var/lib/rkhunter/db/i18n/en
  4245. + cut -d: -f2-
  4246. + head -n 1
  4247. + LINE1='Running $1 version $2 on $3'
  4248. + [ 0 -eq 1 ]
  4249. + [ -z 'Running $1 version $2 on $3' ]
  4250. + echo 'Running $1 version $2 on $3'
  4251. + sed -e 's/`/\\`/g'
  4252. + LINE1='Running $1 version $2 on $3'
  4253. + test -n 'Running $1 version $2 on $3'
  4254. + eval 'echo "Running $1 version $2 on $3" | sed -e '\''s/;/\;/g'\'
  4255. + echo 'Running Rootkit Hunter version 1.4.2 on beaglebone'
  4256. + sed -e 's/;/\;/g'
  4257. + LINE1='Running Rootkit Hunter version 1.4.2 on beaglebone'
  4258. + [ 1 -eq 1 ]
  4259. + date '+[%H:%M:%S]'
  4260. + LOGLINE1='[04:21:43]'
  4261. + test 0 -gt 0 -o 0 -eq 1
  4262. + [ -n '' ]
  4263. + test 0 -gt 0
  4264. + LOGLINE1='[04:21:43] Running Rootkit Hunter version 1.4.2 on beaglebone'
  4265. + [ 0 -eq 1 -a 0 -gt 0 ]
  4266. + [ -n '' ]
  4267. + [ 0 -eq 1 -a -n '' ]
  4268. + [ 0 -eq 1 ]
  4269. + [ 0 -eq 1 ]
  4270. + [ 1 -eq 1 ]
  4271. + echo -e '[04:21:43] Running Rootkit Hunter version 1.4.2 on beaglebone'
  4272. + [ 0 -eq 1 ]
  4273. + echo '[04:21:43] Running Rootkit Hunter version 1.4.2 on beaglebone'
  4274. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  4275. + [ 0 -eq 1 -a -n '' ]
  4276. + test 0 -eq 1 -a 0 -eq 1
  4277. + return
  4278. + date
  4279. + display --to LOG --type INFO --nl RKH_STARTDATE 'Sun Oct 4 04:21:43 MDT 2015'
  4280. + WARN_MSG=0
  4281. + NL=0
  4282. + NLAFTER=0
  4283. + LOGINDENT=0
  4284. + SCREENINDENT=0
  4285. + LOGNL=0
  4286. + SCREENNL=0
  4287. + WRITETO=''
  4288. + TYPE=''
  4289. + RESULT=''
  4290. + COLOR=''
  4291. + MSG=''
  4292. + LINE1=''
  4293. + LOGLINE1=''
  4294. + SPACES=''
  4295. + NONL=''
  4296. + DISPLAY_LINE='display --to LOG --type INFO --nl RKH_STARTDATE Sun Oct 4 04:21:43 MDT 2015'
  4297. + [ 7 -le 0 ]
  4298. + [ 7 -ge 1 ]
  4299. + WRITETO=LOG
  4300. + shift
  4301. + shift
  4302. + [ 5 -ge 1 ]
  4303. + eval echo '$MSG_TYPE_INFO'
  4304. + echo Info
  4305. + TYPE=Info
  4306. + [ -z Info -a INFO != PLAIN ]
  4307. + test INFO = WARNING
  4308. + shift
  4309. + shift
  4310. + [ 3 -ge 1 ]
  4311. + NL=1
  4312. + shift
  4313. + [ 2 -ge 1 ]
  4314. + MSG=RKH_STARTDATE
  4315. + shift
  4316. + break
  4317. + test 0 -eq 1
  4318. + [ 0 -eq 1 ]
  4319. + [ 0 -eq 1 ]
  4320. + test LOG = SCREEN -o LOG = SCREEN+LOG
  4321. + WRITETOTTY=0
  4322. + test LOG = LOG -o LOG = SCREEN+LOG
  4323. + WRITETOLOG=1
  4324. + [ 0 -eq 0 -a 1 -eq 0 ]
  4325. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  4326. + test -n Info
  4327. + NONL=''
  4328. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  4329. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  4330. + [ -n RKH_STARTDATE ]
  4331. + cut -d: -f2-
  4332. + grep -a ^RKH_STARTDATE: /usr/local/var/lib/rkhunter/db/i18n/en
  4333. + head -n 1
  4334. + LINE1='Start date is $1'
  4335. + [ 0 -eq 1 ]
  4336. + [ -z 'Start date is $1' ]
  4337. + sed -e 's/`/\\`/g'
  4338. + echo 'Start date is $1'
  4339. + LINE1='Start date is $1'
  4340. + test -n 'Start date is $1'
  4341. + eval 'echo "Start date is $1" | sed -e '\''s/;/\;/g'\'
  4342. + sed -e 's/;/\;/g'
  4343. + echo 'Start date is Sun Oct 4 04:21:43 MDT 2015'
  4344. + LINE1='Start date is Sun Oct 4 04:21:43 MDT 2015'
  4345. + [ 1 -eq 1 ]
  4346. + date '+[%H:%M:%S]'
  4347. + LOGLINE1='[04:21:43]'
  4348. + test 1 -gt 0 -o 0 -eq 1
  4349. + echo '[04:21:43]'
  4350. + [ -n Info ]
  4351. + LOGLINE1='[04:21:43] Info: Start date is Sun Oct 4 04:21:43 MDT 2015'
  4352. + [ 0 -eq 1 -a 0 -gt 0 ]
  4353. + [ -n '' ]
  4354. + [ 0 -eq 1 -a -n '' ]
  4355. + [ 0 -eq 1 ]
  4356. + [ 0 -eq 1 ]
  4357. + [ 1 -eq 1 ]
  4358. + echo -e '[04:21:43] Info: Start date is Sun Oct 4 04:21:43 MDT 2015'
  4359. + [ 0 -eq 1 ]
  4360. + echo '[04:21:43] Info: Start date is Sun Oct 4 04:21:43 MDT 2015'
  4361. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  4362. + [ 0 -eq 1 -a -n '' ]
  4363. + test 0 -eq 1 -a 0 -eq 1
  4364. + return
  4365. + display --to LOG --type PLAIN --nl CONFIG_CHECK_START
  4366. + WARN_MSG=0
  4367. + NL=0
  4368. + NLAFTER=0
  4369. + LOGINDENT=0
  4370. + SCREENINDENT=0
  4371. + LOGNL=0
  4372. + SCREENNL=0
  4373. + WRITETO=''
  4374. + TYPE=''
  4375. + RESULT=''
  4376. + COLOR=''
  4377. + MSG=''
  4378. + LINE1=''
  4379. + LOGLINE1=''
  4380. + SPACES=''
  4381. + NONL=''
  4382. + DISPLAY_LINE='display --to LOG --type PLAIN --nl CONFIG_CHECK_START'
  4383. + [ 6 -le 0 ]
  4384. + [ 6 -ge 1 ]
  4385. + WRITETO=LOG
  4386. + shift
  4387. + shift
  4388. + [ 4 -ge 1 ]
  4389. + eval echo '$MSG_TYPE_PLAIN'
  4390. + echo
  4391. + TYPE=''
  4392. + [ -z '' -a PLAIN != PLAIN ]
  4393. + test PLAIN = WARNING
  4394. + shift
  4395. + shift
  4396. + [ 2 -ge 1 ]
  4397. + NL=1
  4398. + shift
  4399. + [ 1 -ge 1 ]
  4400. + MSG=CONFIG_CHECK_START
  4401. + shift
  4402. + break
  4403. + test 0 -eq 1
  4404. + [ 0 -eq 1 ]
  4405. + [ 0 -eq 1 ]
  4406. + test LOG = SCREEN -o LOG = SCREEN+LOG
  4407. + WRITETOTTY=0
  4408. + test LOG = LOG -o LOG = SCREEN+LOG
  4409. + WRITETOLOG=1
  4410. + [ 0 -eq 0 -a 1 -eq 0 ]
  4411. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  4412. + test -n ''
  4413. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  4414. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  4415. + [ -n CONFIG_CHECK_START ]
  4416. + grep -a ^CONFIG_CHECK_START: /usr/local/var/lib/rkhunter/db/i18n/en
  4417. + head -n 1
  4418. + cut -d: -f2-
  4419. + LINE1='Checking configuration file and command-line options...'
  4420. + [ 0 -eq 1 ]
  4421. + [ -z 'Checking configuration file and command-line options...' ]
  4422. + echo 'Checking configuration file and command-line options...'
  4423. + sed -e 's/`/\\`/g'
  4424. + LINE1='Checking configuration file and command-line options...'
  4425. + test -n 'Checking configuration file and command-line options...'
  4426. + eval 'echo "Checking configuration file and command-line options..." | sed -e '\''s/;/\;/g'\'
  4427. + echo 'Checking configuration file and command-line options...'
  4428. + sed -e 's/;/\;/g'
  4429. + LINE1='Checking configuration file and command-line options...'
  4430. + [ 1 -eq 1 ]
  4431. + date '+[%H:%M:%S]'
  4432. + LOGLINE1='[04:21:44]'
  4433. + test 1 -gt 0 -o 0 -eq 1
  4434. + echo '[04:21:44]'
  4435. + [ -n '' ]
  4436. + test 0 -gt 0
  4437. + LOGLINE1='[04:21:44] Checking configuration file and command-line options...'
  4438. + [ 0 -eq 1 -a 0 -gt 0 ]
  4439. + [ -n '' ]
  4440. + [ 0 -eq 1 -a -n '' ]
  4441. + [ 0 -eq 1 ]
  4442. + [ 0 -eq 1 ]
  4443. + [ 1 -eq 1 ]
  4444. + echo -e '[04:21:44] Checking configuration file and command-line options...'
  4445. + [ 0 -eq 1 ]
  4446. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  4447. + echo '[04:21:44] Checking configuration file and command-line options...'
  4448. + [ 0 -eq 1 -a -n '' ]
  4449. + test 0 -eq 1 -a 0 -eq 1
  4450. + return
  4451. + display --to LOG --type INFO OPSYS FreeBSD
  4452. + WARN_MSG=0
  4453. + NL=0
  4454. + NLAFTER=0
  4455. + LOGINDENT=0
  4456. + SCREENINDENT=0
  4457. + LOGNL=0
  4458. + SCREENNL=0
  4459. + WRITETO=''
  4460. + TYPE=''
  4461. + RESULT=''
  4462. + COLOR=''
  4463. + MSG=''
  4464. + LINE1=''
  4465. + LOGLINE1=''
  4466. + SPACES=''
  4467. + NONL=''
  4468. + DISPLAY_LINE='display --to LOG --type INFO OPSYS FreeBSD'
  4469. + [ 6 -le 0 ]
  4470. + [ 6 -ge 1 ]
  4471. + WRITETO=LOG
  4472. + shift
  4473. + shift
  4474. + [ 4 -ge 1 ]
  4475. + eval echo '$MSG_TYPE_INFO'
  4476. + echo Info
  4477. + TYPE=Info
  4478. + [ -z Info -a INFO != PLAIN ]
  4479. + test INFO = WARNING
  4480. + shift
  4481. + shift
  4482. + [ 2 -ge 1 ]
  4483. + MSG=OPSYS
  4484. + shift
  4485. + break
  4486. + test 0 -eq 1
  4487. + [ 0 -eq 1 ]
  4488. + [ 0 -eq 1 ]
  4489. + test LOG = SCREEN -o LOG = SCREEN+LOG
  4490. + WRITETOTTY=0
  4491. + test LOG = LOG -o LOG = SCREEN+LOG
  4492. + WRITETOLOG=1
  4493. + [ 0 -eq 0 -a 1 -eq 0 ]
  4494. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  4495. + test -n Info
  4496. + NONL=''
  4497. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  4498. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  4499. + [ -n OPSYS ]
  4500. + grep -a ^OPSYS: /usr/local/var/lib/rkhunter/db/i18n/en
  4501. + cut -d: -f2-
  4502. + head -n 1
  4503. + LINE1='Detected operating system is '\''$1'\'
  4504. + [ 0 -eq 1 ]
  4505. + [ -z 'Detected operating system is '\''$1'\' ]
  4506. + echo 'Detected operating system is '\''$1'\'
  4507. + sed -e 's/`/\\`/g'
  4508. + LINE1='Detected operating system is '\''$1'\'
  4509. + test -n 'Detected operating system is '\''$1'\'
  4510. + eval 'echo "Detected operating system is '\''$1'\''" | sed -e '\''s/;/\;/g'\'
  4511. + echo 'Detected operating system is '\''FreeBSD'\'
  4512. + sed -e 's/;/\;/g'
  4513. + LINE1='Detected operating system is '\''FreeBSD'\'
  4514. + [ 1 -eq 1 ]
  4515. + date '+[%H:%M:%S]'
  4516. + LOGLINE1='[04:21:44]'
  4517. + test 0 -gt 0 -o 0 -eq 1
  4518. + [ -n Info ]
  4519. + LOGLINE1='[04:21:44] Info: Detected operating system is '\''FreeBSD'\'
  4520. + [ 0 -eq 1 -a 0 -gt 0 ]
  4521. + [ -n '' ]
  4522. + [ 0 -eq 1 -a -n '' ]
  4523. + [ 0 -eq 1 ]
  4524. + [ 0 -eq 1 ]
  4525. + [ 1 -eq 1 ]
  4526. + echo -e '[04:21:44] Info: Detected operating system is '\''FreeBSD'\'
  4527. + [ 0 -eq 1 ]
  4528. + echo '[04:21:44] Info: Detected operating system is '\''FreeBSD'\'
  4529. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  4530. + [ 0 -eq 1 -a -n '' ]
  4531. + test 0 -eq 1 -a 0 -eq 1
  4532. + return
  4533. + [ -s /usr/local/var/lib/rkhunter/db/rkhunter.dat ]
  4534. + grep ^OS: /usr/local/var/lib/rkhunter/db/rkhunter.dat
  4535. + sed -e s/^OS://
  4536. + RKHTMPVAR='FreeBSD 10.2-STABLE'
  4537. + [ -n 'FreeBSD 10.2-STABLE' ]
  4538. + display --to LOG --type INFO PROPUPD_OSNAME_FOUND 'FreeBSD 10.2-STABLE'
  4539. + WARN_MSG=0
  4540. + NL=0
  4541. + NLAFTER=0
  4542. + LOGINDENT=0
  4543. + SCREENINDENT=0
  4544. + LOGNL=0
  4545. + SCREENNL=0
  4546. + WRITETO=''
  4547. + TYPE=''
  4548. + RESULT=''
  4549. + COLOR=''
  4550. + MSG=''
  4551. + LINE1=''
  4552. + LOGLINE1=''
  4553. + SPACES=''
  4554. + NONL=''
  4555. + DISPLAY_LINE='display --to LOG --type INFO PROPUPD_OSNAME_FOUND FreeBSD 10.2-STABLE'
  4556. + [ 6 -le 0 ]
  4557. + [ 6 -ge 1 ]
  4558. + WRITETO=LOG
  4559. + shift
  4560. + shift
  4561. + [ 4 -ge 1 ]
  4562. + eval echo '$MSG_TYPE_INFO'
  4563. + echo Info
  4564. + TYPE=Info
  4565. + [ -z Info -a INFO != PLAIN ]
  4566. + test INFO = WARNING
  4567. + shift
  4568. + shift
  4569. + [ 2 -ge 1 ]
  4570. + MSG=PROPUPD_OSNAME_FOUND
  4571. + shift
  4572. + break
  4573. + test 0 -eq 1
  4574. + [ 0 -eq 1 ]
  4575. + [ 0 -eq 1 ]
  4576. + test LOG = SCREEN -o LOG = SCREEN+LOG
  4577. + WRITETOTTY=0
  4578. + test LOG = LOG -o LOG = SCREEN+LOG
  4579. + WRITETOLOG=1
  4580. + [ 0 -eq 0 -a 1 -eq 0 ]
  4581. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  4582. + test -n Info
  4583. + NONL=''
  4584. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  4585. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  4586. + [ -n PROPUPD_OSNAME_FOUND ]
  4587. + grep -a ^PROPUPD_OSNAME_FOUND: /usr/local/var/lib/rkhunter/db/i18n/en
  4588. + head -n 1
  4589. + cut -d: -f2-
  4590. + LINE1='Found O/S name: $1'
  4591. + [ 0 -eq 1 ]
  4592. + [ -z 'Found O/S name: $1' ]
  4593. + echo 'Found O/S name: $1'
  4594. + sed -e 's/`/\\`/g'
  4595. + LINE1='Found O/S name: $1'
  4596. + test -n 'Found O/S name: $1'
  4597. + eval 'echo "Found O/S name: $1" | sed -e '\''s/;/\;/g'\'
  4598. + echo 'Found O/S name: FreeBSD 10.2-STABLE'
  4599. + sed -e 's/;/\;/g'
  4600. + LINE1='Found O/S name: FreeBSD 10.2-STABLE'
  4601. + [ 1 -eq 1 ]
  4602. + date '+[%H:%M:%S]'
  4603. + LOGLINE1='[04:21:44]'
  4604. + test 0 -gt 0 -o 0 -eq 1
  4605. + [ -n Info ]
  4606. + LOGLINE1='[04:21:44] Info: Found O/S name: FreeBSD 10.2-STABLE'
  4607. + [ 0 -eq 1 -a 0 -gt 0 ]
  4608. + [ -n '' ]
  4609. + [ 0 -eq 1 -a -n '' ]
  4610. + [ 0 -eq 1 ]
  4611. + [ 0 -eq 1 ]
  4612. + [ 1 -eq 1 ]
  4613. + echo -e '[04:21:44] Info: Found O/S name: FreeBSD 10.2-STABLE'
  4614. + [ 0 -eq 1 ]
  4615. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  4616. + echo '[04:21:44] Info: Found O/S name: FreeBSD 10.2-STABLE'
  4617. + [ 0 -eq 1 -a -n '' ]
  4618. + test 0 -eq 1 -a 0 -eq 1
  4619. + return
  4620. + display --to LOG --type INFO CONFIG_CMDLINE '/usr/local/bin/rkhunter --enable filesystem --check --debug'
  4621. + WARN_MSG=0
  4622. + NL=0
  4623. + NLAFTER=0
  4624. + LOGINDENT=0
  4625. + SCREENINDENT=0
  4626. + LOGNL=0
  4627. + SCREENNL=0
  4628. + WRITETO=''
  4629. + TYPE=''
  4630. + RESULT=''
  4631. + COLOR=''
  4632. + MSG=''
  4633. + LINE1=''
  4634. + LOGLINE1=''
  4635. + SPACES=''
  4636. + NONL=''
  4637. + DISPLAY_LINE='display --to LOG --type INFO CONFIG_CMDLINE /usr/local/bin/rkhunter --enable filesystem --check --debug'
  4638. + [ 6 -le 0 ]
  4639. + [ 6 -ge 1 ]
  4640. + WRITETO=LOG
  4641. + shift
  4642. + shift
  4643. + [ 4 -ge 1 ]
  4644. + eval echo '$MSG_TYPE_INFO'
  4645. + echo Info
  4646. + TYPE=Info
  4647. + [ -z Info -a INFO != PLAIN ]
  4648. + test INFO = WARNING
  4649. + shift
  4650. + shift
  4651. + [ 2 -ge 1 ]
  4652. + MSG=CONFIG_CMDLINE
  4653. + shift
  4654. + break
  4655. + test 0 -eq 1
  4656. + [ 0 -eq 1 ]
  4657. + [ 0 -eq 1 ]
  4658. + test LOG = SCREEN -o LOG = SCREEN+LOG
  4659. + WRITETOTTY=0
  4660. + test LOG = LOG -o LOG = SCREEN+LOG
  4661. + WRITETOLOG=1
  4662. + [ 0 -eq 0 -a 1 -eq 0 ]
  4663. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  4664. + test -n Info
  4665. + NONL=''
  4666. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  4667. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  4668. + [ -n CONFIG_CMDLINE ]
  4669. + grep -a ^CONFIG_CMDLINE: /usr/local/var/lib/rkhunter/db/i18n/en
  4670. + cut -d: -f2-
  4671. + head -n 1
  4672. + LINE1='Command line is $1'
  4673. + [ 0 -eq 1 ]
  4674. + [ -z 'Command line is $1' ]
  4675. + echo 'Command line is $1'
  4676. + sed -e 's/`/\\`/g'
  4677. + LINE1='Command line is $1'
  4678. + test -n 'Command line is $1'
  4679. + eval 'echo "Command line is $1" | sed -e '\''s/;/\;/g'\'
  4680. + echo 'Command line is /usr/local/bin/rkhunter --enable filesystem --check --debug'
  4681. + sed -e 's/;/\;/g'
  4682. + LINE1='Command line is /usr/local/bin/rkhunter --enable filesystem --check --debug'
  4683. + [ 1 -eq 1 ]
  4684. + date '+[%H:%M:%S]'
  4685. + LOGLINE1='[04:21:44]'
  4686. + test 0 -gt 0 -o 0 -eq 1
  4687. + [ -n Info ]
  4688. + LOGLINE1='[04:21:44] Info: Command line is /usr/local/bin/rkhunter --enable filesystem --check --debug'
  4689. + [ 0 -eq 1 -a 0 -gt 0 ]
  4690. + [ -n '' ]
  4691. + [ 0 -eq 1 -a -n '' ]
  4692. + [ 0 -eq 1 ]
  4693. + [ 0 -eq 1 ]
  4694. + [ 1 -eq 1 ]
  4695. + echo -e '[04:21:44] Info: Command line is /usr/local/bin/rkhunter --enable filesystem --check --debug'
  4696. + [ 0 -eq 1 ]
  4697. + echo '[04:21:44] Info: Command line is /usr/local/bin/rkhunter --enable filesystem --check --debug'
  4698. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  4699. + [ 0 -eq 1 -a -n '' ]
  4700. + test 0 -eq 1 -a 0 -eq 1
  4701. + return
  4702. + test 1 -eq 1
  4703. + display --to LOG --type INFO CONFIG_DEBUGFILE /tmp/rkhunter-debug.5iMmvgeVys
  4704. + WARN_MSG=0
  4705. + NL=0
  4706. + NLAFTER=0
  4707. + LOGINDENT=0
  4708. + SCREENINDENT=0
  4709. + LOGNL=0
  4710. + SCREENNL=0
  4711. + WRITETO=''
  4712. + TYPE=''
  4713. + RESULT=''
  4714. + COLOR=''
  4715. + MSG=''
  4716. + LINE1=''
  4717. + LOGLINE1=''
  4718. + SPACES=''
  4719. + NONL=''
  4720. + DISPLAY_LINE='display --to LOG --type INFO CONFIG_DEBUGFILE /tmp/rkhunter-debug.5iMmvgeVys'
  4721. + [ 6 -le 0 ]
  4722. + [ 6 -ge 1 ]
  4723. + WRITETO=LOG
  4724. + shift
  4725. + shift
  4726. + [ 4 -ge 1 ]
  4727. + eval echo '$MSG_TYPE_INFO'
  4728. + echo Info
  4729. + TYPE=Info
  4730. + [ -z Info -a INFO != PLAIN ]
  4731. + test INFO = WARNING
  4732. + shift
  4733. + shift
  4734. + [ 2 -ge 1 ]
  4735. + MSG=CONFIG_DEBUGFILE
  4736. + shift
  4737. + break
  4738. + test 0 -eq 1
  4739. + [ 0 -eq 1 ]
  4740. + [ 0 -eq 1 ]
  4741. + test LOG = SCREEN -o LOG = SCREEN+LOG
  4742. + WRITETOTTY=0
  4743. + test LOG = LOG -o LOG = SCREEN+LOG
  4744. + WRITETOLOG=1
  4745. + [ 0 -eq 0 -a 1 -eq 0 ]
  4746. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  4747. + test -n Info
  4748. + NONL=''
  4749. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  4750. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  4751. + [ -n CONFIG_DEBUGFILE ]
  4752. + head -n 1
  4753. + cut -d: -f2-
  4754. + grep -a ^CONFIG_DEBUGFILE: /usr/local/var/lib/rkhunter/db/i18n/en
  4755. + LINE1='Debug file is $1'
  4756. + [ 0 -eq 1 ]
  4757. + [ -z 'Debug file is $1' ]
  4758. + sed -e 's/`/\\`/g'
  4759. + echo 'Debug file is $1'
  4760. + LINE1='Debug file is $1'
  4761. + test -n 'Debug file is $1'
  4762. + eval 'echo "Debug file is $1" | sed -e '\''s/;/\;/g'\'
  4763. + sed -e 's/;/\;/g'
  4764. + echo 'Debug file is /tmp/rkhunter-debug.5iMmvgeVys'
  4765. + LINE1='Debug file is /tmp/rkhunter-debug.5iMmvgeVys'
  4766. + [ 1 -eq 1 ]
  4767. + date '+[%H:%M:%S]'
  4768. + LOGLINE1='[04:21:44]'
  4769. + test 0 -gt 0 -o 0 -eq 1
  4770. + [ -n Info ]
  4771. + LOGLINE1='[04:21:44] Info: Debug file is /tmp/rkhunter-debug.5iMmvgeVys'
  4772. + [ 0 -eq 1 -a 0 -gt 0 ]
  4773. + [ -n '' ]
  4774. + [ 0 -eq 1 -a -n '' ]
  4775. + [ 0 -eq 1 ]
  4776. + [ 0 -eq 1 ]
  4777. + [ 1 -eq 1 ]
  4778. + echo -e '[04:21:44] Info: Debug file is /tmp/rkhunter-debug.5iMmvgeVys'
  4779. + [ 0 -eq 1 ]
  4780. + echo '[04:21:44] Info: Debug file is /tmp/rkhunter-debug.5iMmvgeVys'
  4781. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  4782. + [ 0 -eq 1 -a -n '' ]
  4783. + test 0 -eq 1 -a 0 -eq 1
  4784. + return
  4785. + display --to LOG --type INFO CONFIG_ENVSHELL /bin/tcsh sh
  4786. + WARN_MSG=0
  4787. + NL=0
  4788. + NLAFTER=0
  4789. + LOGINDENT=0
  4790. + SCREENINDENT=0
  4791. + LOGNL=0
  4792. + SCREENNL=0
  4793. + WRITETO=''
  4794. + TYPE=''
  4795. + RESULT=''
  4796. + COLOR=''
  4797. + MSG=''
  4798. + LINE1=''
  4799. + LOGLINE1=''
  4800. + SPACES=''
  4801. + NONL=''
  4802. + DISPLAY_LINE='display --to LOG --type INFO CONFIG_ENVSHELL /bin/tcsh sh'
  4803. + [ 7 -le 0 ]
  4804. + [ 7 -ge 1 ]
  4805. + WRITETO=LOG
  4806. + shift
  4807. + shift
  4808. + [ 5 -ge 1 ]
  4809. + eval echo '$MSG_TYPE_INFO'
  4810. + echo Info
  4811. + TYPE=Info
  4812. + [ -z Info -a INFO != PLAIN ]
  4813. + test INFO = WARNING
  4814. + shift
  4815. + shift
  4816. + [ 3 -ge 1 ]
  4817. + MSG=CONFIG_ENVSHELL
  4818. + shift
  4819. + break
  4820. + test 0 -eq 1
  4821. + [ 0 -eq 1 ]
  4822. + [ 0 -eq 1 ]
  4823. + test LOG = SCREEN -o LOG = SCREEN+LOG
  4824. + WRITETOTTY=0
  4825. + test LOG = LOG -o LOG = SCREEN+LOG
  4826. + WRITETOLOG=1
  4827. + [ 0 -eq 0 -a 1 -eq 0 ]
  4828. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  4829. + test -n Info
  4830. + NONL=''
  4831. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  4832. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  4833. + [ -n CONFIG_ENVSHELL ]
  4834. + grep -a ^CONFIG_ENVSHELL: /usr/local/var/lib/rkhunter/db/i18n/en
  4835. + head -n 1
  4836. + cut -d: -f2-
  4837. + LINE1='Environment shell is $1; rkhunter is using $2'
  4838. + [ 0 -eq 1 ]
  4839. + [ -z 'Environment shell is $1; rkhunter is using $2' ]
  4840. + echo 'Environment shell is $1; rkhunter is using $2'
  4841. + sed -e 's/`/\\`/g'
  4842. + LINE1='Environment shell is $1; rkhunter is using $2'
  4843. + test -n 'Environment shell is $1; rkhunter is using $2'
  4844. + eval 'echo "Environment shell is $1; rkhunter is using $2" | sed -e '\''s/;/\;/g'\'
  4845. + echo 'Environment shell is /bin/tcsh; rkhunter is using sh'
  4846. + sed -e 's/;/\;/g'
  4847. + LINE1='Environment shell is /bin/tcsh; rkhunter is using sh'
  4848. + [ 1 -eq 1 ]
  4849. + date '+[%H:%M:%S]'
  4850. + LOGLINE1='[04:21:45]'
  4851. + test 0 -gt 0 -o 0 -eq 1
  4852. + [ -n Info ]
  4853. + LOGLINE1='[04:21:45] Info: Environment shell is /bin/tcsh; rkhunter is using sh'
  4854. + [ 0 -eq 1 -a 0 -gt 0 ]
  4855. + [ -n '' ]
  4856. + [ 0 -eq 1 -a -n '' ]
  4857. + [ 0 -eq 1 ]
  4858. + [ 0 -eq 1 ]
  4859. + [ 1 -eq 1 ]
  4860. + echo -e '[04:21:45] Info: Environment shell is /bin/tcsh; rkhunter is using sh'
  4861. + [ 0 -eq 1 ]
  4862. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  4863. + echo '[04:21:45] Info: Environment shell is /bin/tcsh; rkhunter is using sh'
  4864. + [ 0 -eq 1 -a -n '' ]
  4865. + test 0 -eq 1 -a 0 -eq 1
  4866. + return
  4867. + display --to LOG --type INFO CONFIG_CONFIGFILE /usr/local/etc/rkhunter.conf
  4868. + WARN_MSG=0
  4869. + NL=0
  4870. + NLAFTER=0
  4871. + LOGINDENT=0
  4872. + SCREENINDENT=0
  4873. + LOGNL=0
  4874. + SCREENNL=0
  4875. + WRITETO=''
  4876. + TYPE=''
  4877. + RESULT=''
  4878. + COLOR=''
  4879. + MSG=''
  4880. + LINE1=''
  4881. + LOGLINE1=''
  4882. + SPACES=''
  4883. + NONL=''
  4884. + DISPLAY_LINE='display --to LOG --type INFO CONFIG_CONFIGFILE /usr/local/etc/rkhunter.conf'
  4885. + [ 6 -le 0 ]
  4886. + [ 6 -ge 1 ]
  4887. + WRITETO=LOG
  4888. + shift
  4889. + shift
  4890. + [ 4 -ge 1 ]
  4891. + eval echo '$MSG_TYPE_INFO'
  4892. + echo Info
  4893. + TYPE=Info
  4894. + [ -z Info -a INFO != PLAIN ]
  4895. + test INFO = WARNING
  4896. + shift
  4897. + shift
  4898. + [ 2 -ge 1 ]
  4899. + MSG=CONFIG_CONFIGFILE
  4900. + shift
  4901. + break
  4902. + test 0 -eq 1
  4903. + [ 0 -eq 1 ]
  4904. + [ 0 -eq 1 ]
  4905. + test LOG = SCREEN -o LOG = SCREEN+LOG
  4906. + WRITETOTTY=0
  4907. + test LOG = LOG -o LOG = SCREEN+LOG
  4908. + WRITETOLOG=1
  4909. + [ 0 -eq 0 -a 1 -eq 0 ]
  4910. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  4911. + test -n Info
  4912. + NONL=''
  4913. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  4914. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  4915. + [ -n CONFIG_CONFIGFILE ]
  4916. + grep -a ^CONFIG_CONFIGFILE: /usr/local/var/lib/rkhunter/db/i18n/en
  4917. + cut -d: -f2-
  4918. + head -n 1
  4919. + LINE1='Using configuration file '\''$1'\'
  4920. + [ 0 -eq 1 ]
  4921. + [ -z 'Using configuration file '\''$1'\' ]
  4922. + echo 'Using configuration file '\''$1'\'
  4923. + sed -e 's/`/\\`/g'
  4924. + LINE1='Using configuration file '\''$1'\'
  4925. + test -n 'Using configuration file '\''$1'\'
  4926. + eval 'echo "Using configuration file '\''$1'\''" | sed -e '\''s/;/\;/g'\'
  4927. + echo 'Using configuration file '\''/usr/local/etc/rkhunter.conf'\'
  4928. + sed -e 's/;/\;/g'
  4929. + LINE1='Using configuration file '\''/usr/local/etc/rkhunter.conf'\'
  4930. + [ 1 -eq 1 ]
  4931. + date '+[%H:%M:%S]'
  4932. + LOGLINE1='[04:21:45]'
  4933. + test 0 -gt 0 -o 0 -eq 1
  4934. + [ -n Info ]
  4935. + LOGLINE1='[04:21:45] Info: Using configuration file '\''/usr/local/etc/rkhunter.conf'\'
  4936. + [ 0 -eq 1 -a 0 -gt 0 ]
  4937. + [ -n '' ]
  4938. + [ 0 -eq 1 -a -n '' ]
  4939. + [ 0 -eq 1 ]
  4940. + [ 0 -eq 1 ]
  4941. + [ 1 -eq 1 ]
  4942. + echo -e '[04:21:45] Info: Using configuration file '\''/usr/local/etc/rkhunter.conf'\'
  4943. + [ 0 -eq 1 ]
  4944. + echo '[04:21:45] Info: Using configuration file '\''/usr/local/etc/rkhunter.conf'\'
  4945. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  4946. + [ 0 -eq 1 -a -n '' ]
  4947. + test 0 -eq 1 -a 0 -eq 1
  4948. + return
  4949. + test -n ''
  4950. + [ -n '' ]
  4951. + display --to LOG --type INFO CONFIG_INSTALLDIR /usr/local
  4952. + WARN_MSG=0
  4953. + NL=0
  4954. + NLAFTER=0
  4955. + LOGINDENT=0
  4956. + SCREENINDENT=0
  4957. + LOGNL=0
  4958. + SCREENNL=0
  4959. + WRITETO=''
  4960. + TYPE=''
  4961. + RESULT=''
  4962. + COLOR=''
  4963. + MSG=''
  4964. + LINE1=''
  4965. + LOGLINE1=''
  4966. + SPACES=''
  4967. + NONL=''
  4968. + DISPLAY_LINE='display --to LOG --type INFO CONFIG_INSTALLDIR /usr/local'
  4969. + [ 6 -le 0 ]
  4970. + [ 6 -ge 1 ]
  4971. + WRITETO=LOG
  4972. + shift
  4973. + shift
  4974. + [ 4 -ge 1 ]
  4975. + eval echo '$MSG_TYPE_INFO'
  4976. + echo Info
  4977. + TYPE=Info
  4978. + [ -z Info -a INFO != PLAIN ]
  4979. + test INFO = WARNING
  4980. + shift
  4981. + shift
  4982. + [ 2 -ge 1 ]
  4983. + MSG=CONFIG_INSTALLDIR
  4984. + shift
  4985. + break
  4986. + test 0 -eq 1
  4987. + [ 0 -eq 1 ]
  4988. + [ 0 -eq 1 ]
  4989. + test LOG = SCREEN -o LOG = SCREEN+LOG
  4990. + WRITETOTTY=0
  4991. + test LOG = LOG -o LOG = SCREEN+LOG
  4992. + WRITETOLOG=1
  4993. + [ 0 -eq 0 -a 1 -eq 0 ]
  4994. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  4995. + test -n Info
  4996. + NONL=''
  4997. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  4998. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  4999. + [ -n CONFIG_INSTALLDIR ]
  5000. + head -n 1
  5001. + cut -d: -f2-
  5002. + grep -a ^CONFIG_INSTALLDIR: /usr/local/var/lib/rkhunter/db/i18n/en
  5003. + LINE1='Installation directory is '\''$1'\'
  5004. + [ 0 -eq 1 ]
  5005. + [ -z 'Installation directory is '\''$1'\' ]
  5006. + sed -e 's/`/\\`/g'
  5007. + echo 'Installation directory is '\''$1'\'
  5008. + LINE1='Installation directory is '\''$1'\'
  5009. + test -n 'Installation directory is '\''$1'\'
  5010. + eval 'echo "Installation directory is '\''$1'\''" | sed -e '\''s/;/\;/g'\'
  5011. + sed -e 's/;/\;/g'
  5012. + echo 'Installation directory is '\''/usr/local'\'
  5013. + LINE1='Installation directory is '\''/usr/local'\'
  5014. + [ 1 -eq 1 ]
  5015. + date '+[%H:%M:%S]'
  5016. + LOGLINE1='[04:21:45]'
  5017. + test 0 -gt 0 -o 0 -eq 1
  5018. + [ -n Info ]
  5019. + LOGLINE1='[04:21:45] Info: Installation directory is '\''/usr/local'\'
  5020. + [ 0 -eq 1 -a 0 -gt 0 ]
  5021. + [ -n '' ]
  5022. + [ 0 -eq 1 -a -n '' ]
  5023. + [ 0 -eq 1 ]
  5024. + [ 0 -eq 1 ]
  5025. + [ 1 -eq 1 ]
  5026. + echo -e '[04:21:45] Info: Installation directory is '\''/usr/local'\'
  5027. + [ 0 -eq 1 ]
  5028. + echo '[04:21:45] Info: Installation directory is '\''/usr/local'\'
  5029. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  5030. + [ 0 -eq 1 -a -n '' ]
  5031. + test 0 -eq 1 -a 0 -eq 1
  5032. + return
  5033. + display --to LOG --type INFO CONFIG_LANGUAGE en
  5034. + WARN_MSG=0
  5035. + NL=0
  5036. + NLAFTER=0
  5037. + LOGINDENT=0
  5038. + SCREENINDENT=0
  5039. + LOGNL=0
  5040. + SCREENNL=0
  5041. + WRITETO=''
  5042. + TYPE=''
  5043. + RESULT=''
  5044. + COLOR=''
  5045. + MSG=''
  5046. + LINE1=''
  5047. + LOGLINE1=''
  5048. + SPACES=''
  5049. + NONL=''
  5050. + DISPLAY_LINE='display --to LOG --type INFO CONFIG_LANGUAGE en'
  5051. + [ 6 -le 0 ]
  5052. + [ 6 -ge 1 ]
  5053. + WRITETO=LOG
  5054. + shift
  5055. + shift
  5056. + [ 4 -ge 1 ]
  5057. + eval echo '$MSG_TYPE_INFO'
  5058. + echo Info
  5059. + TYPE=Info
  5060. + [ -z Info -a INFO != PLAIN ]
  5061. + test INFO = WARNING
  5062. + shift
  5063. + shift
  5064. + [ 2 -ge 1 ]
  5065. + MSG=CONFIG_LANGUAGE
  5066. + shift
  5067. + break
  5068. + test 0 -eq 1
  5069. + [ 0 -eq 1 ]
  5070. + [ 0 -eq 1 ]
  5071. + test LOG = SCREEN -o LOG = SCREEN+LOG
  5072. + WRITETOTTY=0
  5073. + test LOG = LOG -o LOG = SCREEN+LOG
  5074. + WRITETOLOG=1
  5075. + [ 0 -eq 0 -a 1 -eq 0 ]
  5076. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  5077. + test -n Info
  5078. + NONL=''
  5079. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  5080. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  5081. + [ -n CONFIG_LANGUAGE ]
  5082. + grep -a ^CONFIG_LANGUAGE: /usr/local/var/lib/rkhunter/db/i18n/en
  5083. + head -n 1
  5084. + cut -d: -f2-
  5085. + LINE1='Using language '\''$1'\'
  5086. + [ 0 -eq 1 ]
  5087. + [ -z 'Using language '\''$1'\' ]
  5088. + echo 'Using language '\''$1'\'
  5089. + sed -e 's/`/\\`/g'
  5090. + LINE1='Using language '\''$1'\'
  5091. + test -n 'Using language '\''$1'\'
  5092. + eval 'echo "Using language '\''$1'\''" | sed -e '\''s/;/\;/g'\'
  5093. + echo 'Using language '\''en'\'
  5094. + sed -e 's/;/\;/g'
  5095. + LINE1='Using language '\''en'\'
  5096. + [ 1 -eq 1 ]
  5097. + date '+[%H:%M:%S]'
  5098. + LOGLINE1='[04:21:45]'
  5099. + test 0 -gt 0 -o 0 -eq 1
  5100. + [ -n Info ]
  5101. + LOGLINE1='[04:21:45] Info: Using language '\''en'\'
  5102. + [ 0 -eq 1 -a 0 -gt 0 ]
  5103. + [ -n '' ]
  5104. + [ 0 -eq 1 -a -n '' ]
  5105. + [ 0 -eq 1 ]
  5106. + [ 0 -eq 1 ]
  5107. + [ 1 -eq 1 ]
  5108. + echo -e '[04:21:45] Info: Using language '\''en'\'
  5109. + [ 0 -eq 1 ]
  5110. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  5111. + echo '[04:21:45] Info: Using language '\''en'\'
  5112. + [ 0 -eq 1 -a -n '' ]
  5113. + test 0 -eq 1 -a 0 -eq 1
  5114. + return
  5115. + display --to LOG --type INFO CONFIG_DBDIR /usr/local/var/lib/rkhunter/db
  5116. + WARN_MSG=0
  5117. + NL=0
  5118. + NLAFTER=0
  5119. + LOGINDENT=0
  5120. + SCREENINDENT=0
  5121. + LOGNL=0
  5122. + SCREENNL=0
  5123. + WRITETO=''
  5124. + TYPE=''
  5125. + RESULT=''
  5126. + COLOR=''
  5127. + MSG=''
  5128. + LINE1=''
  5129. + LOGLINE1=''
  5130. + SPACES=''
  5131. + NONL=''
  5132. + DISPLAY_LINE='display --to LOG --type INFO CONFIG_DBDIR /usr/local/var/lib/rkhunter/db'
  5133. + [ 6 -le 0 ]
  5134. + [ 6 -ge 1 ]
  5135. + WRITETO=LOG
  5136. + shift
  5137. + shift
  5138. + [ 4 -ge 1 ]
  5139. + eval echo '$MSG_TYPE_INFO'
  5140. + echo Info
  5141. + TYPE=Info
  5142. + [ -z Info -a INFO != PLAIN ]
  5143. + test INFO = WARNING
  5144. + shift
  5145. + shift
  5146. + [ 2 -ge 1 ]
  5147. + MSG=CONFIG_DBDIR
  5148. + shift
  5149. + break
  5150. + test 0 -eq 1
  5151. + [ 0 -eq 1 ]
  5152. + [ 0 -eq 1 ]
  5153. + test LOG = SCREEN -o LOG = SCREEN+LOG
  5154. + WRITETOTTY=0
  5155. + test LOG = LOG -o LOG = SCREEN+LOG
  5156. + WRITETOLOG=1
  5157. + [ 0 -eq 0 -a 1 -eq 0 ]
  5158. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  5159. + test -n Info
  5160. + NONL=''
  5161. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  5162. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  5163. + [ -n CONFIG_DBDIR ]
  5164. + grep -a ^CONFIG_DBDIR: /usr/local/var/lib/rkhunter/db/i18n/en
  5165. + head -n 1
  5166. + cut -d: -f2-
  5167. + LINE1='Using '\''$1'\'' as the database directory'
  5168. + [ 0 -eq 1 ]
  5169. + [ -z 'Using '\''$1'\'' as the database directory' ]
  5170. + echo 'Using '\''$1'\'' as the database directory'
  5171. + sed -e 's/`/\\`/g'
  5172. + LINE1='Using '\''$1'\'' as the database directory'
  5173. + test -n 'Using '\''$1'\'' as the database directory'
  5174. + eval 'echo "Using '\''$1'\'' as the database directory" | sed -e '\''s/;/\;/g'\'
  5175. + echo 'Using '\''/usr/local/var/lib/rkhunter/db'\'' as the database directory'
  5176. + sed -e 's/;/\;/g'
  5177. + LINE1='Using '\''/usr/local/var/lib/rkhunter/db'\'' as the database directory'
  5178. + [ 1 -eq 1 ]
  5179. + date '+[%H:%M:%S]'
  5180. + LOGLINE1='[04:21:45]'
  5181. + test 0 -gt 0 -o 0 -eq 1
  5182. + [ -n Info ]
  5183. + LOGLINE1='[04:21:45] Info: Using '\''/usr/local/var/lib/rkhunter/db'\'' as the database directory'
  5184. + [ 0 -eq 1 -a 0 -gt 0 ]
  5185. + [ -n '' ]
  5186. + [ 0 -eq 1 -a -n '' ]
  5187. + [ 0 -eq 1 ]
  5188. + [ 0 -eq 1 ]
  5189. + [ 1 -eq 1 ]
  5190. + echo -e '[04:21:45] Info: Using '\''/usr/local/var/lib/rkhunter/db'\'' as the database directory'
  5191. + [ 0 -eq 1 ]
  5192. + echo '[04:21:45] Info: Using '\''/usr/local/var/lib/rkhunter/db'\'' as the database directory'
  5193. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  5194. + [ 0 -eq 1 -a -n '' ]
  5195. + test 0 -eq 1 -a 0 -eq 1
  5196. + return
  5197. + display --to LOG --type INFO CONFIG_SCRIPTDIR /usr/local/lib/rkhunter/scripts
  5198. + WARN_MSG=0
  5199. + NL=0
  5200. + NLAFTER=0
  5201. + LOGINDENT=0
  5202. + SCREENINDENT=0
  5203. + LOGNL=0
  5204. + SCREENNL=0
  5205. + WRITETO=''
  5206. + TYPE=''
  5207. + RESULT=''
  5208. + COLOR=''
  5209. + MSG=''
  5210. + LINE1=''
  5211. + LOGLINE1=''
  5212. + SPACES=''
  5213. + NONL=''
  5214. + DISPLAY_LINE='display --to LOG --type INFO CONFIG_SCRIPTDIR /usr/local/lib/rkhunter/scripts'
  5215. + [ 6 -le 0 ]
  5216. + [ 6 -ge 1 ]
  5217. + WRITETO=LOG
  5218. + shift
  5219. + shift
  5220. + [ 4 -ge 1 ]
  5221. + eval echo '$MSG_TYPE_INFO'
  5222. + echo Info
  5223. + TYPE=Info
  5224. + [ -z Info -a INFO != PLAIN ]
  5225. + test INFO = WARNING
  5226. + shift
  5227. + shift
  5228. + [ 2 -ge 1 ]
  5229. + MSG=CONFIG_SCRIPTDIR
  5230. + shift
  5231. + break
  5232. + test 0 -eq 1
  5233. + [ 0 -eq 1 ]
  5234. + [ 0 -eq 1 ]
  5235. + test LOG = SCREEN -o LOG = SCREEN+LOG
  5236. + WRITETOTTY=0
  5237. + test LOG = LOG -o LOG = SCREEN+LOG
  5238. + WRITETOLOG=1
  5239. + [ 0 -eq 0 -a 1 -eq 0 ]
  5240. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  5241. + test -n Info
  5242. + NONL=''
  5243. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  5244. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  5245. + [ -n CONFIG_SCRIPTDIR ]
  5246. + head -n 1
  5247. + cut -d: -f2-
  5248. + grep -a ^CONFIG_SCRIPTDIR: /usr/local/var/lib/rkhunter/db/i18n/en
  5249. + LINE1='Using '\''$1'\'' as the support script directory'
  5250. + [ 0 -eq 1 ]
  5251. + [ -z 'Using '\''$1'\'' as the support script directory' ]
  5252. + sed -e 's/`/\\`/g'
  5253. + echo 'Using '\''$1'\'' as the support script directory'
  5254. + LINE1='Using '\''$1'\'' as the support script directory'
  5255. + test -n 'Using '\''$1'\'' as the support script directory'
  5256. + eval 'echo "Using '\''$1'\'' as the support script directory" | sed -e '\''s/;/\;/g'\'
  5257. + sed -e 's/;/\;/g'
  5258. + echo 'Using '\''/usr/local/lib/rkhunter/scripts'\'' as the support script directory'
  5259. + LINE1='Using '\''/usr/local/lib/rkhunter/scripts'\'' as the support script directory'
  5260. + [ 1 -eq 1 ]
  5261. + date '+[%H:%M:%S]'
  5262. + LOGLINE1='[04:21:45]'
  5263. + test 0 -gt 0 -o 0 -eq 1
  5264. + [ -n Info ]
  5265. + LOGLINE1='[04:21:45] Info: Using '\''/usr/local/lib/rkhunter/scripts'\'' as the support script directory'
  5266. + [ 0 -eq 1 -a 0 -gt 0 ]
  5267. + [ -n '' ]
  5268. + [ 0 -eq 1 -a -n '' ]
  5269. + [ 0 -eq 1 ]
  5270. + [ 0 -eq 1 ]
  5271. + [ 1 -eq 1 ]
  5272. + echo -e '[04:21:45] Info: Using '\''/usr/local/lib/rkhunter/scripts'\'' as the support script directory'
  5273. + [ 0 -eq 1 ]
  5274. + echo '[04:21:45] Info: Using '\''/usr/local/lib/rkhunter/scripts'\'' as the support script directory'
  5275. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  5276. + [ 0 -eq 1 -a -n '' ]
  5277. + test 0 -eq 1 -a 0 -eq 1
  5278. + return
  5279. + display --to LOG --type INFO CONFIG_BINDIR '/sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin /usr/libexec /usr/local/libexec'
  5280. + WARN_MSG=0
  5281. + NL=0
  5282. + NLAFTER=0
  5283. + LOGINDENT=0
  5284. + SCREENINDENT=0
  5285. + LOGNL=0
  5286. + SCREENNL=0
  5287. + WRITETO=''
  5288. + TYPE=''
  5289. + RESULT=''
  5290. + COLOR=''
  5291. + MSG=''
  5292. + LINE1=''
  5293. + LOGLINE1=''
  5294. + SPACES=''
  5295. + NONL=''
  5296. + DISPLAY_LINE='display --to LOG --type INFO CONFIG_BINDIR /sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin /usr/libexec /usr/local/libexec'
  5297. + [ 6 -le 0 ]
  5298. + [ 6 -ge 1 ]
  5299. + WRITETO=LOG
  5300. + shift
  5301. + shift
  5302. + [ 4 -ge 1 ]
  5303. + eval echo '$MSG_TYPE_INFO'
  5304. + echo Info
  5305. + TYPE=Info
  5306. + [ -z Info -a INFO != PLAIN ]
  5307. + test INFO = WARNING
  5308. + shift
  5309. + shift
  5310. + [ 2 -ge 1 ]
  5311. + MSG=CONFIG_BINDIR
  5312. + shift
  5313. + break
  5314. + test 0 -eq 1
  5315. + [ 0 -eq 1 ]
  5316. + [ 0 -eq 1 ]
  5317. + test LOG = SCREEN -o LOG = SCREEN+LOG
  5318. + WRITETOTTY=0
  5319. + test LOG = LOG -o LOG = SCREEN+LOG
  5320. + WRITETOLOG=1
  5321. + [ 0 -eq 0 -a 1 -eq 0 ]
  5322. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  5323. + test -n Info
  5324. + NONL=''
  5325. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  5326. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  5327. + [ -n CONFIG_BINDIR ]
  5328. + grep -a ^CONFIG_BINDIR: /usr/local/var/lib/rkhunter/db/i18n/en
  5329. + head -n 1
  5330. + cut -d: -f2-
  5331. + LINE1='Using '\''$1'\'' as the command directories'
  5332. + [ 0 -eq 1 ]
  5333. + [ -z 'Using '\''$1'\'' as the command directories' ]
  5334. + echo 'Using '\''$1'\'' as the command directories'
  5335. + sed -e 's/`/\\`/g'
  5336. + LINE1='Using '\''$1'\'' as the command directories'
  5337. + test -n 'Using '\''$1'\'' as the command directories'
  5338. + eval 'echo "Using '\''$1'\'' as the command directories" | sed -e '\''s/;/\;/g'\'
  5339. + echo 'Using '\''/sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin /usr/libexec /usr/local/libexec'\'' as the command directories'
  5340. + sed -e 's/;/\;/g'
  5341. + LINE1='Using '\''/sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin /usr/libexec /usr/local/libexec'\'' as the command directories'
  5342. + [ 1 -eq 1 ]
  5343. + date '+[%H:%M:%S]'
  5344. + LOGLINE1='[04:21:46]'
  5345. + test 0 -gt 0 -o 0 -eq 1
  5346. + [ -n Info ]
  5347. + LOGLINE1='[04:21:46] Info: Using '\''/sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin /usr/libexec /usr/local/libexec'\'' as the command directories'
  5348. + [ 0 -eq 1 -a 0 -gt 0 ]
  5349. + [ -n '' ]
  5350. + [ 0 -eq 1 -a -n '' ]
  5351. + [ 0 -eq 1 ]
  5352. + [ 0 -eq 1 ]
  5353. + [ 1 -eq 1 ]
  5354. + echo -e '[04:21:46] Info: Using '\''/sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin /usr/libexec /usr/local/libexec'\'' as the command directories'
  5355. + [ 0 -eq 1 ]
  5356. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  5357. + echo '[04:21:46] Info: Using '\''/sbin /bin /usr/sbin /usr/bin /usr/games /usr/local/sbin /usr/local/bin /usr/libexec /usr/local/libexec'\'' as the command directories'
  5358. + [ 0 -eq 1 -a -n '' ]
  5359. + test 0 -eq 1 -a 0 -eq 1
  5360. + return
  5361. + display --to LOG --type INFO CONFIG_TMPDIR /usr/local/var/lib/rkhunter/tmp
  5362. + WARN_MSG=0
  5363. + NL=0
  5364. + NLAFTER=0
  5365. + LOGINDENT=0
  5366. + SCREENINDENT=0
  5367. + LOGNL=0
  5368. + SCREENNL=0
  5369. + WRITETO=''
  5370. + TYPE=''
  5371. + RESULT=''
  5372. + COLOR=''
  5373. + MSG=''
  5374. + LINE1=''
  5375. + LOGLINE1=''
  5376. + SPACES=''
  5377. + NONL=''
  5378. + DISPLAY_LINE='display --to LOG --type INFO CONFIG_TMPDIR /usr/local/var/lib/rkhunter/tmp'
  5379. + [ 6 -le 0 ]
  5380. + [ 6 -ge 1 ]
  5381. + WRITETO=LOG
  5382. + shift
  5383. + shift
  5384. + [ 4 -ge 1 ]
  5385. + eval echo '$MSG_TYPE_INFO'
  5386. + echo Info
  5387. + TYPE=Info
  5388. + [ -z Info -a INFO != PLAIN ]
  5389. + test INFO = WARNING
  5390. + shift
  5391. + shift
  5392. + [ 2 -ge 1 ]
  5393. + MSG=CONFIG_TMPDIR
  5394. + shift
  5395. + break
  5396. + test 0 -eq 1
  5397. + [ 0 -eq 1 ]
  5398. + [ 0 -eq 1 ]
  5399. + test LOG = SCREEN -o LOG = SCREEN+LOG
  5400. + WRITETOTTY=0
  5401. + test LOG = LOG -o LOG = SCREEN+LOG
  5402. + WRITETOLOG=1
  5403. + [ 0 -eq 0 -a 1 -eq 0 ]
  5404. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  5405. + test -n Info
  5406. + NONL=''
  5407. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  5408. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  5409. + [ -n CONFIG_TMPDIR ]
  5410. + grep -a ^CONFIG_TMPDIR: /usr/local/var/lib/rkhunter/db/i18n/en
  5411. + head -n 1
  5412. + cut -d: -f2-
  5413. + LINE1='Using '\''$1'\'' as the temporary directory'
  5414. + [ 0 -eq 1 ]
  5415. + [ -z 'Using '\''$1'\'' as the temporary directory' ]
  5416. + echo 'Using '\''$1'\'' as the temporary directory'
  5417. + sed -e 's/`/\\`/g'
  5418. + LINE1='Using '\''$1'\'' as the temporary directory'
  5419. + test -n 'Using '\''$1'\'' as the temporary directory'
  5420. + eval 'echo "Using '\''$1'\'' as the temporary directory" | sed -e '\''s/;/\;/g'\'
  5421. + echo 'Using '\''/usr/local/var/lib/rkhunter/tmp'\'' as the temporary directory'
  5422. + sed -e 's/;/\;/g'
  5423. + LINE1='Using '\''/usr/local/var/lib/rkhunter/tmp'\'' as the temporary directory'
  5424. + [ 1 -eq 1 ]
  5425. + date '+[%H:%M:%S]'
  5426. + LOGLINE1='[04:21:46]'
  5427. + test 0 -gt 0 -o 0 -eq 1
  5428. + [ -n Info ]
  5429. + LOGLINE1='[04:21:46] Info: Using '\''/usr/local/var/lib/rkhunter/tmp'\'' as the temporary directory'
  5430. + [ 0 -eq 1 -a 0 -gt 0 ]
  5431. + [ -n '' ]
  5432. + [ 0 -eq 1 -a -n '' ]
  5433. + [ 0 -eq 1 ]
  5434. + [ 0 -eq 1 ]
  5435. + [ 1 -eq 1 ]
  5436. + echo -e '[04:21:46] Info: Using '\''/usr/local/var/lib/rkhunter/tmp'\'' as the temporary directory'
  5437. + [ 0 -eq 1 ]
  5438. + echo '[04:21:46] Info: Using '\''/usr/local/var/lib/rkhunter/tmp'\'' as the temporary directory'
  5439. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  5440. + [ 0 -eq 1 -a -n '' ]
  5441. + test 0 -eq 1 -a 0 -eq 1
  5442. + return
  5443. + [ 1 -eq 1 ]
  5444. + [ 0 -eq 1 ]
  5445. + [ -z '' ]
  5446. + display --to LOG --type INFO CONFIG_NO_MAIL_ON_WARN
  5447. + WARN_MSG=0
  5448. + NL=0
  5449. + NLAFTER=0
  5450. + LOGINDENT=0
  5451. + SCREENINDENT=0
  5452. + LOGNL=0
  5453. + SCREENNL=0
  5454. + WRITETO=''
  5455. + TYPE=''
  5456. + RESULT=''
  5457. + COLOR=''
  5458. + MSG=''
  5459. + LINE1=''
  5460. + LOGLINE1=''
  5461. + SPACES=''
  5462. + NONL=''
  5463. + DISPLAY_LINE='display --to LOG --type INFO CONFIG_NO_MAIL_ON_WARN'
  5464. + [ 5 -le 0 ]
  5465. + [ 5 -ge 1 ]
  5466. + WRITETO=LOG
  5467. + shift
  5468. + shift
  5469. + [ 3 -ge 1 ]
  5470. + eval echo '$MSG_TYPE_INFO'
  5471. + echo Info
  5472. + TYPE=Info
  5473. + [ -z Info -a INFO != PLAIN ]
  5474. + test INFO = WARNING
  5475. + shift
  5476. + shift
  5477. + [ 1 -ge 1 ]
  5478. + MSG=CONFIG_NO_MAIL_ON_WARN
  5479. + shift
  5480. + break
  5481. + test 0 -eq 1
  5482. + [ 0 -eq 1 ]
  5483. + [ 0 -eq 1 ]
  5484. + test LOG = SCREEN -o LOG = SCREEN+LOG
  5485. + WRITETOTTY=0
  5486. + test LOG = LOG -o LOG = SCREEN+LOG
  5487. + WRITETOLOG=1
  5488. + [ 0 -eq 0 -a 1 -eq 0 ]
  5489. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  5490. + test -n Info
  5491. + NONL=''
  5492. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  5493. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  5494. + [ -n CONFIG_NO_MAIL_ON_WARN ]
  5495. + head -n 1
  5496. + cut -d: -f2-
  5497. + grep -a ^CONFIG_NO_MAIL_ON_WARN: /usr/local/var/lib/rkhunter/db/i18n/en
  5498. + LINE1='No mail-on-warning address configured'
  5499. + [ 0 -eq 1 ]
  5500. + [ -z 'No mail-on-warning address configured' ]
  5501. + sed -e 's/`/\\`/g'
  5502. + echo 'No mail-on-warning address configured'
  5503. + LINE1='No mail-on-warning address configured'
  5504. + test -n 'No mail-on-warning address configured'
  5505. + eval 'echo "No mail-on-warning address configured" | sed -e '\''s/;/\;/g'\'
  5506. + sed -e 's/;/\;/g'
  5507. + echo 'No mail-on-warning address configured'
  5508. + LINE1='No mail-on-warning address configured'
  5509. + [ 1 -eq 1 ]
  5510. + date '+[%H:%M:%S]'
  5511. + LOGLINE1='[04:21:46]'
  5512. + test 0 -gt 0 -o 0 -eq 1
  5513. + [ -n Info ]
  5514. + LOGLINE1='[04:21:46] Info: No mail-on-warning address configured'
  5515. + [ 0 -eq 1 -a 0 -gt 0 ]
  5516. + [ -n '' ]
  5517. + [ 0 -eq 1 -a -n '' ]
  5518. + [ 0 -eq 1 ]
  5519. + [ 0 -eq 1 ]
  5520. + [ 1 -eq 1 ]
  5521. + echo -e '[04:21:46] Info: No mail-on-warning address configured'
  5522. + [ 0 -eq 1 ]
  5523. + echo '[04:21:46] Info: No mail-on-warning address configured'
  5524. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  5525. + [ 0 -eq 1 -a -n '' ]
  5526. + test 0 -eq 1 -a 0 -eq 1
  5527. + return
  5528. + test 1 -eq 1
  5529. + display --to LOG --type INFO CONFIG_X_AUTO
  5530. + WARN_MSG=0
  5531. + NL=0
  5532. + NLAFTER=0
  5533. + LOGINDENT=0
  5534. + SCREENINDENT=0
  5535. + LOGNL=0
  5536. + SCREENNL=0
  5537. + WRITETO=''
  5538. + TYPE=''
  5539. + RESULT=''
  5540. + COLOR=''
  5541. + MSG=''
  5542. + LINE1=''
  5543. + LOGLINE1=''
  5544. + SPACES=''
  5545. + NONL=''
  5546. + DISPLAY_LINE='display --to LOG --type INFO CONFIG_X_AUTO'
  5547. + [ 5 -le 0 ]
  5548. + [ 5 -ge 1 ]
  5549. + WRITETO=LOG
  5550. + shift
  5551. + shift
  5552. + [ 3 -ge 1 ]
  5553. + eval echo '$MSG_TYPE_INFO'
  5554. + echo Info
  5555. + TYPE=Info
  5556. + [ -z Info -a INFO != PLAIN ]
  5557. + test INFO = WARNING
  5558. + shift
  5559. + shift
  5560. + [ 1 -ge 1 ]
  5561. + MSG=CONFIG_X_AUTO
  5562. + shift
  5563. + break
  5564. + test 0 -eq 1
  5565. + [ 0 -eq 1 ]
  5566. + [ 0 -eq 1 ]
  5567. + test LOG = SCREEN -o LOG = SCREEN+LOG
  5568. + WRITETOTTY=0
  5569. + test LOG = LOG -o LOG = SCREEN+LOG
  5570. + WRITETOLOG=1
  5571. + [ 0 -eq 0 -a 1 -eq 0 ]
  5572. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  5573. + test -n Info
  5574. + NONL=''
  5575. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  5576. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  5577. + [ -n CONFIG_X_AUTO ]
  5578. + grep -a ^CONFIG_X_AUTO: /usr/local/var/lib/rkhunter/db/i18n/en
  5579. + head -n 1
  5580. + cut -d: -f2-
  5581. + LINE1='X will be automatically detected'
  5582. + [ 0 -eq 1 ]
  5583. + [ -z 'X will be automatically detected' ]
  5584. + echo 'X will be automatically detected'
  5585. + sed -e 's/`/\\`/g'
  5586. + LINE1='X will be automatically detected'
  5587. + test -n 'X will be automatically detected'
  5588. + eval 'echo "X will be automatically detected" | sed -e '\''s/;/\;/g'\'
  5589. + echo 'X will be automatically detected'
  5590. + sed -e 's/;/\;/g'
  5591. + LINE1='X will be automatically detected'
  5592. + [ 1 -eq 1 ]
  5593. + date '+[%H:%M:%S]'
  5594. + LOGLINE1='[04:21:46]'
  5595. + test 0 -gt 0 -o 0 -eq 1
  5596. + [ -n Info ]
  5597. + LOGLINE1='[04:21:46] Info: X will be automatically detected'
  5598. + [ 0 -eq 1 -a 0 -gt 0 ]
  5599. + [ -n '' ]
  5600. + [ 0 -eq 1 -a -n '' ]
  5601. + [ 0 -eq 1 ]
  5602. + [ 0 -eq 1 ]
  5603. + [ 1 -eq 1 ]
  5604. + echo -e '[04:21:46] Info: X will be automatically detected'
  5605. + [ 0 -eq 1 ]
  5606. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  5607. + echo '[04:21:46] Info: X will be automatically detected'
  5608. + [ 0 -eq 1 -a -n '' ]
  5609. + test 0 -eq 1 -a 0 -eq 1
  5610. + return
  5611. + test 0 -eq 1
  5612. + echo basename
  5613. + tr '[:lower:]' '[:upper:]'
  5614. + RKHTMPVAR=BASENAME
  5615. + eval echo '$BASENAME_CMD'
  5616. + echo /usr/bin/basename
  5617. + RKHTMPVAR=/usr/bin/basename
  5618. + [ -n /usr/bin/basename ]
  5619. + display --to LOG --type INFO FOUND_CMD basename /usr/bin/basename
  5620. + WARN_MSG=0
  5621. + NL=0
  5622. + NLAFTER=0
  5623. + LOGINDENT=0
  5624. + SCREENINDENT=0
  5625. + LOGNL=0
  5626. + SCREENNL=0
  5627. + WRITETO=''
  5628. + TYPE=''
  5629. + RESULT=''
  5630. + COLOR=''
  5631. + MSG=''
  5632. + LINE1=''
  5633. + LOGLINE1=''
  5634. + SPACES=''
  5635. + NONL=''
  5636. + DISPLAY_LINE='display --to LOG --type INFO FOUND_CMD basename /usr/bin/basename'
  5637. + [ 7 -le 0 ]
  5638. + [ 7 -ge 1 ]
  5639. + WRITETO=LOG
  5640. + shift
  5641. + shift
  5642. + [ 5 -ge 1 ]
  5643. + eval echo '$MSG_TYPE_INFO'
  5644. + echo Info
  5645. + TYPE=Info
  5646. + [ -z Info -a INFO != PLAIN ]
  5647. + test INFO = WARNING
  5648. + shift
  5649. + shift
  5650. + [ 3 -ge 1 ]
  5651. + MSG=FOUND_CMD
  5652. + shift
  5653. + break
  5654. + test 0 -eq 1
  5655. + [ 0 -eq 1 ]
  5656. + [ 0 -eq 1 ]
  5657. + test LOG = SCREEN -o LOG = SCREEN+LOG
  5658. + WRITETOTTY=0
  5659. + test LOG = LOG -o LOG = SCREEN+LOG
  5660. + WRITETOLOG=1
  5661. + [ 0 -eq 0 -a 1 -eq 0 ]
  5662. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  5663. + test -n Info
  5664. + NONL=''
  5665. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  5666. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  5667. + [ -n FOUND_CMD ]
  5668. + grep -a ^FOUND_CMD: /usr/local/var/lib/rkhunter/db/i18n/en
  5669. + cut -d: -f2-
  5670. + head -n 1
  5671. + LINE1='Found the '\''$1'\'' command: $2'
  5672. + [ 0 -eq 1 ]
  5673. + [ -z 'Found the '\''$1'\'' command: $2' ]
  5674. + echo 'Found the '\''$1'\'' command: $2'
  5675. + sed -e 's/`/\\`/g'
  5676. + LINE1='Found the '\''$1'\'' command: $2'
  5677. + test -n 'Found the '\''$1'\'' command: $2'
  5678. + eval 'echo "Found the '\''$1'\'' command: $2" | sed -e '\''s/;/\;/g'\'
  5679. + echo 'Found the '\''basename'\'' command: /usr/bin/basename'
  5680. + sed -e 's/;/\;/g'
  5681. + LINE1='Found the '\''basename'\'' command: /usr/bin/basename'
  5682. + [ 1 -eq 1 ]
  5683. + date '+[%H:%M:%S]'
  5684. + LOGLINE1='[04:21:46]'
  5685. + test 0 -gt 0 -o 0 -eq 1
  5686. + [ -n Info ]
  5687. + LOGLINE1='[04:21:46] Info: Found the '\''basename'\'' command: /usr/bin/basename'
  5688. + [ 0 -eq 1 -a 0 -gt 0 ]
  5689. + [ -n '' ]
  5690. + [ 0 -eq 1 -a -n '' ]
  5691. + [ 0 -eq 1 ]
  5692. + [ 0 -eq 1 ]
  5693. + [ 1 -eq 1 ]
  5694. + echo -e '[04:21:46] Info: Found the '\''basename'\'' command: /usr/bin/basename'
  5695. + [ 0 -eq 1 ]
  5696. + echo '[04:21:46] Info: Found the '\''basename'\'' command: /usr/bin/basename'
  5697. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  5698. + [ 0 -eq 1 -a -n '' ]
  5699. + test 0 -eq 1 -a 0 -eq 1
  5700. + return
  5701. + echo diff
  5702. + tr '[:lower:]' '[:upper:]'
  5703. + RKHTMPVAR=DIFF
  5704. + eval echo '$DIFF_CMD'
  5705. + echo /usr/bin/diff
  5706. + RKHTMPVAR=/usr/bin/diff
  5707. + [ -n /usr/bin/diff ]
  5708. + display --to LOG --type INFO FOUND_CMD diff /usr/bin/diff
  5709. + WARN_MSG=0
  5710. + NL=0
  5711. + NLAFTER=0
  5712. + LOGINDENT=0
  5713. + SCREENINDENT=0
  5714. + LOGNL=0
  5715. + SCREENNL=0
  5716. + WRITETO=''
  5717. + TYPE=''
  5718. + RESULT=''
  5719. + COLOR=''
  5720. + MSG=''
  5721. + LINE1=''
  5722. + LOGLINE1=''
  5723. + SPACES=''
  5724. + NONL=''
  5725. + DISPLAY_LINE='display --to LOG --type INFO FOUND_CMD diff /usr/bin/diff'
  5726. + [ 7 -le 0 ]
  5727. + [ 7 -ge 1 ]
  5728. + WRITETO=LOG
  5729. + shift
  5730. + shift
  5731. + [ 5 -ge 1 ]
  5732. + eval echo '$MSG_TYPE_INFO'
  5733. + echo Info
  5734. + TYPE=Info
  5735. + [ -z Info -a INFO != PLAIN ]
  5736. + test INFO = WARNING
  5737. + shift
  5738. + shift
  5739. + [ 3 -ge 1 ]
  5740. + MSG=FOUND_CMD
  5741. + shift
  5742. + break
  5743. + test 0 -eq 1
  5744. + [ 0 -eq 1 ]
  5745. + [ 0 -eq 1 ]
  5746. + test LOG = SCREEN -o LOG = SCREEN+LOG
  5747. + WRITETOTTY=0
  5748. + test LOG = LOG -o LOG = SCREEN+LOG
  5749. + WRITETOLOG=1
  5750. + [ 0 -eq 0 -a 1 -eq 0 ]
  5751. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  5752. + test -n Info
  5753. + NONL=''
  5754. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  5755. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  5756. + [ -n FOUND_CMD ]
  5757. + head -n 1
  5758. + cut -d: -f2-
  5759. + grep -a ^FOUND_CMD: /usr/local/var/lib/rkhunter/db/i18n/en
  5760. + LINE1='Found the '\''$1'\'' command: $2'
  5761. + [ 0 -eq 1 ]
  5762. + [ -z 'Found the '\''$1'\'' command: $2' ]
  5763. + sed -e 's/`/\\`/g'
  5764. + echo 'Found the '\''$1'\'' command: $2'
  5765. + LINE1='Found the '\''$1'\'' command: $2'
  5766. + test -n 'Found the '\''$1'\'' command: $2'
  5767. + eval 'echo "Found the '\''$1'\'' command: $2" | sed -e '\''s/;/\;/g'\'
  5768. + sed -e 's/;/\;/g'
  5769. + echo 'Found the '\''diff'\'' command: /usr/bin/diff'
  5770. + LINE1='Found the '\''diff'\'' command: /usr/bin/diff'
  5771. + [ 1 -eq 1 ]
  5772. + date '+[%H:%M:%S]'
  5773. + LOGLINE1='[04:21:47]'
  5774. + test 0 -gt 0 -o 0 -eq 1
  5775. + [ -n Info ]
  5776. + LOGLINE1='[04:21:47] Info: Found the '\''diff'\'' command: /usr/bin/diff'
  5777. + [ 0 -eq 1 -a 0 -gt 0 ]
  5778. + [ -n '' ]
  5779. + [ 0 -eq 1 -a -n '' ]
  5780. + [ 0 -eq 1 ]
  5781. + [ 0 -eq 1 ]
  5782. + [ 1 -eq 1 ]
  5783. + echo -e '[04:21:47] Info: Found the '\''diff'\'' command: /usr/bin/diff'
  5784. + [ 0 -eq 1 ]
  5785. + echo '[04:21:47] Info: Found the '\''diff'\'' command: /usr/bin/diff'
  5786. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  5787. + [ 0 -eq 1 -a -n '' ]
  5788. + test 0 -eq 1 -a 0 -eq 1
  5789. + return
  5790. + tr '[:lower:]' '[:upper:]'
  5791. + echo dirname
  5792. + RKHTMPVAR=DIRNAME
  5793. + eval echo '$DIRNAME_CMD'
  5794. + echo /usr/bin/dirname
  5795. + RKHTMPVAR=/usr/bin/dirname
  5796. + [ -n /usr/bin/dirname ]
  5797. + display --to LOG --type INFO FOUND_CMD dirname /usr/bin/dirname
  5798. + WARN_MSG=0
  5799. + NL=0
  5800. + NLAFTER=0
  5801. + LOGINDENT=0
  5802. + SCREENINDENT=0
  5803. + LOGNL=0
  5804. + SCREENNL=0
  5805. + WRITETO=''
  5806. + TYPE=''
  5807. + RESULT=''
  5808. + COLOR=''
  5809. + MSG=''
  5810. + LINE1=''
  5811. + LOGLINE1=''
  5812. + SPACES=''
  5813. + NONL=''
  5814. + DISPLAY_LINE='display --to LOG --type INFO FOUND_CMD dirname /usr/bin/dirname'
  5815. + [ 7 -le 0 ]
  5816. + [ 7 -ge 1 ]
  5817. + WRITETO=LOG
  5818. + shift
  5819. + shift
  5820. + [ 5 -ge 1 ]
  5821. + eval echo '$MSG_TYPE_INFO'
  5822. + echo Info
  5823. + TYPE=Info
  5824. + [ -z Info -a INFO != PLAIN ]
  5825. + test INFO = WARNING
  5826. + shift
  5827. + shift
  5828. + [ 3 -ge 1 ]
  5829. + MSG=FOUND_CMD
  5830. + shift
  5831. + break
  5832. + test 0 -eq 1
  5833. + [ 0 -eq 1 ]
  5834. + [ 0 -eq 1 ]
  5835. + test LOG = SCREEN -o LOG = SCREEN+LOG
  5836. + WRITETOTTY=0
  5837. + test LOG = LOG -o LOG = SCREEN+LOG
  5838. + WRITETOLOG=1
  5839. + [ 0 -eq 0 -a 1 -eq 0 ]
  5840. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  5841. + test -n Info
  5842. + NONL=''
  5843. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  5844. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  5845. + [ -n FOUND_CMD ]
  5846. + grep -a ^FOUND_CMD: /usr/local/var/lib/rkhunter/db/i18n/en
  5847. + head -n 1
  5848. + cut -d: -f2-
  5849. + LINE1='Found the '\''$1'\'' command: $2'
  5850. + [ 0 -eq 1 ]
  5851. + [ -z 'Found the '\''$1'\'' command: $2' ]
  5852. + sed -e 's/`/\\`/g'
  5853. + echo 'Found the '\''$1'\'' command: $2'
  5854. + LINE1='Found the '\''$1'\'' command: $2'
  5855. + test -n 'Found the '\''$1'\'' command: $2'
  5856. + eval 'echo "Found the '\''$1'\'' command: $2" | sed -e '\''s/;/\;/g'\'
  5857. + sed -e 's/;/\;/g'
  5858. + echo 'Found the '\''dirname'\'' command: /usr/bin/dirname'
  5859. + LINE1='Found the '\''dirname'\'' command: /usr/bin/dirname'
  5860. + [ 1 -eq 1 ]
  5861. + date '+[%H:%M:%S]'
  5862. + LOGLINE1='[04:21:47]'
  5863. + test 0 -gt 0 -o 0 -eq 1
  5864. + [ -n Info ]
  5865. + LOGLINE1='[04:21:47] Info: Found the '\''dirname'\'' command: /usr/bin/dirname'
  5866. + [ 0 -eq 1 -a 0 -gt 0 ]
  5867. + [ -n '' ]
  5868. + [ 0 -eq 1 -a -n '' ]
  5869. + [ 0 -eq 1 ]
  5870. + [ 0 -eq 1 ]
  5871. + [ 1 -eq 1 ]
  5872. + echo -e '[04:21:47] Info: Found the '\''dirname'\'' command: /usr/bin/dirname'
  5873. + [ 0 -eq 1 ]
  5874. + echo '[04:21:47] Info: Found the '\''dirname'\'' command: /usr/bin/dirname'
  5875. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  5876. + [ 0 -eq 1 -a -n '' ]
  5877. + test 0 -eq 1 -a 0 -eq 1
  5878. + return
  5879. + echo file
  5880. + tr '[:lower:]' '[:upper:]'
  5881. + RKHTMPVAR=FILE
  5882. + eval echo '$FILE_CMD'
  5883. + echo /usr/bin/file
  5884. + RKHTMPVAR=/usr/bin/file
  5885. + [ -n /usr/bin/file ]
  5886. + display --to LOG --type INFO FOUND_CMD file /usr/bin/file
  5887. + WARN_MSG=0
  5888. + NL=0
  5889. + NLAFTER=0
  5890. + LOGINDENT=0
  5891. + SCREENINDENT=0
  5892. + LOGNL=0
  5893. + SCREENNL=0
  5894. + WRITETO=''
  5895. + TYPE=''
  5896. + RESULT=''
  5897. + COLOR=''
  5898. + MSG=''
  5899. + LINE1=''
  5900. + LOGLINE1=''
  5901. + SPACES=''
  5902. + NONL=''
  5903. + DISPLAY_LINE='display --to LOG --type INFO FOUND_CMD file /usr/bin/file'
  5904. + [ 7 -le 0 ]
  5905. + [ 7 -ge 1 ]
  5906. + WRITETO=LOG
  5907. + shift
  5908. + shift
  5909. + [ 5 -ge 1 ]
  5910. + eval echo '$MSG_TYPE_INFO'
  5911. + echo Info
  5912. + TYPE=Info
  5913. + [ -z Info -a INFO != PLAIN ]
  5914. + test INFO = WARNING
  5915. + shift
  5916. + shift
  5917. + [ 3 -ge 1 ]
  5918. + MSG=FOUND_CMD
  5919. + shift
  5920. + break
  5921. + test 0 -eq 1
  5922. + [ 0 -eq 1 ]
  5923. + [ 0 -eq 1 ]
  5924. + test LOG = SCREEN -o LOG = SCREEN+LOG
  5925. + WRITETOTTY=0
  5926. + test LOG = LOG -o LOG = SCREEN+LOG
  5927. + WRITETOLOG=1
  5928. + [ 0 -eq 0 -a 1 -eq 0 ]
  5929. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  5930. + test -n Info
  5931. + NONL=''
  5932. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  5933. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  5934. + [ -n FOUND_CMD ]
  5935. + grep -a ^FOUND_CMD: /usr/local/var/lib/rkhunter/db/i18n/en
  5936. + cut -d: -f2-
  5937. + head -n 1
  5938. + LINE1='Found the '\''$1'\'' command: $2'
  5939. + [ 0 -eq 1 ]
  5940. + [ -z 'Found the '\''$1'\'' command: $2' ]
  5941. + echo 'Found the '\''$1'\'' command: $2'
  5942. + sed -e 's/`/\\`/g'
  5943. + LINE1='Found the '\''$1'\'' command: $2'
  5944. + test -n 'Found the '\''$1'\'' command: $2'
  5945. + eval 'echo "Found the '\''$1'\'' command: $2" | sed -e '\''s/;/\;/g'\'
  5946. + echo 'Found the '\''file'\'' command: /usr/bin/file'
  5947. + sed -e 's/;/\;/g'
  5948. + LINE1='Found the '\''file'\'' command: /usr/bin/file'
  5949. + [ 1 -eq 1 ]
  5950. + date '+[%H:%M:%S]'
  5951. + LOGLINE1='[04:21:47]'
  5952. + test 0 -gt 0 -o 0 -eq 1
  5953. + [ -n Info ]
  5954. + LOGLINE1='[04:21:47] Info: Found the '\''file'\'' command: /usr/bin/file'
  5955. + [ 0 -eq 1 -a 0 -gt 0 ]
  5956. + [ -n '' ]
  5957. + [ 0 -eq 1 -a -n '' ]
  5958. + [ 0 -eq 1 ]
  5959. + [ 0 -eq 1 ]
  5960. + [ 1 -eq 1 ]
  5961. + echo -e '[04:21:47] Info: Found the '\''file'\'' command: /usr/bin/file'
  5962. + [ 0 -eq 1 ]
  5963. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  5964. + echo '[04:21:47] Info: Found the '\''file'\'' command: /usr/bin/file'
  5965. + [ 0 -eq 1 -a -n '' ]
  5966. + test 0 -eq 1 -a 0 -eq 1
  5967. + return
  5968. + echo find
  5969. + tr '[:lower:]' '[:upper:]'
  5970. + RKHTMPVAR=FIND
  5971. + eval echo '$FIND_CMD'
  5972. + echo /usr/bin/find
  5973. + RKHTMPVAR=/usr/bin/find
  5974. + [ -n /usr/bin/find ]
  5975. + display --to LOG --type INFO FOUND_CMD find /usr/bin/find
  5976. + WARN_MSG=0
  5977. + NL=0
  5978. + NLAFTER=0
  5979. + LOGINDENT=0
  5980. + SCREENINDENT=0
  5981. + LOGNL=0
  5982. + SCREENNL=0
  5983. + WRITETO=''
  5984. + TYPE=''
  5985. + RESULT=''
  5986. + COLOR=''
  5987. + MSG=''
  5988. + LINE1=''
  5989. + LOGLINE1=''
  5990. + SPACES=''
  5991. + NONL=''
  5992. + DISPLAY_LINE='display --to LOG --type INFO FOUND_CMD find /usr/bin/find'
  5993. + [ 7 -le 0 ]
  5994. + [ 7 -ge 1 ]
  5995. + WRITETO=LOG
  5996. + shift
  5997. + shift
  5998. + [ 5 -ge 1 ]
  5999. + eval echo '$MSG_TYPE_INFO'
  6000. + echo Info
  6001. + TYPE=Info
  6002. + [ -z Info -a INFO != PLAIN ]
  6003. + test INFO = WARNING
  6004. + shift
  6005. + shift
  6006. + [ 3 -ge 1 ]
  6007. + MSG=FOUND_CMD
  6008. + shift
  6009. + break
  6010. + test 0 -eq 1
  6011. + [ 0 -eq 1 ]
  6012. + [ 0 -eq 1 ]
  6013. + test LOG = SCREEN -o LOG = SCREEN+LOG
  6014. + WRITETOTTY=0
  6015. + test LOG = LOG -o LOG = SCREEN+LOG
  6016. + WRITETOLOG=1
  6017. + [ 0 -eq 0 -a 1 -eq 0 ]
  6018. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  6019. + test -n Info
  6020. + NONL=''
  6021. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  6022. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  6023. + [ -n FOUND_CMD ]
  6024. + head -n 1
  6025. + cut -d: -f2-
  6026. + grep -a ^FOUND_CMD: /usr/local/var/lib/rkhunter/db/i18n/en
  6027. + LINE1='Found the '\''$1'\'' command: $2'
  6028. + [ 0 -eq 1 ]
  6029. + [ -z 'Found the '\''$1'\'' command: $2' ]
  6030. + echo 'Found the '\''$1'\'' command: $2'
  6031. + sed -e 's/`/\\`/g'
  6032. + LINE1='Found the '\''$1'\'' command: $2'
  6033. + test -n 'Found the '\''$1'\'' command: $2'
  6034. + eval 'echo "Found the '\''$1'\'' command: $2" | sed -e '\''s/;/\;/g'\'
  6035. + echo 'Found the '\''find'\'' command: /usr/bin/find'
  6036. + sed -e 's/;/\;/g'
  6037. + LINE1='Found the '\''find'\'' command: /usr/bin/find'
  6038. + [ 1 -eq 1 ]
  6039. + date '+[%H:%M:%S]'
  6040. + LOGLINE1='[04:21:47]'
  6041. + test 0 -gt 0 -o 0 -eq 1
  6042. + [ -n Info ]
  6043. + LOGLINE1='[04:21:47] Info: Found the '\''find'\'' command: /usr/bin/find'
  6044. + [ 0 -eq 1 -a 0 -gt 0 ]
  6045. + [ -n '' ]
  6046. + [ 0 -eq 1 -a -n '' ]
  6047. + [ 0 -eq 1 ]
  6048. + [ 0 -eq 1 ]
  6049. + [ 1 -eq 1 ]
  6050. + echo -e '[04:21:47] Info: Found the '\''find'\'' command: /usr/bin/find'
  6051. + [ 0 -eq 1 ]
  6052. + echo '[04:21:47] Info: Found the '\''find'\'' command: /usr/bin/find'
  6053. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  6054. + [ 0 -eq 1 -a -n '' ]
  6055. + test 0 -eq 1 -a 0 -eq 1
  6056. + return
  6057. + echo ifconfig
  6058. + tr '[:lower:]' '[:upper:]'
  6059. + RKHTMPVAR=IFCONFIG
  6060. + eval echo '$IFCONFIG_CMD'
  6061. + echo /sbin/ifconfig
  6062. + RKHTMPVAR=/sbin/ifconfig
  6063. + [ -n /sbin/ifconfig ]
  6064. + display --to LOG --type INFO FOUND_CMD ifconfig /sbin/ifconfig
  6065. + WARN_MSG=0
  6066. + NL=0
  6067. + NLAFTER=0
  6068. + LOGINDENT=0
  6069. + SCREENINDENT=0
  6070. + LOGNL=0
  6071. + SCREENNL=0
  6072. + WRITETO=''
  6073. + TYPE=''
  6074. + RESULT=''
  6075. + COLOR=''
  6076. + MSG=''
  6077. + LINE1=''
  6078. + LOGLINE1=''
  6079. + SPACES=''
  6080. + NONL=''
  6081. + DISPLAY_LINE='display --to LOG --type INFO FOUND_CMD ifconfig /sbin/ifconfig'
  6082. + [ 7 -le 0 ]
  6083. + [ 7 -ge 1 ]
  6084. + WRITETO=LOG
  6085. + shift
  6086. + shift
  6087. + [ 5 -ge 1 ]
  6088. + eval echo '$MSG_TYPE_INFO'
  6089. + echo Info
  6090. + TYPE=Info
  6091. + [ -z Info -a INFO != PLAIN ]
  6092. + test INFO = WARNING
  6093. + shift
  6094. + shift
  6095. + [ 3 -ge 1 ]
  6096. + MSG=FOUND_CMD
  6097. + shift
  6098. + break
  6099. + test 0 -eq 1
  6100. + [ 0 -eq 1 ]
  6101. + [ 0 -eq 1 ]
  6102. + test LOG = SCREEN -o LOG = SCREEN+LOG
  6103. + WRITETOTTY=0
  6104. + test LOG = LOG -o LOG = SCREEN+LOG
  6105. + WRITETOLOG=1
  6106. + [ 0 -eq 0 -a 1 -eq 0 ]
  6107. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  6108. + test -n Info
  6109. + NONL=''
  6110. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  6111. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  6112. + [ -n FOUND_CMD ]
  6113. + head -n 1
  6114. + cut -d: -f2-
  6115. + grep -a ^FOUND_CMD: /usr/local/var/lib/rkhunter/db/i18n/en
  6116. + LINE1='Found the '\''$1'\'' command: $2'
  6117. + [ 0 -eq 1 ]
  6118. + [ -z 'Found the '\''$1'\'' command: $2' ]
  6119. + sed -e 's/`/\\`/g'
  6120. + echo 'Found the '\''$1'\'' command: $2'
  6121. + LINE1='Found the '\''$1'\'' command: $2'
  6122. + test -n 'Found the '\''$1'\'' command: $2'
  6123. + eval 'echo "Found the '\''$1'\'' command: $2" | sed -e '\''s/;/\;/g'\'
  6124. + sed -e 's/;/\;/g'
  6125. + echo 'Found the '\''ifconfig'\'' command: /sbin/ifconfig'
  6126. + LINE1='Found the '\''ifconfig'\'' command: /sbin/ifconfig'
  6127. + [ 1 -eq 1 ]
  6128. + date '+[%H:%M:%S]'
  6129. + LOGLINE1='[04:21:48]'
  6130. + test 0 -gt 0 -o 0 -eq 1
  6131. + [ -n Info ]
  6132. + LOGLINE1='[04:21:48] Info: Found the '\''ifconfig'\'' command: /sbin/ifconfig'
  6133. + [ 0 -eq 1 -a 0 -gt 0 ]
  6134. + [ -n '' ]
  6135. + [ 0 -eq 1 -a -n '' ]
  6136. + [ 0 -eq 1 ]
  6137. + [ 0 -eq 1 ]
  6138. + [ 1 -eq 1 ]
  6139. + echo -e '[04:21:48] Info: Found the '\''ifconfig'\'' command: /sbin/ifconfig'
  6140. + [ 0 -eq 1 ]
  6141. + echo '[04:21:48] Info: Found the '\''ifconfig'\'' command: /sbin/ifconfig'
  6142. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  6143. + [ 0 -eq 1 -a -n '' ]
  6144. + test 0 -eq 1 -a 0 -eq 1
  6145. + return
  6146. + tr '[:lower:]' '[:upper:]'
  6147. + echo ip
  6148. + RKHTMPVAR=IP
  6149. + eval echo '$IP_CMD'
  6150. + echo
  6151. + RKHTMPVAR=''
  6152. + [ -n '' ]
  6153. + display --to LOG --type INFO NOT_FOUND_CMD ip
  6154. + WARN_MSG=0
  6155. + NL=0
  6156. + NLAFTER=0
  6157. + LOGINDENT=0
  6158. + SCREENINDENT=0
  6159. + LOGNL=0
  6160. + SCREENNL=0
  6161. + WRITETO=''
  6162. + TYPE=''
  6163. + RESULT=''
  6164. + COLOR=''
  6165. + MSG=''
  6166. + LINE1=''
  6167. + LOGLINE1=''
  6168. + SPACES=''
  6169. + NONL=''
  6170. + DISPLAY_LINE='display --to LOG --type INFO NOT_FOUND_CMD ip'
  6171. + [ 6 -le 0 ]
  6172. + [ 6 -ge 1 ]
  6173. + WRITETO=LOG
  6174. + shift
  6175. + shift
  6176. + [ 4 -ge 1 ]
  6177. + eval echo '$MSG_TYPE_INFO'
  6178. + echo Info
  6179. + TYPE=Info
  6180. + [ -z Info -a INFO != PLAIN ]
  6181. + test INFO = WARNING
  6182. + shift
  6183. + shift
  6184. + [ 2 -ge 1 ]
  6185. + MSG=NOT_FOUND_CMD
  6186. + shift
  6187. + break
  6188. + test 0 -eq 1
  6189. + [ 0 -eq 1 ]
  6190. + [ 0 -eq 1 ]
  6191. + test LOG = SCREEN -o LOG = SCREEN+LOG
  6192. + WRITETOTTY=0
  6193. + test LOG = LOG -o LOG = SCREEN+LOG
  6194. + WRITETOLOG=1
  6195. + [ 0 -eq 0 -a 1 -eq 0 ]
  6196. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  6197. + test -n Info
  6198. + NONL=''
  6199. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  6200. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  6201. + [ -n NOT_FOUND_CMD ]
  6202. + grep -a ^NOT_FOUND_CMD: /usr/local/var/lib/rkhunter/db/i18n/en
  6203. + head -n 1
  6204. + cut -d: -f2-
  6205. + LINE1='Unable to find the '\''$1'\'' command'
  6206. + [ 0 -eq 1 ]
  6207. + [ -z 'Unable to find the '\''$1'\'' command' ]
  6208. + echo 'Unable to find the '\''$1'\'' command'
  6209. + sed -e 's/`/\\`/g'
  6210. + LINE1='Unable to find the '\''$1'\'' command'
  6211. + test -n 'Unable to find the '\''$1'\'' command'
  6212. + eval 'echo "Unable to find the '\''$1'\'' command" | sed -e '\''s/;/\;/g'\'
  6213. + echo 'Unable to find the '\''ip'\'' command'
  6214. + sed -e 's/;/\;/g'
  6215. + LINE1='Unable to find the '\''ip'\'' command'
  6216. + [ 1 -eq 1 ]
  6217. + date '+[%H:%M:%S]'
  6218. + LOGLINE1='[04:21:48]'
  6219. + test 0 -gt 0 -o 0 -eq 1
  6220. + [ -n Info ]
  6221. + LOGLINE1='[04:21:48] Info: Unable to find the '\''ip'\'' command'
  6222. + [ 0 -eq 1 -a 0 -gt 0 ]
  6223. + [ -n '' ]
  6224. + [ 0 -eq 1 -a -n '' ]
  6225. + [ 0 -eq 1 ]
  6226. + [ 0 -eq 1 ]
  6227. + [ 1 -eq 1 ]
  6228. + echo -e '[04:21:48] Info: Unable to find the '\''ip'\'' command'
  6229. + [ 0 -eq 1 ]
  6230. + echo '[04:21:48] Info: Unable to find the '\''ip'\'' command'
  6231. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  6232. + [ 0 -eq 1 -a -n '' ]
  6233. + test 0 -eq 1 -a 0 -eq 1
  6234. + return
  6235. + echo ipcs
  6236. + tr '[:lower:]' '[:upper:]'
  6237. + RKHTMPVAR=IPCS
  6238. + eval echo '$IPCS_CMD'
  6239. + echo /usr/bin/ipcs
  6240. + RKHTMPVAR=/usr/bin/ipcs
  6241. + [ -n /usr/bin/ipcs ]
  6242. + display --to LOG --type INFO FOUND_CMD ipcs /usr/bin/ipcs
  6243. + WARN_MSG=0
  6244. + NL=0
  6245. + NLAFTER=0
  6246. + LOGINDENT=0
  6247. + SCREENINDENT=0
  6248. + LOGNL=0
  6249. + SCREENNL=0
  6250. + WRITETO=''
  6251. + TYPE=''
  6252. + RESULT=''
  6253. + COLOR=''
  6254. + MSG=''
  6255. + LINE1=''
  6256. + LOGLINE1=''
  6257. + SPACES=''
  6258. + NONL=''
  6259. + DISPLAY_LINE='display --to LOG --type INFO FOUND_CMD ipcs /usr/bin/ipcs'
  6260. + [ 7 -le 0 ]
  6261. + [ 7 -ge 1 ]
  6262. + WRITETO=LOG
  6263. + shift
  6264. + shift
  6265. + [ 5 -ge 1 ]
  6266. + eval echo '$MSG_TYPE_INFO'
  6267. + echo Info
  6268. + TYPE=Info
  6269. + [ -z Info -a INFO != PLAIN ]
  6270. + test INFO = WARNING
  6271. + shift
  6272. + shift
  6273. + [ 3 -ge 1 ]
  6274. + MSG=FOUND_CMD
  6275. + shift
  6276. + break
  6277. + test 0 -eq 1
  6278. + [ 0 -eq 1 ]
  6279. + [ 0 -eq 1 ]
  6280. + test LOG = SCREEN -o LOG = SCREEN+LOG
  6281. + WRITETOTTY=0
  6282. + test LOG = LOG -o LOG = SCREEN+LOG
  6283. + WRITETOLOG=1
  6284. + [ 0 -eq 0 -a 1 -eq 0 ]
  6285. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  6286. + test -n Info
  6287. + NONL=''
  6288. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  6289. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  6290. + [ -n FOUND_CMD ]
  6291. + head -n 1
  6292. + cut -d: -f2-
  6293. + grep -a ^FOUND_CMD: /usr/local/var/lib/rkhunter/db/i18n/en
  6294. + LINE1='Found the '\''$1'\'' command: $2'
  6295. + [ 0 -eq 1 ]
  6296. + [ -z 'Found the '\''$1'\'' command: $2' ]
  6297. + echo 'Found the '\''$1'\'' command: $2'
  6298. + sed -e 's/`/\\`/g'
  6299. + LINE1='Found the '\''$1'\'' command: $2'
  6300. + test -n 'Found the '\''$1'\'' command: $2'
  6301. + eval 'echo "Found the '\''$1'\'' command: $2" | sed -e '\''s/;/\;/g'\'
  6302. + echo 'Found the '\''ipcs'\'' command: /usr/bin/ipcs'
  6303. + sed -e 's/;/\;/g'
  6304. + LINE1='Found the '\''ipcs'\'' command: /usr/bin/ipcs'
  6305. + [ 1 -eq 1 ]
  6306. + date '+[%H:%M:%S]'
  6307. + LOGLINE1='[04:21:48]'
  6308. + test 0 -gt 0 -o 0 -eq 1
  6309. + [ -n Info ]
  6310. + LOGLINE1='[04:21:48] Info: Found the '\''ipcs'\'' command: /usr/bin/ipcs'
  6311. + [ 0 -eq 1 -a 0 -gt 0 ]
  6312. + [ -n '' ]
  6313. + [ 0 -eq 1 -a -n '' ]
  6314. + [ 0 -eq 1 ]
  6315. + [ 0 -eq 1 ]
  6316. + [ 1 -eq 1 ]
  6317. + echo -e '[04:21:48] Info: Found the '\''ipcs'\'' command: /usr/bin/ipcs'
  6318. + [ 0 -eq 1 ]
  6319. + echo '[04:21:48] Info: Found the '\''ipcs'\'' command: /usr/bin/ipcs'
  6320. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  6321. + [ 0 -eq 1 -a -n '' ]
  6322. + test 0 -eq 1 -a 0 -eq 1
  6323. + return
  6324. + echo ldd
  6325. + tr '[:lower:]' '[:upper:]'
  6326. + RKHTMPVAR=LDD
  6327. + eval echo '$LDD_CMD'
  6328. + echo /usr/bin/ldd
  6329. + RKHTMPVAR=/usr/bin/ldd
  6330. + [ -n /usr/bin/ldd ]
  6331. + display --to LOG --type INFO FOUND_CMD ldd /usr/bin/ldd
  6332. + WARN_MSG=0
  6333. + NL=0
  6334. + NLAFTER=0
  6335. + LOGINDENT=0
  6336. + SCREENINDENT=0
  6337. + LOGNL=0
  6338. + SCREENNL=0
  6339. + WRITETO=''
  6340. + TYPE=''
  6341. + RESULT=''
  6342. + COLOR=''
  6343. + MSG=''
  6344. + LINE1=''
  6345. + LOGLINE1=''
  6346. + SPACES=''
  6347. + NONL=''
  6348. + DISPLAY_LINE='display --to LOG --type INFO FOUND_CMD ldd /usr/bin/ldd'
  6349. + [ 7 -le 0 ]
  6350. + [ 7 -ge 1 ]
  6351. + WRITETO=LOG
  6352. + shift
  6353. + shift
  6354. + [ 5 -ge 1 ]
  6355. + eval echo '$MSG_TYPE_INFO'
  6356. + echo Info
  6357. + TYPE=Info
  6358. + [ -z Info -a INFO != PLAIN ]
  6359. + test INFO = WARNING
  6360. + shift
  6361. + shift
  6362. + [ 3 -ge 1 ]
  6363. + MSG=FOUND_CMD
  6364. + shift
  6365. + break
  6366. + test 0 -eq 1
  6367. + [ 0 -eq 1 ]
  6368. + [ 0 -eq 1 ]
  6369. + test LOG = SCREEN -o LOG = SCREEN+LOG
  6370. + WRITETOTTY=0
  6371. + test LOG = LOG -o LOG = SCREEN+LOG
  6372. + WRITETOLOG=1
  6373. + [ 0 -eq 0 -a 1 -eq 0 ]
  6374. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  6375. + test -n Info
  6376. + NONL=''
  6377. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  6378. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  6379. + [ -n FOUND_CMD ]
  6380. + head -n 1
  6381. + cut -d: -f2-
  6382. + grep -a ^FOUND_CMD: /usr/local/var/lib/rkhunter/db/i18n/en
  6383. + LINE1='Found the '\''$1'\'' command: $2'
  6384. + [ 0 -eq 1 ]
  6385. + [ -z 'Found the '\''$1'\'' command: $2' ]
  6386. + sed -e 's/`/\\`/g'
  6387. + echo 'Found the '\''$1'\'' command: $2'
  6388. + LINE1='Found the '\''$1'\'' command: $2'
  6389. + test -n 'Found the '\''$1'\'' command: $2'
  6390. + eval 'echo "Found the '\''$1'\'' command: $2" | sed -e '\''s/;/\;/g'\'
  6391. + sed -e 's/;/\;/g'
  6392. + echo 'Found the '\''ldd'\'' command: /usr/bin/ldd'
  6393. + LINE1='Found the '\''ldd'\'' command: /usr/bin/ldd'
  6394. + [ 1 -eq 1 ]
  6395. + date '+[%H:%M:%S]'
  6396. + LOGLINE1='[04:21:48]'
  6397. + test 0 -gt 0 -o 0 -eq 1
  6398. + [ -n Info ]
  6399. + LOGLINE1='[04:21:48] Info: Found the '\''ldd'\'' command: /usr/bin/ldd'
  6400. + [ 0 -eq 1 -a 0 -gt 0 ]
  6401. + [ -n '' ]
  6402. + [ 0 -eq 1 -a -n '' ]
  6403. + [ 0 -eq 1 ]
  6404. + [ 0 -eq 1 ]
  6405. + [ 1 -eq 1 ]
  6406. + echo -e '[04:21:48] Info: Found the '\''ldd'\'' command: /usr/bin/ldd'
  6407. + [ 0 -eq 1 ]
  6408. + echo '[04:21:48] Info: Found the '\''ldd'\'' command: /usr/bin/ldd'
  6409. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  6410. + [ 0 -eq 1 -a -n '' ]
  6411. + test 0 -eq 1 -a 0 -eq 1
  6412. + return
  6413. + tr '[:lower:]' '[:upper:]'
  6414. + echo lsattr
  6415. + RKHTMPVAR=LSATTR
  6416. + eval echo '$LSATTR_CMD'
  6417. + echo
  6418. + RKHTMPVAR=''
  6419. + [ -n '' ]
  6420. + display --to LOG --type INFO NOT_FOUND_CMD lsattr
  6421. + WARN_MSG=0
  6422. + NL=0
  6423. + NLAFTER=0
  6424. + LOGINDENT=0
  6425. + SCREENINDENT=0
  6426. + LOGNL=0
  6427. + SCREENNL=0
  6428. + WRITETO=''
  6429. + TYPE=''
  6430. + RESULT=''
  6431. + COLOR=''
  6432. + MSG=''
  6433. + LINE1=''
  6434. + LOGLINE1=''
  6435. + SPACES=''
  6436. + NONL=''
  6437. + DISPLAY_LINE='display --to LOG --type INFO NOT_FOUND_CMD lsattr'
  6438. + [ 6 -le 0 ]
  6439. + [ 6 -ge 1 ]
  6440. + WRITETO=LOG
  6441. + shift
  6442. + shift
  6443. + [ 4 -ge 1 ]
  6444. + eval echo '$MSG_TYPE_INFO'
  6445. + echo Info
  6446. + TYPE=Info
  6447. + [ -z Info -a INFO != PLAIN ]
  6448. + test INFO = WARNING
  6449. + shift
  6450. + shift
  6451. + [ 2 -ge 1 ]
  6452. + MSG=NOT_FOUND_CMD
  6453. + shift
  6454. + break
  6455. + test 0 -eq 1
  6456. + [ 0 -eq 1 ]
  6457. + [ 0 -eq 1 ]
  6458. + test LOG = SCREEN -o LOG = SCREEN+LOG
  6459. + WRITETOTTY=0
  6460. + test LOG = LOG -o LOG = SCREEN+LOG
  6461. + WRITETOLOG=1
  6462. + [ 0 -eq 0 -a 1 -eq 0 ]
  6463. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  6464. + test -n Info
  6465. + NONL=''
  6466. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  6467. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  6468. + [ -n NOT_FOUND_CMD ]
  6469. + grep -a ^NOT_FOUND_CMD: /usr/local/var/lib/rkhunter/db/i18n/en
  6470. + head -n 1
  6471. + cut -d: -f2-
  6472. + LINE1='Unable to find the '\''$1'\'' command'
  6473. + [ 0 -eq 1 ]
  6474. + [ -z 'Unable to find the '\''$1'\'' command' ]
  6475. + echo 'Unable to find the '\''$1'\'' command'
  6476. + sed -e 's/`/\\`/g'
  6477. + LINE1='Unable to find the '\''$1'\'' command'
  6478. + test -n 'Unable to find the '\''$1'\'' command'
  6479. + eval 'echo "Unable to find the '\''$1'\'' command" | sed -e '\''s/;/\;/g'\'
  6480. + echo 'Unable to find the '\''lsattr'\'' command'
  6481. + sed -e 's/;/\;/g'
  6482. + LINE1='Unable to find the '\''lsattr'\'' command'
  6483. + [ 1 -eq 1 ]
  6484. + date '+[%H:%M:%S]'
  6485. + LOGLINE1='[04:21:48]'
  6486. + test 0 -gt 0 -o 0 -eq 1
  6487. + [ -n Info ]
  6488. + LOGLINE1='[04:21:48] Info: Unable to find the '\''lsattr'\'' command'
  6489. + [ 0 -eq 1 -a 0 -gt 0 ]
  6490. + [ -n '' ]
  6491. + [ 0 -eq 1 -a -n '' ]
  6492. + [ 0 -eq 1 ]
  6493. + [ 0 -eq 1 ]
  6494. + [ 1 -eq 1 ]
  6495. + echo -e '[04:21:48] Info: Unable to find the '\''lsattr'\'' command'
  6496. + [ 0 -eq 1 ]
  6497. + echo '[04:21:48] Info: Unable to find the '\''lsattr'\'' command'
  6498. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  6499. + [ 0 -eq 1 -a -n '' ]
  6500. + test 0 -eq 1 -a 0 -eq 1
  6501. + return
  6502. + echo lsmod
  6503. + tr '[:lower:]' '[:upper:]'
  6504. + RKHTMPVAR=LSMOD
  6505. + eval echo '$LSMOD_CMD'
  6506. + echo
  6507. + RKHTMPVAR=''
  6508. + [ -n '' ]
  6509. + display --to LOG --type INFO NOT_FOUND_CMD lsmod
  6510. + WARN_MSG=0
  6511. + NL=0
  6512. + NLAFTER=0
  6513. + LOGINDENT=0
  6514. + SCREENINDENT=0
  6515. + LOGNL=0
  6516. + SCREENNL=0
  6517. + WRITETO=''
  6518. + TYPE=''
  6519. + RESULT=''
  6520. + COLOR=''
  6521. + MSG=''
  6522. + LINE1=''
  6523. + LOGLINE1=''
  6524. + SPACES=''
  6525. + NONL=''
  6526. + DISPLAY_LINE='display --to LOG --type INFO NOT_FOUND_CMD lsmod'
  6527. + [ 6 -le 0 ]
  6528. + [ 6 -ge 1 ]
  6529. + WRITETO=LOG
  6530. + shift
  6531. + shift
  6532. + [ 4 -ge 1 ]
  6533. + eval echo '$MSG_TYPE_INFO'
  6534. + echo Info
  6535. + TYPE=Info
  6536. + [ -z Info -a INFO != PLAIN ]
  6537. + test INFO = WARNING
  6538. + shift
  6539. + shift
  6540. + [ 2 -ge 1 ]
  6541. + MSG=NOT_FOUND_CMD
  6542. + shift
  6543. + break
  6544. + test 0 -eq 1
  6545. + [ 0 -eq 1 ]
  6546. + [ 0 -eq 1 ]
  6547. + test LOG = SCREEN -o LOG = SCREEN+LOG
  6548. + WRITETOTTY=0
  6549. + test LOG = LOG -o LOG = SCREEN+LOG
  6550. + WRITETOLOG=1
  6551. + [ 0 -eq 0 -a 1 -eq 0 ]
  6552. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  6553. + test -n Info
  6554. + NONL=''
  6555. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  6556. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  6557. + [ -n NOT_FOUND_CMD ]
  6558. + head -n 1
  6559. + cut -d: -f2-
  6560. + grep -a ^NOT_FOUND_CMD: /usr/local/var/lib/rkhunter/db/i18n/en
  6561. + LINE1='Unable to find the '\''$1'\'' command'
  6562. + [ 0 -eq 1 ]
  6563. + [ -z 'Unable to find the '\''$1'\'' command' ]
  6564. + sed -e 's/`/\\`/g'
  6565. + echo 'Unable to find the '\''$1'\'' command'
  6566. + LINE1='Unable to find the '\''$1'\'' command'
  6567. + test -n 'Unable to find the '\''$1'\'' command'
  6568. + eval 'echo "Unable to find the '\''$1'\'' command" | sed -e '\''s/;/\;/g'\'
  6569. + sed -e 's/;/\;/g'
  6570. + echo 'Unable to find the '\''lsmod'\'' command'
  6571. + LINE1='Unable to find the '\''lsmod'\'' command'
  6572. + [ 1 -eq 1 ]
  6573. + date '+[%H:%M:%S]'
  6574. + LOGLINE1='[04:21:49]'
  6575. + test 0 -gt 0 -o 0 -eq 1
  6576. + [ -n Info ]
  6577. + LOGLINE1='[04:21:49] Info: Unable to find the '\''lsmod'\'' command'
  6578. + [ 0 -eq 1 -a 0 -gt 0 ]
  6579. + [ -n '' ]
  6580. + [ 0 -eq 1 -a -n '' ]
  6581. + [ 0 -eq 1 ]
  6582. + [ 0 -eq 1 ]
  6583. + [ 1 -eq 1 ]
  6584. + echo -e '[04:21:49] Info: Unable to find the '\''lsmod'\'' command'
  6585. + [ 0 -eq 1 ]
  6586. + echo '[04:21:49] Info: Unable to find the '\''lsmod'\'' command'
  6587. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  6588. + [ 0 -eq 1 -a -n '' ]
  6589. + test 0 -eq 1 -a 0 -eq 1
  6590. + return
  6591. + tr '[:lower:]' '[:upper:]'
  6592. + echo lsof
  6593. + RKHTMPVAR=LSOF
  6594. + eval echo '$LSOF_CMD'
  6595. + echo /usr/local/sbin/lsof
  6596. + RKHTMPVAR=/usr/local/sbin/lsof
  6597. + [ -n /usr/local/sbin/lsof ]
  6598. + display --to LOG --type INFO FOUND_CMD lsof /usr/local/sbin/lsof
  6599. + WARN_MSG=0
  6600. + NL=0
  6601. + NLAFTER=0
  6602. + LOGINDENT=0
  6603. + SCREENINDENT=0
  6604. + LOGNL=0
  6605. + SCREENNL=0
  6606. + WRITETO=''
  6607. + TYPE=''
  6608. + RESULT=''
  6609. + COLOR=''
  6610. + MSG=''
  6611. + LINE1=''
  6612. + LOGLINE1=''
  6613. + SPACES=''
  6614. + NONL=''
  6615. + DISPLAY_LINE='display --to LOG --type INFO FOUND_CMD lsof /usr/local/sbin/lsof'
  6616. + [ 7 -le 0 ]
  6617. + [ 7 -ge 1 ]
  6618. + WRITETO=LOG
  6619. + shift
  6620. + shift
  6621. + [ 5 -ge 1 ]
  6622. + eval echo '$MSG_TYPE_INFO'
  6623. + echo Info
  6624. + TYPE=Info
  6625. + [ -z Info -a INFO != PLAIN ]
  6626. + test INFO = WARNING
  6627. + shift
  6628. + shift
  6629. + [ 3 -ge 1 ]
  6630. + MSG=FOUND_CMD
  6631. + shift
  6632. + break
  6633. + test 0 -eq 1
  6634. + [ 0 -eq 1 ]
  6635. + [ 0 -eq 1 ]
  6636. + test LOG = SCREEN -o LOG = SCREEN+LOG
  6637. + WRITETOTTY=0
  6638. + test LOG = LOG -o LOG = SCREEN+LOG
  6639. + WRITETOLOG=1
  6640. + [ 0 -eq 0 -a 1 -eq 0 ]
  6641. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  6642. + test -n Info
  6643. + NONL=''
  6644. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  6645. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  6646. + [ -n FOUND_CMD ]
  6647. + grep -a ^FOUND_CMD: /usr/local/var/lib/rkhunter/db/i18n/en
  6648. + head -n 1
  6649. + cut -d: -f2-
  6650. + LINE1='Found the '\''$1'\'' command: $2'
  6651. + [ 0 -eq 1 ]
  6652. + [ -z 'Found the '\''$1'\'' command: $2' ]
  6653. + echo 'Found the '\''$1'\'' command: $2'
  6654. + sed -e 's/`/\\`/g'
  6655. + LINE1='Found the '\''$1'\'' command: $2'
  6656. + test -n 'Found the '\''$1'\'' command: $2'
  6657. + eval 'echo "Found the '\''$1'\'' command: $2" | sed -e '\''s/;/\;/g'\'
  6658. + echo 'Found the '\''lsof'\'' command: /usr/local/sbin/lsof'
  6659. + sed -e 's/;/\;/g'
  6660. + LINE1='Found the '\''lsof'\'' command: /usr/local/sbin/lsof'
  6661. + [ 1 -eq 1 ]
  6662. + date '+[%H:%M:%S]'
  6663. + LOGLINE1='[04:21:49]'
  6664. + test 0 -gt 0 -o 0 -eq 1
  6665. + [ -n Info ]
  6666. + LOGLINE1='[04:21:49] Info: Found the '\''lsof'\'' command: /usr/local/sbin/lsof'
  6667. + [ 0 -eq 1 -a 0 -gt 0 ]
  6668. + [ -n '' ]
  6669. + [ 0 -eq 1 -a -n '' ]
  6670. + [ 0 -eq 1 ]
  6671. + [ 0 -eq 1 ]
  6672. + [ 1 -eq 1 ]
  6673. + echo -e '[04:21:49] Info: Found the '\''lsof'\'' command: /usr/local/sbin/lsof'
  6674. + [ 0 -eq 1 ]
  6675. + echo '[04:21:49] Info: Found the '\''lsof'\'' command: /usr/local/sbin/lsof'
  6676. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  6677. + [ 0 -eq 1 -a -n '' ]
  6678. + test 0 -eq 1 -a 0 -eq 1
  6679. + return
  6680. + echo mktemp
  6681. + tr '[:lower:]' '[:upper:]'
  6682. + RKHTMPVAR=MKTEMP
  6683. + eval echo '$MKTEMP_CMD'
  6684. + echo /usr/bin/mktemp
  6685. + RKHTMPVAR=/usr/bin/mktemp
  6686. + [ -n /usr/bin/mktemp ]
  6687. + display --to LOG --type INFO FOUND_CMD mktemp /usr/bin/mktemp
  6688. + WARN_MSG=0
  6689. + NL=0
  6690. + NLAFTER=0
  6691. + LOGINDENT=0
  6692. + SCREENINDENT=0
  6693. + LOGNL=0
  6694. + SCREENNL=0
  6695. + WRITETO=''
  6696. + TYPE=''
  6697. + RESULT=''
  6698. + COLOR=''
  6699. + MSG=''
  6700. + LINE1=''
  6701. + LOGLINE1=''
  6702. + SPACES=''
  6703. + NONL=''
  6704. + DISPLAY_LINE='display --to LOG --type INFO FOUND_CMD mktemp /usr/bin/mktemp'
  6705. + [ 7 -le 0 ]
  6706. + [ 7 -ge 1 ]
  6707. + WRITETO=LOG
  6708. + shift
  6709. + shift
  6710. + [ 5 -ge 1 ]
  6711. + eval echo '$MSG_TYPE_INFO'
  6712. + echo Info
  6713. + TYPE=Info
  6714. + [ -z Info -a INFO != PLAIN ]
  6715. + test INFO = WARNING
  6716. + shift
  6717. + shift
  6718. + [ 3 -ge 1 ]
  6719. + MSG=FOUND_CMD
  6720. + shift
  6721. + break
  6722. + test 0 -eq 1
  6723. + [ 0 -eq 1 ]
  6724. + [ 0 -eq 1 ]
  6725. + test LOG = SCREEN -o LOG = SCREEN+LOG
  6726. + WRITETOTTY=0
  6727. + test LOG = LOG -o LOG = SCREEN+LOG
  6728. + WRITETOLOG=1
  6729. + [ 0 -eq 0 -a 1 -eq 0 ]
  6730. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  6731. + test -n Info
  6732. + NONL=''
  6733. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  6734. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  6735. + [ -n FOUND_CMD ]
  6736. + grep -a ^FOUND_CMD: /usr/local/var/lib/rkhunter/db/i18n/en
  6737. + cut -d: -f2-
  6738. + head -n 1
  6739. + LINE1='Found the '\''$1'\'' command: $2'
  6740. + [ 0 -eq 1 ]
  6741. + [ -z 'Found the '\''$1'\'' command: $2' ]
  6742. + echo 'Found the '\''$1'\'' command: $2'
  6743. + sed -e 's/`/\\`/g'
  6744. + LINE1='Found the '\''$1'\'' command: $2'
  6745. + test -n 'Found the '\''$1'\'' command: $2'
  6746. + eval 'echo "Found the '\''$1'\'' command: $2" | sed -e '\''s/;/\;/g'\'
  6747. + echo 'Found the '\''mktemp'\'' command: /usr/bin/mktemp'
  6748. + sed -e 's/;/\;/g'
  6749. + LINE1='Found the '\''mktemp'\'' command: /usr/bin/mktemp'
  6750. + [ 1 -eq 1 ]
  6751. + date '+[%H:%M:%S]'
  6752. + LOGLINE1='[04:21:49]'
  6753. + test 0 -gt 0 -o 0 -eq 1
  6754. + [ -n Info ]
  6755. + LOGLINE1='[04:21:49] Info: Found the '\''mktemp'\'' command: /usr/bin/mktemp'
  6756. + [ 0 -eq 1 -a 0 -gt 0 ]
  6757. + [ -n '' ]
  6758. + [ 0 -eq 1 -a -n '' ]
  6759. + [ 0 -eq 1 ]
  6760. + [ 0 -eq 1 ]
  6761. + [ 1 -eq 1 ]
  6762. + echo -e '[04:21:49] Info: Found the '\''mktemp'\'' command: /usr/bin/mktemp'
  6763. + [ 0 -eq 1 ]
  6764. + echo '[04:21:49] Info: Found the '\''mktemp'\'' command: /usr/bin/mktemp'
  6765. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  6766. + [ 0 -eq 1 -a -n '' ]
  6767. + test 0 -eq 1 -a 0 -eq 1
  6768. + return
  6769. + echo netstat
  6770. + tr '[:lower:]' '[:upper:]'
  6771. + RKHTMPVAR=NETSTAT
  6772. + eval echo '$NETSTAT_CMD'
  6773. + echo /usr/bin/netstat
  6774. + RKHTMPVAR=/usr/bin/netstat
  6775. + [ -n /usr/bin/netstat ]
  6776. + display --to LOG --type INFO FOUND_CMD netstat /usr/bin/netstat
  6777. + WARN_MSG=0
  6778. + NL=0
  6779. + NLAFTER=0
  6780. + LOGINDENT=0
  6781. + SCREENINDENT=0
  6782. + LOGNL=0
  6783. + SCREENNL=0
  6784. + WRITETO=''
  6785. + TYPE=''
  6786. + RESULT=''
  6787. + COLOR=''
  6788. + MSG=''
  6789. + LINE1=''
  6790. + LOGLINE1=''
  6791. + SPACES=''
  6792. + NONL=''
  6793. + DISPLAY_LINE='display --to LOG --type INFO FOUND_CMD netstat /usr/bin/netstat'
  6794. + [ 7 -le 0 ]
  6795. + [ 7 -ge 1 ]
  6796. + WRITETO=LOG
  6797. + shift
  6798. + shift
  6799. + [ 5 -ge 1 ]
  6800. + eval echo '$MSG_TYPE_INFO'
  6801. + echo Info
  6802. + TYPE=Info
  6803. + [ -z Info -a INFO != PLAIN ]
  6804. + test INFO = WARNING
  6805. + shift
  6806. + shift
  6807. + [ 3 -ge 1 ]
  6808. + MSG=FOUND_CMD
  6809. + shift
  6810. + break
  6811. + test 0 -eq 1
  6812. + [ 0 -eq 1 ]
  6813. + [ 0 -eq 1 ]
  6814. + test LOG = SCREEN -o LOG = SCREEN+LOG
  6815. + WRITETOTTY=0
  6816. + test LOG = LOG -o LOG = SCREEN+LOG
  6817. + WRITETOLOG=1
  6818. + [ 0 -eq 0 -a 1 -eq 0 ]
  6819. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  6820. + test -n Info
  6821. + NONL=''
  6822. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  6823. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  6824. + [ -n FOUND_CMD ]
  6825. + head -n 1
  6826. + cut -d: -f2-
  6827. + grep -a ^FOUND_CMD: /usr/local/var/lib/rkhunter/db/i18n/en
  6828. + LINE1='Found the '\''$1'\'' command: $2'
  6829. + [ 0 -eq 1 ]
  6830. + [ -z 'Found the '\''$1'\'' command: $2' ]
  6831. + sed -e 's/`/\\`/g'
  6832. + echo 'Found the '\''$1'\'' command: $2'
  6833. + LINE1='Found the '\''$1'\'' command: $2'
  6834. + test -n 'Found the '\''$1'\'' command: $2'
  6835. + eval 'echo "Found the '\''$1'\'' command: $2" | sed -e '\''s/;/\;/g'\'
  6836. + sed -e 's/;/\;/g'
  6837. + echo 'Found the '\''netstat'\'' command: /usr/bin/netstat'
  6838. + LINE1='Found the '\''netstat'\'' command: /usr/bin/netstat'
  6839. + [ 1 -eq 1 ]
  6840. + date '+[%H:%M:%S]'
  6841. + LOGLINE1='[04:21:49]'
  6842. + test 0 -gt 0 -o 0 -eq 1
  6843. + [ -n Info ]
  6844. + LOGLINE1='[04:21:49] Info: Found the '\''netstat'\'' command: /usr/bin/netstat'
  6845. + [ 0 -eq 1 -a 0 -gt 0 ]
  6846. + [ -n '' ]
  6847. + [ 0 -eq 1 -a -n '' ]
  6848. + [ 0 -eq 1 ]
  6849. + [ 0 -eq 1 ]
  6850. + [ 1 -eq 1 ]
  6851. + echo -e '[04:21:49] Info: Found the '\''netstat'\'' command: /usr/bin/netstat'
  6852. + [ 0 -eq 1 ]
  6853. + echo '[04:21:49] Info: Found the '\''netstat'\'' command: /usr/bin/netstat'
  6854. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  6855. + [ 0 -eq 1 -a -n '' ]
  6856. + test 0 -eq 1 -a 0 -eq 1
  6857. + return
  6858. + tr '[:lower:]' '[:upper:]'
  6859. + echo perl
  6860. + RKHTMPVAR=PERL
  6861. + eval echo '$PERL_CMD'
  6862. + echo /usr/local/bin/perl
  6863. + RKHTMPVAR=/usr/local/bin/perl
  6864. + [ -n /usr/local/bin/perl ]
  6865. + display --to LOG --type INFO FOUND_CMD perl /usr/local/bin/perl
  6866. + WARN_MSG=0
  6867. + NL=0
  6868. + NLAFTER=0
  6869. + LOGINDENT=0
  6870. + SCREENINDENT=0
  6871. + LOGNL=0
  6872. + SCREENNL=0
  6873. + WRITETO=''
  6874. + TYPE=''
  6875. + RESULT=''
  6876. + COLOR=''
  6877. + MSG=''
  6878. + LINE1=''
  6879. + LOGLINE1=''
  6880. + SPACES=''
  6881. + NONL=''
  6882. + DISPLAY_LINE='display --to LOG --type INFO FOUND_CMD perl /usr/local/bin/perl'
  6883. + [ 7 -le 0 ]
  6884. + [ 7 -ge 1 ]
  6885. + WRITETO=LOG
  6886. + shift
  6887. + shift
  6888. + [ 5 -ge 1 ]
  6889. + eval echo '$MSG_TYPE_INFO'
  6890. + echo Info
  6891. + TYPE=Info
  6892. + [ -z Info -a INFO != PLAIN ]
  6893. + test INFO = WARNING
  6894. + shift
  6895. + shift
  6896. + [ 3 -ge 1 ]
  6897. + MSG=FOUND_CMD
  6898. + shift
  6899. + break
  6900. + test 0 -eq 1
  6901. + [ 0 -eq 1 ]
  6902. + [ 0 -eq 1 ]
  6903. + test LOG = SCREEN -o LOG = SCREEN+LOG
  6904. + WRITETOTTY=0
  6905. + test LOG = LOG -o LOG = SCREEN+LOG
  6906. + WRITETOLOG=1
  6907. + [ 0 -eq 0 -a 1 -eq 0 ]
  6908. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  6909. + test -n Info
  6910. + NONL=''
  6911. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  6912. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  6913. + [ -n FOUND_CMD ]
  6914. + grep -a ^FOUND_CMD: /usr/local/var/lib/rkhunter/db/i18n/en
  6915. + head -n 1
  6916. + cut -d: -f2-
  6917. + LINE1='Found the '\''$1'\'' command: $2'
  6918. + [ 0 -eq 1 ]
  6919. + [ -z 'Found the '\''$1'\'' command: $2' ]
  6920. + echo 'Found the '\''$1'\'' command: $2'
  6921. + sed -e 's/`/\\`/g'
  6922. + LINE1='Found the '\''$1'\'' command: $2'
  6923. + test -n 'Found the '\''$1'\'' command: $2'
  6924. + eval 'echo "Found the '\''$1'\'' command: $2" | sed -e '\''s/;/\;/g'\'
  6925. + sed -e 's/;/\;/g'
  6926. + echo 'Found the '\''perl'\'' command: /usr/local/bin/perl'
  6927. + LINE1='Found the '\''perl'\'' command: /usr/local/bin/perl'
  6928. + [ 1 -eq 1 ]
  6929. + date '+[%H:%M:%S]'
  6930. + LOGLINE1='[04:21:50]'
  6931. + test 0 -gt 0 -o 0 -eq 1
  6932. + [ -n Info ]
  6933. + LOGLINE1='[04:21:50] Info: Found the '\''perl'\'' command: /usr/local/bin/perl'
  6934. + [ 0 -eq 1 -a 0 -gt 0 ]
  6935. + [ -n '' ]
  6936. + [ 0 -eq 1 -a -n '' ]
  6937. + [ 0 -eq 1 ]
  6938. + [ 0 -eq 1 ]
  6939. + [ 1 -eq 1 ]
  6940. + echo -e '[04:21:50] Info: Found the '\''perl'\'' command: /usr/local/bin/perl'
  6941. + [ 0 -eq 1 ]
  6942. + echo '[04:21:50] Info: Found the '\''perl'\'' command: /usr/local/bin/perl'
  6943. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  6944. + [ 0 -eq 1 -a -n '' ]
  6945. + test 0 -eq 1 -a 0 -eq 1
  6946. + return
  6947. + tr '[:lower:]' '[:upper:]'
  6948. + echo pgrep
  6949. + RKHTMPVAR=PGREP
  6950. + eval echo '$PGREP_CMD'
  6951. + echo /bin/pgrep
  6952. + RKHTMPVAR=/bin/pgrep
  6953. + [ -n /bin/pgrep ]
  6954. + display --to LOG --type INFO FOUND_CMD pgrep /bin/pgrep
  6955. + WARN_MSG=0
  6956. + NL=0
  6957. + NLAFTER=0
  6958. + LOGINDENT=0
  6959. + SCREENINDENT=0
  6960. + LOGNL=0
  6961. + SCREENNL=0
  6962. + WRITETO=''
  6963. + TYPE=''
  6964. + RESULT=''
  6965. + COLOR=''
  6966. + MSG=''
  6967. + LINE1=''
  6968. + LOGLINE1=''
  6969. + SPACES=''
  6970. + NONL=''
  6971. + DISPLAY_LINE='display --to LOG --type INFO FOUND_CMD pgrep /bin/pgrep'
  6972. + [ 7 -le 0 ]
  6973. + [ 7 -ge 1 ]
  6974. + WRITETO=LOG
  6975. + shift
  6976. + shift
  6977. + [ 5 -ge 1 ]
  6978. + eval echo '$MSG_TYPE_INFO'
  6979. + echo Info
  6980. + TYPE=Info
  6981. + [ -z Info -a INFO != PLAIN ]
  6982. + test INFO = WARNING
  6983. + shift
  6984. + shift
  6985. + [ 3 -ge 1 ]
  6986. + MSG=FOUND_CMD
  6987. + shift
  6988. + break
  6989. + test 0 -eq 1
  6990. + [ 0 -eq 1 ]
  6991. + [ 0 -eq 1 ]
  6992. + test LOG = SCREEN -o LOG = SCREEN+LOG
  6993. + WRITETOTTY=0
  6994. + test LOG = LOG -o LOG = SCREEN+LOG
  6995. + WRITETOLOG=1
  6996. + [ 0 -eq 0 -a 1 -eq 0 ]
  6997. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  6998. + test -n Info
  6999. + NONL=''
  7000. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  7001. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  7002. + [ -n FOUND_CMD ]
  7003. + grep -a ^FOUND_CMD: /usr/local/var/lib/rkhunter/db/i18n/en
  7004. + head -n 1
  7005. + cut -d: -f2-
  7006. + LINE1='Found the '\''$1'\'' command: $2'
  7007. + [ 0 -eq 1 ]
  7008. + [ -z 'Found the '\''$1'\'' command: $2' ]
  7009. + echo 'Found the '\''$1'\'' command: $2'
  7010. + sed -e 's/`/\\`/g'
  7011. + LINE1='Found the '\''$1'\'' command: $2'
  7012. + test -n 'Found the '\''$1'\'' command: $2'
  7013. + eval 'echo "Found the '\''$1'\'' command: $2" | sed -e '\''s/;/\;/g'\'
  7014. + echo 'Found the '\''pgrep'\'' command: /bin/pgrep'
  7015. + sed -e 's/;/\;/g'
  7016. + LINE1='Found the '\''pgrep'\'' command: /bin/pgrep'
  7017. + [ 1 -eq 1 ]
  7018. + date '+[%H:%M:%S]'
  7019. + LOGLINE1='[04:21:50]'
  7020. + test 0 -gt 0 -o 0 -eq 1
  7021. + [ -n Info ]
  7022. + LOGLINE1='[04:21:50] Info: Found the '\''pgrep'\'' command: /bin/pgrep'
  7023. + [ 0 -eq 1 -a 0 -gt 0 ]
  7024. + [ -n '' ]
  7025. + [ 0 -eq 1 -a -n '' ]
  7026. + [ 0 -eq 1 ]
  7027. + [ 0 -eq 1 ]
  7028. + [ 1 -eq 1 ]
  7029. + echo -e '[04:21:50] Info: Found the '\''pgrep'\'' command: /bin/pgrep'
  7030. + [ 0 -eq 1 ]
  7031. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  7032. + echo '[04:21:50] Info: Found the '\''pgrep'\'' command: /bin/pgrep'
  7033. + [ 0 -eq 1 -a -n '' ]
  7034. + test 0 -eq 1 -a 0 -eq 1
  7035. + return
  7036. + echo ps
  7037. + tr '[:lower:]' '[:upper:]'
  7038. + RKHTMPVAR=PS
  7039. + eval echo '$PS_CMD'
  7040. + echo /bin/ps
  7041. + RKHTMPVAR=/bin/ps
  7042. + [ -n /bin/ps ]
  7043. + display --to LOG --type INFO FOUND_CMD ps /bin/ps
  7044. + WARN_MSG=0
  7045. + NL=0
  7046. + NLAFTER=0
  7047. + LOGINDENT=0
  7048. + SCREENINDENT=0
  7049. + LOGNL=0
  7050. + SCREENNL=0
  7051. + WRITETO=''
  7052. + TYPE=''
  7053. + RESULT=''
  7054. + COLOR=''
  7055. + MSG=''
  7056. + LINE1=''
  7057. + LOGLINE1=''
  7058. + SPACES=''
  7059. + NONL=''
  7060. + DISPLAY_LINE='display --to LOG --type INFO FOUND_CMD ps /bin/ps'
  7061. + [ 7 -le 0 ]
  7062. + [ 7 -ge 1 ]
  7063. + WRITETO=LOG
  7064. + shift
  7065. + shift
  7066. + [ 5 -ge 1 ]
  7067. + eval echo '$MSG_TYPE_INFO'
  7068. + echo Info
  7069. + TYPE=Info
  7070. + [ -z Info -a INFO != PLAIN ]
  7071. + test INFO = WARNING
  7072. + shift
  7073. + shift
  7074. + [ 3 -ge 1 ]
  7075. + MSG=FOUND_CMD
  7076. + shift
  7077. + break
  7078. + test 0 -eq 1
  7079. + [ 0 -eq 1 ]
  7080. + [ 0 -eq 1 ]
  7081. + test LOG = SCREEN -o LOG = SCREEN+LOG
  7082. + WRITETOTTY=0
  7083. + test LOG = LOG -o LOG = SCREEN+LOG
  7084. + WRITETOLOG=1
  7085. + [ 0 -eq 0 -a 1 -eq 0 ]
  7086. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  7087. + test -n Info
  7088. + NONL=''
  7089. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  7090. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  7091. + [ -n FOUND_CMD ]
  7092. + head -n 1
  7093. + cut -d: -f2-
  7094. + grep -a ^FOUND_CMD: /usr/local/var/lib/rkhunter/db/i18n/en
  7095. + LINE1='Found the '\''$1'\'' command: $2'
  7096. + [ 0 -eq 1 ]
  7097. + [ -z 'Found the '\''$1'\'' command: $2' ]
  7098. + echo 'Found the '\''$1'\'' command: $2'
  7099. + sed -e 's/`/\\`/g'
  7100. + LINE1='Found the '\''$1'\'' command: $2'
  7101. + test -n 'Found the '\''$1'\'' command: $2'
  7102. + eval 'echo "Found the '\''$1'\'' command: $2" | sed -e '\''s/;/\;/g'\'
  7103. + echo 'Found the '\''ps'\'' command: /bin/ps'
  7104. + sed -e 's/;/\;/g'
  7105. + LINE1='Found the '\''ps'\'' command: /bin/ps'
  7106. + [ 1 -eq 1 ]
  7107. + date '+[%H:%M:%S]'
  7108. + LOGLINE1='[04:21:50]'
  7109. + test 0 -gt 0 -o 0 -eq 1
  7110. + [ -n Info ]
  7111. + LOGLINE1='[04:21:50] Info: Found the '\''ps'\'' command: /bin/ps'
  7112. + [ 0 -eq 1 -a 0 -gt 0 ]
  7113. + [ -n '' ]
  7114. + [ 0 -eq 1 -a -n '' ]
  7115. + [ 0 -eq 1 ]
  7116. + [ 0 -eq 1 ]
  7117. + [ 1 -eq 1 ]
  7118. + echo -e '[04:21:50] Info: Found the '\''ps'\'' command: /bin/ps'
  7119. + [ 0 -eq 1 ]
  7120. + echo '[04:21:50] Info: Found the '\''ps'\'' command: /bin/ps'
  7121. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  7122. + [ 0 -eq 1 -a -n '' ]
  7123. + test 0 -eq 1 -a 0 -eq 1
  7124. + return
  7125. + tr '[:lower:]' '[:upper:]'
  7126. + echo pwd
  7127. + RKHTMPVAR=PWD
  7128. + eval echo '$PWD_CMD'
  7129. + echo /bin/pwd
  7130. + RKHTMPVAR=/bin/pwd
  7131. + [ -n /bin/pwd ]
  7132. + display --to LOG --type INFO FOUND_CMD pwd /bin/pwd
  7133. + WARN_MSG=0
  7134. + NL=0
  7135. + NLAFTER=0
  7136. + LOGINDENT=0
  7137. + SCREENINDENT=0
  7138. + LOGNL=0
  7139. + SCREENNL=0
  7140. + WRITETO=''
  7141. + TYPE=''
  7142. + RESULT=''
  7143. + COLOR=''
  7144. + MSG=''
  7145. + LINE1=''
  7146. + LOGLINE1=''
  7147. + SPACES=''
  7148. + NONL=''
  7149. + DISPLAY_LINE='display --to LOG --type INFO FOUND_CMD pwd /bin/pwd'
  7150. + [ 7 -le 0 ]
  7151. + [ 7 -ge 1 ]
  7152. + WRITETO=LOG
  7153. + shift
  7154. + shift
  7155. + [ 5 -ge 1 ]
  7156. + eval echo '$MSG_TYPE_INFO'
  7157. + echo Info
  7158. + TYPE=Info
  7159. + [ -z Info -a INFO != PLAIN ]
  7160. + test INFO = WARNING
  7161. + shift
  7162. + shift
  7163. + [ 3 -ge 1 ]
  7164. + MSG=FOUND_CMD
  7165. + shift
  7166. + break
  7167. + test 0 -eq 1
  7168. + [ 0 -eq 1 ]
  7169. + [ 0 -eq 1 ]
  7170. + test LOG = SCREEN -o LOG = SCREEN+LOG
  7171. + WRITETOTTY=0
  7172. + test LOG = LOG -o LOG = SCREEN+LOG
  7173. + WRITETOLOG=1
  7174. + [ 0 -eq 0 -a 1 -eq 0 ]
  7175. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  7176. + test -n Info
  7177. + NONL=''
  7178. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  7179. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  7180. + [ -n FOUND_CMD ]
  7181. + head -n 1
  7182. + grep -a ^FOUND_CMD: /usr/local/var/lib/rkhunter/db/i18n/en
  7183. + cut -d: -f2-
  7184. + LINE1='Found the '\''$1'\'' command: $2'
  7185. + [ 0 -eq 1 ]
  7186. + [ -z 'Found the '\''$1'\'' command: $2' ]
  7187. + sed -e 's/`/\\`/g'
  7188. + echo 'Found the '\''$1'\'' command: $2'
  7189. + LINE1='Found the '\''$1'\'' command: $2'
  7190. + test -n 'Found the '\''$1'\'' command: $2'
  7191. + eval 'echo "Found the '\''$1'\'' command: $2" | sed -e '\''s/;/\;/g'\'
  7192. + echo 'Found the '\''pwd'\'' command: /bin/pwd'
  7193. + sed -e 's/;/\;/g'
  7194. + LINE1='Found the '\''pwd'\'' command: /bin/pwd'
  7195. + [ 1 -eq 1 ]
  7196. + date '+[%H:%M:%S]'
  7197. + LOGLINE1='[04:21:50]'
  7198. + test 0 -gt 0 -o 0 -eq 1
  7199. + [ -n Info ]
  7200. + LOGLINE1='[04:21:50] Info: Found the '\''pwd'\'' command: /bin/pwd'
  7201. + [ 0 -eq 1 -a 0 -gt 0 ]
  7202. + [ -n '' ]
  7203. + [ 0 -eq 1 -a -n '' ]
  7204. + [ 0 -eq 1 ]
  7205. + [ 0 -eq 1 ]
  7206. + [ 1 -eq 1 ]
  7207. + echo -e '[04:21:50] Info: Found the '\''pwd'\'' command: /bin/pwd'
  7208. + [ 0 -eq 1 ]
  7209. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  7210. + echo '[04:21:50] Info: Found the '\''pwd'\'' command: /bin/pwd'
  7211. + [ 0 -eq 1 -a -n '' ]
  7212. + test 0 -eq 1 -a 0 -eq 1
  7213. + return
  7214. + echo readlink
  7215. + tr '[:lower:]' '[:upper:]'
  7216. + RKHTMPVAR=READLINK
  7217. + eval echo '$READLINK_CMD'
  7218. + echo /usr/bin/readlink
  7219. + RKHTMPVAR=/usr/bin/readlink
  7220. + [ -n /usr/bin/readlink ]
  7221. + display --to LOG --type INFO FOUND_CMD readlink /usr/bin/readlink
  7222. + WARN_MSG=0
  7223. + NL=0
  7224. + NLAFTER=0
  7225. + LOGINDENT=0
  7226. + SCREENINDENT=0
  7227. + LOGNL=0
  7228. + SCREENNL=0
  7229. + WRITETO=''
  7230. + TYPE=''
  7231. + RESULT=''
  7232. + COLOR=''
  7233. + MSG=''
  7234. + LINE1=''
  7235. + LOGLINE1=''
  7236. + SPACES=''
  7237. + NONL=''
  7238. + DISPLAY_LINE='display --to LOG --type INFO FOUND_CMD readlink /usr/bin/readlink'
  7239. + [ 7 -le 0 ]
  7240. + [ 7 -ge 1 ]
  7241. + WRITETO=LOG
  7242. + shift
  7243. + shift
  7244. + [ 5 -ge 1 ]
  7245. + eval echo '$MSG_TYPE_INFO'
  7246. + echo Info
  7247. + TYPE=Info
  7248. + [ -z Info -a INFO != PLAIN ]
  7249. + test INFO = WARNING
  7250. + shift
  7251. + shift
  7252. + [ 3 -ge 1 ]
  7253. + MSG=FOUND_CMD
  7254. + shift
  7255. + break
  7256. + test 0 -eq 1
  7257. + [ 0 -eq 1 ]
  7258. + [ 0 -eq 1 ]
  7259. + test LOG = SCREEN -o LOG = SCREEN+LOG
  7260. + WRITETOTTY=0
  7261. + test LOG = LOG -o LOG = SCREEN+LOG
  7262. + WRITETOLOG=1
  7263. + [ 0 -eq 0 -a 1 -eq 0 ]
  7264. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  7265. + test -n Info
  7266. + NONL=''
  7267. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  7268. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  7269. + [ -n FOUND_CMD ]
  7270. + grep -a ^FOUND_CMD: /usr/local/var/lib/rkhunter/db/i18n/en
  7271. + cut -d: -f2-
  7272. + head -n 1
  7273. + LINE1='Found the '\''$1'\'' command: $2'
  7274. + [ 0 -eq 1 ]
  7275. + [ -z 'Found the '\''$1'\'' command: $2' ]
  7276. + echo 'Found the '\''$1'\'' command: $2'
  7277. + sed -e 's/`/\\`/g'
  7278. + LINE1='Found the '\''$1'\'' command: $2'
  7279. + test -n 'Found the '\''$1'\'' command: $2'
  7280. + eval 'echo "Found the '\''$1'\'' command: $2" | sed -e '\''s/;/\;/g'\'
  7281. + echo 'Found the '\''readlink'\'' command: /usr/bin/readlink'
  7282. + sed -e 's/;/\;/g'
  7283. + LINE1='Found the '\''readlink'\'' command: /usr/bin/readlink'
  7284. + [ 1 -eq 1 ]
  7285. + date '+[%H:%M:%S]'
  7286. + LOGLINE1='[04:21:50]'
  7287. + test 0 -gt 0 -o 0 -eq 1
  7288. + [ -n Info ]
  7289. + LOGLINE1='[04:21:50] Info: Found the '\''readlink'\'' command: /usr/bin/readlink'
  7290. + [ 0 -eq 1 -a 0 -gt 0 ]
  7291. + [ -n '' ]
  7292. + [ 0 -eq 1 -a -n '' ]
  7293. + [ 0 -eq 1 ]
  7294. + [ 0 -eq 1 ]
  7295. + [ 1 -eq 1 ]
  7296. + echo -e '[04:21:50] Info: Found the '\''readlink'\'' command: /usr/bin/readlink'
  7297. + [ 0 -eq 1 ]
  7298. + echo '[04:21:50] Info: Found the '\''readlink'\'' command: /usr/bin/readlink'
  7299. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  7300. + [ 0 -eq 1 -a -n '' ]
  7301. + test 0 -eq 1 -a 0 -eq 1
  7302. + return
  7303. + echo stat
  7304. + tr '[:lower:]' '[:upper:]'
  7305. + RKHTMPVAR=STAT
  7306. + eval echo '$STAT_CMD'
  7307. + echo /usr/bin/stat
  7308. + RKHTMPVAR=/usr/bin/stat
  7309. + [ -n /usr/bin/stat ]
  7310. + display --to LOG --type INFO FOUND_CMD stat /usr/bin/stat
  7311. + WARN_MSG=0
  7312. + NL=0
  7313. + NLAFTER=0
  7314. + LOGINDENT=0
  7315. + SCREENINDENT=0
  7316. + LOGNL=0
  7317. + SCREENNL=0
  7318. + WRITETO=''
  7319. + TYPE=''
  7320. + RESULT=''
  7321. + COLOR=''
  7322. + MSG=''
  7323. + LINE1=''
  7324. + LOGLINE1=''
  7325. + SPACES=''
  7326. + NONL=''
  7327. + DISPLAY_LINE='display --to LOG --type INFO FOUND_CMD stat /usr/bin/stat'
  7328. + [ 7 -le 0 ]
  7329. + [ 7 -ge 1 ]
  7330. + WRITETO=LOG
  7331. + shift
  7332. + shift
  7333. + [ 5 -ge 1 ]
  7334. + eval echo '$MSG_TYPE_INFO'
  7335. + echo Info
  7336. + TYPE=Info
  7337. + [ -z Info -a INFO != PLAIN ]
  7338. + test INFO = WARNING
  7339. + shift
  7340. + shift
  7341. + [ 3 -ge 1 ]
  7342. + MSG=FOUND_CMD
  7343. + shift
  7344. + break
  7345. + test 0 -eq 1
  7346. + [ 0 -eq 1 ]
  7347. + [ 0 -eq 1 ]
  7348. + test LOG = SCREEN -o LOG = SCREEN+LOG
  7349. + WRITETOTTY=0
  7350. + test LOG = LOG -o LOG = SCREEN+LOG
  7351. + WRITETOLOG=1
  7352. + [ 0 -eq 0 -a 1 -eq 0 ]
  7353. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  7354. + test -n Info
  7355. + NONL=''
  7356. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  7357. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  7358. + [ -n FOUND_CMD ]
  7359. + head -n 1
  7360. + cut -d: -f2-
  7361. + grep -a ^FOUND_CMD: /usr/local/var/lib/rkhunter/db/i18n/en
  7362. + LINE1='Found the '\''$1'\'' command: $2'
  7363. + [ 0 -eq 1 ]
  7364. + [ -z 'Found the '\''$1'\'' command: $2' ]
  7365. + echo 'Found the '\''$1'\'' command: $2'
  7366. + sed -e 's/`/\\`/g'
  7367. + LINE1='Found the '\''$1'\'' command: $2'
  7368. + test -n 'Found the '\''$1'\'' command: $2'
  7369. + eval 'echo "Found the '\''$1'\'' command: $2" | sed -e '\''s/;/\;/g'\'
  7370. + echo 'Found the '\''stat'\'' command: /usr/bin/stat'
  7371. + sed -e 's/;/\;/g'
  7372. + LINE1='Found the '\''stat'\'' command: /usr/bin/stat'
  7373. + [ 1 -eq 1 ]
  7374. + date '+[%H:%M:%S]'
  7375. + LOGLINE1='[04:21:51]'
  7376. + test 0 -gt 0 -o 0 -eq 1
  7377. + [ -n Info ]
  7378. + LOGLINE1='[04:21:51] Info: Found the '\''stat'\'' command: /usr/bin/stat'
  7379. + [ 0 -eq 1 -a 0 -gt 0 ]
  7380. + [ -n '' ]
  7381. + [ 0 -eq 1 -a -n '' ]
  7382. + [ 0 -eq 1 ]
  7383. + [ 0 -eq 1 ]
  7384. + [ 1 -eq 1 ]
  7385. + echo -e '[04:21:51] Info: Found the '\''stat'\'' command: /usr/bin/stat'
  7386. + [ 0 -eq 1 ]
  7387. + echo '[04:21:51] Info: Found the '\''stat'\'' command: /usr/bin/stat'
  7388. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  7389. + [ 0 -eq 1 -a -n '' ]
  7390. + test 0 -eq 1 -a 0 -eq 1
  7391. + return
  7392. + tr '[:lower:]' '[:upper:]'
  7393. + echo strings
  7394. + RKHTMPVAR=STRINGS
  7395. + eval echo '$STRINGS_CMD'
  7396. + echo /usr/bin/strings
  7397. + RKHTMPVAR=/usr/bin/strings
  7398. + [ -n /usr/bin/strings ]
  7399. + display --to LOG --type INFO FOUND_CMD strings /usr/bin/strings
  7400. + WARN_MSG=0
  7401. + NL=0
  7402. + NLAFTER=0
  7403. + LOGINDENT=0
  7404. + SCREENINDENT=0
  7405. + LOGNL=0
  7406. + SCREENNL=0
  7407. + WRITETO=''
  7408. + TYPE=''
  7409. + RESULT=''
  7410. + COLOR=''
  7411. + MSG=''
  7412. + LINE1=''
  7413. + LOGLINE1=''
  7414. + SPACES=''
  7415. + NONL=''
  7416. + DISPLAY_LINE='display --to LOG --type INFO FOUND_CMD strings /usr/bin/strings'
  7417. + [ 7 -le 0 ]
  7418. + [ 7 -ge 1 ]
  7419. + WRITETO=LOG
  7420. + shift
  7421. + shift
  7422. + [ 5 -ge 1 ]
  7423. + eval echo '$MSG_TYPE_INFO'
  7424. + echo Info
  7425. + TYPE=Info
  7426. + [ -z Info -a INFO != PLAIN ]
  7427. + test INFO = WARNING
  7428. + shift
  7429. + shift
  7430. + [ 3 -ge 1 ]
  7431. + MSG=FOUND_CMD
  7432. + shift
  7433. + break
  7434. + test 0 -eq 1
  7435. + [ 0 -eq 1 ]
  7436. + [ 0 -eq 1 ]
  7437. + test LOG = SCREEN -o LOG = SCREEN+LOG
  7438. + WRITETOTTY=0
  7439. + test LOG = LOG -o LOG = SCREEN+LOG
  7440. + WRITETOLOG=1
  7441. + [ 0 -eq 0 -a 1 -eq 0 ]
  7442. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  7443. + test -n Info
  7444. + NONL=''
  7445. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  7446. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  7447. + [ -n FOUND_CMD ]
  7448. + head -n 1
  7449. + cut -d: -f2-
  7450. + grep -a ^FOUND_CMD: /usr/local/var/lib/rkhunter/db/i18n/en
  7451. + LINE1='Found the '\''$1'\'' command: $2'
  7452. + [ 0 -eq 1 ]
  7453. + [ -z 'Found the '\''$1'\'' command: $2' ]
  7454. + sed -e 's/`/\\`/g'
  7455. + echo 'Found the '\''$1'\'' command: $2'
  7456. + LINE1='Found the '\''$1'\'' command: $2'
  7457. + test -n 'Found the '\''$1'\'' command: $2'
  7458. + eval 'echo "Found the '\''$1'\'' command: $2" | sed -e '\''s/;/\;/g'\'
  7459. + sed -e 's/;/\;/g'
  7460. + echo 'Found the '\''strings'\'' command: /usr/bin/strings'
  7461. + LINE1='Found the '\''strings'\'' command: /usr/bin/strings'
  7462. + [ 1 -eq 1 ]
  7463. + date '+[%H:%M:%S]'
  7464. + LOGLINE1='[04:21:51]'
  7465. + test 0 -gt 0 -o 0 -eq 1
  7466. + [ -n Info ]
  7467. + LOGLINE1='[04:21:51] Info: Found the '\''strings'\'' command: /usr/bin/strings'
  7468. + [ 0 -eq 1 -a 0 -gt 0 ]
  7469. + [ -n '' ]
  7470. + [ 0 -eq 1 -a -n '' ]
  7471. + [ 0 -eq 1 ]
  7472. + [ 0 -eq 1 ]
  7473. + [ 1 -eq 1 ]
  7474. + echo -e '[04:21:51] Info: Found the '\''strings'\'' command: /usr/bin/strings'
  7475. + [ 0 -eq 1 ]
  7476. + echo '[04:21:51] Info: Found the '\''strings'\'' command: /usr/bin/strings'
  7477. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  7478. + [ 0 -eq 1 -a -n '' ]
  7479. + test 0 -eq 1 -a 0 -eq 1
  7480. + return
  7481. + test -n ''
  7482. + [ 0 -eq 1 -o 0 -eq 1 ]
  7483. + RKHTMPVAR=0
  7484. + test 1 -eq 1
  7485. + check_test attributes
  7486. + echo ' filesystem local_host '
  7487. + grep ' attributes '
  7488. + [ 'filesystem local_host' = all -o -n '' ]
  7489. + return 1
  7490. +
  7491. + [ 0 -eq 1 ]
  7492. + [ 0 -eq 1 ]
  7493. + [ 1 -eq 1 ]
  7494. + display --to LOG --type INFO ENABLED_TESTS 'filesystem local_host'
  7495. + WARN_MSG=0
  7496. + NL=0
  7497. + NLAFTER=0
  7498. + LOGINDENT=0
  7499. + SCREENINDENT=0
  7500. + LOGNL=0
  7501. + SCREENNL=0
  7502. + WRITETO=''
  7503. + TYPE=''
  7504. + RESULT=''
  7505. + COLOR=''
  7506. + MSG=''
  7507. + LINE1=''
  7508. + LOGLINE1=''
  7509. + SPACES=''
  7510. + NONL=''
  7511. + DISPLAY_LINE='display --to LOG --type INFO ENABLED_TESTS filesystem local_host'
  7512. + [ 6 -le 0 ]
  7513. + [ 6 -ge 1 ]
  7514. + WRITETO=LOG
  7515. + shift
  7516. + shift
  7517. + [ 4 -ge 1 ]
  7518. + eval echo '$MSG_TYPE_INFO'
  7519. + echo Info
  7520. + TYPE=Info
  7521. + [ -z Info -a INFO != PLAIN ]
  7522. + test INFO = WARNING
  7523. + shift
  7524. + shift
  7525. + [ 2 -ge 1 ]
  7526. + MSG=ENABLED_TESTS
  7527. + shift
  7528. + break
  7529. + test 0 -eq 1
  7530. + [ 0 -eq 1 ]
  7531. + [ 0 -eq 1 ]
  7532. + test LOG = SCREEN -o LOG = SCREEN+LOG
  7533. + WRITETOTTY=0
  7534. + test LOG = LOG -o LOG = SCREEN+LOG
  7535. + WRITETOLOG=1
  7536. + [ 0 -eq 0 -a 1 -eq 0 ]
  7537. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  7538. + test -n Info
  7539. + NONL=''
  7540. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  7541. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  7542. + [ -n ENABLED_TESTS ]
  7543. + grep -a ^ENABLED_TESTS: /usr/local/var/lib/rkhunter/db/i18n/en
  7544. + cut -d: -f2-
  7545. + head -n 1
  7546. + LINE1='Enabled tests are: $1'
  7547. + [ 0 -eq 1 ]
  7548. + [ -z 'Enabled tests are: $1' ]
  7549. + echo 'Enabled tests are: $1'
  7550. + sed -e 's/`/\\`/g'
  7551. + LINE1='Enabled tests are: $1'
  7552. + test -n 'Enabled tests are: $1'
  7553. + eval 'echo "Enabled tests are: $1" | sed -e '\''s/;/\;/g'\'
  7554. + echo 'Enabled tests are: filesystem local_host'
  7555. + sed -e 's/;/\;/g'
  7556. + LINE1='Enabled tests are: filesystem local_host'
  7557. + [ 1 -eq 1 ]
  7558. + date '+[%H:%M:%S]'
  7559. + LOGLINE1='[04:21:51]'
  7560. + test 0 -gt 0 -o 0 -eq 1
  7561. + [ -n Info ]
  7562. + LOGLINE1='[04:21:51] Info: Enabled tests are: filesystem local_host'
  7563. + [ 0 -eq 1 -a 0 -gt 0 ]
  7564. + [ -n '' ]
  7565. + [ 0 -eq 1 -a -n '' ]
  7566. + [ 0 -eq 1 ]
  7567. + [ 0 -eq 1 ]
  7568. + [ 1 -eq 1 ]
  7569. + echo -e '[04:21:51] Info: Enabled tests are: filesystem local_host'
  7570. + [ 0 -eq 1 ]
  7571. + echo '[04:21:51] Info: Enabled tests are: filesystem local_host'
  7572. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  7573. + [ 0 -eq 1 -a -n '' ]
  7574. + test 0 -eq 1 -a 0 -eq 1
  7575. + return
  7576. + display --to LOG --type INFO DISABLED_TESTS 'deleted_files hidden_ports hidden_procs packet_cap_apps suspscan'
  7577. + WARN_MSG=0
  7578. + NL=0
  7579. + NLAFTER=0
  7580. + LOGINDENT=0
  7581. + SCREENINDENT=0
  7582. + LOGNL=0
  7583. + SCREENNL=0
  7584. + WRITETO=''
  7585. + TYPE=''
  7586. + RESULT=''
  7587. + COLOR=''
  7588. + MSG=''
  7589. + LINE1=''
  7590. + LOGLINE1=''
  7591. + SPACES=''
  7592. + NONL=''
  7593. + DISPLAY_LINE='display --to LOG --type INFO DISABLED_TESTS deleted_files hidden_ports hidden_procs packet_cap_apps suspscan'
  7594. + [ 6 -le 0 ]
  7595. + [ 6 -ge 1 ]
  7596. + WRITETO=LOG
  7597. + shift
  7598. + shift
  7599. + [ 4 -ge 1 ]
  7600. + eval echo '$MSG_TYPE_INFO'
  7601. + echo Info
  7602. + TYPE=Info
  7603. + [ -z Info -a INFO != PLAIN ]
  7604. + test INFO = WARNING
  7605. + shift
  7606. + shift
  7607. + [ 2 -ge 1 ]
  7608. + MSG=DISABLED_TESTS
  7609. + shift
  7610. + break
  7611. + test 0 -eq 1
  7612. + [ 0 -eq 1 ]
  7613. + [ 0 -eq 1 ]
  7614. + test LOG = SCREEN -o LOG = SCREEN+LOG
  7615. + WRITETOTTY=0
  7616. + test LOG = LOG -o LOG = SCREEN+LOG
  7617. + WRITETOLOG=1
  7618. + [ 0 -eq 0 -a 1 -eq 0 ]
  7619. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  7620. + test -n Info
  7621. + NONL=''
  7622. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  7623. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  7624. + [ -n DISABLED_TESTS ]
  7625. + head -n 1
  7626. + cut -d: -f2-
  7627. + grep -a ^DISABLED_TESTS: /usr/local/var/lib/rkhunter/db/i18n/en
  7628. + LINE1='Disabled tests are: $1'
  7629. + [ 0 -eq 1 ]
  7630. + [ -z 'Disabled tests are: $1' ]
  7631. + echo 'Disabled tests are: $1'
  7632. + sed -e 's/`/\\`/g'
  7633. + LINE1='Disabled tests are: $1'
  7634. + test -n 'Disabled tests are: $1'
  7635. + eval 'echo "Disabled tests are: $1" | sed -e '\''s/;/\;/g'\'
  7636. + echo 'Disabled tests are: deleted_files hidden_ports hidden_procs packet_cap_apps suspscan'
  7637. + sed -e 's/;/\;/g'
  7638. + LINE1='Disabled tests are: deleted_files hidden_ports hidden_procs packet_cap_apps suspscan'
  7639. + [ 1 -eq 1 ]
  7640. + date '+[%H:%M:%S]'
  7641. + LOGLINE1='[04:21:51]'
  7642. + test 0 -gt 0 -o 0 -eq 1
  7643. + [ -n Info ]
  7644. + LOGLINE1='[04:21:51] Info: Disabled tests are: deleted_files hidden_ports hidden_procs packet_cap_apps suspscan'
  7645. + [ 0 -eq 1 -a 0 -gt 0 ]
  7646. + [ -n '' ]
  7647. + [ 0 -eq 1 -a -n '' ]
  7648. + [ 0 -eq 1 ]
  7649. + [ 0 -eq 1 ]
  7650. + [ 1 -eq 1 ]
  7651. + echo -e '[04:21:51] Info: Disabled tests are: deleted_files hidden_ports hidden_procs packet_cap_apps suspscan'
  7652. + [ 0 -eq 1 ]
  7653. + echo '[04:21:51] Info: Disabled tests are: deleted_files hidden_ports hidden_procs packet_cap_apps suspscan'
  7654. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  7655. + [ 0 -eq 1 -a -n '' ]
  7656. + test 0 -eq 1 -a 0 -eq 1
  7657. + return
  7658. + check_test properties
  7659. + grep ' properties '
  7660. + echo ' filesystem local_host '
  7661. + [ 'filesystem local_host' = all -o -n '' ]
  7662. + return 1
  7663. +
  7664. + test 0 -eq 1
  7665. + [ 0 -eq 1 -o 0 -eq 1 ]
  7666. + [ 0 -eq 0 ]
  7667. + test 1 -eq 0 -o 1 -eq 0
  7668. + test 1 -eq 0
  7669. + test 0 -eq 1
  7670. + test 0 -eq 1
  7671. + [ 1 -eq 1 ]
  7672. + [ -n '' ]
  7673. + [ -f /proc/ksyms ]
  7674. + [ -f /proc/kallsyms ]
  7675. + display --to LOG --type INFO KSYMS_MISSING
  7676. + WARN_MSG=0
  7677. + NL=0
  7678. + NLAFTER=0
  7679. + LOGINDENT=0
  7680. + SCREENINDENT=0
  7681. + LOGNL=0
  7682. + SCREENNL=0
  7683. + WRITETO=''
  7684. + TYPE=''
  7685. + RESULT=''
  7686. + COLOR=''
  7687. + MSG=''
  7688. + LINE1=''
  7689. + LOGLINE1=''
  7690. + SPACES=''
  7691. + NONL=''
  7692. + DISPLAY_LINE='display --to LOG --type INFO KSYMS_MISSING'
  7693. + [ 5 -le 0 ]
  7694. + [ 5 -ge 1 ]
  7695. + WRITETO=LOG
  7696. + shift
  7697. + shift
  7698. + [ 3 -ge 1 ]
  7699. + eval echo '$MSG_TYPE_INFO'
  7700. + echo Info
  7701. + TYPE=Info
  7702. + [ -z Info -a INFO != PLAIN ]
  7703. + test INFO = WARNING
  7704. + shift
  7705. + shift
  7706. + [ 1 -ge 1 ]
  7707. + MSG=KSYMS_MISSING
  7708. + shift
  7709. + break
  7710. + test 0 -eq 1
  7711. + [ 0 -eq 1 ]
  7712. + [ 0 -eq 1 ]
  7713. + test LOG = SCREEN -o LOG = SCREEN+LOG
  7714. + WRITETOTTY=0
  7715. + test LOG = LOG -o LOG = SCREEN+LOG
  7716. + WRITETOLOG=1
  7717. + [ 0 -eq 0 -a 1 -eq 0 ]
  7718. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  7719. + test -n Info
  7720. + NONL=''
  7721. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  7722. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  7723. + [ -n KSYMS_MISSING ]
  7724. + grep -a ^KSYMS_MISSING: /usr/local/var/lib/rkhunter/db/i18n/en
  7725. + head -n 1
  7726. + cut -d: -f2-
  7727. + LINE1='All ksyms and kallsyms checks will be skipped - neither file is present on the system.'
  7728. + [ 0 -eq 1 ]
  7729. + [ -z 'All ksyms and kallsyms checks will be skipped - neither file is present on the system.' ]
  7730. + sed -e 's/`/\\`/g'
  7731. + echo 'All ksyms and kallsyms checks will be skipped - neither file is present on the system.'
  7732. + LINE1='All ksyms and kallsyms checks will be skipped - neither file is present on the system.'
  7733. + test -n 'All ksyms and kallsyms checks will be skipped - neither file is present on the system.'
  7734. + eval 'echo "All ksyms and kallsyms checks will be skipped - neither file is present on the system." | sed -e '\''s/;/\;/g'\'
  7735. + sed -e 's/;/\;/g'
  7736. + echo 'All ksyms and kallsyms checks will be skipped - neither file is present on the system.'
  7737. + LINE1='All ksyms and kallsyms checks will be skipped - neither file is present on the system.'
  7738. + [ 1 -eq 1 ]
  7739. + date '+[%H:%M:%S]'
  7740. + LOGLINE1='[04:21:52]'
  7741. + test 0 -gt 0 -o 0 -eq 1
  7742. + [ -n Info ]
  7743. + LOGLINE1='[04:21:52] Info: All ksyms and kallsyms checks will be skipped - neither file is present on the system.'
  7744. + [ 0 -eq 1 -a 0 -gt 0 ]
  7745. + [ -n '' ]
  7746. + [ 0 -eq 1 -a -n '' ]
  7747. + [ 0 -eq 1 ]
  7748. + [ 0 -eq 1 ]
  7749. + [ 1 -eq 1 ]
  7750. + echo -e '[04:21:52] Info: All ksyms and kallsyms checks will be skipped - neither file is present on the system.'
  7751. + [ 0 -eq 1 ]
  7752. + echo '[04:21:52] Info: All ksyms and kallsyms checks will be skipped - neither file is present on the system.'
  7753. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  7754. + [ 0 -eq 1 -a -n '' ]
  7755. + test 0 -eq 1 -a 0 -eq 1
  7756. + return
  7757. + test 1 -eq 0
  7758. + [ -n '' ]
  7759. + [ '' = NONE ]
  7760. + [ -n '' ]
  7761. + [ -n /usr/local/bin/perl ]
  7762. + display --to LOG --type INFO FILE_PROP_EPOCH_DATE_CMD /usr/local/bin/perl
  7763. + WARN_MSG=0
  7764. + NL=0
  7765. + NLAFTER=0
  7766. + LOGINDENT=0
  7767. + SCREENINDENT=0
  7768. + LOGNL=0
  7769. + SCREENNL=0
  7770. + WRITETO=''
  7771. + TYPE=''
  7772. + RESULT=''
  7773. + COLOR=''
  7774. + MSG=''
  7775. + LINE1=''
  7776. + LOGLINE1=''
  7777. + SPACES=''
  7778. + NONL=''
  7779. + DISPLAY_LINE='display --to LOG --type INFO FILE_PROP_EPOCH_DATE_CMD /usr/local/bin/perl'
  7780. + [ 6 -le 0 ]
  7781. + [ 6 -ge 1 ]
  7782. + WRITETO=LOG
  7783. + shift
  7784. + shift
  7785. + [ 4 -ge 1 ]
  7786. + eval echo '$MSG_TYPE_INFO'
  7787. + echo Info
  7788. + TYPE=Info
  7789. + [ -z Info -a INFO != PLAIN ]
  7790. + test INFO = WARNING
  7791. + shift
  7792. + shift
  7793. + [ 2 -ge 1 ]
  7794. + MSG=FILE_PROP_EPOCH_DATE_CMD
  7795. + shift
  7796. + break
  7797. + test 0 -eq 1
  7798. + [ 0 -eq 1 ]
  7799. + [ 0 -eq 1 ]
  7800. + test LOG = SCREEN -o LOG = SCREEN+LOG
  7801. + WRITETOTTY=0
  7802. + test LOG = LOG -o LOG = SCREEN+LOG
  7803. + WRITETOLOG=1
  7804. + [ 0 -eq 0 -a 1 -eq 0 ]
  7805. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  7806. + test -n Info
  7807. + NONL=''
  7808. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  7809. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  7810. + [ -n FILE_PROP_EPOCH_DATE_CMD ]
  7811. + grep -a ^FILE_PROP_EPOCH_DATE_CMD: /usr/local/var/lib/rkhunter/db/i18n/en
  7812. + cut -d: -f2-
  7813. + head -n 1
  7814. + LINE1='Using '\''$1'\'' to process epoch second times'
  7815. + [ 0 -eq 1 ]
  7816. + [ -z 'Using '\''$1'\'' to process epoch second times' ]
  7817. + echo 'Using '\''$1'\'' to process epoch second times'
  7818. + sed -e 's/`/\\`/g'
  7819. + LINE1='Using '\''$1'\'' to process epoch second times'
  7820. + test -n 'Using '\''$1'\'' to process epoch second times'
  7821. + eval 'echo "Using '\''$1'\'' to process epoch second times" | sed -e '\''s/;/\;/g'\'
  7822. + echo 'Using '\''/usr/local/bin/perl'\'' to process epoch second times'
  7823. + sed -e 's/;/\;/g'
  7824. + LINE1='Using '\''/usr/local/bin/perl'\'' to process epoch second times'
  7825. + [ 1 -eq 1 ]
  7826. + date '+[%H:%M:%S]'
  7827. + LOGLINE1='[04:21:52]'
  7828. + test 0 -gt 0 -o 0 -eq 1
  7829. + [ -n Info ]
  7830. + LOGLINE1='[04:21:52] Info: Using '\''/usr/local/bin/perl'\'' to process epoch second times'
  7831. + [ 0 -eq 1 -a 0 -gt 0 ]
  7832. + [ -n '' ]
  7833. + [ 0 -eq 1 -a -n '' ]
  7834. + [ 0 -eq 1 ]
  7835. + [ 0 -eq 1 ]
  7836. + [ 1 -eq 1 ]
  7837. + echo -e '[04:21:52] Info: Using '\''/usr/local/bin/perl'\'' to process epoch second times'
  7838. + [ 0 -eq 1 ]
  7839. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  7840. + echo '[04:21:52] Info: Using '\''/usr/local/bin/perl'\'' to process epoch second times'
  7841. + [ 0 -eq 1 -a -n '' ]
  7842. + test 0 -eq 1 -a 0 -eq 1
  7843. + return
  7844. + check_test properties
  7845. + grep ' properties '
  7846. + echo ' filesystem local_host '
  7847. + [ 'filesystem local_host' = all -o -n '' ]
  7848. + return 1
  7849. +
  7850. + [ 0 -eq 1 ]
  7851. + display --to LOG --type INFO LOCK_UNUSED
  7852. + WARN_MSG=0
  7853. + NL=0
  7854. + NLAFTER=0
  7855. + LOGINDENT=0
  7856. + SCREENINDENT=0
  7857. + LOGNL=0
  7858. + SCREENNL=0
  7859. + WRITETO=''
  7860. + TYPE=''
  7861. + RESULT=''
  7862. + COLOR=''
  7863. + MSG=''
  7864. + LINE1=''
  7865. + LOGLINE1=''
  7866. + SPACES=''
  7867. + NONL=''
  7868. + DISPLAY_LINE='display --to LOG --type INFO LOCK_UNUSED'
  7869. + [ 5 -le 0 ]
  7870. + [ 5 -ge 1 ]
  7871. + WRITETO=LOG
  7872. + shift
  7873. + shift
  7874. + [ 3 -ge 1 ]
  7875. + eval echo '$MSG_TYPE_INFO'
  7876. + echo Info
  7877. + TYPE=Info
  7878. + [ -z Info -a INFO != PLAIN ]
  7879. + test INFO = WARNING
  7880. + shift
  7881. + shift
  7882. + [ 1 -ge 1 ]
  7883. + MSG=LOCK_UNUSED
  7884. + shift
  7885. + break
  7886. + test 0 -eq 1
  7887. + [ 0 -eq 1 ]
  7888. + [ 0 -eq 1 ]
  7889. + test LOG = SCREEN -o LOG = SCREEN+LOG
  7890. + WRITETOTTY=0
  7891. + test LOG = LOG -o LOG = SCREEN+LOG
  7892. + WRITETOLOG=1
  7893. + [ 0 -eq 0 -a 1 -eq 0 ]
  7894. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  7895. + test -n Info
  7896. + NONL=''
  7897. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  7898. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  7899. + [ -n LOCK_UNUSED ]
  7900. + head -n 1
  7901. + cut -d: -f2-
  7902. + grep -a ^LOCK_UNUSED: /usr/local/var/lib/rkhunter/db/i18n/en
  7903. + LINE1='Locking is not being used'
  7904. + [ 0 -eq 1 ]
  7905. + [ -z 'Locking is not being used' ]
  7906. + echo 'Locking is not being used'
  7907. + sed -e 's/`/\\`/g'
  7908. + LINE1='Locking is not being used'
  7909. + test -n 'Locking is not being used'
  7910. + eval 'echo "Locking is not being used" | sed -e '\''s/;/\;/g'\'
  7911. + echo 'Locking is not being used'
  7912. + sed -e 's/;/\;/g'
  7913. + LINE1='Locking is not being used'
  7914. + [ 1 -eq 1 ]
  7915. + date '+[%H:%M:%S]'
  7916. + LOGLINE1='[04:21:52]'
  7917. + test 0 -gt 0 -o 0 -eq 1
  7918. + [ -n Info ]
  7919. + LOGLINE1='[04:21:52] Info: Locking is not being used'
  7920. + [ 0 -eq 1 -a 0 -gt 0 ]
  7921. + [ -n '' ]
  7922. + [ 0 -eq 1 -a -n '' ]
  7923. + [ 0 -eq 1 ]
  7924. + [ 0 -eq 1 ]
  7925. + [ 1 -eq 1 ]
  7926. + echo -e '[04:21:52] Info: Locking is not being used'
  7927. + [ 0 -eq 1 ]
  7928. + echo '[04:21:52] Info: Locking is not being used'
  7929. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  7930. + [ 0 -eq 1 -a -n '' ]
  7931. + test 0 -eq 1 -a 0 -eq 1
  7932. + return
  7933. + test 0 -eq 1
  7934. + test 0 -eq 1
  7935. + test 0 -eq 1
  7936. + test 1 -eq 1 -o 1 -eq 1
  7937. + do_system_check
  7938. + display --to LOG --type PLAIN --nl CHECK_START
  7939. + WARN_MSG=0
  7940. + NL=0
  7941. + NLAFTER=0
  7942. + LOGINDENT=0
  7943. + SCREENINDENT=0
  7944. + LOGNL=0
  7945. + SCREENNL=0
  7946. + WRITETO=''
  7947. + TYPE=''
  7948. + RESULT=''
  7949. + COLOR=''
  7950. + MSG=''
  7951. + LINE1=''
  7952. + LOGLINE1=''
  7953. + SPACES=''
  7954. + NONL=''
  7955. + DISPLAY_LINE='display --to LOG --type PLAIN --nl CHECK_START'
  7956. + [ 6 -le 0 ]
  7957. + [ 6 -ge 1 ]
  7958. + WRITETO=LOG
  7959. + shift
  7960. + shift
  7961. + [ 4 -ge 1 ]
  7962. + eval echo '$MSG_TYPE_PLAIN'
  7963. + echo
  7964. + TYPE=''
  7965. + [ -z '' -a PLAIN != PLAIN ]
  7966. + test PLAIN = WARNING
  7967. + shift
  7968. + shift
  7969. + [ 2 -ge 1 ]
  7970. + NL=1
  7971. + shift
  7972. + [ 1 -ge 1 ]
  7973. + MSG=CHECK_START
  7974. + shift
  7975. + break
  7976. + test 0 -eq 1
  7977. + [ 0 -eq 1 ]
  7978. + [ 0 -eq 1 ]
  7979. + test LOG = SCREEN -o LOG = SCREEN+LOG
  7980. + WRITETOTTY=0
  7981. + test LOG = LOG -o LOG = SCREEN+LOG
  7982. + WRITETOLOG=1
  7983. + [ 0 -eq 0 -a 1 -eq 0 ]
  7984. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  7985. + test -n ''
  7986. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  7987. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  7988. + [ -n CHECK_START ]
  7989. + head -n 1
  7990. + cut -d: -f2-
  7991. + grep -a ^CHECK_START: /usr/local/var/lib/rkhunter/db/i18n/en
  7992. + LINE1='Starting system checks...'
  7993. + [ 0 -eq 1 ]
  7994. + [ -z 'Starting system checks...' ]
  7995. + sed -e 's/`/\\`/g'
  7996. + echo 'Starting system checks...'
  7997. + LINE1='Starting system checks...'
  7998. + test -n 'Starting system checks...'
  7999. + eval 'echo "Starting system checks..." | sed -e '\''s/;/\;/g'\'
  8000. + sed -e 's/;/\;/g'
  8001. + echo 'Starting system checks...'
  8002. + LINE1='Starting system checks...'
  8003. + [ 1 -eq 1 ]
  8004. + date '+[%H:%M:%S]'
  8005. + LOGLINE1='[04:21:52]'
  8006. + test 1 -gt 0 -o 0 -eq 1
  8007. + echo '[04:21:52]'
  8008. + [ -n '' ]
  8009. + test 0 -gt 0
  8010. + LOGLINE1='[04:21:52] Starting system checks...'
  8011. + [ 0 -eq 1 -a 0 -gt 0 ]
  8012. + [ -n '' ]
  8013. + [ 0 -eq 1 -a -n '' ]
  8014. + [ 0 -eq 1 ]
  8015. + [ 0 -eq 1 ]
  8016. + [ 1 -eq 1 ]
  8017. + echo -e '[04:21:52] Starting system checks...'
  8018. + [ 0 -eq 1 ]
  8019. + echo '[04:21:52] Starting system checks...'
  8020. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  8021. + [ 0 -eq 1 -a -n '' ]
  8022. + test 0 -eq 1 -a 0 -eq 1
  8023. + return
  8024. + do_system_check_initialisation
  8025. + W55808A_FILES='/tmp/.../r
  8026. /tmp/.../a'
  8027. + W55808A_DIRS=''
  8028. + W55808A_KSYMS=''
  8029. + AKIT_FILES='/usr/secure
  8030. /usr/doc/sys/qrt
  8031. /usr/doc/sys/run
  8032. /usr/doc/sys/crond
  8033. /usr/sbin/kfd
  8034. /usr/doc/kern/var
  8035. /usr/doc/kern/string.o
  8036. /usr/doc/kern/ava
  8037. /usr/doc/kern/adore.o
  8038. /var/log/ssh/old'
  8039. + AKIT_DIRS='/lib/security/.config/ssh
  8040. /usr/doc/kern
  8041. /usr/doc/backup
  8042. /usr/doc/backup/txt
  8043. /lib/backup
  8044. /lib/backup/txt
  8045. /usr/doc/work
  8046. /usr/doc/sys
  8047. /var/log/ssh
  8048. /usr/doc/.spool
  8049. /usr/lib/kterm'
  8050. + AKIT_KSYMS=''
  8051. + AJAKIT_FILES='/dev/tux/.addr
  8052. /dev/tux/.proc
  8053. /dev/tux/.file
  8054. /lib/.libgh-gh/cleaner
  8055. /lib/.libgh-gh/Patch/patch
  8056. /lib/.libgh-gh/sb0k'
  8057. + AJAKIT_DIRS='/dev/tux
  8058. /lib/.libgh-gh'
  8059. + AJAKIT_KSYMS=''
  8060. + APAKIT_FILES=/usr/share/.aPa
  8061. + APAKIT_DIRS=''
  8062. + APAKIT_KSYMS=''
  8063. + APACHEWORM_FILES=/bin/.log
  8064. + APACHEWORM_DIRS=''
  8065. + APACHEWORM_KSYMS=''
  8066. + ARK_FILES='/usr/lib/.ark?
  8067. /dev/ptyxx/.log
  8068. /dev/ptyxx/.file
  8069. /dev/ptyxx/.proc
  8070. /dev/ptyxx/.addr'
  8071. + ARK_DIRS=/dev/ptyxx
  8072. + ARK_KSYMS=''
  8073. + BALAUR_FILES=/usr/lib/liblog.o
  8074. + BALAUR_DIRS='/usr/lib/.kinetic
  8075. /usr/lib/.egcs
  8076. /usr/lib/.wormie'
  8077. + BALAUR_KSYMS=''
  8078. + BEASTKIT_FILES='/usr/sbin/arobia
  8079. /usr/sbin/idrun
  8080. /usr/lib/elm/arobia/elm
  8081. /usr/lib/elm/arobia/elm/hk
  8082. /usr/lib/elm/arobia/elm/hk.pub
  8083. /usr/lib/elm/arobia/elm/sc
  8084. /usr/lib/elm/arobia/elm/sd.pp
  8085. /usr/lib/elm/arobia/elm/sdco
  8086. /usr/lib/elm/arobia/elm/srsd'
  8087. + BEASTKIT_DIRS=/lib/ldd.so/bktools
  8088. + BEASTKIT_KSYMS=''
  8089. + BEX_FILES='/usr/info/termcap.info-5.gz
  8090. /usr/bin/sshd2'
  8091. + BEX_DIRS=/usr/include/bex
  8092. + BEX_KSYMS=''
  8093. + BOBKIT_FILES='/usr/sbin/ntpsx
  8094. /usr/sbin/.../bkit-ava
  8095. /usr/sbin/.../bkit-d
  8096. /usr/sbin/.../bkit-shd
  8097. /usr/sbin/.../bkit-f
  8098. /usr/include/.../proc.h
  8099. /usr/include/.../.bash_history
  8100. /usr/include/.../bkit-get
  8101. /usr/include/.../bkit-dl
  8102. /usr/include/.../bkit-screen
  8103. /usr/include/.../bkit-sleep
  8104. /usr/lib/.../bkit-adore.o
  8105. /usr/lib/.../ls
  8106. /usr/lib/.../netstat
  8107. /usr/lib/.../lsof
  8108. /usr/lib/.../bkit-ssh/bkit-shdcfg
  8109. /usr/lib/.../bkit-ssh/bkit-shhk
  8110. /usr/lib/.../bkit-ssh/bkit-pw
  8111. /usr/lib/.../bkit-ssh/bkit-shrs
  8112. /usr/lib/.../bkit-ssh/bkit-mots
  8113. /usr/lib/.../uconf.inv
  8114. /usr/lib/.../psr
  8115. /usr/lib/.../find
  8116. /usr/lib/.../pstree
  8117. /usr/lib/.../slocate
  8118. /usr/lib/.../du
  8119. /usr/lib/.../top'
  8120. + BOBKIT_DIRS='/usr/sbin/...
  8121. /usr/include/...
  8122. /usr/include/.../.tmp
  8123. /usr/lib/...
  8124. /usr/lib/.../.ssh
  8125. /usr/lib/.../bkit-ssh
  8126. /usr/lib/.bkit-
  8127. /tmp/.bkp'
  8128. + BOBKIT_KSYMS=''
  8129. + BOONANA_FILES='/Library/StartupItems/OSXDriverUpdates/OSXDriverUpdates
  8130. /Library/StartupItems/OSXDriverUpdates/StartupParameters.plist'
  8131. + BOONANA_DIRS=/var/root/.jnana
  8132. + BOONANA_KSYMS=''
  8133. + CB_FILES='/dev/srd0
  8134. /lib/libproc.so.2.0.6
  8135. /dev/mounnt
  8136. /etc/rc.d/init.d/init
  8137. /usr/bin/.zeen/..%/cl
  8138. /usr/bin/.zeen/..%/.x.tgz
  8139. /usr/bin/.zeen/..%/statdx
  8140. /usr/bin/.zeen/..%/wted
  8141. /usr/bin/.zeen/..%/write
  8142. /usr/bin/.zeen/..%/scan
  8143. /usr/bin/.zeen/..%/sc
  8144. /usr/bin/.zeen/..%/sl2
  8145. /usr/bin/.zeen/..%/wroot
  8146. /usr/bin/.zeen/..%/wscan
  8147. /usr/bin/.zeen/..%/wu
  8148. /usr/bin/.zeen/..%/v
  8149. /usr/bin/.zeen/..%/read
  8150. /usr/lib/sshrc
  8151. /usr/lib/ssh_host_key
  8152. /usr/lib/ssh_host_key.pub
  8153. /usr/lib/ssh_random_seed
  8154. /usr/lib/sshd_config
  8155. /usr/lib/shosts.equiv
  8156. /usr/lib/ssh_known_hosts
  8157. /u/zappa/.ssh/pid
  8158. /usr/bin/.system/..%/tcp.log
  8159. /usr/bin/.zeen/..%/curatare/attrib
  8160. /usr/bin/.zeen/..%/curatare/chattr
  8161. /usr/bin/.zeen/..%/curatare/ps
  8162. /usr/bin/.zeen/..%/curatare/pstree
  8163. /usr/bin/.system/..%/.x/xC.o'
  8164. + CB_DIRS='/usr/bin/.zeen
  8165. /usr/bin/.zeen/..%/curatare
  8166. /usr/bin/.zeen/..%/scan
  8167. /usr/bin/.system/..%'
  8168. + CB_KSYMS=''
  8169. + CINIK_FILES=/tmp/.cinik
  8170. + CINIK_DIRS=/tmp/.font-unix/.cinik
  8171. + CINIK_KSYMS=''
  8172. + CXKIT_FILES='/usr/lib/ldlibso
  8173. /usr/lib/configlibso
  8174. /usr/lib/shklibso
  8175. /usr/lib/randomlibso
  8176. /usr/lib/ldlibstrings.so
  8177. /usr/lib/ldlibdu.so
  8178. /usr/lib/ldlibns.so
  8179. /usr/include/db'
  8180. + CXKIT_DIRS=/usr/include/cxk
  8181. + CXKIT_KSYMS=''
  8182. + DANNYBOYS_FILES='/dev/mdev
  8183. /usr/lib/libX.a'
  8184. + DANNYBOYS_DIRS=''
  8185. + DANNYBOYS_KSYMS=''
  8186. + DEVIL_FILES='/var/lib/games/.src
  8187. /dev/dsx
  8188. /dev/caca
  8189. /dev/pro
  8190. /bin/bye
  8191. /bin/homedir
  8192. /usr/bin/xfss
  8193. /usr/sbin/tzava
  8194. /usr/doc/tar/.../.dracusor/stuff/holber
  8195. /usr/doc/tar/.../.dracusor/stuff/sense
  8196. /usr/doc/tar/.../.dracusor/stuff/clear
  8197. /usr/doc/tar/.../.dracusor/stuff/tzava
  8198. /usr/doc/tar/.../.dracusor/stuff/citeste
  8199. /usr/doc/tar/.../.dracusor/stuff/killrk
  8200. /usr/doc/tar/.../.dracusor/stuff/searchlog
  8201. /usr/doc/tar/.../.dracusor/stuff/gaoaza
  8202. /usr/doc/tar/.../.dracusor/stuff/cleaner
  8203. /usr/doc/tar/.../.dracusor/stuff/shk
  8204. /usr/doc/tar/.../.dracusor/stuff/srs
  8205. /usr/doc/tar/.../.dracusor/utile.tgz
  8206. /usr/doc/tar/.../.dracusor/webpage
  8207. /usr/doc/tar/.../.dracusor/getpsy
  8208. /usr/doc/tar/.../.dracusor/getbnc
  8209. /usr/doc/tar/.../.dracusor/getemech
  8210. /usr/doc/tar/.../.dracusor/localroot.sh
  8211. /usr/doc/tar/.../.dracusor/stuff/old/sense'
  8212. + DEVIL_DIRS=/usr/doc/tar/.../.dracusor
  8213. + DEVIL_KSYMS=''
  8214. + DICA_FILES='/lib/.sso
  8215. /lib/.so
  8216. /var/run/...dica/clean
  8217. /var/run/...dica/dxr
  8218. /var/run/...dica/read
  8219. /var/run/...dica/write
  8220. /var/run/...dica/lf
  8221. /var/run/...dica/xl
  8222. /var/run/...dica/xdr
  8223. /var/run/...dica/psg
  8224. /var/run/...dica/secure
  8225. /var/run/...dica/rdx
  8226. /var/run/...dica/va
  8227. /var/run/...dica/cl.sh
  8228. /var/run/...dica/last.log
  8229. /usr/bin/.etc
  8230. /etc/sshd_config
  8231. /etc/ssh_host_key
  8232. /etc/ssh_random_seed'
  8233. + DICA_DIRS='/var/run/...dica
  8234. /var/run/...dica/mh
  8235. /var/run/...dica/scan'
  8236. + DICA_KSYMS=''
  8237. + DREAMS_FILES='/dev/ttyoa
  8238. /dev/ttyof
  8239. /dev/ttyop
  8240. /usr/bin/sense
  8241. /usr/bin/sl2
  8242. /usr/bin/logclear
  8243. /usr/bin/(swapd)
  8244. /usr/bin/initrd
  8245. /usr/bin/crontabs
  8246. /usr/bin/snfs
  8247. /usr/lib/libsss
  8248. /usr/lib/libsnf.log
  8249. /usr/lib/libshtift/top
  8250. /usr/lib/libshtift/ps
  8251. /usr/lib/libshtift/netstat
  8252. /usr/lib/libshtift/ls
  8253. /usr/lib/libshtift/ifconfig
  8254. /usr/include/linseed.h
  8255. /usr/include/linpid.h
  8256. /usr/include/linkey.h
  8257. /usr/include/linconf.h
  8258. /usr/include/iceseed.h
  8259. /usr/include/icepid.h
  8260. /usr/include/icekey.h
  8261. /usr/include/iceconf.h'
  8262. + DREAMS_DIRS='/dev/ida/.hpd
  8263. /usr/lib/libshtift'
  8264. + DREAMS_KSYMS=''
  8265. + DUARAWKZ_FILES=/usr/bin/duarawkz/loginpass
  8266. + DUARAWKZ_DIRS=/usr/bin/duarawkz
  8267. + DUARAWKZ_KSYMS=''
  8268. + ENYELKM_FILES='/etc/.enyelkmHIDE^IT.ko
  8269. /etc/.enyelkmOCULTAR.ko'
  8270. + ENYELKM_DIRS=''
  8271. + ENYELKM_KSYMS=''
  8272. + FLEA_FILES='/etc/ld.so.hash
  8273. /lib/security/.config/ssh/sshd_config
  8274. /lib/security/.config/ssh/ssh_host_key
  8275. /lib/security/.config/ssh/ssh_host_key.pub
  8276. /lib/security/.config/ssh/ssh_random_seed
  8277. /usr/bin/ssh2d
  8278. /usr/lib/ldlibns.so
  8279. /usr/lib/ldlibps.so
  8280. /usr/lib/ldlibpst.so
  8281. /usr/lib/ldlibdu.so
  8282. /usr/lib/ldlibct.so'
  8283. + FLEA_DIRS='/lib/security/.config/ssh
  8284. /dev/..0
  8285. /dev/..0/backup'
  8286. + FLEA_KSYMS=''
  8287. + FREEBSD_RK_FILES='/dev/ptyp
  8288. /dev/ptyq
  8289. /dev/ptyr
  8290. /dev/ptys
  8291. /dev/ptyt
  8292. /dev/fd/.88/freshb-bsd
  8293. /dev/fd/.88/fresht
  8294. /dev/fd/.88/zxsniff
  8295. /dev/fd/.88/zxsniff.log
  8296. /dev/fd/.99/.ttyf00
  8297. /dev/fd/.99/.ttyp00
  8298. /dev/fd/.99/.ttyq00
  8299. /dev/fd/.99/.ttys00
  8300. /dev/fd/.99/.pwsx00
  8301. /etc/.acid
  8302. /usr/lib/.fx/sched_host.2
  8303. /usr/lib/.fx/random_d.2
  8304. /usr/lib/.fx/set_pid.2
  8305. /usr/lib/.fx/setrgrp.2
  8306. /usr/lib/.fx/TOHIDE
  8307. /usr/lib/.fx/cons.saver
  8308. /usr/lib/.fx/adore/ava/ava
  8309. /usr/lib/.fx/adore/adore/adore.ko
  8310. /bin/sysback
  8311. /usr/local/bin/sysback'
  8312. + FREEBSD_RK_DIRS='/dev/fd/.88
  8313. /dev/fd/.99
  8314. /usr/lib/.fx
  8315. /usr/lib/.fx/adore'
  8316. + FREEBSD_RK_KSYMS=''
  8317. + FU_FILES='/sbin/xc
  8318. /usr/include/ivtype.h
  8319. /bin/.lib'
  8320. + FU_DIRS=''
  8321. + FU_KSYMS=''
  8322. + FUCKIT_FILES='/lib/libproc.so.2.0.7
  8323. /dev/proc/.bash_profile
  8324. /dev/proc/.bashrc
  8325. /dev/proc/.cshrc
  8326. /dev/proc/fuckit/hax0r
  8327. /dev/proc/fuckit/hax0rshell
  8328. /dev/proc/fuckit/config/lports
  8329. /dev/proc/fuckit/config/rports
  8330. /dev/proc/fuckit/config/rkconf
  8331. /dev/proc/fuckit/config/password
  8332. /dev/proc/fuckit/config/progs
  8333. /dev/proc/fuckit/system-bins/init
  8334. /usr/lib/libcps.a
  8335. /usr/lib/libtty.a'
  8336. + FUCKIT_DIRS='/dev/proc
  8337. /dev/proc/fuckit
  8338. /dev/proc/fuckit/system-bins
  8339. /dev/proc/toolz'
  8340. + FUCKIT_KSYMS=''
  8341. + GASKIT_FILES=/dev/dev/gaskit/sshd/sshdd
  8342. + GASKIT_DIRS='/dev/dev
  8343. /dev/dev/gaskit
  8344. /dev/dev/gaskit/sshd'
  8345. + GASKIT_KSYMS=''
  8346. + HEROIN_FILES=''
  8347. + HEROIN_DIRS=''
  8348. + HEROIN_KSYMS=heroin
  8349. + HJCKIT_FILES=''
  8350. + HJCKIT_DIRS=/dev/.hijackerz
  8351. + HJCKIT_KSYMS=''
  8352. + IGNOKIT_FILES='/lib/defs/p
  8353. /lib/defs/q
  8354. /lib/defs/r
  8355. /lib/defs/s
  8356. /lib/defs/t
  8357. /usr/lib/defs/p
  8358. /usr/lib/defs/q
  8359. /usr/lib/defs/r
  8360. /usr/lib/defs/s
  8361. /usr/lib/defs/t
  8362. /usr/lib/.libigno/pkunsec
  8363. /usr/lib/.libigno/.igno/psybnc/psybnc'
  8364. + IGNOKIT_DIRS='/usr/lib/.libigno
  8365. /usr/lib/.libigno/.igno'
  8366. + IGNOKIT_KSYMS=''
  8367. + ILLOGIC_FILES='/dev/kmod
  8368. /dev/dos
  8369. /usr/lib/crth.o
  8370. /usr/lib/crtz.o
  8371. /etc/ld.so.hash
  8372. /usr/bin/sia
  8373. /usr/bin/ssh2d
  8374. /lib/security/.config/sn
  8375. /lib/security/.config/iver
  8376. /lib/security/.config/uconf.inv
  8377. /lib/security/.config/ssh/ssh_host_key
  8378. /lib/security/.config/ssh/ssh_host_key.pub
  8379. /lib/security/.config/ssh/sshport
  8380. /lib/security/.config/ssh/ssh_random_seed
  8381. /lib/security/.config/ava
  8382. /lib/security/.config/cleaner
  8383. /lib/security/.config/lpsched
  8384. /lib/security/.config/sz
  8385. /lib/security/.config/rcp
  8386. /lib/security/.config/patcher
  8387. /lib/security/.config/pg
  8388. /lib/security/.config/crypt
  8389. /lib/security/.config/utime
  8390. /lib/security/.config/wget
  8391. /lib/security/.config/instmod
  8392. /lib/security/.config/bin/find
  8393. /lib/security/.config/bin/du
  8394. /lib/security/.config/bin/ls
  8395. /lib/security/.config/bin/psr
  8396. /lib/security/.config/bin/netstat
  8397. /lib/security/.config/bin/su
  8398. /lib/security/.config/bin/ping
  8399. /lib/security/.config/bin/passwd'
  8400. + ILLOGIC_DIRS='/lib/security/.config
  8401. /lib/security/.config/ssh
  8402. /lib/security/.config/bin
  8403. /lib/security/.config/backup
  8404. /root/%%%/.dir
  8405. /root/%%%/.dir/mass-scan
  8406. /root/%%%/.dir/flood'
  8407. + ILLOGIC_KSYMS=''
  8408. + INQTANAA_FILES='/Users/w0rm-support.tgz
  8409. /Users/InqTest.class
  8410. /Users/com.openbundle.plist
  8411. /Users/com.pwned.plist
  8412. /Users/libavetanaBT.jnilib'
  8413. + INQTANAA_DIRS='/Users/de
  8414. /Users/javax'
  8415. + INQTANAA_KSYMS=''
  8416. + INQTANAB_FILES='/Users/w0rms.love.apples.tgz
  8417. /Users/InqTest.class
  8418. /Users/InqTest.java
  8419. /Users/libavetanaBT.jnilib
  8420. /Users/InqTanaHandler
  8421. /Users/InqTanaHandler.bundle'
  8422. + INQTANAB_DIRS='/Users/de
  8423. /Users/javax'
  8424. + INQTANAB_KSYMS=''
  8425. + INQTANAC_FILES='/Users/applec0re.tgz
  8426. /Users/InqTest.class
  8427. /Users/InqTest.java
  8428. /Users/libavetanaBT.jnilib
  8429. /Users/environment.plist
  8430. /Users/pwned.c
  8431. /Users/pwned.dylib'
  8432. + INQTANAC_DIRS='/Users/de
  8433. /Users/javax'
  8434. + INQTANAC_KSYMS=''
  8435. + INTOXONIA_FILES=''
  8436. + INTOXONIA_DIRS=''
  8437. + INTOXONIA_KSYMS='funces
  8438. ixinit
  8439. tricks
  8440. kernel_unlink
  8441. rootme
  8442. hide_module
  8443. find_sys_call_tbl'
  8444. + IRIXRK_FILES=''
  8445. + IRIXRK_DIRS='/dev/pts/01
  8446. /dev/pts/01/backup
  8447. /dev/pts/01/etc
  8448. /dev/pts/01/tmp'
  8449. + IRIXRK_KSYMS=''
  8450. + JYNX_FILES='/xochikit/bc
  8451. /xochikit/ld_poison.so
  8452. /omgxochi/bc
  8453. /omgxochi/ld_poison.so
  8454. /var/local/^^/bc
  8455. /var/local/^^/ld_poison.so'
  8456. + JYNX_DIRS='/xochikit
  8457. /omgxochi
  8458. /var/local/^^'
  8459. + JYNX_KSYMS=''
  8460. + KBEAST_FILES='/usr/_h4x_/ipsecs-kbeast-v1.ko
  8461. /usr/_h4x_/_h4x_bd
  8462. /usr/_h4x_/acctlog'
  8463. + KBEAST_DIRS=/usr/_h4x_
  8464. + KBEAST_KSYMS='h4x_delete_module
  8465. h4x_getdents64
  8466. h4x_kill
  8467. h4x_open
  8468. h4x_read
  8469. h4x_rename
  8470. h4x_rmdir
  8471. h4x_tcp4_seq_show
  8472. h4x_write'
  8473. + KITKO_FILES=''
  8474. + KITKO_DIRS=/usr/src/redhat/SRPMS/...
  8475. + KITKO_KSYMS=''
  8476. + KNARK_FILES=/proc/knark/pids
  8477. + KNARK_DIRS=/proc/knark
  8478. + KNARK_KSYMS=''
  8479. + LINUXV_FILES=/lib/ld-linuxv.so.1
  8480. + LINUXV_DIRS='/var/opt/_so_cache
  8481. /var/opt/_so_cache/ld
  8482. /var/opt/_so_cache/lc'
  8483. + LINUXV_KSYMS=''
  8484. + LION_FILES='/bin/in.telnetd
  8485. /bin/mjy
  8486. /usr/man/man1/man1/lib/.lib/mjy
  8487. /usr/man/man1/man1/lib/.lib/in.telnetd
  8488. /usr/man/man1/man1/lib/.lib/.x
  8489. /dev/.lib/lib/scan/1i0n.sh
  8490. /dev/.lib/lib/scan/hack.sh
  8491. /dev/.lib/lib/scan/bind
  8492. /dev/.lib/lib/scan/randb
  8493. /dev/.lib/lib/scan/scan.sh
  8494. /dev/.lib/lib/scan/pscan
  8495. /dev/.lib/lib/scan/star.sh
  8496. /dev/.lib/lib/scan/bindx.sh
  8497. /dev/.lib/lib/scan/bindname.log
  8498. /dev/.lib/lib/1i0n.sh
  8499. /dev/.lib/lib/lib/netstat
  8500. /dev/.lib/lib/lib/dev/.1addr
  8501. /dev/.lib/lib/lib/dev/.1logz
  8502. /dev/.lib/lib/lib/dev/.1proc
  8503. /dev/.lib/lib/lib/dev/.1file'
  8504. + LION_DIRS=''
  8505. + LION_KSYMS=''
  8506. + LOCKIT_FILES='/usr/lib/libmen.oo/.LJK2/ssh_config
  8507. /usr/lib/libmen.oo/.LJK2/ssh_host_key
  8508. /usr/lib/libmen.oo/.LJK2/ssh_host_key.pub
  8509. /usr/lib/libmen.oo/.LJK2/ssh_random_seed*
  8510. /usr/lib/libmen.oo/.LJK2/sshd_config
  8511. /usr/lib/libmen.oo/.LJK2/backdoor/RK1bd
  8512. /usr/lib/libmen.oo/.LJK2/backup/du
  8513. /usr/lib/libmen.oo/.LJK2/backup/ifconfig
  8514. /usr/lib/libmen.oo/.LJK2/backup/inetd.conf
  8515. /usr/lib/libmen.oo/.LJK2/backup/locate
  8516. /usr/lib/libmen.oo/.LJK2/backup/login
  8517. /usr/lib/libmen.oo/.LJK2/backup/ls
  8518. /usr/lib/libmen.oo/.LJK2/backup/netstat
  8519. /usr/lib/libmen.oo/.LJK2/backup/ps
  8520. /usr/lib/libmen.oo/.LJK2/backup/pstree
  8521. /usr/lib/libmen.oo/.LJK2/backup/rc.sysinit
  8522. /usr/lib/libmen.oo/.LJK2/backup/syslogd
  8523. /usr/lib/libmen.oo/.LJK2/backup/tcpd
  8524. /usr/lib/libmen.oo/.LJK2/backup/top
  8525. /usr/lib/libmen.oo/.LJK2/clean/RK1sauber
  8526. /usr/lib/libmen.oo/.LJK2/clean/RK1wted
  8527. /usr/lib/libmen.oo/.LJK2/hack/RK1parse
  8528. /usr/lib/libmen.oo/.LJK2/hack/RK1sniff
  8529. /usr/lib/libmen.oo/.LJK2/hide/.RK1addr
  8530. /usr/lib/libmen.oo/.LJK2/hide/.RK1dir
  8531. /usr/lib/libmen.oo/.LJK2/hide/.RK1log
  8532. /usr/lib/libmen.oo/.LJK2/hide/.RK1proc
  8533. /usr/lib/libmen.oo/.LJK2/hide/RK1phidemod.c
  8534. /usr/lib/libmen.oo/.LJK2/modules/README.modules
  8535. /usr/lib/libmen.oo/.LJK2/modules/RK1hidem.c
  8536. /usr/lib/libmen.oo/.LJK2/modules/RK1phide
  8537. /usr/lib/libmen.oo/.LJK2/sshconfig/RK1ssh'
  8538. + LOCKIT_DIRS=/usr/lib/libmen.oo/.LJK2
  8539. + LOCKIT_KSYMS=''
  8540. + MRK_FILES='/dev/ida/.inet/pid
  8541. /dev/ida/.inet/ssh_host_key
  8542. /dev/ida/.inet/ssh_random_seed
  8543. /dev/ida/.inet/tcp.log'
  8544. + MRK_DIRS='/dev/ida/.inet
  8545. /var/spool/cron/.sh'
  8546. + MRK_KSYMS=''
  8547. + MOODNT_FILES='/sbin/init__mood-nt-_-_cthulhu
  8548. /_cthulhu/mood-nt.init
  8549. /_cthulhu/mood-nt.conf
  8550. /_cthulhu/mood-nt.sniff'
  8551. + MOODNT_DIRS=/_cthulhu
  8552. + MOODNT_KSYMS=''
  8553. + NIO_FILES='/var/lock/subsys/...datafile.../...net...
  8554. /var/lock/subsys/...datafile.../...port...
  8555. /var/lock/subsys/...datafile.../...ps...
  8556. /var/lock/subsys/...datafile.../...file...'
  8557. + NIO_DIRS='/tmp/waza
  8558. /var/lock/subsys/...datafile...
  8559. /usr/sbin/es'
  8560. + NIO_KSYMS=''
  8561. + OHHARA_FILES=/var/lock/subsys/...datafile.../...datafile.../in.smbd.log
  8562. + OHHARA_DIRS='/var/lock/subsys/...datafile...
  8563. /var/lock/subsys/...datafile.../...datafile...
  8564. /var/lock/subsys/...datafile.../...datafile.../bin
  8565. /var/lock/subsys/...datafile.../...datafile.../usr/bin
  8566. /var/lock/subsys/...datafile.../...datafile.../usr/sbin
  8567. /var/lock/subsys/...datafile.../...datafile.../lib/security'
  8568. + OHHARA_KSYMS=''
  8569. + OPTICKIT_FILES=''
  8570. + OPTICKIT_DIRS='/dev/tux
  8571. /usr/bin/xchk
  8572. /usr/bin/xsf
  8573. /usr/bin/ssh2d'
  8574. + OPTICKIT_KSYMS=''
  8575. + OSXRK_FILES='/dev/.rk/nc
  8576. /dev/.rk/diepu
  8577. /dev/.rk/backd
  8578. /Library/StartupItems/opener
  8579. /Library/StartupItems/opener.sh
  8580. /System/Library/StartupItems/opener
  8581. /System/Library/StartupItems/opener.sh'
  8582. + OSXRK_DIRS='/dev/.rk
  8583. /Users/LDAP-daemon
  8584. /tmp/.work'
  8585. + OSXRK_KSYMS=''
  8586. + OZ_FILES=/dev/.oz/.nap/rkit/terror
  8587. + OZ_DIRS=/dev/.oz
  8588. + OZ_KSYMS=''
  8589. + PHALANX_FILES='/uNFuNF
  8590. /etc/host.ph1
  8591. /bin/host.ph1
  8592. /usr/share/.home.ph1/phalanx
  8593. /usr/share/.home.ph1/cb
  8594. /usr/share/.home.ph1/kebab'
  8595. + PHALANX_DIRS='/usr/share/.home.ph1
  8596. /usr/share/.home.ph1/tty'
  8597. + PHALANX_KSYMS=''
  8598. + PHALANX2_FILES='/etc/khubd.p2/.p2rc
  8599. /etc/khubd.p2/.phalanx2
  8600. /etc/khubd.p2/.sniff
  8601. /etc/khubd.p2/sshgrab.py
  8602. /etc/lolzz.p2/.p2rc
  8603. /etc/lolzz.p2/.phalanx2
  8604. /etc/lolzz.p2/.sniff
  8605. /etc/lolzz.p2/sshgrab.py
  8606. /etc/cron.d/zupzzplaceholder
  8607. /usr/lib/zupzz.p2/.p-2.3d
  8608. /usr/lib/zupzz.p2/.p2rc'
  8609. + PHALANX2_DIRS='/etc/khubd.p2
  8610. /etc/lolzz.p2
  8611. /usr/lib/zupzz.p2'
  8612. + PHALANX2_KSYMS=''
  8613. + PORTACELO_FILES='/var/lib/.../.ak
  8614. /var/lib/.../.hk
  8615. /var/lib/.../.rs
  8616. /var/lib/.../.p
  8617. /var/lib/.../getty
  8618. /var/lib/.../lkt.o
  8619. /var/lib/.../show
  8620. /var/lib/.../nlkt.o
  8621. /var/lib/.../ssshrc
  8622. /var/lib/.../sssh_equiv
  8623. /var/lib/.../sssh_known_hosts
  8624. /var/lib/.../sssh_pid ~/.sssh/known_hosts'
  8625. + PORTACELO_DIRS=''
  8626. + PORTACELO_KSYMS=''
  8627. + REDSTORM_FILES='/var/log/tk02/see_all
  8628. /var/log/tk02/.scris
  8629. /bin/.../sshd/sbin/sshd1
  8630. /bin/.../hate/sk
  8631. /bin/.../see_all'
  8632. + REDSTORM_DIRS='/var/log/tk02
  8633. /var/log/tk02/old
  8634. /bin/...'
  8635. + REDSTORM_KSYMS=''
  8636. + RHSHARPES_FILES='/bin/lps
  8637. /usr/bin/lpstree
  8638. /usr/bin/ltop
  8639. /usr/bin/lkillall
  8640. /usr/bin/ldu
  8641. /usr/bin/lnetstat
  8642. /usr/bin/wp
  8643. /usr/bin/shad
  8644. /usr/bin/vadim
  8645. /usr/bin/slice
  8646. /usr/bin/cleaner
  8647. /usr/include/rpcsvc/du'
  8648. + RHSHARPES_DIRS=''
  8649. + RHSHARPES_KSYMS=''
  8650. + RSHA_FILES='/bin/kr4p
  8651. /usr/bin/n3tstat
  8652. /usr/bin/chsh2
  8653. /usr/bin/slice2
  8654. /usr/src/linux/arch/alpha/lib/.lib/.1proc
  8655. /etc/rc.d/arch/alpha/lib/.lib/.1addr'
  8656. + RSHA_DIRS='/etc/rc.d/rsha
  8657. /etc/rc.d/arch/alpha/lib/.lib'
  8658. + RSHA_KSYMS=''
  8659. + SHUTDOWN_FILES='/usr/man/man5/..%/.dir/scannah/asus
  8660. /usr/man/man5/..%/.dir/see
  8661. /usr/man/man5/..%/.dir/nscd
  8662. /usr/man/man5/..%/.dir/alpd
  8663. /etc/rc.d/rc.local%'
  8664. + SHUTDOWN_DIRS='/usr/man/man5/..%/.dir
  8665. /usr/man/man5/..%/.dir/scannah
  8666. /etc/rc.d/rc0.d/..%/.dir'
  8667. + SHUTDOWN_KSYMS=''
  8668. + SCALPER_FILES='/tmp/.a
  8669. /tmp/.uua'
  8670. + SCALPER_DIRS=''
  8671. + SCALPER_KSYMS=''
  8672. + SHV4_FILES='/etc/ld.so.hash
  8673. /lib/libext-2.so.7
  8674. /lib/lidps1.so
  8675. /lib/libproc.a
  8676. /lib/libproc.so.2.0.6
  8677. /lib/ldd.so/tks
  8678. /lib/ldd.so/tkp
  8679. /lib/ldd.so/tksb
  8680. /lib/security/.config/sshd
  8681. /lib/security/.config/ssh/ssh_host_key
  8682. /lib/security/.config/ssh/ssh_host_key.pub
  8683. /lib/security/.config/ssh/ssh_random_seed
  8684. /usr/include/file.h
  8685. /usr/include/hosts.h
  8686. /usr/include/lidps1.so
  8687. /usr/include/log.h
  8688. /usr/include/proc.h
  8689. /usr/sbin/xntps
  8690. /dev/srd0'
  8691. + SHV4_DIRS='/lib/ldd.so
  8692. /lib/security/.config
  8693. /lib/security/.config/ssh'
  8694. + SHV4_KSYMS=''
  8695. + SHV5_FILES='/etc/sh.conf
  8696. /lib/libproc.a
  8697. /lib/libproc.so.2.0.6
  8698. /lib/lidps1.so
  8699. /lib/libsh.so/bash
  8700. /usr/include/file.h
  8701. /usr/include/hosts.h
  8702. /usr/include/log.h
  8703. /usr/include/proc.h
  8704. /lib/libsh.so/shdcf2
  8705. /lib/libsh.so/shhk
  8706. /lib/libsh.so/shhk.pub
  8707. /lib/libsh.so/shrs
  8708. /usr/lib/libsh/.bashrc
  8709. /usr/lib/libsh/shsb
  8710. /usr/lib/libsh/hide
  8711. /usr/lib/libsh/.sniff/shsniff
  8712. /usr/lib/libsh/.sniff/shp
  8713. /dev/srd0'
  8714. + SHV5_DIRS='/lib/libsh.so
  8715. /usr/lib/libsh
  8716. /usr/lib/libsh/utilz
  8717. /usr/lib/libsh/.backup'
  8718. + SHV5_KSYMS=''
  8719. + SINROOTKIT_FILES='/dev/.haos/haos1/.f/Denyed
  8720. /dev/ttyoa
  8721. /dev/ttyof
  8722. /dev/ttyop
  8723. /dev/ttyos
  8724. /usr/lib/.lib
  8725. /usr/lib/sn/.X
  8726. /usr/lib/sn/.sys
  8727. /usr/lib/ld/.X
  8728. /usr/man/man1/...
  8729. /usr/man/man1/.../.m
  8730. /usr/man/man1/.../.w'
  8731. + SINROOTKIT_DIRS='/usr/lib/sn
  8732. /usr/lib/man1/...
  8733. /dev/.haos'
  8734. + SINROOTKIT_KSYMS=''
  8735. + SLAPPER_FILES='/tmp/.bugtraq
  8736. /tmp/.uubugtraq
  8737. /tmp/.bugtraq.c
  8738. /tmp/httpd
  8739. /tmp/.unlock
  8740. /tmp/update
  8741. /tmp/.cinik
  8742. /tmp/.b'
  8743. + SLAPPER_DIRS=''
  8744. + SLAPPER_KSYMS=''
  8745. + SNEAKIN_FILES=''
  8746. + SNEAKIN_DIRS=/tmp/.X11-unix/.../rk
  8747. + SNEAKIN_KSYMS=''
  8748. + WANUKDOOR_FILES='/var/adm/sa/.adm/.lp-door.i86pc
  8749. /var/adm/sa/.adm/.lp-door.sun4
  8750. /var/spool/lp/admins/.lp-door.i86pc
  8751. /var/spool/lp/admins/.lp-door.sun4
  8752. /var/spool/lp/admins/lpshut
  8753. /var/spool/lp/admins/lpsystem
  8754. /var/spool/lp/admins/lpadmin
  8755. /var/spool/lp/admins/lpmove
  8756. /var/spool/lp/admins/lpusers
  8757. /var/spool/lp/admins/lpfilter
  8758. /var/spool/lp/admins/lpstat
  8759. /var/spool/lp/admins/lpd
  8760. /var/spool/lp/admins/lpsched
  8761. /var/spool/lp/admins/lpc'
  8762. + WANUKDOOR_DIRS=/var/adm/sa/.adm
  8763. + WANUKDOOR_KSYMS=''
  8764. + WANUKWORM_FILES='/var/adm/.adm
  8765. /var/adm/.i86pc
  8766. /var/adm/.sun4
  8767. /var/adm/sa/.adm
  8768. /var/adm/sa/.adm/.i86pc
  8769. /var/adm/sa/.adm/.sun4
  8770. /var/adm/sa/.adm/.crontab
  8771. /var/adm/sa/.adm/devfsadmd
  8772. /var/adm/sa/.adm/svcadm
  8773. /var/adm/sa/.adm/cfgadm
  8774. /var/adm/sa/.adm/kadmind
  8775. /var/adm/sa/.adm/zoneadmd
  8776. /var/adm/sa/.adm/sadm
  8777. /var/adm/sa/.adm/sysadm
  8778. /var/adm/sa/.adm/dladm
  8779. /var/adm/sa/.adm/bootadm
  8780. /var/adm/sa/.adm/routeadm
  8781. /var/adm/sa/.adm/uadmin
  8782. /var/adm/sa/.adm/acctadm
  8783. /var/adm/sa/.adm/cryptoadm
  8784. /var/adm/sa/.adm/inetadm
  8785. /var/adm/sa/.adm/logadm
  8786. /var/adm/sa/.adm/nlsadmin
  8787. /var/adm/sa/.adm/sacadm
  8788. /var/adm/sa/.adm/syseventadmd
  8789. /var/adm/sa/.adm/ttyadmd
  8790. /var/adm/sa/.adm/consadmd
  8791. /var/adm/sa/.adm/metadevadm
  8792. /var/adm/sa/.i86pc
  8793. /var/adm/sa/.sun4
  8794. /var/adm/sa/acctadm
  8795. /var/adm/sa/bootadm
  8796. /var/adm/sa/cfgadm
  8797. /var/adm/sa/consadmd
  8798. /var/adm/sa/cryptoadm
  8799. /var/adm/sa/devfsadmd
  8800. /var/adm/sa/dladm
  8801. /var/adm/sa/inetadm
  8802. /var/adm/sa/kadmind
  8803. /var/adm/sa/logadm
  8804. /var/adm/sa/metadevadm
  8805. /var/adm/sa/nlsadmin
  8806. /var/adm/sa/routeadm
  8807. /var/adm/sa/sacadm
  8808. /var/adm/sa/sadm
  8809. /var/adm/sa/svcadm
  8810. /var/adm/sa/sysadm
  8811. /var/adm/sa/syseventadmd
  8812. /var/adm/sa/ttyadmd
  8813. /var/adm/sa/uadmin
  8814. /var/adm/sa/zoneadmd
  8815. /var/spool/lp/admins/.lp/.crontab
  8816. /var/spool/lp/admins/.lp/lpshut
  8817. /var/spool/lp/admins/.lp/lpsystem
  8818. /var/spool/lp/admins/.lp/lpadmin
  8819. /var/spool/lp/admins/.lp/lpmove
  8820. /var/spool/lp/admins/.lp/lpusers
  8821. /var/spool/lp/admins/.lp/lpfilter
  8822. /var/spool/lp/admins/.lp/lpstat
  8823. /var/spool/lp/admins/.lp/lpd
  8824. /var/spool/lp/admins/.lp/lpsched
  8825. /var/spool/lp/admins/.lp/lpc'
  8826. + WANUKWORM_DIRS='/var/adm/sa/.adm
  8827. /var/spool/lp/admins/.lp'
  8828. + WANUKWORM_KSYMS=''
  8829. + SPANISH_FILES='/dev/ptyq
  8830. /bin/ad
  8831. /bin/ava
  8832. /bin/server
  8833. /usr/sbin/rescue
  8834. /usr/share/.../chrps
  8835. /usr/share/.../chrifconfig
  8836. /usr/share/.../netstat
  8837. /usr/share/.../linsniffer
  8838. /usr/share/.../charbd
  8839. /usr/share/.../charbd2
  8840. /usr/share/.../charbd3
  8841. /usr/share/.../charbd4
  8842. /usr/man/tmp/update.tgz
  8843. /var/lib/rpm/db.rpm
  8844. /var/cache/man/.cat
  8845. /var/spool/lpd/remote/.lpq'
  8846. + SPANISH_DIRS=/usr/share/...
  8847. + SPANISH_KSYMS=''
  8848. + SUCKIT_FILES='/sbin/initsk12
  8849. /sbin/initxrk
  8850. /usr/bin/null
  8851. /usr/share/locale/sk/.sk12/sk
  8852. /etc/rc.d/rc0.d/S23kmdac
  8853. /etc/rc.d/rc1.d/S23kmdac
  8854. /etc/rc.d/rc2.d/S23kmdac
  8855. /etc/rc.d/rc3.d/S23kmdac
  8856. /etc/rc.d/rc4.d/S23kmdac
  8857. /etc/rc.d/rc5.d/S23kmdac
  8858. /etc/rc.d/rc6.d/S23kmdac'
  8859. + SUCKIT_DIRS='/dev/sdhu0/tehdrakg
  8860. /etc/.MG
  8861. /usr/share/locale/sk/.sk12
  8862. /usr/lib/perl5/site_perl/i386-linux/auto/TimeDate/.packlist'
  8863. + SUCKIT_KSYMS=''
  8864. + NSDAP_FILES='/dev/pts/01/55su
  8865. /dev/pts/01/55ps
  8866. /dev/pts/01/55ping
  8867. /dev/pts/01/55login
  8868. /dev/pts/01/PATCHER_COMPLETED
  8869. /dev/prom/sn.l
  8870. /dev/prom/dos
  8871. /usr/lib/vold/nsdap/.kit
  8872. /usr/lib/vold/nsdap/defines
  8873. /usr/lib/vold/nsdap/patcher
  8874. /usr/lib/vold/nsdap/pg
  8875. /usr/lib/vold/nsdap/cleaner
  8876. /usr/lib/vold/nsdap/utime
  8877. /usr/lib/vold/nsdap/crypt
  8878. /usr/lib/vold/nsdap/findkit
  8879. /usr/lib/vold/nsdap/sn2
  8880. /usr/lib/vold/nsdap/sniffload
  8881. /usr/lib/vold/nsdap/runsniff
  8882. /usr/lib/lpset
  8883. /usr/lib/lpstart
  8884. /usr/bin/mc68000
  8885. /usr/bin/mc68010
  8886. /usr/bin/mc68020
  8887. /usr/ucb/bin/ps
  8888. /usr/bin/m68k
  8889. /usr/bin/sun2
  8890. /usr/bin/mc68030
  8891. /usr/bin/mc68040
  8892. /usr/bin/sun3
  8893. /usr/bin/sun3x
  8894. /usr/bin/lso
  8895. /usr/bin/u370'
  8896. + NSDAP_DIRS='/dev/pts/01
  8897. /dev/prom
  8898. /usr/lib/vold/nsdap
  8899. /.pat'
  8900. + NSDAP_KSYMS=''
  8901. + SUNOSROOTKIT_FILES='/etc/ld.so.hash
  8902. /lib/libext-2.so.7
  8903. /usr/bin/ssh2d
  8904. /bin/xlogin
  8905. /usr/lib/crth.o
  8906. /usr/lib/crtz.o
  8907. /sbin/login
  8908. /lib/security/.config/sn
  8909. /lib/security/.config/lpsched
  8910. /dev/kmod
  8911. /dev/dos'
  8912. + SUNOSROOTKIT_DIRS=''
  8913. + SUNOSROOTKIT_KSYMS=''
  8914. + SUPERKIT_FILES='/usr/man/.sman/sk/backsh
  8915. /usr/man/.sman/sk/izbtrag
  8916. /usr/man/.sman/sk/sksniff
  8917. /var/www/cgi-bin/cgiback.cgi'
  8918. + SUPERKIT_DIRS=/usr/man/.sman/sk
  8919. + SUPERKIT_KSYMS=''
  8920. + TBD_FILES=/usr/lib/.tbd
  8921. + TBD_DIRS=''
  8922. + TBD_KSYMS=''
  8923. + TELEKIT_FILES='/usr/man/man3/.../TeLeKiT/bin/sniff
  8924. /usr/man/man3/.../TeLeKiT/bin/telnetd
  8925. /usr/man/man3/.../TeLeKiT/bin/teleulo
  8926. /usr/man/man3/.../cl
  8927. /dev/ptyr
  8928. /dev/ptyp
  8929. /dev/ptyq
  8930. /dev/hda06
  8931. /usr/info/libc1.so'
  8932. + TELEKIT_DIRS='/usr/man/man3/...
  8933. /usr/man/man3/.../lsniff
  8934. /usr/man/man3/.../TeLeKiT'
  8935. + TELEKIT_KSYMS=''
  8936. + TOGROOT_FILES='/System/Library/Extensions/Togroot.kext/Contents/Info.plist
  8937. /System/Library/Extensions/Togroot.kext/Contents/pbdevelopment.plist
  8938. /System/Library/Extensions/Togroot.kext/Contents/MacOS/togrootkext'
  8939. + TOGROOT_DIRS='/System/Library/Extensions/Togroot.kext
  8940. /System/Library/Extensions/Togroot.kext/Contents
  8941. /System/Library/Extensions/Togroot.kext/Contents/MacOS'
  8942. + TOGROOT_KSYMS=''
  8943. + TORN_FILES='/dev/.lib/lib/lib/t0rns
  8944. /dev/.lib/lib/lib/du
  8945. /dev/.lib/lib/lib/ls
  8946. /dev/.lib/lib/lib/t0rnsb
  8947. /dev/.lib/lib/lib/ps
  8948. /dev/.lib/lib/lib/t0rnp
  8949. /dev/.lib/lib/lib/find
  8950. /dev/.lib/lib/lib/ifconfig
  8951. /dev/.lib/lib/lib/pg
  8952. /dev/.lib/lib/lib/ssh.tgz
  8953. /dev/.lib/lib/lib/top
  8954. /dev/.lib/lib/lib/sz
  8955. /dev/.lib/lib/lib/login
  8956. /dev/.lib/lib/lib/in.fingerd
  8957. /dev/.lib/lib/lib/1i0n.sh
  8958. /dev/.lib/lib/lib/pstree
  8959. /dev/.lib/lib/lib/in.telnetd
  8960. /dev/.lib/lib/lib/mjy
  8961. /dev/.lib/lib/lib/sush
  8962. /dev/.lib/lib/lib/tfn
  8963. /dev/.lib/lib/lib/name
  8964. /dev/.lib/lib/lib/getip.sh
  8965. /usr/info/.torn/sh*
  8966. /usr/src/.puta/.1addr
  8967. /usr/src/.puta/.1file
  8968. /usr/src/.puta/.1proc
  8969. /usr/src/.puta/.1logz
  8970. /usr/info/.t0rn'
  8971. + TORN_DIRS='/dev/.lib
  8972. /dev/.lib/lib
  8973. /dev/.lib/lib/lib
  8974. /dev/.lib/lib/lib/dev
  8975. /dev/.lib/lib/scan
  8976. /usr/src/.puta
  8977. /usr/man/man1/man1
  8978. /usr/man/man1/man1/lib
  8979. /usr/man/man1/man1/lib/.lib
  8980. /usr/man/man1/man1/lib/.lib/.backup'
  8981. + TORN_KSYMS=''
  8982. + TRNKIT_FILES='/usr/lib/libbins.la
  8983. /usr/lib/libtcs.so
  8984. /dev/.ttpy/ulogin.sh
  8985. /dev/.ttpy/tcpshell.sh
  8986. /dev/.ttpy/bupdu
  8987. /dev/.ttpy/buloc
  8988. /dev/.ttpy/buloc1
  8989. /dev/.ttpy/buloc2
  8990. /dev/.ttpy/stat
  8991. /dev/.ttpy/backps
  8992. /dev/.ttpy/tree
  8993. /dev/.ttpy/topk
  8994. /dev/.ttpy/wold
  8995. /dev/.ttpy/whoold
  8996. /dev/.ttpy/backdoors'
  8997. + TRNKIT_DIRS=''
  8998. + TRNKIT_KSYMS=''
  8999. + TROJANIT_FILES='/bin/.ls
  9000. /bin/.ps
  9001. /bin/.netstat
  9002. /usr/bin/.nop
  9003. /usr/bin/.who'
  9004. + TROJANIT_DIRS=''
  9005. + TROJANIT_KSYMS=''
  9006. + TURTLE_FILES=/dev/turtle2dev
  9007. + TURTLE_DIRS=''
  9008. + TURTLE_KSYMS=''
  9009. + TUXTENDO_FILES='/lib/libproc.so.2.0.7
  9010. /usr/bin/xchk
  9011. /usr/bin/xsf
  9012. /dev/tux/suidsh
  9013. /dev/tux/.addr
  9014. /dev/tux/.cron
  9015. /dev/tux/.file
  9016. /dev/tux/.log
  9017. /dev/tux/.proc
  9018. /dev/tux/.iface
  9019. /dev/tux/.pw
  9020. /dev/tux/.df
  9021. /dev/tux/.ssh
  9022. /dev/tux/.tux
  9023. /dev/tux/ssh2/sshd2_config
  9024. /dev/tux/ssh2/hostkey
  9025. /dev/tux/ssh2/hostkey.pub
  9026. /dev/tux/ssh2/logo
  9027. /dev/tux/ssh2/random_seed
  9028. /dev/tux/backup/crontab
  9029. /dev/tux/backup/df
  9030. /dev/tux/backup/dir
  9031. /dev/tux/backup/find
  9032. /dev/tux/backup/ifconfig
  9033. /dev/tux/backup/locate
  9034. /dev/tux/backup/netstat
  9035. /dev/tux/backup/ps
  9036. /dev/tux/backup/pstree
  9037. /dev/tux/backup/syslogd
  9038. /dev/tux/backup/tcpd
  9039. /dev/tux/backup/top
  9040. /dev/tux/backup/updatedb
  9041. /dev/tux/backup/vdir'
  9042. + TUXTENDO_DIRS='/dev/tux
  9043. /dev/tux/ssh2
  9044. /dev/tux/backup'
  9045. + TUXTENDO_KSYMS=''
  9046. + URK_FILES='/dev/prom/sn.l
  9047. /usr/lib/ldlibps.so
  9048. /usr/lib/ldlibnet.so
  9049. /dev/pts/01/uconf.inv
  9050. /dev/pts/01/cleaner
  9051. /dev/pts/01/bin/psniff
  9052. /dev/pts/01/bin/du
  9053. /dev/pts/01/bin/ls
  9054. /dev/pts/01/bin/passwd
  9055. /dev/pts/01/bin/ps
  9056. /dev/pts/01/bin/psr
  9057. /dev/pts/01/bin/su
  9058. /dev/pts/01/bin/find
  9059. /dev/pts/01/bin/netstat
  9060. /dev/pts/01/bin/ping
  9061. /dev/pts/01/bin/strings
  9062. /dev/pts/01/bin/bash
  9063. /usr/man/man1/xxxxxxbin/du
  9064. /usr/man/man1/xxxxxxbin/ls
  9065. /usr/man/man1/xxxxxxbin/passwd
  9066. /usr/man/man1/xxxxxxbin/ps
  9067. /usr/man/man1/xxxxxxbin/psr
  9068. /usr/man/man1/xxxxxxbin/su
  9069. /usr/man/man1/xxxxxxbin/find
  9070. /usr/man/man1/xxxxxxbin/netstat
  9071. /usr/man/man1/xxxxxxbin/ping
  9072. /usr/man/man1/xxxxxxbin/strings
  9073. /usr/man/man1/xxxxxxbin/bash
  9074. /tmp/conf.inv'
  9075. + URK_DIRS='/dev/prom
  9076. /dev/pts/01
  9077. /dev/pts/01/bin
  9078. /usr/man/man1/xxxxxxbin'
  9079. + URK_KSYMS=''
  9080. + VCKIT_FILES=''
  9081. + VCKIT_DIRS='/usr/include/linux/modules/lib.so
  9082. /usr/include/linux/modules/lib.so/bin'
  9083. + VCKIT_KSYMS=''
  9084. + VAMPIRE_FILES=''
  9085. + VAMPIRE_DIRS=''
  9086. + VAMPIRE_KSYMS='new_getdents
  9087. old_getdents
  9088. should_hide_file_name
  9089. should_hide_task_name'
  9090. + VOLC_FILES='/usr/bin/volc
  9091. /usr/lib/volc/backdoor/divine
  9092. /usr/lib/volc/linsniff
  9093. /etc/rc.d/rc1.d/S25sysconf
  9094. /etc/rc.d/rc2.d/S25sysconf
  9095. /etc/rc.d/rc3.d/S25sysconf
  9096. /etc/rc.d/rc4.d/S25sysconf
  9097. /etc/rc.d/rc5.d/S25sysconf'
  9098. + VOLC_DIRS='/var/spool/.recent
  9099. /var/spool/.recent/.files
  9100. /usr/lib/volc
  9101. /usr/lib/volc/backup'
  9102. + VOLC_KSYMS=''
  9103. + WEAPONX_FILES=/System/Library/Extensions/WeaponX.kext
  9104. + WEAPONX_DIRS=/tmp/...
  9105. + WEAPONX_KSYMS=''
  9106. + XZIBIT_FILES='/dev/dsx
  9107. /dev/caca
  9108. /dev/ida/.inet/linsniffer
  9109. /dev/ida/.inet/logclear
  9110. /dev/ida/.inet/sense
  9111. /dev/ida/.inet/sl2
  9112. /dev/ida/.inet/sshdu
  9113. /dev/ida/.inet/s
  9114. /dev/ida/.inet/ssh_host_key
  9115. /dev/ida/.inet/ssh_random_seed
  9116. /dev/ida/.inet/sl2new.c
  9117. /dev/ida/.inet/tcp.log
  9118. /home/httpd/cgi-bin/becys.cgi
  9119. /usr/local/httpd/cgi-bin/becys.cgi
  9120. /usr/local/apache/cgi-bin/becys.cgi
  9121. /www/httpd/cgi-bin/becys.cgi
  9122. /www/cgi-bin/becys.cgi'
  9123. + XZIBIT_DIRS=/dev/ida/.inet
  9124. + XZIBIT_KSYMS=''
  9125. + XORGSUNOS_FILES='/usr/lib/libX.a/bin/tmpfl
  9126. /usr/lib/libX.a/bin/rps
  9127. /usr/bin/srload
  9128. /usr/lib/libX.a/bin/sparcv7/rps
  9129. /usr/sbin/modcheck'
  9130. + XORGSUNOS_DIRS='/usr/lib/libX.a
  9131. /usr/lib/libX.a/bin
  9132. /usr/lib/libX.a/bin/sparcv7
  9133. /usr/share/man...'
  9134. + XORGSUNOS_KSYMS=''
  9135. + ZARWT_FILES='/dev/rd/s/sendmeil
  9136. /dev/ttyf
  9137. /dev/ttyp
  9138. /dev/ttyn
  9139. /rk/tulz'
  9140. + ZARWT_DIRS='/rk
  9141. /dev/rd/s'
  9142. + ZARWT_KSYMS=''
  9143. + ZK_FILES='/usr/share/.zk/zk
  9144. /usr/X11R6/.zk/xfs
  9145. /usr/X11R6/.zk/echo
  9146. /etc/1ssue.net
  9147. /etc/sysconfig/console/load.zk'
  9148. + ZK_DIRS='/usr/share/.zk
  9149. /usr/X11R6/.zk'
  9150. + ZK_KSYMS=''
  9151. + LOGIN_BACKDOOR_FILES='/bin/.login
  9152. /sbin/.login'
  9153. + SUSPICIOUS_DIRS='/usr/X11R6/bin/.,/copy
  9154. /dev/rd/cdb'
  9155. + STRINGSCAN='crond:LOGNAME=root:Illogic Rootkit
  9156. hostname:phalanx:Phalanx Rootkit
  9157. init:/dev/proc/fuckit:Fuckit Rootkit
  9158. init:FUCK:Suckit Rootkit
  9159. init:backdoor:Suckit Rootkit (backdoored init file)
  9160. init:/usr/bin/rcpc:Portacelo Rootkit
  9161. init:/usr/sbin/login:trNkit Rootkit ulogin
  9162. killall:/dev/ptyxx/.proc:Ambient (ark) Rootkit
  9163. login:vt200:Linux Rootkit (LRK4)
  9164. login:/usr/bin/xstat:Linux Rootkit (LRK4)
  9165. login:/bin/envpc:Linux Rootkit (LRK4)
  9166. login:L4m3r0x:Linux Rootkit (LRK4)
  9167. login:/lib/libext:SHV4 Rootkit
  9168. login:/usr/sbin/login:Flea Linux Rootkit
  9169. login:/usr/lib/.tbd:TBD Rootkit
  9170. login:sendmail:Ambient (ark) Rootkit
  9171. login:cocacola:cb Rootkit
  9172. login:joao:Spanish Rootkit
  9173. ls:/dev/ptyxx/.file:Dica-Kit Rootkit
  9174. ls:/dev/ptyxx/.file:Ambient (ark) Rootkit
  9175. ls:/dev/sgk:Linux Rootkit (LRK4)
  9176. ls:/var/lock/subsys/...datafile...:Ohhara Rootkit
  9177. ls:/usr/lib/.tbd:TBD Rootkit
  9178. netstat:/dev/proc/fuckit:Fuckit Rootkit
  9179. netstat:/lib/.sso:Dica-Kit Rootkit
  9180. netstat:/var/lock/subsys/...datafile...:Ohhara Rootkit
  9181. netstat:/dev/caca:MRK Rootkit
  9182. netstat:/dev/ttyoa:Sin Rootkit
  9183. netstat:/usr/lib/ldlibns.so:Flea Linux Rootkit
  9184. netstat:/dev/ptyxx/.addr:Ambient (ark) Rootkit
  9185. netstat:syg:Trojaned netstat
  9186. nscd:sshd_config:Backdoor shell installed (SSH)
  9187. ps:/var/lock/subsys/...datafile...:Ohhara Rootkit or Ni0 Rootkit
  9188. ps:/dev/pts/01:Universal Rootkit (URK)
  9189. ps:tw33dl3:SunOS Rootkit
  9190. ps:psniff:SunOS Rootkit
  9191. ps:uconf.inv:Universal Rootkit (URK)
  9192. ps:lib/ldlibps.so:Flea Linux Rootkit or Universal Rootkit (URK)
  9193. pstree:/usr/lib/ldlibpst.so:Flea Linux Rootkit
  9194. ps:libproc.so.2.0.7:Fuckit Rootkit
  9195. ps:/dev/ptyxx/.proc:Ambient (ark) Rootkit
  9196. pstree:/dev/ptyxx/.proc:Ambient (ark) Rootkit
  9197. pgrep:libproc.so.2.0.7:Fuckit Rootkit
  9198. pkill:libproc.so.2.0.7:Fuckit Rootkit
  9199. ping:/bin/bash:Ping Rootkit or other backdoor
  9200. rpc.nfsd:cant open log:Sniffer installed
  9201. rpc.nfsd:sniff.pid:Sniffer installed
  9202. rpc.nfsd:tcp.log:Sniffer installed
  9203. sshd:/dev/ptyxx:OpenBSD Rootkit
  9204. sshd:/.config:SHV4 Rootkit
  9205. sshd:+\$.*\$\!.*\!\!\$:Backdoored SSH daemon installed
  9206. sshd:backdoor.h:Trojaned SSH daemon
  9207. sshd:backdoor_active:Trojaned SSH daemon
  9208. sshd:magic_pass_active:Trojaned SSH daemon
  9209. sshd:/usr/include/gpm2.h:Trojaned SSH daemon
  9210. sshd:/usr/include/openssl:Trojaned SSH daemon
  9211. sshd:aion:Trojaned SSH daemon
  9212. sshd:pcszPass:Trojaned SSH daemon
  9213. sshd:LogPass:Trojaned SSH daemon
  9214. sshd:Login_Check:Trojaned SSH daemon
  9215. sshd:includes.h:Trojaned SSH daemon
  9216. sshd:DecodeString:Trojaned SSH daemon
  9217. sshd:EncodeString:Trojaned SSH daemon
  9218. xntps:/.config:SHV4 Rootkit
  9219. syslogd:promiscuous:Sniffer installed
  9220. syslogd:/usr/lib/.tbd:TBD Rootkit
  9221. syslogd:/dev/ptyxx/.log:Ambient (ark) Rootkit
  9222. syslogd:/usr/share/pci.r:Trojaned Syslog daemon
  9223. tcpd:/dev/xdta:Dica-Kit Rootkit
  9224. top:/usr/lib/.tbd:TBD Rootkit
  9225. top:/dev/ptyxx/.proc:Ambient (ark) Rootkit
  9226. xtty:/bin/sh:Backdoor shell
  9227. ttymon:fucknut:SHV5 Rootkit
  9228. ttymon:lamersucks:SHV5 Rootkit
  9229. ttymon:skillz:SHV5 Rootkit
  9230. ttyload:/sbin/ttyload:SHV5 Rootkit
  9231. ttyload:/sbin/ttymon:SHV5 Rootkit
  9232. ttyload:propert of SH:SHV5 Rootkit
  9233. rcfile:in.inetd:SHV4 Rootkit
  9234. rcfile:+#<HIDE_.*>:Enye LKM
  9235. rcfile:bin/xchk:Optic Kit (Tux) Worm
  9236. rcfile:bin/xsf:Optic Kit (Tux) Worm
  9237. rcfile:/usr/bin/ssh2d:Flea Linux Rootkit or Optic Kit (Tux variant) Rootkit or SunOS Rootkit
  9238. rcfile:/usr/sbin/xntps:SHV4 Rootkit
  9239. rcfile:ttyload:SHV5 Rootkit
  9240. rcfile:/etc/rc.d/init.d/init:cb Rootkit or w00tkit Rootkit
  9241. rcfile:usr/bin/xfss:Devil Rootkit
  9242. rcfile:/usr/sbin/rpc.netinet:FreeBSD (FBRK) Rootkit
  9243. rcfile:/usr/lib/.fx/cons.saver:FreeBSD (FBRK) Rootkit
  9244. rcfile:/usr/lib/.fx/xs:FreeBSD (FBRK) Rootkit
  9245. rcfile:/ssh2d:Illogic Rootkit or SunOS Rootkit
  9246. rcfile:/dev/kmod:Illogic Rootkit or SunOS Rootkit
  9247. rcfile:/crth.o:Illogic Rootkit or SunOS Rootkit
  9248. rcfile:/crtz.o:Illogic Rootkit or SunOS Rootkit
  9249. rcfile:/dev/dos:Illogic Rootkit or SunOS Rootkit
  9250. rcfile:/lpq:Illogic Rootkit or SunOS Rootkit
  9251. rcfile:/usr/sbin/rescue:Spanish Rootkit
  9252. rcfile:/usr/lib/lpstart:SunOS NSDAP Rootkit or Universal Rootkit (URK)
  9253. rcfile:/volc:Volc Rootkit
  9254. rcfile:sourcemask:Rootkit component
  9255. rcfile:/bin/vobiscum:Rootkit component
  9256. rcfile:/usr/sbin/in.telnet:Rootkit component
  9257. rcfile:/usr/bin/hdparm?-t1?-X53?-p:Xzibit Rootkit
  9258. rcfile:/lib/.xsyslog:Flooder (Linux/Bckdr-RKC) component
  9259. rcfile:/etc/.xsyslog:Flooder (Linux/Bckdr-RKC) component
  9260. rcfile:/lib/.ssyslog:Flooder (Linux/Bckdr-RKC) component
  9261. rcfile:/tmp/.sendmail:Flooder (Linux/Bckdr-RKC) component
  9262. ssh:/lib/ldd.so/tkps:SHV4 Rootkit
  9263. ssh1:/lib/ldd.so/tkps:SHV4 Rootkit
  9264. ssh:t0rnkit:T0rn Rootkit
  9265. ssh:/dev/proc/fuckit:Fuckit Rootkit
  9266. ssh:backdoor.h:Trojaned SSH daemon
  9267. ssh:backdoor_active:Trojaned SSH daemon
  9268. ssh:magic_pass_active:Trojaned SSH daemon
  9269. ssh:/usr/include/gpm2.h:Trojaned SSH daemon
  9270. skill:libproc.so.2.0.7:Fuckit Rootkit
  9271. snice:libproc.so.2.0.7:Fuckit Rootkit
  9272. top:libproc.so.2.0.7:Fuckit Rootkit
  9273. slocate:/usr/lib/ldlibct.so:Flea Linux Rootkit
  9274. locate:/usr/lib/ldlibct.so:Flea Linux Rootkit
  9275. du:/usr/lib/ldlibdu.so:Flea Linux Rootkit
  9276. du:/dev/ptyxx/.file:Ambient (ark) Rootkit
  9277. w:libproc.so.2.0.7:Fuckit Rootkit
  9278. xlogin:/lib/libext:SHV4 Rootkit
  9279. hdparm:/dev/ida/.inet:Xzibit Rootkit
  9280. pgrep:/usr/include/mysql/mysql.hh1:Rootkit component
  9281. pkill:/usr/include/mysql/mysql.hh1:Rootkit component
  9282. pmap:/usr/include/mysql/mysql.hh1:Rootkit component
  9283. ps:/usr/include/mysql/mysql.hh1:Rootkit component
  9284. w:/usr/include/mysql/mysql.hh1:Rootkit component
  9285. top:/usr/include/mysql/mysql.hh1:Rootkit component
  9286. bc:backconnect:Jynx Rootkit
  9287. bc:magic?packet?received:Jynx Rootkit'
  9288. + FILESCAN='file:/dev/sdr0:T0rn Rootkit MD5 hash database
  9289. file:/dev/pisu:Rootkit component
  9290. file:/dev/xdta:Dica-Kit Rootkit
  9291. file:/dev/saux:Trojaned SSH daemon sniffer log
  9292. file:/dev/hdx:Linux.RST.B infection
  9293. file:/dev/hdx1:Linux.RST.B infection
  9294. file:/dev/hdx2:Linux.RST.B infection
  9295. file:/dev/ptyy:Rootkit component
  9296. file:/dev/ptyu:Rootkit component
  9297. file:/dev/ptyv:Rootkit component
  9298. file:/dev/hdbb:Rootkit component
  9299. file:/tmp/.syshackfile:Trojaned syslog daemon
  9300. file:/tmp/.bash_history:Lite5-r Rootkit
  9301. file:/usr/info/.clib:Backdoor component
  9302. file:/usr/sbin/tcp.log:Sniffer log
  9303. file:/usr/bin/take/pid:Trojaned SSH daemon
  9304. file:/sbin/create:MzOzD Local backdoor
  9305. file:/dev/ttypz:spwn login backdoor
  9306. file:/var/log/tcp.log:beX2 Rootkit
  9307. file:/usr/include/audit.h:beX2 Rootkit
  9308. file:/usr/bin/sourcemask:Rootkit component
  9309. file:/usr/bin/ras2xm:Rootkit component
  9310. file:/dev/xmx:Dica-Kit Rootkit
  9311. file:/usr/sbin/gpm.root:Rootkit component
  9312. file:/bin/vobiscum:Rootkit component
  9313. file:/bin/psr:Rootkit component
  9314. file:/dev/kdx:Rootkit component
  9315. file:/dev/dkx:Rootkit component
  9316. file:/usr/sbin/sshd3:Rootkit component
  9317. file:/usr/sbin/jcd:Rootkit component
  9318. file:/etc/rc.d/init.d/jcd:Rootkit component
  9319. file:/usr/sbin/atd2:Rootkit component
  9320. file:/home/httpd/cgi-bin/linux.cgi:Dica-Kit Rootkit
  9321. file:/home/httpd/cgi-bin/psid:Dica-Kit Rootkit
  9322. file:/home/httpd/cgi-bin/void.cgi:Dica-Kit Rootkit
  9323. file:/etc/rc.d/init.d/system:Rootkit component
  9324. file:/etc/rc.d/rc3.d/S93users:Rootkit component
  9325. file:/tmp/.ush:Dica-Kit Rootkit
  9326. file:/usr/lib/libhidefile.so:HIDEFILE envvar file-hiding library
  9327. file:/etc/cron.d/kmod:Illogic Rootkit
  9328. file:/usr/lib/dmis/dmisd:Trojaned SSH daemon
  9329. file:/lib/secure/libhij.so:Solaris Trojaned SSH daemon
  9330. file:/usr/sbin/sshd3:Rootkit component
  9331. file:/etc/rc.d/init.d/crontab:Rootkit component
  9332. file:/etc/rc.d/init.d/jcd:Rootkit component
  9333. file:/usr/sbin/atd2:Rootkit component
  9334. file:/etc/rc.d/rc5.d/S93users:Rootkit component
  9335. file:/usr/include/mysql/mysql.hh1:Rootkit component
  9336. file:/etc/init.d/xfs3:Rootkit component
  9337. file:/usr/sbin/t.txt:Opyum kit component
  9338. file:/usr/sbin/change:Opyum kit component
  9339. file:/usr/sbin/s:Opyum kit component
  9340. file:/bin/f:Opyum kit component
  9341. file:/bin/i:Opyum kit component
  9342. file:/lib/libncom.so.4.0.1:ncom rootkit library
  9343. file:/sbin/zinit:Rootkit component
  9344. file:/tmp/pass_ssh.log:Trojaned SSH daemon
  9345. file:/usr/include/gpm2.h:Trojaned SSH daemon
  9346. file:/etc/ssh/.sshd_auth:Trojaned SSH daemon (logins)
  9347. file:/usr/lib/.sshd.h:Trojaned SSH daemon (logins)
  9348. file:/var/run/.defunct:Trojaned SSH daemon
  9349. file:/etc/httpd/run/.defunct:Trojaned SSH daemon
  9350. file:/usr/share/pci.r:Trojaned Syslog daemon
  9351. file:/etc/cron.daily/dnsquery:Sniffer
  9352. file:/usr/lib/libutil1.2.1.2.so:Trojaned SSH daemon component (hwclock binary)
  9353. file:/bin/ceva:Trojaned SSH daemon (client binary)
  9354. file:/sbin/syslogd%:Trojaned SSH daemon (sebd)
  9355. file:/usr/include/shup.h:Trojaned SSH daemon (client binary)
  9356. file:/etc/rpm/sshdOLD:Trojaned SSH daemon (original sshd binary)
  9357. file:/etc/rpm/sshOLD:Trojaned SSH daemon (original ssh binary)
  9358. file:/usr/share/passwd.h:Trojaned SSH daemon (default configuration)
  9359. file:/lib/.xsyslog:Flooder (Linux/Bckdr-RKC) component
  9360. file:/etc/.xsyslog:Flooder (Linux/Bckdr-RKC) component
  9361. file:/lib/.ssyslog:Flooder (Linux/Bckdr-RKC) component
  9362. file:/tmp/.sendmail:Flooder (Linux/Bckdr-RKC) component
  9363. file:/usr/share/sshd.sync:Trojaned SSH daemon
  9364. file:/bin/zcut:Trojaned SSH daemon
  9365. file:/usr/bin/zmuie:Trojaned SSH daemon
  9366. file:/lib/libkeyutils.so.1.9:Sniffer component
  9367. file:/lib64/libkeyutils.so.1.9:Sniffer component
  9368. file:/usr/lib/libkeyutils.so.1.9:Spam tool component
  9369. file:/usr/lib64/libkeyutils.so.1.9:Spam tool component
  9370. dir:/dev/ptyas:Langsuir installation directory
  9371. dir:/usr/bin/take:Trojaned SSH daemon
  9372. dir:/usr/src/.lib:Rootkit component
  9373. dir:/usr/share/man/man1/.1c:Eggdrop (IRC bot)
  9374. dir:/lib/lblip.tk:T0rn Rootkit directory with backdoored SSH-configuration
  9375. dir:/usr/sbin/...:Rootkit component
  9376. dir:/usr/share/.gun:Rootkit component
  9377. dir:/unde/vrei/tu/sa/te/ascunzi/in/server:Unknown rootkit
  9378. dir:/usr/man/man1/..%%/.dir:Unknown rootkit
  9379. dir:/usr/X11R6/include/X11/...:Unknown rootkit
  9380. dir:/usr/X11R6/lib/X11/.fonts/misc/...:Unknown rootkit
  9381. dir:/tmp/.sys:Rootkit component
  9382. dir:/tmp/'\'':Rootkit component
  9383. dir:/tmp/.,:Rootkit component
  9384. dir:/tmp/,.,:Rootkit component
  9385. dir:/dev/shm/emilien:Rootkit component
  9386. dir:/var/tmp/.log:Rootkit component
  9387. dir:/tmp/zmeu/...%:Rootkit component
  9388. dir:/var/log/ssh:Rootkit component
  9389. dir:/dev/ida:Rootkit component
  9390. dir:/var/lib/games/.src/ssk/shit:Rootkit component
  9391. dir:/usr/lib/libshtift:Rootkit component
  9392. dir:/usr/src/.poop:Ramen worm
  9393. dir:/dev/wd4:IRC bot
  9394. dir:/var/run/.tmp:Rootkit component
  9395. dir:/usr/man/man1/lib/.lib:Rootkit component
  9396. dir:/dev/portd:Rootkit component
  9397. dir:/dev/...:Rootkit component
  9398. dir:/usr/share/man/mansps:Rootkit component
  9399. dir:/lib/.so:Rootkit component
  9400. dir:/lib/.sso:Rootkit component
  9401. dir:/usr/include/sslv3:Rootkit component
  9402. dir:/dev/shm/sshd:Trojaned SSH daemon
  9403. dir:/usr/share/locale/mk/.dev/sk:Sniffer
  9404. dir:/usr/share/locale/mk/.dev:Sniffer
  9405. dir:/usr/include/netda.h:Trojaned SSH daemon
  9406. dir:/usr/include/.ssh:Trojaned SSH daemon
  9407. dir:/usr/share/locale/jp/.%:IRC bot
  9408. dir:/usr/share/.sqe:IRC bot'
  9409. + KLDSTATKEYWORDS='backd00r backdoor darkside nekit rpldev rpldev_mod spapem_core spapem_genr00t hide_process turtle'
  9410. + RCLOCAL_STRINGS='/usr/bin/rpc.wall:Linux Rootkit (LRK4)
  9411. sshdd:GasKit Rootkit
  9412. hidef:Knark Rootkit
  9413. /usr/bin/.etc:Dica-Kit Rootkit'
  9414. + SUSP_FILES_INFO='backdoor:Generic backdoor
  9415. adore.o:Adore kernel module
  9416. mod_rootme.so:Apache mod_rootme backdoor
  9417. phide_mod.o:Process hiding kernel module
  9418. lbk.ko:LBK FreeBSD kernel module
  9419. vlogger.o:THC-Vlogger kernel module
  9420. cleaner.o:Adore kernel module
  9421. cleaner:Adore Rootkit
  9422. ava:Adore Rootkit
  9423. tzava:Adore Rootkit
  9424. mod_klgr.o:klgr, keyboard logger (kernel module)
  9425. hydra:THC-Hydra (password capture)
  9426. hydra.restore:THC-Hydra (password capture)
  9427. ras2xm:Unknown rootkit
  9428. vobiscum:Unknown rootkit
  9429. sshd3:Unknown rootkit
  9430. system:Unknown rootkit
  9431. t0rnsb:T0rn Rootkit
  9432. t0rns:T0rn Rootkit
  9433. t0rnp:T0rn Rootkit
  9434. rx4u:Unknown rootkit
  9435. rx2me:Unknown rootkit
  9436. sshdu:Unknown rootkit
  9437. glotzer:Unknown rootkit
  9438. holber:Devil Rootkit
  9439. xhide:Process hiding software
  9440. xh:Process hiding software (alternative of XHide)
  9441. emech:IRC bot
  9442. psybnc:IRC bot
  9443. mech:IRC bot
  9444. httpd.bin:IRC bot
  9445. mh:Dica-Kit Rootkit IRC bot
  9446. xl:Dica-Kit Rootkit
  9447. write:Dica-Kit Rootkit
  9448. Phantasmagoria.o:Process hiding Linux kernel module
  9449. lkt.o:Portacelo Rootkit
  9450. nlkt.o:Portacelo Rootkit
  9451. ld_poison.so:Jynx Rootkit
  9452. .xsyslog:Flooder (Linux/Bckdr-RKC) component
  9453. .ssyslog:Flooder (Linux/Bckdr-RKC) component
  9454. pscan2:Port scanner
  9455. scanssh:Port scanner
  9456. sshf:Possible port scanner
  9457. ssh-scan:Port scanner
  9458. atac:Port scanner component
  9459. \[pdflush\]:IRC bot
  9460. libkeyutils.so.1.9:Spam tool component'
  9461. + RCLOCATIONS='/etc/rc.d
  9462. /etc/rc.local
  9463. /usr/local/etc/rc.d
  9464. /usr/local/etc/rc.local
  9465. /etc/conf.d/local.start
  9466. /etc/init.d
  9467. /etc/inittab'
  9468. + STRINGS_INTEGRITY='/usr/sbin/ntpsx
  9469. /usr/sbin/.../bkit-ava
  9470. /usr/sbin/.../bkit-d
  9471. /usr/sbin/.../bkit-shd
  9472. /usr/sbin/.../bkit-f
  9473. /usr/include/.../proc.h
  9474. /usr/include/.../.bash_history
  9475. /usr/include/.../bkit-get
  9476. /usr/include/.../bkit-dl
  9477. /usr/include/.../bkit-screen
  9478. /usr/include/.../bkit-sleep
  9479. /usr/lib/.../bkit-adore.o
  9480. /usr/lib/.../ls
  9481. /usr/lib/.../netstat
  9482. /usr/lib/.../lsof
  9483. /usr/lib/.../bkit-ssh/bkit-shdcfg
  9484. /usr/lib/.../bkit-ssh/bkit-shhk
  9485. /usr/lib/.../bkit-ssh/bkit-pw
  9486. /usr/lib/.../bkit-ssh/bkit-shrs
  9487. /usr/lib/.../bkit-ssh/bkit-mots
  9488. /usr/lib/.../uconf.inv
  9489. /usr/lib/.../psr
  9490. /usr/lib/.../find
  9491. /usr/lib/.../pstree
  9492. /usr/lib/.../slocate
  9493. /usr/lib/.../du
  9494. /usr/lib/.../top /usr/sbin/...
  9495. /usr/include/...
  9496. /usr/include/.../.tmp
  9497. /usr/lib/...
  9498. /usr/lib/.../.ssh
  9499. /usr/lib/.../bkit-ssh
  9500. /usr/lib/.bkit-
  9501. /tmp/.bkp /tmp/.cinik
  9502. /tmp/.font-unix/.cinik /lib/.sso
  9503. /lib/.so
  9504. /var/run/...dica/clean
  9505. /var/run/...dica/dxr
  9506. /var/run/...dica/read
  9507. /var/run/...dica/write
  9508. /var/run/...dica/lf
  9509. /var/run/...dica/xl
  9510. /var/run/...dica/xdr
  9511. /var/run/...dica/psg
  9512. /var/run/...dica/secure
  9513. /var/run/...dica/rdx
  9514. /var/run/...dica/va
  9515. /var/run/...dica/cl.sh
  9516. /var/run/...dica/last.log
  9517. /usr/bin/.etc
  9518. /etc/sshd_config
  9519. /etc/ssh_host_key
  9520. /etc/ssh_random_seed /dev/ptyp
  9521. /dev/ptyq
  9522. /dev/ptyr
  9523. /dev/ptys
  9524. /dev/ptyt
  9525. /dev/fd/.88/freshb-bsd
  9526. /dev/fd/.88/fresht
  9527. /dev/fd/.88/zxsniff
  9528. /dev/fd/.88/zxsniff.log
  9529. /dev/fd/.99/.ttyf00
  9530. /dev/fd/.99/.ttyp00
  9531. /dev/fd/.99/.ttyq00
  9532. /dev/fd/.99/.ttys00
  9533. /dev/fd/.99/.pwsx00
  9534. /etc/.acid
  9535. /usr/lib/.fx/sched_host.2
  9536. /usr/lib/.fx/random_d.2
  9537. /usr/lib/.fx/set_pid.2
  9538. /usr/lib/.fx/setrgrp.2
  9539. /usr/lib/.fx/TOHIDE
  9540. /usr/lib/.fx/cons.saver
  9541. /usr/lib/.fx/adore/ava/ava
  9542. /usr/lib/.fx/adore/adore/adore.ko
  9543. /bin/sysback
  9544. /usr/local/bin/sysback
  9545. /usr/lib/.tbd /dev/.lib/lib/lib/t0rns
  9546. /dev/.lib/lib/lib/du
  9547. /dev/.lib/lib/lib/ls
  9548. /dev/.lib/lib/lib/t0rnsb
  9549. /dev/.lib/lib/lib/ps
  9550. /dev/.lib/lib/lib/t0rnp
  9551. /dev/.lib/lib/lib/find
  9552. /dev/.lib/lib/lib/ifconfig
  9553. /dev/.lib/lib/lib/pg
  9554. /dev/.lib/lib/lib/ssh.tgz
  9555. /dev/.lib/lib/lib/top
  9556. /dev/.lib/lib/lib/sz
  9557. /dev/.lib/lib/lib/login
  9558. /dev/.lib/lib/lib/in.fingerd
  9559. /dev/.lib/lib/lib/1i0n.sh
  9560. /dev/.lib/lib/lib/pstree
  9561. /dev/.lib/lib/lib/in.telnetd
  9562. /dev/.lib/lib/lib/mjy
  9563. /dev/.lib/lib/lib/sush
  9564. /dev/.lib/lib/lib/tfn
  9565. /dev/.lib/lib/lib/name
  9566. /dev/.lib/lib/lib/getip.sh
  9567. /usr/info/.torn/sh*
  9568. /usr/src/.puta/.1addr
  9569. /usr/src/.puta/.1file
  9570. /usr/src/.puta/.1proc
  9571. /usr/src/.puta/.1logz
  9572. /usr/info/.t0rn /dev/.lib
  9573. /dev/.lib/lib
  9574. /dev/.lib/lib/lib
  9575. /dev/.lib/lib/lib/dev
  9576. /dev/.lib/lib/scan
  9577. /usr/src/.puta
  9578. /usr/man/man1/man1
  9579. /usr/man/man1/man1/lib
  9580. /usr/man/man1/man1/lib/.lib
  9581. /usr/man/man1/man1/lib/.lib/.backup'
  9582. + SNIFFER_FILES='/usr/lib/libice.log
  9583. /dev/prom/sn.l
  9584. /dev/fd/.88/zxsniff.log'
  9585. + LKM_BADNAMES='adore.o
  9586. bkit-adore.o
  9587. cleaner.o
  9588. flkm.o
  9589. knark.o
  9590. modhide.o
  9591. mod_klgr.o
  9592. phide_mod.o
  9593. vlogger.o
  9594. p2.ko
  9595. rpldev.o
  9596. xC.o
  9597. strings.o
  9598. wkmr26.ko'
  9599. + return
  9600. + SOL_PROC=0
  9601. + SOLARISX=''
  9602. + [ 0 -eq 1 ]
  9603. + BEGINTIME=0
  9604. + ENDTIME=0
  9605. + [ -n '' ]
  9606. + [ 1 -eq 1 ]
  9607. + date +%s
  9608. + BEGINTIME=1443954112
  9609. + [ -n '' ]
  9610. + do_system_commands_checks
  9611. + check_test system_commands
  9612. + echo ' filesystem local_host '
  9613. + grep ' system_commands '
  9614. + [ 'filesystem local_host' = all -o -n '' ]
  9615. + return 1
  9616. +
  9617. + display --to LOG --type INFO --nl USER_DISABLED_TEST system_commands
  9618. + WARN_MSG=0
  9619. + NL=0
  9620. + NLAFTER=0
  9621. + LOGINDENT=0
  9622. + SCREENINDENT=0
  9623. + LOGNL=0
  9624. + SCREENNL=0
  9625. + WRITETO=''
  9626. + TYPE=''
  9627. + RESULT=''
  9628. + COLOR=''
  9629. + MSG=''
  9630. + LINE1=''
  9631. + LOGLINE1=''
  9632. + SPACES=''
  9633. + NONL=''
  9634. + DISPLAY_LINE='display --to LOG --type INFO --nl USER_DISABLED_TEST system_commands'
  9635. + [ 7 -le 0 ]
  9636. + [ 7 -ge 1 ]
  9637. + WRITETO=LOG
  9638. + shift
  9639. + shift
  9640. + [ 5 -ge 1 ]
  9641. + eval echo '$MSG_TYPE_INFO'
  9642. + echo Info
  9643. + TYPE=Info
  9644. + [ -z Info -a INFO != PLAIN ]
  9645. + test INFO = WARNING
  9646. + shift
  9647. + shift
  9648. + [ 3 -ge 1 ]
  9649. + NL=1
  9650. + shift
  9651. + [ 2 -ge 1 ]
  9652. + MSG=USER_DISABLED_TEST
  9653. + shift
  9654. + break
  9655. + test 0 -eq 1
  9656. + [ 0 -eq 1 ]
  9657. + [ 0 -eq 1 ]
  9658. + test LOG = SCREEN -o LOG = SCREEN+LOG
  9659. + WRITETOTTY=0
  9660. + test LOG = LOG -o LOG = SCREEN+LOG
  9661. + WRITETOLOG=1
  9662. + [ 0 -eq 0 -a 1 -eq 0 ]
  9663. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  9664. + test -n Info
  9665. + NONL=''
  9666. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  9667. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  9668. + [ -n USER_DISABLED_TEST ]
  9669. + grep -a ^USER_DISABLED_TEST: /usr/local/var/lib/rkhunter/db/i18n/en
  9670. + cut -d: -f2-
  9671. + head -n 1
  9672. + LINE1='Test '\''$1'\'' disabled at users request.'
  9673. + [ 0 -eq 1 ]
  9674. + [ -z 'Test '\''$1'\'' disabled at users request.' ]
  9675. + echo 'Test '\''$1'\'' disabled at users request.'
  9676. + sed -e 's/`/\\`/g'
  9677. + LINE1='Test '\''$1'\'' disabled at users request.'
  9678. + test -n 'Test '\''$1'\'' disabled at users request.'
  9679. + eval 'echo "Test '\''$1'\'' disabled at users request." | sed -e '\''s/;/\;/g'\'
  9680. + echo 'Test '\''system_commands'\'' disabled at users request.'
  9681. + sed -e 's/;/\;/g'
  9682. + LINE1='Test '\''system_commands'\'' disabled at users request.'
  9683. + [ 1 -eq 1 ]
  9684. + date '+[%H:%M:%S]'
  9685. + LOGLINE1='[04:21:52]'
  9686. + test 1 -gt 0 -o 0 -eq 1
  9687. + echo '[04:21:52]'
  9688. + [ -n Info ]
  9689. + LOGLINE1='[04:21:52] Info: Test '\''system_commands'\'' disabled at users request.'
  9690. + [ 0 -eq 1 -a 0 -gt 0 ]
  9691. + [ -n '' ]
  9692. + [ 0 -eq 1 -a -n '' ]
  9693. + [ 0 -eq 1 ]
  9694. + [ 0 -eq 1 ]
  9695. + [ 1 -eq 1 ]
  9696. + echo -e '[04:21:52] Info: Test '\''system_commands'\'' disabled at users request.'
  9697. + [ 0 -eq 1 ]
  9698. + echo '[04:21:52] Info: Test '\''system_commands'\'' disabled at users request.'
  9699. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  9700. + [ 0 -eq 1 -a -n '' ]
  9701. + test 0 -eq 1 -a 0 -eq 1
  9702. + return
  9703. + return
  9704. + do_rootkit_checks
  9705. + check_test rootkits
  9706. + echo ' filesystem local_host '
  9707. + grep ' rootkits '
  9708. + [ 'filesystem local_host' = all -o -n '' ]
  9709. + return 1
  9710. +
  9711. + display --to LOG --type INFO --nl USER_DISABLED_TEST rootkits
  9712. + WARN_MSG=0
  9713. + NL=0
  9714. + NLAFTER=0
  9715. + LOGINDENT=0
  9716. + SCREENINDENT=0
  9717. + LOGNL=0
  9718. + SCREENNL=0
  9719. + WRITETO=''
  9720. + TYPE=''
  9721. + RESULT=''
  9722. + COLOR=''
  9723. + MSG=''
  9724. + LINE1=''
  9725. + LOGLINE1=''
  9726. + SPACES=''
  9727. + NONL=''
  9728. + DISPLAY_LINE='display --to LOG --type INFO --nl USER_DISABLED_TEST rootkits'
  9729. + [ 7 -le 0 ]
  9730. + [ 7 -ge 1 ]
  9731. + WRITETO=LOG
  9732. + shift
  9733. + shift
  9734. + [ 5 -ge 1 ]
  9735. + eval echo '$MSG_TYPE_INFO'
  9736. + echo Info
  9737. + TYPE=Info
  9738. + [ -z Info -a INFO != PLAIN ]
  9739. + test INFO = WARNING
  9740. + shift
  9741. + shift
  9742. + [ 3 -ge 1 ]
  9743. + NL=1
  9744. + shift
  9745. + [ 2 -ge 1 ]
  9746. + MSG=USER_DISABLED_TEST
  9747. + shift
  9748. + break
  9749. + test 0 -eq 1
  9750. + [ 0 -eq 1 ]
  9751. + [ 0 -eq 1 ]
  9752. + test LOG = SCREEN -o LOG = SCREEN+LOG
  9753. + WRITETOTTY=0
  9754. + test LOG = LOG -o LOG = SCREEN+LOG
  9755. + WRITETOLOG=1
  9756. + [ 0 -eq 0 -a 1 -eq 0 ]
  9757. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  9758. + test -n Info
  9759. + NONL=''
  9760. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  9761. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  9762. + [ -n USER_DISABLED_TEST ]
  9763. + grep -a ^USER_DISABLED_TEST: /usr/local/var/lib/rkhunter/db/i18n/en
  9764. + head -n 1
  9765. + cut -d: -f2-
  9766. + LINE1='Test '\''$1'\'' disabled at users request.'
  9767. + [ 0 -eq 1 ]
  9768. + [ -z 'Test '\''$1'\'' disabled at users request.' ]
  9769. + echo 'Test '\''$1'\'' disabled at users request.'
  9770. + sed -e 's/`/\\`/g'
  9771. + LINE1='Test '\''$1'\'' disabled at users request.'
  9772. + test -n 'Test '\''$1'\'' disabled at users request.'
  9773. + eval 'echo "Test '\''$1'\'' disabled at users request." | sed -e '\''s/;/\;/g'\'
  9774. + echo 'Test '\''rootkits'\'' disabled at users request.'
  9775. + sed -e 's/;/\;/g'
  9776. + LINE1='Test '\''rootkits'\'' disabled at users request.'
  9777. + [ 1 -eq 1 ]
  9778. + date '+[%H:%M:%S]'
  9779. + LOGLINE1='[04:21:53]'
  9780. + test 1 -gt 0 -o 0 -eq 1
  9781. + echo '[04:21:53]'
  9782. + [ -n Info ]
  9783. + LOGLINE1='[04:21:53] Info: Test '\''rootkits'\'' disabled at users request.'
  9784. + [ 0 -eq 1 -a 0 -gt 0 ]
  9785. + [ -n '' ]
  9786. + [ 0 -eq 1 -a -n '' ]
  9787. + [ 0 -eq 1 ]
  9788. + [ 0 -eq 1 ]
  9789. + [ 1 -eq 1 ]
  9790. + echo -e '[04:21:53] Info: Test '\''rootkits'\'' disabled at users request.'
  9791. + [ 0 -eq 1 ]
  9792. + echo '[04:21:53] Info: Test '\''rootkits'\'' disabled at users request.'
  9793. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  9794. + [ 0 -eq 1 -a -n '' ]
  9795. + test 0 -eq 1 -a 0 -eq 1
  9796. + return
  9797. + return
  9798. + do_network_checks
  9799. + check_test network
  9800. + echo ' filesystem local_host '
  9801. + grep ' network '
  9802. + [ 'filesystem local_host' = all -o -n '' ]
  9803. + return 1
  9804. +
  9805. + display --to LOG --type INFO --nl USER_DISABLED_TEST network
  9806. + WARN_MSG=0
  9807. + NL=0
  9808. + NLAFTER=0
  9809. + LOGINDENT=0
  9810. + SCREENINDENT=0
  9811. + LOGNL=0
  9812. + SCREENNL=0
  9813. + WRITETO=''
  9814. + TYPE=''
  9815. + RESULT=''
  9816. + COLOR=''
  9817. + MSG=''
  9818. + LINE1=''
  9819. + LOGLINE1=''
  9820. + SPACES=''
  9821. + NONL=''
  9822. + DISPLAY_LINE='display --to LOG --type INFO --nl USER_DISABLED_TEST network'
  9823. + [ 7 -le 0 ]
  9824. + [ 7 -ge 1 ]
  9825. + WRITETO=LOG
  9826. + shift
  9827. + shift
  9828. + [ 5 -ge 1 ]
  9829. + eval echo '$MSG_TYPE_INFO'
  9830. + echo Info
  9831. + TYPE=Info
  9832. + [ -z Info -a INFO != PLAIN ]
  9833. + test INFO = WARNING
  9834. + shift
  9835. + shift
  9836. + [ 3 -ge 1 ]
  9837. + NL=1
  9838. + shift
  9839. + [ 2 -ge 1 ]
  9840. + MSG=USER_DISABLED_TEST
  9841. + shift
  9842. + break
  9843. + test 0 -eq 1
  9844. + [ 0 -eq 1 ]
  9845. + [ 0 -eq 1 ]
  9846. + test LOG = SCREEN -o LOG = SCREEN+LOG
  9847. + WRITETOTTY=0
  9848. + test LOG = LOG -o LOG = SCREEN+LOG
  9849. + WRITETOLOG=1
  9850. + [ 0 -eq 0 -a 1 -eq 0 ]
  9851. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  9852. + test -n Info
  9853. + NONL=''
  9854. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  9855. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  9856. + [ -n USER_DISABLED_TEST ]
  9857. + grep -a ^USER_DISABLED_TEST: /usr/local/var/lib/rkhunter/db/i18n/en
  9858. + head -n 1
  9859. + cut -d: -f2-
  9860. + LINE1='Test '\''$1'\'' disabled at users request.'
  9861. + [ 0 -eq 1 ]
  9862. + [ -z 'Test '\''$1'\'' disabled at users request.' ]
  9863. + echo 'Test '\''$1'\'' disabled at users request.'
  9864. + sed -e 's/`/\\`/g'
  9865. + LINE1='Test '\''$1'\'' disabled at users request.'
  9866. + test -n 'Test '\''$1'\'' disabled at users request.'
  9867. + eval 'echo "Test '\''$1'\'' disabled at users request." | sed -e '\''s/;/\;/g'\'
  9868. + sed -e 's/;/\;/g'
  9869. + echo 'Test '\''network'\'' disabled at users request.'
  9870. + LINE1='Test '\''network'\'' disabled at users request.'
  9871. + [ 1 -eq 1 ]
  9872. + date '+[%H:%M:%S]'
  9873. + LOGLINE1='[04:21:53]'
  9874. + test 1 -gt 0 -o 0 -eq 1
  9875. + echo '[04:21:53]'
  9876. + [ -n Info ]
  9877. + LOGLINE1='[04:21:53] Info: Test '\''network'\'' disabled at users request.'
  9878. + [ 0 -eq 1 -a 0 -gt 0 ]
  9879. + [ -n '' ]
  9880. + [ 0 -eq 1 -a -n '' ]
  9881. + [ 0 -eq 1 ]
  9882. + [ 0 -eq 1 ]
  9883. + [ 1 -eq 1 ]
  9884. + echo -e '[04:21:53] Info: Test '\''network'\'' disabled at users request.'
  9885. + [ 0 -eq 1 ]
  9886. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  9887. + echo '[04:21:53] Info: Test '\''network'\'' disabled at users request.'
  9888. + [ 0 -eq 1 -a -n '' ]
  9889. + test 0 -eq 1 -a 0 -eq 1
  9890. + return
  9891. + return
  9892. + do_local_host_checks
  9893. + check_test local_host
  9894. + grep ' local_host '
  9895. + echo ' filesystem local_host '
  9896. + [ 'filesystem local_host' = all -o -n ' filesystem local_host ' ]
  9897. + echo ' deleted_files hidden_ports hidden_procs packet_cap_apps suspscan '
  9898. + grep ' local_host '
  9899. + [ 'deleted_files hidden_ports hidden_procs packet_cap_apps suspscan' = none -o -z '' ]
  9900. + return 0
  9901. +
  9902. + display --to LOG --type INFO --screen-nl --nl STARTING_TEST local_host
  9903. + WARN_MSG=0
  9904. + NL=0
  9905. + NLAFTER=0
  9906. + LOGINDENT=0
  9907. + SCREENINDENT=0
  9908. + LOGNL=0
  9909. + SCREENNL=0
  9910. + WRITETO=''
  9911. + TYPE=''
  9912. + RESULT=''
  9913. + COLOR=''
  9914. + MSG=''
  9915. + LINE1=''
  9916. + LOGLINE1=''
  9917. + SPACES=''
  9918. + NONL=''
  9919. + DISPLAY_LINE='display --to LOG --type INFO --screen-nl --nl STARTING_TEST local_host'
  9920. + [ 8 -le 0 ]
  9921. + [ 8 -ge 1 ]
  9922. + WRITETO=LOG
  9923. + shift
  9924. + shift
  9925. + [ 6 -ge 1 ]
  9926. + eval echo '$MSG_TYPE_INFO'
  9927. + echo Info
  9928. + TYPE=Info
  9929. + [ -z Info -a INFO != PLAIN ]
  9930. + test INFO = WARNING
  9931. + shift
  9932. + shift
  9933. + [ 4 -ge 1 ]
  9934. + SCREENNL=1
  9935. + shift
  9936. + [ 3 -ge 1 ]
  9937. + NL=1
  9938. + shift
  9939. + [ 2 -ge 1 ]
  9940. + MSG=STARTING_TEST
  9941. + shift
  9942. + break
  9943. + test 0 -eq 1
  9944. + [ 0 -eq 1 ]
  9945. + [ 0 -eq 1 ]
  9946. + test LOG = SCREEN -o LOG = SCREEN+LOG
  9947. + WRITETOTTY=0
  9948. + test LOG = LOG -o LOG = SCREEN+LOG
  9949. + WRITETOLOG=1
  9950. + [ 0 -eq 0 -a 1 -eq 0 ]
  9951. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  9952. + test -n Info
  9953. + NONL=''
  9954. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  9955. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  9956. + [ -n STARTING_TEST ]
  9957. + head -n 1
  9958. + cut -d: -f2-
  9959. + grep -a ^STARTING_TEST: /usr/local/var/lib/rkhunter/db/i18n/en
  9960. + LINE1='Starting test name '\''$1'\'
  9961. + [ 0 -eq 1 ]
  9962. + [ -z 'Starting test name '\''$1'\' ]
  9963. + sed -e 's/`/\\`/g'
  9964. + echo 'Starting test name '\''$1'\'
  9965. + LINE1='Starting test name '\''$1'\'
  9966. + test -n 'Starting test name '\''$1'\'
  9967. + eval 'echo "Starting test name '\''$1'\''" | sed -e '\''s/;/\;/g'\'
  9968. + echo 'Starting test name '\''local_host'\'
  9969. + sed -e 's/;/\;/g'
  9970. + LINE1='Starting test name '\''local_host'\'
  9971. + [ 1 -eq 1 ]
  9972. + date '+[%H:%M:%S]'
  9973. + LOGLINE1='[04:21:53]'
  9974. + test 1 -gt 0 -o 0 -eq 1
  9975. + echo '[04:21:53]'
  9976. + [ -n Info ]
  9977. + LOGLINE1='[04:21:53] Info: Starting test name '\''local_host'\'
  9978. + [ 0 -eq 1 -a 0 -gt 0 ]
  9979. + [ -n '' ]
  9980. + [ 0 -eq 1 -a -n '' ]
  9981. + [ 1 -eq 1 ]
  9982. + test 0 -eq 0 -a 0 -eq 0 -a 0 -eq 0
  9983. + echo ''
  9984.  
  9985. + [ 0 -eq 1 ]
  9986. + [ 1 -eq 1 ]
  9987. + echo -e '[04:21:53] Info: Starting test name '\''local_host'\'
  9988. + [ 0 -eq 1 ]
  9989. + echo '[04:21:53] Info: Starting test name '\''local_host'\'
  9990. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  9991. + [ 0 -eq 1 -a -n '' ]
  9992. + test 0 -eq 1 -a 0 -eq 1
  9993. + return
  9994. + display --to SCREEN+LOG --type PLAIN --color YELLOW CHECK_LOCALHOST
  9995. + WARN_MSG=0
  9996. + NL=0
  9997. + NLAFTER=0
  9998. + LOGINDENT=0
  9999. + SCREENINDENT=0
  10000. + LOGNL=0
  10001. + SCREENNL=0
  10002. + WRITETO=''
  10003. + TYPE=''
  10004. + RESULT=''
  10005. + COLOR=''
  10006. + MSG=''
  10007. + LINE1=''
  10008. + LOGLINE1=''
  10009. + SPACES=''
  10010. + NONL=''
  10011. + DISPLAY_LINE='display --to SCREEN+LOG --type PLAIN --color YELLOW CHECK_LOCALHOST'
  10012. + [ 7 -le 0 ]
  10013. + [ 7 -ge 1 ]
  10014. + WRITETO=SCREEN+LOG
  10015. + shift
  10016. + shift
  10017. + [ 5 -ge 1 ]
  10018. + eval echo '$MSG_TYPE_PLAIN'
  10019. + echo
  10020. + TYPE=''
  10021. + [ -z '' -a PLAIN != PLAIN ]
  10022. + test PLAIN = WARNING
  10023. + shift
  10024. + shift
  10025. + [ 3 -ge 1 ]
  10026. + [ 1 -eq 1 ]
  10027. + test -n YELLOW
  10028. + eval 'echo ${YELLOW}'
  10029. + echo ''
  10030. + COLOR=''
  10031. + [ -z '' ]
  10032. + shift
  10033. + shift
  10034. + [ 1 -ge 1 ]
  10035. + MSG=CHECK_LOCALHOST
  10036. + shift
  10037. + break
  10038. + test 0 -eq 1
  10039. + [ 0 -eq 1 ]
  10040. + [ 0 -eq 1 ]
  10041. + test SCREEN+LOG = SCREEN -o SCREEN+LOG = SCREEN+LOG
  10042. + WRITETOTTY=1
  10043. + test SCREEN+LOG = LOG -o SCREEN+LOG = SCREEN+LOG
  10044. + WRITETOLOG=1
  10045. + [ 1 -eq 0 -a 1 -eq 0 ]
  10046. + [ 1 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  10047. + test -n ''
  10048. + [ 0 -eq 1 -a 1 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  10049. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  10050. + [ -n CHECK_LOCALHOST ]
  10051. + grep -a ^CHECK_LOCALHOST: /usr/local/var/lib/rkhunter/db/i18n/en
  10052. + head -n 1
  10053. + cut -d: -f2-
  10054. + LINE1='Checking the local host...'
  10055. + [ 0 -eq 1 ]
  10056. + [ -z 'Checking the local host...' ]
  10057. + echo 'Checking the local host...'
  10058. + sed -e 's/`/\\`/g'
  10059. + LINE1='Checking the local host...'
  10060. + test -n 'Checking the local host...'
  10061. + eval 'echo "Checking the local host..." | sed -e '\''s/;/\;/g'\'
  10062. + echo 'Checking the local host...'
  10063. + sed -e 's/;/\;/g'
  10064. + LINE1='Checking the local host...'
  10065. + [ 1 -eq 1 ]
  10066. + date '+[%H:%M:%S]'
  10067. + LOGLINE1='[04:21:53]'
  10068. + test 0 -gt 0 -o 0 -eq 1
  10069. + [ -n '' ]
  10070. + test 0 -gt 0
  10071. + LOGLINE1='[04:21:53] Checking the local host...'
  10072. + [ 1 -eq 1 -a 0 -gt 0 ]
  10073. + [ -n '' ]
  10074. + [ 1 -eq 1 -a -n '' ]
  10075. + LINE1='Checking the local host...'
  10076. + [ 0 -eq 1 ]
  10077. + [ 1 -eq 1 ]
  10078. + NLLOOP=0
  10079. + test 0 -gt 0
  10080. + [ '' = c ]
  10081. + echo -e 'Checking the local host...'
  10082. Checking the local host...
  10083. + [ 1 -eq 1 ]
  10084. + echo -e '[04:21:53] Checking the local host...'
  10085. + [ 0 -eq 1 ]
  10086. + echo '[04:21:53] Checking the local host...'
  10087. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  10088. + [ 0 -eq 1 -a -n '' ]
  10089. + test 1 -eq 1 -a 0 -eq 1
  10090. + return
  10091. + do_system_startup_file_checks
  10092. + check_test startup_files
  10093. + grep ' startup_files '
  10094. + echo ' filesystem local_host '
  10095. + [ 'filesystem local_host' = all -o -n '' ]
  10096. + return 1
  10097. +
  10098. + display --to LOG --type INFO --nl USER_DISABLED_TEST startup_files
  10099. + WARN_MSG=0
  10100. + NL=0
  10101. + NLAFTER=0
  10102. + LOGINDENT=0
  10103. + SCREENINDENT=0
  10104. + LOGNL=0
  10105. + SCREENNL=0
  10106. + WRITETO=''
  10107. + TYPE=''
  10108. + RESULT=''
  10109. + COLOR=''
  10110. + MSG=''
  10111. + LINE1=''
  10112. + LOGLINE1=''
  10113. + SPACES=''
  10114. + NONL=''
  10115. + DISPLAY_LINE='display --to LOG --type INFO --nl USER_DISABLED_TEST startup_files'
  10116. + [ 7 -le 0 ]
  10117. + [ 7 -ge 1 ]
  10118. + WRITETO=LOG
  10119. + shift
  10120. + shift
  10121. + [ 5 -ge 1 ]
  10122. + eval echo '$MSG_TYPE_INFO'
  10123. + echo Info
  10124. + TYPE=Info
  10125. + [ -z Info -a INFO != PLAIN ]
  10126. + test INFO = WARNING
  10127. + shift
  10128. + shift
  10129. + [ 3 -ge 1 ]
  10130. + NL=1
  10131. + shift
  10132. + [ 2 -ge 1 ]
  10133. + MSG=USER_DISABLED_TEST
  10134. + shift
  10135. + break
  10136. + test 0 -eq 1
  10137. + [ 0 -eq 1 ]
  10138. + [ 0 -eq 1 ]
  10139. + test LOG = SCREEN -o LOG = SCREEN+LOG
  10140. + WRITETOTTY=0
  10141. + test LOG = LOG -o LOG = SCREEN+LOG
  10142. + WRITETOLOG=1
  10143. + [ 0 -eq 0 -a 1 -eq 0 ]
  10144. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  10145. + test -n Info
  10146. + NONL=''
  10147. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  10148. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  10149. + [ -n USER_DISABLED_TEST ]
  10150. + head -n 1
  10151. + cut -d: -f2-
  10152. + grep -a ^USER_DISABLED_TEST: /usr/local/var/lib/rkhunter/db/i18n/en
  10153. + LINE1='Test '\''$1'\'' disabled at users request.'
  10154. + [ 0 -eq 1 ]
  10155. + [ -z 'Test '\''$1'\'' disabled at users request.' ]
  10156. + sed -e 's/`/\\`/g'
  10157. + echo 'Test '\''$1'\'' disabled at users request.'
  10158. + LINE1='Test '\''$1'\'' disabled at users request.'
  10159. + test -n 'Test '\''$1'\'' disabled at users request.'
  10160. + eval 'echo "Test '\''$1'\'' disabled at users request." | sed -e '\''s/;/\;/g'\'
  10161. + sed -e 's/;/\;/g'
  10162. + echo 'Test '\''startup_files'\'' disabled at users request.'
  10163. + LINE1='Test '\''startup_files'\'' disabled at users request.'
  10164. + [ 1 -eq 1 ]
  10165. + date '+[%H:%M:%S]'
  10166. + LOGLINE1='[04:21:54]'
  10167. + test 1 -gt 0 -o 0 -eq 1
  10168. + echo '[04:21:54]'
  10169. + [ -n Info ]
  10170. + LOGLINE1='[04:21:54] Info: Test '\''startup_files'\'' disabled at users request.'
  10171. + [ 0 -eq 1 -a 0 -gt 0 ]
  10172. + [ -n '' ]
  10173. + [ 0 -eq 1 -a -n '' ]
  10174. + [ 0 -eq 1 ]
  10175. + [ 0 -eq 1 ]
  10176. + [ 1 -eq 1 ]
  10177. + echo -e '[04:21:54] Info: Test '\''startup_files'\'' disabled at users request.'
  10178. + [ 0 -eq 1 ]
  10179. + echo '[04:21:54] Info: Test '\''startup_files'\'' disabled at users request.'
  10180. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  10181. + [ 0 -eq 1 -a -n '' ]
  10182. + test 0 -eq 1 -a 0 -eq 1
  10183. + return
  10184. + return
  10185. + do_group_accounts_check
  10186. + check_test group_accounts
  10187. + echo ' filesystem local_host '
  10188. + grep ' group_accounts '
  10189. + [ 'filesystem local_host' = all -o -n '' ]
  10190. + return 1
  10191. +
  10192. + display --to LOG --type INFO --nl USER_DISABLED_TEST group_accounts
  10193. + WARN_MSG=0
  10194. + NL=0
  10195. + NLAFTER=0
  10196. + LOGINDENT=0
  10197. + SCREENINDENT=0
  10198. + LOGNL=0
  10199. + SCREENNL=0
  10200. + WRITETO=''
  10201. + TYPE=''
  10202. + RESULT=''
  10203. + COLOR=''
  10204. + MSG=''
  10205. + LINE1=''
  10206. + LOGLINE1=''
  10207. + SPACES=''
  10208. + NONL=''
  10209. + DISPLAY_LINE='display --to LOG --type INFO --nl USER_DISABLED_TEST group_accounts'
  10210. + [ 7 -le 0 ]
  10211. + [ 7 -ge 1 ]
  10212. + WRITETO=LOG
  10213. + shift
  10214. + shift
  10215. + [ 5 -ge 1 ]
  10216. + eval echo '$MSG_TYPE_INFO'
  10217. + echo Info
  10218. + TYPE=Info
  10219. + [ -z Info -a INFO != PLAIN ]
  10220. + test INFO = WARNING
  10221. + shift
  10222. + shift
  10223. + [ 3 -ge 1 ]
  10224. + NL=1
  10225. + shift
  10226. + [ 2 -ge 1 ]
  10227. + MSG=USER_DISABLED_TEST
  10228. + shift
  10229. + break
  10230. + test 0 -eq 1
  10231. + [ 0 -eq 1 ]
  10232. + [ 0 -eq 1 ]
  10233. + test LOG = SCREEN -o LOG = SCREEN+LOG
  10234. + WRITETOTTY=0
  10235. + test LOG = LOG -o LOG = SCREEN+LOG
  10236. + WRITETOLOG=1
  10237. + [ 0 -eq 0 -a 1 -eq 0 ]
  10238. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  10239. + test -n Info
  10240. + NONL=''
  10241. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  10242. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  10243. + [ -n USER_DISABLED_TEST ]
  10244. + grep -a ^USER_DISABLED_TEST: /usr/local/var/lib/rkhunter/db/i18n/en
  10245. + cut -d: -f2-
  10246. + head -n 1
  10247. + LINE1='Test '\''$1'\'' disabled at users request.'
  10248. + [ 0 -eq 1 ]
  10249. + [ -z 'Test '\''$1'\'' disabled at users request.' ]
  10250. + echo 'Test '\''$1'\'' disabled at users request.'
  10251. + sed -e 's/`/\\`/g'
  10252. + LINE1='Test '\''$1'\'' disabled at users request.'
  10253. + test -n 'Test '\''$1'\'' disabled at users request.'
  10254. + eval 'echo "Test '\''$1'\'' disabled at users request." | sed -e '\''s/;/\;/g'\'
  10255. + echo 'Test '\''group_accounts'\'' disabled at users request.'
  10256. + sed -e 's/;/\;/g'
  10257. + LINE1='Test '\''group_accounts'\'' disabled at users request.'
  10258. + [ 1 -eq 1 ]
  10259. + date '+[%H:%M:%S]'
  10260. + LOGLINE1='[04:21:54]'
  10261. + test 1 -gt 0 -o 0 -eq 1
  10262. + echo '[04:21:54]'
  10263. + [ -n Info ]
  10264. + LOGLINE1='[04:21:54] Info: Test '\''group_accounts'\'' disabled at users request.'
  10265. + [ 0 -eq 1 -a 0 -gt 0 ]
  10266. + [ -n '' ]
  10267. + [ 0 -eq 1 -a -n '' ]
  10268. + [ 0 -eq 1 ]
  10269. + [ 0 -eq 1 ]
  10270. + [ 1 -eq 1 ]
  10271. + echo -e '[04:21:54] Info: Test '\''group_accounts'\'' disabled at users request.'
  10272. + [ 0 -eq 1 ]
  10273. + echo '[04:21:54] Info: Test '\''group_accounts'\'' disabled at users request.'
  10274. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  10275. + [ 0 -eq 1 -a -n '' ]
  10276. + test 0 -eq 1 -a 0 -eq 1
  10277. + return
  10278. + return
  10279. + do_system_config_files_check
  10280. + check_test system_configs
  10281. + echo ' filesystem local_host '
  10282. + grep ' system_configs '
  10283. + [ 'filesystem local_host' = all -o -n '' ]
  10284. + return 1
  10285. +
  10286. + display --to LOG --type INFO --nl USER_DISABLED_TEST system_configs
  10287. + WARN_MSG=0
  10288. + NL=0
  10289. + NLAFTER=0
  10290. + LOGINDENT=0
  10291. + SCREENINDENT=0
  10292. + LOGNL=0
  10293. + SCREENNL=0
  10294. + WRITETO=''
  10295. + TYPE=''
  10296. + RESULT=''
  10297. + COLOR=''
  10298. + MSG=''
  10299. + LINE1=''
  10300. + LOGLINE1=''
  10301. + SPACES=''
  10302. + NONL=''
  10303. + DISPLAY_LINE='display --to LOG --type INFO --nl USER_DISABLED_TEST system_configs'
  10304. + [ 7 -le 0 ]
  10305. + [ 7 -ge 1 ]
  10306. + WRITETO=LOG
  10307. + shift
  10308. + shift
  10309. + [ 5 -ge 1 ]
  10310. + eval echo '$MSG_TYPE_INFO'
  10311. + echo Info
  10312. + TYPE=Info
  10313. + [ -z Info -a INFO != PLAIN ]
  10314. + test INFO = WARNING
  10315. + shift
  10316. + shift
  10317. + [ 3 -ge 1 ]
  10318. + NL=1
  10319. + shift
  10320. + [ 2 -ge 1 ]
  10321. + MSG=USER_DISABLED_TEST
  10322. + shift
  10323. + break
  10324. + test 0 -eq 1
  10325. + [ 0 -eq 1 ]
  10326. + [ 0 -eq 1 ]
  10327. + test LOG = SCREEN -o LOG = SCREEN+LOG
  10328. + WRITETOTTY=0
  10329. + test LOG = LOG -o LOG = SCREEN+LOG
  10330. + WRITETOLOG=1
  10331. + [ 0 -eq 0 -a 1 -eq 0 ]
  10332. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  10333. + test -n Info
  10334. + NONL=''
  10335. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  10336. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  10337. + [ -n USER_DISABLED_TEST ]
  10338. + grep -a ^USER_DISABLED_TEST: /usr/local/var/lib/rkhunter/db/i18n/en
  10339. + head -n 1
  10340. + cut -d: -f2-
  10341. + LINE1='Test '\''$1'\'' disabled at users request.'
  10342. + [ 0 -eq 1 ]
  10343. + [ -z 'Test '\''$1'\'' disabled at users request.' ]
  10344. + echo 'Test '\''$1'\'' disabled at users request.'
  10345. + sed -e 's/`/\\`/g'
  10346. + LINE1='Test '\''$1'\'' disabled at users request.'
  10347. + test -n 'Test '\''$1'\'' disabled at users request.'
  10348. + eval 'echo "Test '\''$1'\'' disabled at users request." | sed -e '\''s/;/\;/g'\'
  10349. + echo 'Test '\''system_configs'\'' disabled at users request.'
  10350. + sed -e 's/;/\;/g'
  10351. + LINE1='Test '\''system_configs'\'' disabled at users request.'
  10352. + [ 1 -eq 1 ]
  10353. + date '+[%H:%M:%S]'
  10354. + LOGLINE1='[04:21:54]'
  10355. + test 1 -gt 0 -o 0 -eq 1
  10356. + echo '[04:21:54]'
  10357. + [ -n Info ]
  10358. + LOGLINE1='[04:21:54] Info: Test '\''system_configs'\'' disabled at users request.'
  10359. + [ 0 -eq 1 -a 0 -gt 0 ]
  10360. + [ -n '' ]
  10361. + [ 0 -eq 1 -a -n '' ]
  10362. + [ 0 -eq 1 ]
  10363. + [ 0 -eq 1 ]
  10364. + [ 1 -eq 1 ]
  10365. + echo -e '[04:21:54] Info: Test '\''system_configs'\'' disabled at users request.'
  10366. + [ 0 -eq 1 ]
  10367. + echo '[04:21:54] Info: Test '\''system_configs'\'' disabled at users request.'
  10368. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  10369. + [ 0 -eq 1 -a -n '' ]
  10370. + test 0 -eq 1 -a 0 -eq 1
  10371. + return
  10372. + return
  10373. + do_filesystem_check
  10374. + check_test filesystem
  10375. + echo ' filesystem local_host '
  10376. + grep ' filesystem '
  10377. + [ 'filesystem local_host' = all -o -n ' filesystem local_host ' ]
  10378. + echo ' deleted_files hidden_ports hidden_procs packet_cap_apps suspscan '
  10379. + grep ' filesystem '
  10380. + [ 'deleted_files hidden_ports hidden_procs packet_cap_apps suspscan' = none -o -z '' ]
  10381. + return 0
  10382. +
  10383. + display --to LOG --type INFO --screen-nl --nl STARTING_TEST filesystem
  10384. + WARN_MSG=0
  10385. + NL=0
  10386. + NLAFTER=0
  10387. + LOGINDENT=0
  10388. + SCREENINDENT=0
  10389. + LOGNL=0
  10390. + SCREENNL=0
  10391. + WRITETO=''
  10392. + TYPE=''
  10393. + RESULT=''
  10394. + COLOR=''
  10395. + MSG=''
  10396. + LINE1=''
  10397. + LOGLINE1=''
  10398. + SPACES=''
  10399. + NONL=''
  10400. + DISPLAY_LINE='display --to LOG --type INFO --screen-nl --nl STARTING_TEST filesystem'
  10401. + [ 8 -le 0 ]
  10402. + [ 8 -ge 1 ]
  10403. + WRITETO=LOG
  10404. + shift
  10405. + shift
  10406. + [ 6 -ge 1 ]
  10407. + eval echo '$MSG_TYPE_INFO'
  10408. + echo Info
  10409. + TYPE=Info
  10410. + [ -z Info -a INFO != PLAIN ]
  10411. + test INFO = WARNING
  10412. + shift
  10413. + shift
  10414. + [ 4 -ge 1 ]
  10415. + SCREENNL=1
  10416. + shift
  10417. + [ 3 -ge 1 ]
  10418. + NL=1
  10419. + shift
  10420. + [ 2 -ge 1 ]
  10421. + MSG=STARTING_TEST
  10422. + shift
  10423. + break
  10424. + test 0 -eq 1
  10425. + [ 0 -eq 1 ]
  10426. + [ 0 -eq 1 ]
  10427. + test LOG = SCREEN -o LOG = SCREEN+LOG
  10428. + WRITETOTTY=0
  10429. + test LOG = LOG -o LOG = SCREEN+LOG
  10430. + WRITETOLOG=1
  10431. + [ 0 -eq 0 -a 1 -eq 0 ]
  10432. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  10433. + test -n Info
  10434. + NONL=''
  10435. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  10436. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  10437. + [ -n STARTING_TEST ]
  10438. + grep -a ^STARTING_TEST: /usr/local/var/lib/rkhunter/db/i18n/en
  10439. + cut -d: -f2-
  10440. + head -n 1
  10441. + LINE1='Starting test name '\''$1'\'
  10442. + [ 0 -eq 1 ]
  10443. + [ -z 'Starting test name '\''$1'\' ]
  10444. + echo 'Starting test name '\''$1'\'
  10445. + sed -e 's/`/\\`/g'
  10446. + LINE1='Starting test name '\''$1'\'
  10447. + test -n 'Starting test name '\''$1'\'
  10448. + eval 'echo "Starting test name '\''$1'\''" | sed -e '\''s/;/\;/g'\'
  10449. + echo 'Starting test name '\''filesystem'\'
  10450. + sed -e 's/;/\;/g'
  10451. + LINE1='Starting test name '\''filesystem'\'
  10452. + [ 1 -eq 1 ]
  10453. + date '+[%H:%M:%S]'
  10454. + LOGLINE1='[04:21:54]'
  10455. + test 1 -gt 0 -o 0 -eq 1
  10456. + echo '[04:21:54]'
  10457. + [ -n Info ]
  10458. + LOGLINE1='[04:21:54] Info: Starting test name '\''filesystem'\'
  10459. + [ 0 -eq 1 -a 0 -gt 0 ]
  10460. + [ -n '' ]
  10461. + [ 0 -eq 1 -a -n '' ]
  10462. + [ 1 -eq 1 ]
  10463. + test 0 -eq 0 -a 0 -eq 0 -a 0 -eq 0
  10464. + echo ''
  10465.  
  10466. + [ 0 -eq 1 ]
  10467. + [ 1 -eq 1 ]
  10468. + echo -e '[04:21:54] Info: Starting test name '\''filesystem'\'
  10469. + [ 0 -eq 1 ]
  10470. + echo '[04:21:54] Info: Starting test name '\''filesystem'\'
  10471. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  10472. + [ 0 -eq 1 -a -n '' ]
  10473. + test 0 -eq 1 -a 0 -eq 1
  10474. + return
  10475. + display --to SCREEN+LOG --type PLAIN --screen-indent 2 FILESYSTEM_START
  10476. + WARN_MSG=0
  10477. + NL=0
  10478. + NLAFTER=0
  10479. + LOGINDENT=0
  10480. + SCREENINDENT=0
  10481. + LOGNL=0
  10482. + SCREENNL=0
  10483. + WRITETO=''
  10484. + TYPE=''
  10485. + RESULT=''
  10486. + COLOR=''
  10487. + MSG=''
  10488. + LINE1=''
  10489. + LOGLINE1=''
  10490. + SPACES=''
  10491. + NONL=''
  10492. + DISPLAY_LINE='display --to SCREEN+LOG --type PLAIN --screen-indent 2 FILESYSTEM_START'
  10493. + [ 7 -le 0 ]
  10494. + [ 7 -ge 1 ]
  10495. + WRITETO=SCREEN+LOG
  10496. + shift
  10497. + shift
  10498. + [ 5 -ge 1 ]
  10499. + eval echo '$MSG_TYPE_PLAIN'
  10500. + echo
  10501. + TYPE=''
  10502. + [ -z '' -a PLAIN != PLAIN ]
  10503. + test PLAIN = WARNING
  10504. + shift
  10505. + shift
  10506. + [ 3 -ge 1 ]
  10507. + SCREENINDENT=2
  10508. + [ -z 2 ]
  10509. + grep '^[0-9]*$'
  10510. + echo 2
  10511. + [ -z 2 ]
  10512. + shift
  10513. + shift
  10514. + [ 1 -ge 1 ]
  10515. + MSG=FILESYSTEM_START
  10516. + shift
  10517. + break
  10518. + test 0 -eq 1
  10519. + [ 0 -eq 1 ]
  10520. + [ 0 -eq 1 ]
  10521. + test SCREEN+LOG = SCREEN -o SCREEN+LOG = SCREEN+LOG
  10522. + WRITETOTTY=1
  10523. + test SCREEN+LOG = LOG -o SCREEN+LOG = SCREEN+LOG
  10524. + WRITETOLOG=1
  10525. + [ 1 -eq 0 -a 1 -eq 0 ]
  10526. + [ 1 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  10527. + test -n ''
  10528. + [ 0 -eq 1 -a 1 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  10529. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  10530. + [ -n FILESYSTEM_START ]
  10531. + grep -a ^FILESYSTEM_START: /usr/local/var/lib/rkhunter/db/i18n/en
  10532. + cut -d: -f2-
  10533. + head -n 1
  10534. + LINE1='Performing filesystem checks'
  10535. + [ 0 -eq 1 ]
  10536. + [ -z 'Performing filesystem checks' ]
  10537. + echo 'Performing filesystem checks'
  10538. + sed -e 's/`/\\`/g'
  10539. + LINE1='Performing filesystem checks'
  10540. + test -n 'Performing filesystem checks'
  10541. + eval 'echo "Performing filesystem checks" | sed -e '\''s/;/\;/g'\'
  10542. + echo 'Performing filesystem checks'
  10543. + sed -e 's/;/\;/g'
  10544. + LINE1='Performing filesystem checks'
  10545. + [ 1 -eq 1 ]
  10546. + date '+[%H:%M:%S]'
  10547. + LOGLINE1='[04:21:55]'
  10548. + test 0 -gt 0 -o 0 -eq 1
  10549. + [ -n '' ]
  10550. + test 0 -gt 0
  10551. + LOGLINE1='[04:21:55] Performing filesystem checks'
  10552. + [ 1 -eq 1 -a 2 -gt 0 ]
  10553. + echo ' '
  10554. + cut -c1-2
  10555. + SPACES=' '
  10556. + LINE1=' Performing filesystem checks'
  10557. + [ -n '' ]
  10558. + [ 1 -eq 1 -a -n '' ]
  10559. + [ 0 -eq 1 ]
  10560. + [ 1 -eq 1 ]
  10561. + NLLOOP=0
  10562. + test 0 -gt 0
  10563. + [ '' = c ]
  10564. + echo -e ' Performing filesystem checks'
  10565. Performing filesystem checks
  10566. + [ 1 -eq 1 ]
  10567. + echo -e '[04:21:55] Performing filesystem checks'
  10568. + [ 0 -eq 1 ]
  10569. + echo '[04:21:55] Performing filesystem checks'
  10570. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  10571. + [ 0 -eq 1 -a -n '' ]
  10572. + test 1 -eq 1 -a 0 -eq 1
  10573. + return
  10574. + [ ! -d /dev ]
  10575. + [ -z /usr/bin/file ]
  10576. + [ THOROUGH = THOROUGH -a -z /usr/bin/find ]
  10577. + display --to LOG --type INFO CONFIG_SCAN_MODE_DEV THOROUGH
  10578. + WARN_MSG=0
  10579. + NL=0
  10580. + NLAFTER=0
  10581. + LOGINDENT=0
  10582. + SCREENINDENT=0
  10583. + LOGNL=0
  10584. + SCREENNL=0
  10585. + WRITETO=''
  10586. + TYPE=''
  10587. + RESULT=''
  10588. + COLOR=''
  10589. + MSG=''
  10590. + LINE1=''
  10591. + LOGLINE1=''
  10592. + SPACES=''
  10593. + NONL=''
  10594. + DISPLAY_LINE='display --to LOG --type INFO CONFIG_SCAN_MODE_DEV THOROUGH'
  10595. + [ 6 -le 0 ]
  10596. + [ 6 -ge 1 ]
  10597. + WRITETO=LOG
  10598. + shift
  10599. + shift
  10600. + [ 4 -ge 1 ]
  10601. + eval echo '$MSG_TYPE_INFO'
  10602. + echo Info
  10603. + TYPE=Info
  10604. + [ -z Info -a INFO != PLAIN ]
  10605. + test INFO = WARNING
  10606. + shift
  10607. + shift
  10608. + [ 2 -ge 1 ]
  10609. + MSG=CONFIG_SCAN_MODE_DEV
  10610. + shift
  10611. + break
  10612. + test 0 -eq 1
  10613. + [ 0 -eq 1 ]
  10614. + [ 0 -eq 1 ]
  10615. + test LOG = SCREEN -o LOG = SCREEN+LOG
  10616. + WRITETOTTY=0
  10617. + test LOG = LOG -o LOG = SCREEN+LOG
  10618. + WRITETOLOG=1
  10619. + [ 0 -eq 0 -a 1 -eq 0 ]
  10620. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  10621. + test -n Info
  10622. + NONL=''
  10623. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  10624. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  10625. + [ -n CONFIG_SCAN_MODE_DEV ]
  10626. + head -n 1
  10627. + cut -d: -f2-
  10628. + grep -a ^CONFIG_SCAN_MODE_DEV: /usr/local/var/lib/rkhunter/db/i18n/en
  10629. + LINE1='SCAN_MODE_DEV set to '\''$1'\'
  10630. + [ 0 -eq 1 ]
  10631. + [ -z 'SCAN_MODE_DEV set to '\''$1'\' ]
  10632. + sed -e 's/`/\\`/g'
  10633. + echo 'SCAN_MODE_DEV set to '\''$1'\'
  10634. + LINE1='SCAN_MODE_DEV set to '\''$1'\'
  10635. + test -n 'SCAN_MODE_DEV set to '\''$1'\'
  10636. + eval 'echo "SCAN_MODE_DEV set to '\''$1'\''" | sed -e '\''s/;/\;/g'\'
  10637. + sed -e 's/;/\;/g'
  10638. + echo 'SCAN_MODE_DEV set to '\''THOROUGH'\'
  10639. + LINE1='SCAN_MODE_DEV set to '\''THOROUGH'\'
  10640. + [ 1 -eq 1 ]
  10641. + date '+[%H:%M:%S]'
  10642. + LOGLINE1='[04:21:55]'
  10643. + test 0 -gt 0 -o 0 -eq 1
  10644. + [ -n Info ]
  10645. + LOGLINE1='[04:21:55] Info: SCAN_MODE_DEV set to '\''THOROUGH'\'
  10646. + [ 0 -eq 1 -a 0 -gt 0 ]
  10647. + [ -n '' ]
  10648. + [ 0 -eq 1 -a -n '' ]
  10649. + [ 0 -eq 1 ]
  10650. + [ 0 -eq 1 ]
  10651. + [ 1 -eq 1 ]
  10652. + echo -e '[04:21:55] Info: SCAN_MODE_DEV set to '\''THOROUGH'\'
  10653. + [ 0 -eq 1 ]
  10654. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  10655. + echo '[04:21:55] Info: SCAN_MODE_DEV set to '\''THOROUGH'\'
  10656. + [ 0 -eq 1 -a -n '' ]
  10657. + test 0 -eq 1 -a 0 -eq 1
  10658. + return
  10659. + [ -n '' ]
  10660. + FDESCFS=0
  10661. + FOUNDFILES=''
  10662. + [ 1 -eq 1 ]
  10663. + find_cmd mount
  10664. + CMD=mount
  10665. + test -z mount
  10666. + grep /
  10667. + echo mount
  10668. + [ -n '' ]
  10669. + [ -f /sbin/mount -a -x /sbin/mount ]
  10670. + echo /sbin/mount
  10671. + return
  10672. + RKHTMPVAR=/sbin/mount
  10673. + [ -n /sbin/mount ]
  10674. + /sbin/mount
  10675. + egrep '^fdesc(fs)? .*type fdesc'
  10676. + test -n ''
  10677. + [ THOROUGH = LAZY ]
  10678. + IFS='
  10679. '
  10680. + /usr/bin/find /dev ! -type d -a ! -type l
  10681. + [ 0 -eq 1 ]
  10682. + grep '/\.[^/]*$'
  10683. + echo /dev/geom.ctl
  10684. + test -z ''
  10685. + do_dev_whitelist_check
  10686. + /usr/bin/file /dev/geom.ctl
  10687. + awk -F: '{ print $NF }'
  10688. + cut -c2-
  10689. + FTYPE='character special (0/3)'
  10690. + echo 'character special (0/3)'
  10691. + grep 'universal binary'
  10692. + [ 0 -eq 1 -a -n '' ]
  10693. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  10694. + echo 'character special (0/3)'
  10695. + [ -z '' ]
  10696. + return
  10697. + [ 0 -eq 1 ]
  10698. + echo /dev/console
  10699. + grep '/\.[^/]*$'
  10700. + test -z ''
  10701. + do_dev_whitelist_check
  10702. + /usr/bin/file /dev/console
  10703. + awk -F: '{ print $NF }'
  10704. + cut -c2-
  10705. + FTYPE='character special (0/4)'
  10706. + echo 'character special (0/4)'
  10707. + grep 'universal binary'
  10708. + [ 0 -eq 1 -a -n '' ]
  10709. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  10710. + echo 'character special (0/4)'
  10711. + [ -z '' ]
  10712. + return
  10713. + [ 0 -eq 1 ]
  10714. + echo /dev/devctl
  10715. + grep '/\.[^/]*$'
  10716. + test -z ''
  10717. + do_dev_whitelist_check
  10718. + awk -F: '{ print $NF }'
  10719. + cut -c2-
  10720. + /usr/bin/file /dev/devctl
  10721. + FTYPE='character special (0/5)'
  10722. + echo 'character special (0/5)'
  10723. + grep 'universal binary'
  10724. + [ 0 -eq 1 -a -n '' ]
  10725. + echo 'character special (0/5)'
  10726. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  10727. + [ -z '' ]
  10728. + return
  10729. + [ 0 -eq 1 ]
  10730. + echo /dev/ctty
  10731. + grep '/\.[^/]*$'
  10732. + test -z ''
  10733. + do_dev_whitelist_check
  10734. + awk -F: '{ print $NF }'
  10735. + cut -c2-
  10736. + /usr/bin/file /dev/ctty
  10737. + FTYPE='character special (0/6)'
  10738. + echo 'character special (0/6)'
  10739. + grep 'universal binary'
  10740. + [ 0 -eq 1 -a -n '' ]
  10741. + echo 'character special (0/6)'
  10742. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  10743. + [ -z '' ]
  10744. + return
  10745. + [ 0 -eq 1 ]
  10746. + echo /dev/klog
  10747. + grep '/\.[^/]*$'
  10748. + test -z ''
  10749. + do_dev_whitelist_check
  10750. + /usr/bin/file /dev/klog
  10751. + cut -c2-
  10752. + awk -F: '{ print $NF }'
  10753. + FTYPE='character special (0/7)'
  10754. + grep 'universal binary'
  10755. + echo 'character special (0/7)'
  10756. + [ 0 -eq 1 -a -n '' ]
  10757. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  10758. + echo 'character special (0/7)'
  10759. + [ -z '' ]
  10760. + return
  10761. + [ 0 -eq 1 ]
  10762. + grep '/\.[^/]*$'
  10763. + echo /dev/fido
  10764. + test -z ''
  10765. + do_dev_whitelist_check
  10766. + /usr/bin/file /dev/fido
  10767. + awk -F: '{ print $NF }'
  10768. + cut -c2-
  10769. + FTYPE='character special (0/8)'
  10770. + grep 'universal binary'
  10771. + echo 'character special (0/8)'
  10772. + [ 0 -eq 1 -a -n '' ]
  10773. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  10774. + echo 'character special (0/8)'
  10775. + [ -z '' ]
  10776. + return
  10777. + [ 0 -eq 1 ]
  10778. + grep '/\.[^/]*$'
  10779. + echo /dev/null
  10780. + test -z ''
  10781. + do_dev_whitelist_check
  10782. + /usr/bin/file /dev/null
  10783. + awk -F: '{ print $NF }'
  10784. + cut -c2-
  10785. + FTYPE='character special (0/9)'
  10786. + echo 'character special (0/9)'
  10787. + grep 'universal binary'
  10788. + [ 0 -eq 1 -a -n '' ]
  10789. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  10790. + echo 'character special (0/9)'
  10791. + [ -z '' ]
  10792. + return
  10793. + [ 0 -eq 1 ]
  10794. + echo /dev/zero
  10795. + grep '/\.[^/]*$'
  10796. + test -z ''
  10797. + do_dev_whitelist_check
  10798. + awk -F: '{ print $NF }'
  10799. + cut -c2-
  10800. + /usr/bin/file /dev/zero
  10801. + FTYPE='character special (0/10)'
  10802. + echo 'character special (0/10)'
  10803. + grep 'universal binary'
  10804. + [ 0 -eq 1 -a -n '' ]
  10805. + echo 'character special (0/10)'
  10806. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  10807. + [ -z '' ]
  10808. + return
  10809. + [ 0 -eq 1 ]
  10810. + echo /dev/bpf
  10811. + grep '/\.[^/]*$'
  10812. + test -z ''
  10813. + do_dev_whitelist_check
  10814. + awk -F: '{ print $NF }'
  10815. + cut -c2-
  10816. + /usr/bin/file /dev/bpf
  10817. + FTYPE='character special (0/11)'
  10818. + echo 'character special (0/11)'
  10819. + grep 'universal binary'
  10820. + [ 0 -eq 1 -a -n '' ]
  10821. + echo 'character special (0/11)'
  10822. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  10823. + [ -z '' ]
  10824. + return
  10825. + [ 0 -eq 1 ]
  10826. + echo /dev/openfirm
  10827. + grep '/\.[^/]*$'
  10828. + test -z ''
  10829. + do_dev_whitelist_check
  10830. + /usr/bin/file /dev/openfirm
  10831. + cut -c2-
  10832. + awk -F: '{ print $NF }'
  10833. + FTYPE='character special (0/13)'
  10834. + echo 'character special (0/13)'
  10835. + grep 'universal binary'
  10836. + [ 0 -eq 1 -a -n '' ]
  10837. + echo 'character special (0/13)'
  10838. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  10839. + [ -z '' ]
  10840. + return
  10841. + [ 0 -eq 1 ]
  10842. + grep '/\.[^/]*$'
  10843. + echo /dev/ptmx
  10844. + test -z ''
  10845. + do_dev_whitelist_check
  10846. + /usr/bin/file /dev/ptmx
  10847. + cut -c2-
  10848. + awk -F: '{ print $NF }'
  10849. + FTYPE='character special (0/14)'
  10850. + grep 'universal binary'
  10851. + echo 'character special (0/14)'
  10852. + [ 0 -eq 1 -a -n '' ]
  10853. + echo 'character special (0/14)'
  10854. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  10855. + [ -z '' ]
  10856. + return
  10857. + [ 0 -eq 1 ]
  10858. + grep '/\.[^/]*$'
  10859. + echo /dev/nfslock
  10860. + test -z ''
  10861. + do_dev_whitelist_check
  10862. + /usr/bin/file /dev/nfslock
  10863. + awk -F: '{ print $NF }'
  10864. + cut -c2-
  10865. + FTYPE='character special (0/15)'
  10866. + grep 'universal binary'
  10867. + echo 'character special (0/15)'
  10868. + [ 0 -eq 1 -a -n '' ]
  10869. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  10870. + echo 'character special (0/15)'
  10871. + [ -z '' ]
  10872. + return
  10873. + [ 0 -eq 1 ]
  10874. + echo /dev/random
  10875. + grep '/\.[^/]*$'
  10876. + test -z ''
  10877. + do_dev_whitelist_check
  10878. + /usr/bin/file /dev/random
  10879. + awk -F: '{ print $NF }'
  10880. + cut -c2-
  10881. + FTYPE='character special (0/16)'
  10882. + echo 'character special (0/16)'
  10883. + grep 'universal binary'
  10884. + [ 0 -eq 1 -a -n '' ]
  10885. + echo 'character special (0/16)'
  10886. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  10887. + [ -z '' ]
  10888. + return
  10889. + [ 0 -eq 1 ]
  10890. + grep '/\.[^/]*$'
  10891. + echo /dev/mem
  10892. + test -z ''
  10893. + do_dev_whitelist_check
  10894. + /usr/bin/file /dev/mem
  10895. + awk -F: '{ print $NF }'
  10896. + cut -c2-
  10897. + FTYPE='character special (0/18)'
  10898. + echo 'character special (0/18)'
  10899. + grep 'universal binary'
  10900. + [ 0 -eq 1 -a -n '' ]
  10901. + echo 'character special (0/18)'
  10902. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  10903. + [ -z '' ]
  10904. + return
  10905. + [ 0 -eq 1 ]
  10906. + grep '/\.[^/]*$'
  10907. + echo /dev/kmem
  10908. + test -z ''
  10909. + do_dev_whitelist_check
  10910. + /usr/bin/file /dev/kmem
  10911. + awk -F: '{ print $NF }'
  10912. + cut -c2-
  10913. + FTYPE='character special (0/19)'
  10914. + grep 'universal binary'
  10915. + echo 'character special (0/19)'
  10916. + [ 0 -eq 1 -a -n '' ]
  10917. + echo 'character special (0/19)'
  10918. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  10919. + [ -z '' ]
  10920. + return
  10921. + [ 0 -eq 1 ]
  10922. + echo /dev/snp
  10923. + grep '/\.[^/]*$'
  10924. + test -z ''
  10925. + do_dev_whitelist_check
  10926. + /usr/bin/file /dev/snp
  10927. + awk -F: '{ print $NF }'
  10928. + cut -c2-
  10929. + FTYPE='character special (0/20)'
  10930. + echo 'character special (0/20)'
  10931. + grep 'universal binary'
  10932. + [ 0 -eq 1 -a -n '' ]
  10933. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  10934. + echo 'character special (0/20)'
  10935. + [ -z '' ]
  10936. + return
  10937. + [ 0 -eq 1 ]
  10938. + echo /dev/fd/0
  10939. + grep '/\.[^/]*$'
  10940. + test -z ''
  10941. + do_dev_whitelist_check
  10942. + awk -F: '{ print $NF }'
  10943. + cut -c2-
  10944. + /usr/bin/file /dev/fd/0
  10945. + FTYPE='character special (0/21)'
  10946. + echo 'character special (0/21)'
  10947. + grep 'universal binary'
  10948. + [ 0 -eq 1 -a -n '' ]
  10949. + echo 'character special (0/21)'
  10950. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  10951. + [ -z '' ]
  10952. + return
  10953. + [ 0 -eq 1 ]
  10954. + echo /dev/fd/1
  10955. + grep '/\.[^/]*$'
  10956. + test -z ''
  10957. + do_dev_whitelist_check
  10958. + cut -c2-
  10959. + /usr/bin/file /dev/fd/1
  10960. + awk -F: '{ print $NF }'
  10961. + FTYPE='character special (0/23)'
  10962. + echo 'character special (0/23)'
  10963. + grep 'universal binary'
  10964. + [ 0 -eq 1 -a -n '' ]
  10965. + echo 'character special (0/23)'
  10966. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  10967. + [ -z '' ]
  10968. + return
  10969. + [ 0 -eq 1 ]
  10970. + echo /dev/fd/2
  10971. + grep '/\.[^/]*$'
  10972. + test -z ''
  10973. + do_dev_whitelist_check
  10974. + /usr/bin/file /dev/fd/2
  10975. + cut -c2-
  10976. + awk -F: '{ print $NF }'
  10977. + FTYPE='character special (0/25)'
  10978. + grep 'universal binary'
  10979. + echo 'character special (0/25)'
  10980. + [ 0 -eq 1 -a -n '' ]
  10981. + echo 'character special (0/25)'
  10982. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  10983. + [ -z '' ]
  10984. + return
  10985. + [ 0 -eq 1 ]
  10986. + grep '/\.[^/]*$'
  10987. + echo /dev/gpioc0
  10988. + test -z ''
  10989. + do_dev_whitelist_check
  10990. + /usr/bin/file /dev/gpioc0
  10991. + awk -F: '{ print $NF }'
  10992. + cut -c2-
  10993. + FTYPE='character special (0/27)'
  10994. + echo 'character special (0/27)'
  10995. + grep 'universal binary'
  10996. + [ 0 -eq 1 -a -n '' ]
  10997. + echo 'character special (0/27)'
  10998. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  10999. + [ -z '' ]
  11000. + return
  11001. + [ 0 -eq 1 ]
  11002. + grep '/\.[^/]*$'
  11003. + echo /dev/led/led1
  11004. + test -z ''
  11005. + do_dev_whitelist_check
  11006. + /usr/bin/file /dev/led/led1
  11007. + awk -F: '{ print $NF }'
  11008. + cut -c2-
  11009. + FTYPE='character special (0/28)'
  11010. + grep 'universal binary'
  11011. + echo 'character special (0/28)'
  11012. + [ 0 -eq 1 -a -n '' ]
  11013. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11014. + echo 'character special (0/28)'
  11015. + [ -z '' ]
  11016. + return
  11017. + [ 0 -eq 1 ]
  11018. + grep '/\.[^/]*$'
  11019. + echo /dev/led/led2
  11020. + test -z ''
  11021. + do_dev_whitelist_check
  11022. + /usr/bin/file /dev/led/led2
  11023. + awk -F: '{ print $NF }'
  11024. + cut -c2-
  11025. + FTYPE='character special (0/29)'
  11026. + echo 'character special (0/29)'
  11027. + grep 'universal binary'
  11028. + [ 0 -eq 1 -a -n '' ]
  11029. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11030. + echo 'character special (0/29)'
  11031. + [ -z '' ]
  11032. + return
  11033. + [ 0 -eq 1 ]
  11034. + echo /dev/led/led3
  11035. + grep '/\.[^/]*$'
  11036. + test -z ''
  11037. + do_dev_whitelist_check
  11038. + awk -F: '{ print $NF }'
  11039. + cut -c2-
  11040. + /usr/bin/file /dev/led/led3
  11041. + FTYPE='character special (0/30)'
  11042. + echo 'character special (0/30)'
  11043. + grep 'universal binary'
  11044. + [ 0 -eq 1 -a -n '' ]
  11045. + echo 'character special (0/30)'
  11046. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11047. + [ -z '' ]
  11048. + return
  11049. + [ 0 -eq 1 ]
  11050. + echo /dev/led/led4
  11051. + grep '/\.[^/]*$'
  11052. + test -z ''
  11053. + do_dev_whitelist_check
  11054. + awk -F: '{ print $NF }'
  11055. + cut -c2-
  11056. + /usr/bin/file /dev/led/led4
  11057. + FTYPE='character special (0/31)'
  11058. + echo 'character special (0/31)'
  11059. + grep 'universal binary'
  11060. + [ 0 -eq 1 -a -n '' ]
  11061. + echo 'character special (0/31)'
  11062. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11063. + [ -z '' ]
  11064. + return
  11065. + [ 0 -eq 1 ]
  11066. + echo /dev/ttyu0
  11067. + grep '/\.[^/]*$'
  11068. + test -z ''
  11069. + do_dev_whitelist_check
  11070. + /usr/bin/file /dev/ttyu0
  11071. + awk -F: '{ print $NF }'
  11072. + cut -c2-
  11073. + FTYPE='character special (0/32)'
  11074. + grep 'universal binary'
  11075. + echo 'character special (0/32)'
  11076. + [ 0 -eq 1 -a -n '' ]
  11077. + echo 'character special (0/32)'
  11078. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11079. + [ -z '' ]
  11080. + return
  11081. + [ 0 -eq 1 ]
  11082. + grep '/\.[^/]*$'
  11083. + echo /dev/ttyu0.init
  11084. + test -z ''
  11085. + do_dev_whitelist_check
  11086. + /usr/bin/file /dev/ttyu0.init
  11087. + awk -F: '{ print $NF }'
  11088. + cut -c2-
  11089. + FTYPE='character special (0/33)'
  11090. + grep 'universal binary'
  11091. + echo 'character special (0/33)'
  11092. + [ 0 -eq 1 -a -n '' ]
  11093. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11094. + echo 'character special (0/33)'
  11095. + [ -z '' ]
  11096. + return
  11097. + [ 0 -eq 1 ]
  11098. + grep '/\.[^/]*$'
  11099. + echo /dev/ttyu0.lock
  11100. + test -z ''
  11101. + do_dev_whitelist_check
  11102. + cut -c2-
  11103. + /usr/bin/file /dev/ttyu0.lock
  11104. + awk -F: '{ print $NF }'
  11105. + FTYPE='character special (0/34)'
  11106. + grep 'universal binary'
  11107. + echo 'character special (0/34)'
  11108. + [ 0 -eq 1 -a -n '' ]
  11109. + echo 'character special (0/34)'
  11110. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11111. + [ -z '' ]
  11112. + return
  11113. + [ 0 -eq 1 ]
  11114. + grep '/\.[^/]*$'
  11115. + echo /dev/cuau0
  11116. + test -z ''
  11117. + do_dev_whitelist_check
  11118. + /usr/bin/file /dev/cuau0
  11119. + awk -F: '{ print $NF }'
  11120. + cut -c2-
  11121. + FTYPE='character special (0/35)'
  11122. + grep 'universal binary'
  11123. + echo 'character special (0/35)'
  11124. + [ 0 -eq 1 -a -n '' ]
  11125. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11126. + echo 'character special (0/35)'
  11127. + [ -z '' ]
  11128. + return
  11129. + [ 0 -eq 1 ]
  11130. + grep '/\.[^/]*$'
  11131. + echo /dev/cuau0.init
  11132. + test -z ''
  11133. + do_dev_whitelist_check
  11134. + /usr/bin/file /dev/cuau0.init
  11135. + awk -F: '{ print $NF }'
  11136. + cut -c2-
  11137. + FTYPE='character special (0/36)'
  11138. + echo 'character special (0/36)'
  11139. + grep 'universal binary'
  11140. + [ 0 -eq 1 -a -n '' ]
  11141. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11142. + echo 'character special (0/36)'
  11143. + [ -z '' ]
  11144. + return
  11145. + [ 0 -eq 1 ]
  11146. + echo /dev/cuau0.lock
  11147. + grep '/\.[^/]*$'
  11148. + test -z ''
  11149. + do_dev_whitelist_check
  11150. + /usr/bin/file /dev/cuau0.lock
  11151. + awk -F: '{ print $NF }'
  11152. + cut -c2-
  11153. + FTYPE='character special (0/37)'
  11154. + echo 'character special (0/37)'
  11155. + grep 'universal binary'
  11156. + [ 0 -eq 1 -a -n '' ]
  11157. + echo 'character special (0/37)'
  11158. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11159. + [ -z '' ]
  11160. + return
  11161. + [ 0 -eq 1 ]
  11162. + echo /dev/iic0
  11163. + grep '/\.[^/]*$'
  11164. + test -z ''
  11165. + do_dev_whitelist_check
  11166. + awk -F: '{ print $NF }'
  11167. + cut -c2-
  11168. + /usr/bin/file /dev/iic0
  11169. + FTYPE='character special (0/38)'
  11170. + echo 'character special (0/38)'
  11171. + grep 'universal binary'
  11172. + [ 0 -eq 1 -a -n '' ]
  11173. + echo 'character special (0/38)'
  11174. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11175. + [ -z '' ]
  11176. + return
  11177. + [ 0 -eq 1 ]
  11178. + echo /dev/iic1
  11179. + grep '/\.[^/]*$'
  11180. + test -z ''
  11181. + do_dev_whitelist_check
  11182. + /usr/bin/file /dev/iic1
  11183. + awk -F: '{ print $NF }'
  11184. + cut -c2-
  11185. + FTYPE='character special (0/39)'
  11186. + echo 'character special (0/39)'
  11187. + grep 'universal binary'
  11188. + [ 0 -eq 1 -a -n '' ]
  11189. + echo 'character special (0/39)'
  11190. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11191. + [ -z '' ]
  11192. + return
  11193. + [ 0 -eq 1 ]
  11194. + echo /dev/iic2
  11195. + grep '/\.[^/]*$'
  11196. + test -z ''
  11197. + do_dev_whitelist_check
  11198. + /usr/bin/file /dev/iic2
  11199. + cut -c2-
  11200. + awk -F: '{ print $NF }'
  11201. + FTYPE='character special (0/40)'
  11202. + grep 'universal binary'
  11203. + echo 'character special (0/40)'
  11204. + [ 0 -eq 1 -a -n '' ]
  11205. + echo 'character special (0/40)'
  11206. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11207. + [ -z '' ]
  11208. + return
  11209. + [ 0 -eq 1 ]
  11210. + grep '/\.[^/]*$'
  11211. + echo /dev/pruss0
  11212. + test -z ''
  11213. + do_dev_whitelist_check
  11214. + /usr/bin/file /dev/pruss0
  11215. + awk -F: '{ print $NF }'
  11216. + cut -c2-
  11217. + FTYPE='character special (0/41)'
  11218. + grep 'universal binary'
  11219. + echo 'character special (0/41)'
  11220. + [ 0 -eq 1 -a -n '' ]
  11221. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11222. + echo 'character special (0/41)'
  11223. + [ -z '' ]
  11224. + return
  11225. + [ 0 -eq 1 ]
  11226. + grep '/\.[^/]*$'
  11227. + echo /dev/ufssuspend
  11228. + test -z ''
  11229. + do_dev_whitelist_check
  11230. + /usr/bin/file /dev/ufssuspend
  11231. + awk -F: '{ print $NF }'
  11232. + cut -c2-
  11233. + FTYPE='character special (0/42)'
  11234. + echo 'character special (0/42)'
  11235. + grep 'universal binary'
  11236. + [ 0 -eq 1 -a -n '' ]
  11237. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11238. + echo 'character special (0/42)'
  11239. + [ -z '' ]
  11240. + return
  11241. + [ 0 -eq 1 ]
  11242. + echo /dev/usbctl
  11243. + grep '/\.[^/]*$'
  11244. + test -z ''
  11245. + do_dev_whitelist_check
  11246. + cut -c2-
  11247. + /usr/bin/file /dev/usbctl
  11248. + awk -F: '{ print $NF }'
  11249. + FTYPE='character special (0/45)'
  11250. + echo 'character special (0/45)'
  11251. + grep 'universal binary'
  11252. + [ 0 -eq 1 -a -n '' ]
  11253. + echo 'character special (0/45)'
  11254. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11255. + [ -z '' ]
  11256. + return
  11257. + [ 0 -eq 1 ]
  11258. + echo /dev/xpt0
  11259. + grep '/\.[^/]*$'
  11260. + test -z ''
  11261. + do_dev_whitelist_check
  11262. + awk -F: '{ print $NF }'
  11263. + cut -c2-
  11264. + /usr/bin/file /dev/xpt0
  11265. + FTYPE='character special (0/46)'
  11266. + echo 'character special (0/46)'
  11267. + grep 'universal binary'
  11268. + [ 0 -eq 1 -a -n '' ]
  11269. + echo 'character special (0/46)'
  11270. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11271. + [ -z '' ]
  11272. + return
  11273. + [ 0 -eq 1 ]
  11274. + echo /dev/usb/0.1.0
  11275. + grep '/\.[^/]*$'
  11276. + test -z ''
  11277. + do_dev_whitelist_check
  11278. + awk -F: '{ print $NF }'
  11279. + cut -c2-
  11280. + /usr/bin/file /dev/usb/0.1.0
  11281. + FTYPE='character special (0/47)'
  11282. + echo 'character special (0/47)'
  11283. + grep 'universal binary'
  11284. + [ 0 -eq 1 -a -n '' ]
  11285. + echo 'character special (0/47)'
  11286. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11287. + [ -z '' ]
  11288. + return
  11289. + [ 0 -eq 1 ]
  11290. + grep '/\.[^/]*$'
  11291. + echo /dev/usb/1.1.0
  11292. + test -z ''
  11293. + do_dev_whitelist_check
  11294. + /usr/bin/file /dev/usb/1.1.0
  11295. + awk -F: '{ print $NF }'
  11296. + cut -c2-
  11297. + FTYPE='character special (0/49)'
  11298. + grep 'universal binary'
  11299. + echo 'character special (0/49)'
  11300. + [ 0 -eq 1 -a -n '' ]
  11301. + echo 'character special (0/49)'
  11302. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11303. + [ -z '' ]
  11304. + return
  11305. + [ 0 -eq 1 ]
  11306. + grep '/\.[^/]*$'
  11307. + echo /dev/usb/0.1.1
  11308. + test -z ''
  11309. + do_dev_whitelist_check
  11310. + /usr/bin/file /dev/usb/0.1.1
  11311. + awk -F: '{ print $NF }'
  11312. + cut -c2-
  11313. + FTYPE='character special (0/52)'
  11314. + grep 'universal binary'
  11315. + echo 'character special (0/52)'
  11316. + [ 0 -eq 1 -a -n '' ]
  11317. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11318. + echo 'character special (0/52)'
  11319. + [ -z '' ]
  11320. + return
  11321. + [ 0 -eq 1 ]
  11322. + grep '/\.[^/]*$'
  11323. + echo /dev/usb/1.1.1
  11324. + test -z ''
  11325. + do_dev_whitelist_check
  11326. + /usr/bin/file /dev/usb/1.1.1
  11327. + awk -F: '{ print $NF }'
  11328. + cut -c2-
  11329. + FTYPE='character special (0/53)'
  11330. + echo 'character special (0/53)'
  11331. + grep 'universal binary'
  11332. + [ 0 -eq 1 -a -n '' ]
  11333. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11334. + echo 'character special (0/53)'
  11335. + [ -z '' ]
  11336. + return
  11337. + [ 0 -eq 1 ]
  11338. + echo /dev/mdctl
  11339. + grep '/\.[^/]*$'
  11340. + test -z ''
  11341. + do_dev_whitelist_check
  11342. + awk -F: '{ print $NF }'
  11343. + cut -c2-
  11344. + /usr/bin/file /dev/mdctl
  11345. + FTYPE='character special (0/51)'
  11346. + echo 'character special (0/51)'
  11347. + grep 'universal binary'
  11348. + [ 0 -eq 1 -a -n '' ]
  11349. + echo 'character special (0/51)'
  11350. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11351. + [ -z '' ]
  11352. + return
  11353. + [ 0 -eq 1 ]
  11354. + echo /dev/devstat
  11355. + grep '/\.[^/]*$'
  11356. + test -z ''
  11357. + do_dev_whitelist_check
  11358. + awk -F: '{ print $NF }'
  11359. + cut -c2-
  11360. + /usr/bin/file /dev/devstat
  11361. + FTYPE='character special (0/54)'
  11362. + echo 'character special (0/54)'
  11363. + grep 'universal binary'
  11364. + [ 0 -eq 1 -a -n '' ]
  11365. + echo 'character special (0/54)'
  11366. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11367. + [ -z '' ]
  11368. + return
  11369. + [ 0 -eq 1 ]
  11370. + grep '/\.[^/]*$'
  11371. + echo /dev/mmcsd0
  11372. + test -z ''
  11373. + do_dev_whitelist_check
  11374. + /usr/bin/file /dev/mmcsd0
  11375. + awk -F: '{ print $NF }'
  11376. + cut -c2-
  11377. + FTYPE='character special (0/55)'
  11378. + grep 'universal binary'
  11379. + echo 'character special (0/55)'
  11380. + [ 0 -eq 1 -a -n '' ]
  11381. + echo 'character special (0/55)'
  11382. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11383. + [ -z '' ]
  11384. + return
  11385. + [ 0 -eq 1 ]
  11386. + grep '/\.[^/]*$'
  11387. + echo /dev/diskid/DISK-34D2DDBF
  11388. + test -z ''
  11389. + do_dev_whitelist_check
  11390. + /usr/bin/file /dev/diskid/DISK-34D2DDBF
  11391. + awk -F: '{ print $NF }'
  11392. + cut -c2-
  11393. + FTYPE='character special (0/67)'
  11394. + grep 'universal binary'
  11395. + echo 'character special (0/67)'
  11396. + [ 0 -eq 1 -a -n '' ]
  11397. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11398. + echo 'character special (0/67)'
  11399. + [ -z '' ]
  11400. + return
  11401. + [ 0 -eq 1 ]
  11402. + echo /dev/diskid/DISK-34D2DDBFs1
  11403. + grep '/\.[^/]*$'
  11404. + test -z ''
  11405. + do_dev_whitelist_check
  11406. + awk -F: '{ print $NF }'
  11407. + cut -c2-
  11408. + /usr/bin/file /dev/diskid/DISK-34D2DDBFs1
  11409. + FTYPE='character special (0/70)'
  11410. + echo 'character special (0/70)'
  11411. + grep 'universal binary'
  11412. + [ 0 -eq 1 -a -n '' ]
  11413. + echo 'character special (0/70)'
  11414. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11415. + [ -z '' ]
  11416. + return
  11417. + [ 0 -eq 1 ]
  11418. + echo /dev/diskid/DISK-34D2DDBFs2
  11419. + grep '/\.[^/]*$'
  11420. + test -z ''
  11421. + do_dev_whitelist_check
  11422. + awk -F: '{ print $NF }'
  11423. + cut -c2-
  11424. + /usr/bin/file /dev/diskid/DISK-34D2DDBFs2
  11425. + FTYPE='character special (0/71)'
  11426. + echo 'character special (0/71)'
  11427. + grep 'universal binary'
  11428. + [ 0 -eq 1 -a -n '' ]
  11429. + echo 'character special (0/71)'
  11430. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11431. + [ -z '' ]
  11432. + return
  11433. + [ 0 -eq 1 ]
  11434. + echo /dev/mmcsd0s1
  11435. + grep '/\.[^/]*$'
  11436. + test -z ''
  11437. + do_dev_whitelist_check
  11438. + /usr/bin/file /dev/mmcsd0s1
  11439. + cut -c2-
  11440. + awk -F: '{ print $NF }'
  11441. + FTYPE='character special (0/57)'
  11442. + echo 'character special (0/57)'
  11443. + grep 'universal binary'
  11444. + [ 0 -eq 1 -a -n '' ]
  11445. + echo 'character special (0/57)'
  11446. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11447. + [ -z '' ]
  11448. + return
  11449. + [ 0 -eq 1 ]
  11450. + grep '/\.[^/]*$'
  11451. + echo /dev/mmcsd0s2
  11452. + test -z ''
  11453. + do_dev_whitelist_check
  11454. + /usr/bin/file /dev/mmcsd0s2
  11455. + awk -F: '{ print $NF }'
  11456. + cut -c2-
  11457. + FTYPE='character special (0/58)'
  11458. + grep 'universal binary'
  11459. + echo 'character special (0/58)'
  11460. + [ 0 -eq 1 -a -n '' ]
  11461. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11462. + echo 'character special (0/58)'
  11463. + [ -z '' ]
  11464. + return
  11465. + [ 0 -eq 1 ]
  11466. + grep '/\.[^/]*$'
  11467. + echo /dev/msdosfs/MSDOSBOOT
  11468. + test -z ''
  11469. + do_dev_whitelist_check
  11470. + /usr/bin/file /dev/msdosfs/MSDOSBOOT
  11471. + awk -F: '{ print $NF }'
  11472. + cut -c2-
  11473. + FTYPE='character special (0/61)'
  11474. + echo 'character special (0/61)'
  11475. + grep 'universal binary'
  11476. + [ 0 -eq 1 -a -n '' ]
  11477. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11478. + echo 'character special (0/61)'
  11479. + [ -z '' ]
  11480. + return
  11481. + [ 0 -eq 1 ]
  11482. + echo /dev/msdosfs/boot
  11483. + grep '/\.[^/]*$'
  11484. + test -z ''
  11485. + do_dev_whitelist_check
  11486. + /usr/bin/file /dev/msdosfs/boot
  11487. + awk -F: '{ print $NF }'
  11488. + cut -c2-
  11489. + FTYPE='character special (0/72)'
  11490. + echo 'character special (0/72)'
  11491. + grep 'universal binary'
  11492. + [ 0 -eq 1 -a -n '' ]
  11493. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11494. + echo 'character special (0/72)'
  11495. + [ -z '' ]
  11496. + return
  11497. + [ 0 -eq 1 ]
  11498. + echo /dev/mmcsd0s2a
  11499. + grep '/\.[^/]*$'
  11500. + test -z ''
  11501. + do_dev_whitelist_check
  11502. + awk -F: '{ print $NF }'
  11503. + cut -c2-
  11504. + /usr/bin/file /dev/mmcsd0s2a
  11505. + FTYPE='character special (0/62)'
  11506. + echo 'character special (0/62)'
  11507. + grep 'universal binary'
  11508. + [ 0 -eq 1 -a -n '' ]
  11509. + echo 'character special (0/62)'
  11510. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11511. + [ -z '' ]
  11512. + return
  11513. + [ 0 -eq 1 ]
  11514. + echo /dev/ufs/rootfs
  11515. + grep '/\.[^/]*$'
  11516. + test -z ''
  11517. + do_dev_whitelist_check
  11518. + awk -F: '{ print $NF }'
  11519. + /usr/bin/file /dev/ufs/rootfs
  11520. + cut -c2-
  11521. + FTYPE='character special (0/65)'
  11522. + echo 'character special (0/65)'
  11523. + grep 'universal binary'
  11524. + [ 0 -eq 1 -a -n '' ]
  11525. + echo 'character special (0/65)'
  11526. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11527. + [ -z '' ]
  11528. + return
  11529. + [ 0 -eq 1 ]
  11530. + echo /dev/mmcsd1
  11531. + grep '/\.[^/]*$'
  11532. + test -z ''
  11533. + do_dev_whitelist_check
  11534. + /usr/bin/file /dev/mmcsd1
  11535. + awk -F: '{ print $NF }'
  11536. + cut -c2-
  11537. + FTYPE='character special (0/66)'
  11538. + grep 'universal binary'
  11539. + echo 'character special (0/66)'
  11540. + [ 0 -eq 1 -a -n '' ]
  11541. + echo 'character special (0/66)'
  11542. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11543. + [ -z '' ]
  11544. + return
  11545. + [ 0 -eq 1 ]
  11546. + grep '/\.[^/]*$'
  11547. + echo /dev/mmcsd1s1
  11548. + test -z ''
  11549. + do_dev_whitelist_check
  11550. + /usr/bin/file /dev/mmcsd1s1
  11551. + awk -F: '{ print $NF }'
  11552. + cut -c2-
  11553. + FTYPE='character special (0/68)'
  11554. + grep 'universal binary'
  11555. + echo 'character special (0/68)'
  11556. + [ 0 -eq 1 -a -n '' ]
  11557. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11558. + echo 'character special (0/68)'
  11559. + [ -z '' ]
  11560. + return
  11561. + [ 0 -eq 1 ]
  11562. + grep '/\.[^/]*$'
  11563. + echo /dev/mmcsd1s2
  11564. + test -z ''
  11565. + do_dev_whitelist_check
  11566. + /usr/bin/file /dev/mmcsd1s2
  11567. + awk -F: '{ print $NF }'
  11568. + cut -c2-
  11569. + FTYPE='character special (0/69)'
  11570. + echo 'character special (0/69)'
  11571. + grep 'universal binary'
  11572. + [ 0 -eq 1 -a -n '' ]
  11573. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11574. + echo 'character special (0/69)'
  11575. + [ -z '' ]
  11576. + return
  11577. + [ 0 -eq 1 ]
  11578. + echo /dev/ext2fs/rootfs
  11579. + grep '/\.[^/]*$'
  11580. + test -z ''
  11581. + do_dev_whitelist_check
  11582. + awk -F: '{ print $NF }'
  11583. + cut -c2-
  11584. + /usr/bin/file /dev/ext2fs/rootfs
  11585. + FTYPE='character special (0/73)'
  11586. + echo 'character special (0/73)'
  11587. + grep 'universal binary'
  11588. + [ 0 -eq 1 -a -n '' ]
  11589. + echo 'character special (0/73)'
  11590. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11591. + [ -z '' ]
  11592. + return
  11593. + [ 0 -eq 1 ]
  11594. + echo /dev/md0
  11595. + grep '/\.[^/]*$'
  11596. + test -z ''
  11597. + do_dev_whitelist_check
  11598. + awk -F: '{ print $NF }'
  11599. + cut -c2-
  11600. + /usr/bin/file /dev/md0
  11601. + FTYPE='character special (0/56)'
  11602. + echo 'character special (0/56)'
  11603. + grep 'universal binary'
  11604. + [ 0 -eq 1 -a -n '' ]
  11605. + echo 'character special (0/56)'
  11606. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11607. + [ -z '' ]
  11608. + return
  11609. + [ 0 -eq 1 ]
  11610. + echo /dev/md1
  11611. + grep '/\.[^/]*$'
  11612. + test -z ''
  11613. + do_dev_whitelist_check
  11614. + awk -F: '{ print $NF }'
  11615. + cut -c2-
  11616. + /usr/bin/file /dev/md1
  11617. + FTYPE='character special (0/60)'
  11618. + echo 'character special (0/60)'
  11619. + grep 'universal binary'
  11620. + [ 0 -eq 1 -a -n '' ]
  11621. + echo 'character special (0/60)'
  11622. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11623. + [ -z '' ]
  11624. + return
  11625. + [ 0 -eq 1 ]
  11626. + grep '/\.[^/]*$'
  11627. + echo /dev/md1.eli
  11628. + test -z ''
  11629. + do_dev_whitelist_check
  11630. + /usr/bin/file /dev/md1.eli
  11631. + awk -F: '{ print $NF }'
  11632. + cut -c2-
  11633. + FTYPE='character special (0/63)'
  11634. + grep 'universal binary'
  11635. + echo 'character special (0/63)'
  11636. + [ 0 -eq 1 -a -n '' ]
  11637. + echo 'character special (0/63)'
  11638. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11639. + [ -z '' ]
  11640. + return
  11641. + [ 0 -eq 1 ]
  11642. + grep '/\.[^/]*$'
  11643. + echo /dev/fuse
  11644. + test -z ''
  11645. + do_dev_whitelist_check
  11646. + /usr/bin/file /dev/fuse
  11647. + awk -F: '{ print $NF }'
  11648. + cut -c2-
  11649. + FTYPE='character special (0/64)'
  11650. + grep 'universal binary'
  11651. + echo 'character special (0/64)'
  11652. + [ 0 -eq 1 -a -n '' ]
  11653. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11654. + echo 'character special (0/64)'
  11655. + [ -z '' ]
  11656. + return
  11657. + [ 0 -eq 1 ]
  11658. + grep '/\.[^/]*$'
  11659. + echo /dev/pts/0
  11660. + test -z ''
  11661. + do_dev_whitelist_check
  11662. + /usr/bin/file /dev/pts/0
  11663. + awk -F: '{ print $NF }'
  11664. + cut -c2-
  11665. + FTYPE='character special (0/79)'
  11666. + echo 'character special (0/79)'
  11667. + grep 'universal binary'
  11668. + [ 0 -eq 1 -a -n '' ]
  11669. + egrep -v '(character special|block special|socket|fifo \(named pipe\)|symbolic link to|empty|directory|/MAKEDEV:)'
  11670. + echo 'character special (0/79)'
  11671. + [ -z '' ]
  11672. + return
  11673. + IFS='
  11674. '
  11675. + echo ''
  11676. + sed -e '/^$/d'
  11677. + FOUNDFILES=''
  11678. + [ -z '' ]
  11679. + display --to SCREEN+LOG --type PLAIN --result NONE_FOUND --color GREEN --log-indent 2 --screen-indent 4 FILESYSTEM_DEV_CHECK
  11680. + WARN_MSG=0
  11681. + NL=0
  11682. + NLAFTER=0
  11683. + LOGINDENT=0
  11684. + SCREENINDENT=0
  11685. + LOGNL=0
  11686. + SCREENNL=0
  11687. + WRITETO=''
  11688. + TYPE=''
  11689. + RESULT=''
  11690. + COLOR=''
  11691. + MSG=''
  11692. + LINE1=''
  11693. + LOGLINE1=''
  11694. + SPACES=''
  11695. + NONL=''
  11696. + DISPLAY_LINE='display --to SCREEN+LOG --type PLAIN --result NONE_FOUND --color GREEN --log-indent 2 --screen-indent 4 FILESYSTEM_DEV_CHECK'
  11697. + [ 13 -le 0 ]
  11698. + [ 13 -ge 1 ]
  11699. + WRITETO=SCREEN+LOG
  11700. + shift
  11701. + shift
  11702. + [ 11 -ge 1 ]
  11703. + eval echo '$MSG_TYPE_PLAIN'
  11704. + echo
  11705. + TYPE=''
  11706. + [ -z '' -a PLAIN != PLAIN ]
  11707. + test PLAIN = WARNING
  11708. + shift
  11709. + shift
  11710. + [ 9 -ge 1 ]
  11711. + eval echo '$MSG_RESULT_NONE_FOUND'
  11712. + echo None found
  11713. + RESULT='None found'
  11714. + [ -z 'None found' ]
  11715. + shift
  11716. + shift
  11717. + [ 7 -ge 1 ]
  11718. + [ 1 -eq 1 ]
  11719. + test -n GREEN
  11720. + eval 'echo ${GREEN}'
  11721. + echo ''
  11722. + COLOR=''
  11723. + [ -z '' ]
  11724. + shift
  11725. + shift
  11726. + [ 5 -ge 1 ]
  11727. + LOGINDENT=2
  11728. + [ -z 2 ]
  11729. + echo 2
  11730. + grep '^[0-9]*$'
  11731. + [ -z 2 ]
  11732. + shift
  11733. + shift
  11734. + [ 3 -ge 1 ]
  11735. + SCREENINDENT=4
  11736. + [ -z 4 ]
  11737. + echo 4
  11738. + grep '^[0-9]*$'
  11739. + [ -z 4 ]
  11740. + shift
  11741. + shift
  11742. + [ 1 -ge 1 ]
  11743. + MSG=FILESYSTEM_DEV_CHECK
  11744. + shift
  11745. + break
  11746. + test 0 -eq 1
  11747. + [ 0 -eq 1 ]
  11748. + [ 0 -eq 1 ]
  11749. + test SCREEN+LOG = SCREEN -o SCREEN+LOG = SCREEN+LOG
  11750. + WRITETOTTY=1
  11751. + test SCREEN+LOG = LOG -o SCREEN+LOG = SCREEN+LOG
  11752. + WRITETOLOG=1
  11753. + [ 1 -eq 0 -a 1 -eq 0 ]
  11754. + [ 1 -eq 1 -a 1 -eq 1 -a -n 'None found' -a -z '' ]
  11755. + test -n ''
  11756. + [ 0 -eq 1 -a 1 -eq 1 -a 1 -eq 1 -a 'None found' = Whitelisted ]
  11757. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  11758. + [ -n FILESYSTEM_DEV_CHECK ]
  11759. + grep -a ^FILESYSTEM_DEV_CHECK: /usr/local/var/lib/rkhunter/db/i18n/en
  11760. + head -n 1
  11761. + cut -d: -f2-
  11762. + LINE1='Checking /dev for suspicious file types'
  11763. + [ 0 -eq 1 ]
  11764. + [ -z 'Checking /dev for suspicious file types' ]
  11765. + echo 'Checking /dev for suspicious file types'
  11766. + sed -e 's/`/\\`/g'
  11767. + LINE1='Checking /dev for suspicious file types'
  11768. + test -n 'Checking /dev for suspicious file types'
  11769. + eval 'echo "Checking /dev for suspicious file types" | sed -e '\''s/;/\;/g'\'
  11770. + echo 'Checking /dev for suspicious file types'
  11771. + sed -e 's/;/\;/g'
  11772. + LINE1='Checking /dev for suspicious file types'
  11773. + [ 1 -eq 1 ]
  11774. + date '+[%H:%M:%S]'
  11775. + LOGLINE1='[04:22:06]'
  11776. + test 0 -gt 0 -o 0 -eq 1
  11777. + [ -n '' ]
  11778. + test 2 -gt 0
  11779. + cut -c1-2
  11780. + echo ' '
  11781. + SPACES=' '
  11782. + LOGLINE1='[04:22:06] Checking /dev for suspicious file types'
  11783. + [ 1 -eq 1 -a 4 -gt 0 ]
  11784. + cut -c1-4
  11785. + echo ' '
  11786. + SPACES=' '
  11787. + LINE1=' Checking /dev for suspicious file types'
  11788. + [ -n 'None found' ]
  11789. + [ 1 -eq 1 ]
  11790. + wc -c
  11791. + tr -d ' '
  11792. + echo ' Checking /dev for suspicious file types'
  11793. + LINE1_NUM=44
  11794. + expr 62 - 44
  11795. + NUM_SPACES=18
  11796. + test 18 -lt 1
  11797. + [ 1 -eq 0 ]
  11798. + LINE1=' Checking /dev for suspicious file types\033[18C[ None found ]'
  11799. + [ 1 -eq 1 ]
  11800. + echo '[04:22:06] Checking /dev for suspicious file types'
  11801. + wc -c
  11802. + tr -d ' '
  11803. + LOGLINE1_NUM=53
  11804. + expr 62 - 53
  11805. + NUM_SPACES=9
  11806. + test 9 -lt 1
  11807. + echo ' '
  11808. + cut -c1-9
  11809. + SPACES=' '
  11810. + LOGLINE1='[04:22:06] Checking /dev for suspicious file types [ None found ]'
  11811. + [ 0 -eq 1 ]
  11812. + [ 1 -eq 1 ]
  11813. + NLLOOP=0
  11814. + test 0 -gt 0
  11815. + [ '' = c ]
  11816. + echo -e ' Checking /dev for suspicious file types\033[18C[ None found ]'
  11817. Checking /dev for suspicious file types[ None found ]
  11818. + [ 1 -eq 1 ]
  11819. + echo -e '[04:22:06] Checking /dev for suspicious file types [ None found ]'
  11820. + [ 0 -eq 1 ]
  11821. + echo '[04:22:06] Checking /dev for suspicious file types [ None found ]'
  11822. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  11823. + [ 0 -eq 1 -a -n '' ]
  11824. + test 1 -eq 1 -a 0 -eq 1
  11825. + return
  11826. + [ -z /usr/bin/file ]
  11827. + FOUNDDIRS=''
  11828. + FOUNDFILES=''
  11829. + LOOKINDIRS=''
  11830. + SHORTSEARCHDIRS='/usr /etc'
  11831. + LONGSEARCHDIRS='/dev /bin /usr/man /usr/share/man /usr/bin /usr/sbin /sbin'
  11832. + [ -z /usr/bin/find ]
  11833. + [ -d /usr ]
  11834. + egrep -v '/\.\.?$'
  11835. + ls -1d /usr/. /usr/..
  11836. + RKHTMPVAR='/usr/.
  11837. /usr/..'
  11838. + test -n '/usr/.
  11839. /usr/..'
  11840. + LOOKINDIRS='
  11841. /usr/.
  11842. /usr/..'
  11843. + [ -d /etc ]
  11844. + egrep -v '/\.\.?$'
  11845. + ls -1d /etc/. /etc/..
  11846. + RKHTMPVAR='/etc/.
  11847. /etc/..'
  11848. + test -n '/etc/.
  11849. /etc/..'
  11850. + LOOKINDIRS='
  11851. /usr/.
  11852. /usr/..
  11853. /etc/.
  11854. /etc/..'
  11855. + [ -d /dev ]
  11856. + /usr/bin/find /dev -name '.*'
  11857. + RKHTMPVAR=''
  11858. + test -n ''
  11859. + [ -d /bin ]
  11860. + /usr/bin/find /bin -name '.*'
  11861. + RKHTMPVAR=''
  11862. + test -n ''
  11863. + [ -d /usr/man ]
  11864. + [ -d /usr/share/man ]
  11865. + /usr/bin/find /usr/share/man -name '.*'
  11866. + RKHTMPVAR=''
  11867. + test -n ''
  11868. + [ -d /usr/bin ]
  11869. + /usr/bin/find /usr/bin -name '.*'
  11870. + RKHTMPVAR=''
  11871. + test -n ''
  11872. + [ -d /usr/sbin ]
  11873. + /usr/bin/find /usr/sbin -name '.*'
  11874. + RKHTMPVAR=''
  11875. + test -n ''
  11876. + [ -d /sbin ]
  11877. + /usr/bin/find /sbin -name '.*'
  11878. + RKHTMPVAR=''
  11879. + test -n ''
  11880. + [ -n '' ]
  11881. + [ -n '' ]
  11882. + IFS='
  11883. '
  11884. + [ 0 -eq 1 ]
  11885. + /usr/bin/file '/usr/.'
  11886. + awk -F: '{ print $NF }'
  11887. + cut -c2-
  11888. + FTYPE='cannot open `\033[1m\033[38;5;6m/usr/.\033[39;49m\033[m'\'' (No such file or directory)'
  11889. + echo 'cannot open `\033[1m\033[38;5;6m/usr/.\033[39;49m\033[m'\'' (No such file or directory)'
  11890. + egrep 'character special|block special|empty'
  11891. + test -n ''
  11892. + sed -e 's/\([.$*?\]\)/\\\1/g; s/\[/\\[/g; s/\]/\\]/g'
  11893. + echo '/usr/.'
  11894. + FNAMEGREP='\[1m\[38;5;6m/usr/\.\[39;49m\[m'
  11895. + grep directory
  11896. + echo 'cannot open `\033[1m\033[38;5;6m/usr/.\033[39;49m\033[m'\'' (No such file or directory)'
  11897. + [ -n 'cannot open `\033[1m\033[38;5;6m/usr/.\033[39;49m\033[m'\'' (No such file or directory)' ]
  11898. + echo ''
  11899. + grep '^\[1m\[38;5;6m/usr/\.\[39;49m\[m$'
  11900. + [ -n '' ]
  11901. + FOUNDDIRS='
  11902. /usr/.: cannot open `\033[1m\033[38;5;6m/usr/.\033[39;49m\033[m'\'' (No such file or directory)'
  11903. + [ 0 -eq 1 ]
  11904. + awk -F: '{ print $NF }'
  11905. + cut -c2-
  11906. + /usr/bin/file '/usr/..'
  11907. + FTYPE='cannot open `\033[1m\033[38;5;6m/usr/..\033[39;49m\033[m'\'' (No such file or directory)'
  11908. + echo 'cannot open `\033[1m\033[38;5;6m/usr/..\033[39;49m\033[m'\'' (No such file or directory)'
  11909. + egrep 'character special|block special|empty'
  11910. + test -n ''
  11911. + sed -e 's/\([.$*?\]\)/\\\1/g; s/\[/\\[/g; s/\]/\\]/g'
  11912. + echo '/usr/..'
  11913. + FNAMEGREP='\[1m\[38;5;6m/usr/\.\.\[39;49m\[m'
  11914. + grep directory
  11915. + echo 'cannot open `\033[1m\033[38;5;6m/usr/..\033[39;49m\033[m'\'' (No such file or directory)'
  11916. + [ -n 'cannot open `\033[1m\033[38;5;6m/usr/..\033[39;49m\033[m'\'' (No such file or directory)' ]
  11917. + echo ''
  11918. + grep '^\[1m\[38;5;6m/usr/\.\.\[39;49m\[m$'
  11919. + [ -n '' ]
  11920. + FOUNDDIRS='
  11921. /usr/.: cannot open `\033[1m\033[38;5;6m/usr/.\033[39;49m\033[m'\'' (No such file or directory)
  11922. /usr/..: cannot open `\033[1m\033[38;5;6m/usr/..\033[39;49m\033[m'\'' (No such file or directory)'
  11923. + [ 0 -eq 1 ]
  11924. + awk -F: '{ print $NF }'
  11925. + cut -c2-
  11926. + /usr/bin/file '/etc/.'
  11927. + FTYPE='cannot open `\033[1m\033[38;5;6m/etc/.\033[39;49m\033[m'\'' (No such file or directory)'
  11928. + echo 'cannot open `\033[1m\033[38;5;6m/etc/.\033[39;49m\033[m'\'' (No such file or directory)'
  11929. + egrep 'character special|block special|empty'
  11930. + test -n ''
  11931. + echo '/etc/.'
  11932. + sed -e 's/\([.$*?\]\)/\\\1/g; s/\[/\\[/g; s/\]/\\]/g'
  11933. + FNAMEGREP='\[1m\[38;5;6m/etc/\.\[39;49m\[m'
  11934. + echo 'cannot open `\033[1m\033[38;5;6m/etc/.\033[39;49m\033[m'\'' (No such file or directory)'
  11935. + grep directory
  11936. + [ -n 'cannot open `\033[1m\033[38;5;6m/etc/.\033[39;49m\033[m'\'' (No such file or directory)' ]
  11937. + grep '^\[1m\[38;5;6m/etc/\.\[39;49m\[m$'
  11938. + echo ''
  11939. + [ -n '' ]
  11940. + FOUNDDIRS='
  11941. /usr/.: cannot open `\033[1m\033[38;5;6m/usr/.\033[39;49m\033[m'\'' (No such file or directory)
  11942. /usr/..: cannot open `\033[1m\033[38;5;6m/usr/..\033[39;49m\033[m'\'' (No such file or directory)
  11943. /etc/.: cannot open `\033[1m\033[38;5;6m/etc/.\033[39;49m\033[m'\'' (No such file or directory)'
  11944. + [ 0 -eq 1 ]
  11945. + /usr/bin/file '/etc/..'
  11946. + awk -F: '{ print $NF }'
  11947. + cut -c2-
  11948. + FTYPE='cannot open `\033[1m\033[38;5;6m/etc/..\033[39;49m\033[m'\'' (No such file or directory)'
  11949. + egrep 'character special|block special|empty'
  11950. + echo 'cannot open `\033[1m\033[38;5;6m/etc/..\033[39;49m\033[m'\'' (No such file or directory)'
  11951. + test -n ''
  11952. + echo '/etc/..'
  11953. + sed -e 's/\([.$*?\]\)/\\\1/g; s/\[/\\[/g; s/\]/\\]/g'
  11954. + FNAMEGREP='\[1m\[38;5;6m/etc/\.\.\[39;49m\[m'
  11955. + echo 'cannot open `\033[1m\033[38;5;6m/etc/..\033[39;49m\033[m'\'' (No such file or directory)'
  11956. + grep directory
  11957. + [ -n 'cannot open `\033[1m\033[38;5;6m/etc/..\033[39;49m\033[m'\'' (No such file or directory)' ]
  11958. + echo ''
  11959. + grep '^\[1m\[38;5;6m/etc/\.\.\[39;49m\[m$'
  11960. + [ -n '' ]
  11961. + FOUNDDIRS='
  11962. /usr/.: cannot open `\033[1m\033[38;5;6m/usr/.\033[39;49m\033[m'\'' (No such file or directory)
  11963. /usr/..: cannot open `\033[1m\033[38;5;6m/usr/..\033[39;49m\033[m'\'' (No such file or directory)
  11964. /etc/.: cannot open `\033[1m\033[38;5;6m/etc/.\033[39;49m\033[m'\'' (No such file or directory)
  11965. /etc/..: cannot open `\033[1m\033[38;5;6m/etc/..\033[39;49m\033[m'\'' (No such file or directory)'
  11966. + IFS='
  11967. '
  11968. + sed -e '/^$/d'
  11969. + echo '
  11970. /usr/.: cannot open `\033[1m\033[38;5;6m/usr/.\033[39;49m\033[m'\'' (No such file or directory)
  11971. /usr/..: cannot open `\033[1m\033[38;5;6m/usr/..\033[39;49m\033[m'\'' (No such file or directory)
  11972. /etc/.: cannot open `\033[1m\033[38;5;6m/etc/.\033[39;49m\033[m'\'' (No such file or directory)
  11973. /etc/..: cannot open `\033[1m\033[38;5;6m/etc/..\033[39;49m\033[m'\'' (No such file or directory)'
  11974. + FOUNDDIRS='/usr/.: cannot open `\033[1m\033[38;5;6m/usr/.\033[39;49m\033[m'\'' (No such file or directory)
  11975. /usr/..: cannot open `\033[1m\033[38;5;6m/usr/..\033[39;49m\033[m'\'' (No such file or directory)
  11976. /etc/.: cannot open `\033[1m\033[38;5;6m/etc/.\033[39;49m\033[m'\'' (No such file or directory)
  11977. /etc/..: cannot open `\033[1m\033[38;5;6m/etc/..\033[39;49m\033[m'\'' (No such file or directory)'
  11978. + echo ''
  11979. + sed -e '/^$/d'
  11980. + FOUNDFILES=''
  11981. + [ -z '/usr/.: cannot open `\033[1m\033[38;5;6m/usr/.\033[39;49m\033[m'\'' (No such file or directory)
  11982. /usr/..: cannot open `\033[1m\033[38;5;6m/usr/..\033[39;49m\033[m'\'' (No such file or directory)
  11983. /etc/.: cannot open `\033[1m\033[38;5;6m/etc/.\033[39;49m\033[m'\'' (No such file or directory)
  11984. /etc/..: cannot open `\033[1m\033[38;5;6m/etc/..\033[39;49m\033[m'\'' (No such file or directory)' -a -z '' ]
  11985. + display --to SCREEN+LOG --type PLAIN --result WARNING --color RED --log-indent 2 --screen-indent 4 FILESYSTEM_HIDDEN_CHECK
  11986. + WARN_MSG=0
  11987. + NL=0
  11988. + NLAFTER=0
  11989. + LOGINDENT=0
  11990. + SCREENINDENT=0
  11991. + LOGNL=0
  11992. + SCREENNL=0
  11993. + WRITETO=''
  11994. + TYPE=''
  11995. + RESULT=''
  11996. + COLOR=''
  11997. + MSG=''
  11998. + LINE1=''
  11999. + LOGLINE1=''
  12000. + SPACES=''
  12001. + NONL=''
  12002. + DISPLAY_LINE='display --to SCREEN+LOG --type PLAIN --result WARNING --color RED --log-indent 2 --screen-indent 4 FILESYSTEM_HIDDEN_CHECK'
  12003. + [ 13 -le 0 ]
  12004. + [ 13 -ge 1 ]
  12005. + WRITETO=SCREEN+LOG
  12006. + shift
  12007. + shift
  12008. + [ 11 -ge 1 ]
  12009. + eval echo '$MSG_TYPE_PLAIN'
  12010. + echo
  12011. + TYPE=''
  12012. + [ -z '' -a PLAIN != PLAIN ]
  12013. + test PLAIN = WARNING
  12014. + shift
  12015. + shift
  12016. + [ 9 -ge 1 ]
  12017. + eval echo '$MSG_RESULT_WARNING'
  12018. + echo Warning
  12019. + RESULT=Warning
  12020. + [ -z Warning ]
  12021. + shift
  12022. + shift
  12023. + [ 7 -ge 1 ]
  12024. + [ 1 -eq 1 ]
  12025. + test -n RED
  12026. + eval 'echo ${RED}'
  12027. + echo ''
  12028. + COLOR=''
  12029. + [ -z '' ]
  12030. + shift
  12031. + shift
  12032. + [ 5 -ge 1 ]
  12033. + LOGINDENT=2
  12034. + [ -z 2 ]
  12035. + grep '^[0-9]*$'
  12036. + echo 2
  12037. + [ -z 2 ]
  12038. + shift
  12039. + shift
  12040. + [ 3 -ge 1 ]
  12041. + SCREENINDENT=4
  12042. + [ -z 4 ]
  12043. + echo 4
  12044. + grep '^[0-9]*$'
  12045. + [ -z 4 ]
  12046. + shift
  12047. + shift
  12048. + [ 1 -ge 1 ]
  12049. + MSG=FILESYSTEM_HIDDEN_CHECK
  12050. + shift
  12051. + break
  12052. + test 0 -eq 1
  12053. + [ 0 -eq 1 ]
  12054. + [ 0 -eq 1 ]
  12055. + test SCREEN+LOG = SCREEN -o SCREEN+LOG = SCREEN+LOG
  12056. + WRITETOTTY=1
  12057. + test SCREEN+LOG = LOG -o SCREEN+LOG = SCREEN+LOG
  12058. + WRITETOLOG=1
  12059. + [ 1 -eq 0 -a 1 -eq 0 ]
  12060. + [ 1 -eq 1 -a 1 -eq 1 -a -n Warning -a -z '' ]
  12061. + test -n ''
  12062. + [ 0 -eq 1 -a 1 -eq 1 -a 1 -eq 1 -a Warning = Whitelisted ]
  12063. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  12064. + [ -n FILESYSTEM_HIDDEN_CHECK ]
  12065. + head -n 1
  12066. + cut -d: -f2-
  12067. + grep -a ^FILESYSTEM_HIDDEN_CHECK: /usr/local/var/lib/rkhunter/db/i18n/en
  12068. + LINE1='Checking for hidden files and directories'
  12069. + [ 0 -eq 1 ]
  12070. + [ -z 'Checking for hidden files and directories' ]
  12071. + sed -e 's/`/\\`/g'
  12072. + echo 'Checking for hidden files and directories'
  12073. + LINE1='Checking for hidden files and directories'
  12074. + test -n 'Checking for hidden files and directories'
  12075. + eval 'echo "Checking for hidden files and directories" | sed -e '\''s/;/\;/g'\'
  12076. + sed -e 's/;/\;/g'
  12077. + echo 'Checking for hidden files and directories'
  12078. + LINE1='Checking for hidden files and directories'
  12079. + [ 1 -eq 1 ]
  12080. + date '+[%H:%M:%S]'
  12081. + LOGLINE1='[04:22:08]'
  12082. + test 0 -gt 0 -o 0 -eq 1
  12083. + [ -n '' ]
  12084. + test 2 -gt 0
  12085. + echo ' '
  12086. + cut -c1-2
  12087. + SPACES=' '
  12088. + LOGLINE1='[04:22:08] Checking for hidden files and directories'
  12089. + [ 1 -eq 1 -a 4 -gt 0 ]
  12090. + echo ' '
  12091. + cut -c1-4
  12092. + SPACES=' '
  12093. + LINE1=' Checking for hidden files and directories'
  12094. + [ -n Warning ]
  12095. + [ 1 -eq 1 ]
  12096. + wc -c
  12097. + tr -d ' '
  12098. + echo ' Checking for hidden files and directories'
  12099. + LINE1_NUM=46
  12100. + expr 62 - 46
  12101. + NUM_SPACES=16
  12102. + test 16 -lt 1
  12103. + [ 1 -eq 0 ]
  12104. + LINE1=' Checking for hidden files and directories\033[16C[ Warning ]'
  12105. + [ 1 -eq 1 ]
  12106. + wc -c
  12107. + tr -d ' '
  12108. + echo '[04:22:08] Checking for hidden files and directories'
  12109. + LOGLINE1_NUM=55
  12110. + expr 62 - 55
  12111. + NUM_SPACES=7
  12112. + test 7 -lt 1
  12113. + cut -c1-7
  12114. + echo ' '
  12115. + SPACES=' '
  12116. + LOGLINE1='[04:22:08] Checking for hidden files and directories [ Warning ]'
  12117. + [ 0 -eq 1 ]
  12118. + [ 1 -eq 1 ]
  12119. + NLLOOP=0
  12120. + test 0 -gt 0
  12121. + [ '' = c ]
  12122. + echo -e ' Checking for hidden files and directories\033[16C[ Warning ]'
  12123. Checking for hidden files and directories[ Warning ]
  12124. + [ 1 -eq 1 ]
  12125. + echo -e '[04:22:08] Checking for hidden files and directories [ Warning ]'
  12126. + [ 0 -eq 1 ]
  12127. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  12128. + echo '[04:22:08] Checking for hidden files and directories [ Warning ]'
  12129. + [ 0 -eq 1 -a -n '' ]
  12130. + test 1 -eq 1 -a 0 -eq 1
  12131. + return
  12132. + IFS='
  12133. '
  12134. + awk -F: '{ print $NF }'
  12135. + cut -c2-
  12136. + echo '/usr/.: cannot open `\033[1m\033[38;5;6m/usr/.\033[39;49m\033[m'\'' (No such file or directory)'
  12137. + FTYPE='cannot open `\033[1m\033[38;5;6m/usr/.\033[39;49m\033[m'\'' (No such file or directory)'
  12138. + echo '/usr/.: cannot open `\033[1m\033[38;5;6m/usr/.\033[39;49m\033[m'\'' (No such file or directory)'
  12139. + sed -e 's/: [^:]*$//'
  12140. + FNAME='/usr/.'
  12141. + [ 'cannot open `\033[1m\033[38;5;6m/usr/.\033[39;49m\033[m'\'' (No such file or directory)' = directory ]
  12142. + name2text '/usr/.'
  12143. + echo -e '/usr/.'
  12144. + sed -e 's/ /<SP>/g; s/ /<TAB>/g'
  12145. + tr -d '\n'
  12146. + tr '[:cntrl:]' '?'
  12147. + return
  12148. + display --to LOG --type WARNING FILESYSTEM_HIDDEN_DIR_FOUND '?[1m?[38;5;6m/usr/.?[39;49m?[m: cannot open `\033[1m\033[38;5;6m/usr/.\033[39;49m\033[m'\'' (No such file or directory)'
  12149. + WARN_MSG=0
  12150. + NL=0
  12151. + NLAFTER=0
  12152. + LOGINDENT=0
  12153. + SCREENINDENT=0
  12154. + LOGNL=0
  12155. + SCREENNL=0
  12156. + WRITETO=''
  12157. + TYPE=''
  12158. + RESULT=''
  12159. + COLOR=''
  12160. + MSG=''
  12161. + LINE1=''
  12162. + LOGLINE1=''
  12163. + SPACES=''
  12164. + NONL=''
  12165. + DISPLAY_LINE='display --to
  12166. LOG
  12167. --type
  12168. WARNING
  12169. FILESYSTEM_HIDDEN_DIR_FOUND
  12170. ?[1m?[38;5;6m/usr/.?[39;49m?[m: cannot open `\033[1m\033[38;5;6m/usr/.\033[39;49m\033[m'\'' (No such file or directory)'
  12171. + [ 6 -le 0 ]
  12172. + [ 6 -ge 1 ]
  12173. + WRITETO=LOG
  12174. + shift
  12175. + shift
  12176. + [ 4 -ge 1 ]
  12177. + eval echo '$MSG_TYPE_WARNING'
  12178. + echo Warning
  12179. + TYPE=Warning
  12180. + [ -z Warning -a WARNING != PLAIN ]
  12181. + test WARNING = WARNING
  12182. + WARN_MSG=1
  12183. + shift
  12184. + shift
  12185. + [ 2 -ge 1 ]
  12186. + MSG=FILESYSTEM_HIDDEN_DIR_FOUND
  12187. + shift
  12188. + break
  12189. + test 1 -eq 1
  12190. + expr 0 + 1
  12191. + WARNING_COUNT=1
  12192. + [ 0 -eq 1 ]
  12193. + [ 0 -eq 1 ]
  12194. + test LOG = SCREEN -o LOG = SCREEN+LOG
  12195. + WRITETOTTY=0
  12196. + test LOG = LOG -o LOG = SCREEN+LOG
  12197. + WRITETOLOG=1
  12198. + [ 0 -eq 0 -a 1 -eq 0 ]
  12199. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  12200. + test -n Warning
  12201. + NONL=''
  12202. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  12203. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  12204. + [ -n FILESYSTEM_HIDDEN_DIR_FOUND ]
  12205. + grep -a ^FILESYSTEM_HIDDEN_DIR_FOUND: /usr/local/var/lib/rkhunter/db/i18n/en
  12206. + cut -d: -f2-
  12207. + head '-n 1'
  12208. + LINE1='Hidden directory found: $1'
  12209. + [ 0 -eq 1 ]
  12210. + [ -z 'Hidden directory found: $1' ]
  12211. + echo 'Hidden directory found: $1'
  12212. + sed -e 's/`/\\`/g'
  12213. + LINE1='Hidden directory found: $1'
  12214. + test -n 'Hidden directory found: $1'
  12215. + eval 'echo "Hidden directory found: $1" | sed -e '\''s/;/\;/g'\'
  12216. + echo 'Hidden directory found: ?[1m?[38;5;6m/usr/.?[39;49m?[m: cannot open `\033[1m\033[38;5;6m/usr/.\033[39;49m\033[m'\'' (No such file or directory)'
  12217. + sed -e 's/;/\;/g'
  12218. + LINE1='Hidden directory found: ?[1m?[38;5;6m/usr/.?[39;49m?[m: cannot open `\033[1m\033[38;5;6m/usr/.\033[39;49m\033[m'\'' (No such file or directory)'
  12219. + [ 1 -eq 1 ]
  12220. + date '+[%H:%M:%S]'
  12221. + LOGLINE1='[04:22:08]'
  12222. + test 0 -gt 0 -o 0 -eq 1
  12223. + [ -n Warning ]
  12224. + LOGLINE1='[04:22:08] Warning: Hidden directory found: ?[1m?[38;5;6m/usr/.?[39;49m?[m: cannot open `\033[1m\033[38;5;6m/usr/.\033[39;49m\033[m'\'' (No such file or directory)'
  12225. + [ 0 -eq 1 -a 0 -gt 0 ]
  12226. + [ -n '' ]
  12227. + [ 0 -eq 1 -a -n '' ]
  12228. + [ 0 -eq 1 ]
  12229. + [ 0 -eq 1 ]
  12230. + [ 1 -eq 1 ]
  12231. + echo -e '[04:22:08] Warning: Hidden directory found: ?[1m?[38;5;6m/usr/.?[39;49m?[m: cannot open `\033[1m\033[38;5;6m/usr/.\033[39;49m\033[m'\'' (No such file or directory)'
  12232. + [ 1 -eq 1 ]
  12233. + test 0 -eq 1
  12234. + LINE1=1
  12235. + OLDIFS='
  12236. '
  12237. + IFS='
  12238. '
  12239. + grep -a ^FILESYSTEM_HIDDEN_DIR_FOUND: /usr/local/var/lib/rkhunter/db/i18n/en
  12240. + cut -d: -f2-
  12241. + [ 1 -eq 1 ]
  12242. + LINE1=0
  12243. + continue
  12244. + IFS='
  12245. '
  12246. + test 0 -eq 1 -a 0 -eq 1
  12247. + return
  12248. + echo '/usr/..: cannot open `\033[1m\033[38;5;6m/usr/..\033[39;49m\033[m'\'' (No such file or directory)'
  12249. + awk -F: '{ print $NF }'
  12250. + cut -c2-
  12251. + FTYPE='cannot open `\033[1m\033[38;5;6m/usr/..\033[39;49m\033[m'\'' (No such file or directory)'
  12252. + sed -e 's/: [^:]*$//'
  12253. + echo '/usr/..: cannot open `\033[1m\033[38;5;6m/usr/..\033[39;49m\033[m'\'' (No such file or directory)'
  12254. + FNAME='/usr/..'
  12255. + [ 'cannot open `\033[1m\033[38;5;6m/usr/..\033[39;49m\033[m'\'' (No such file or directory)' = directory ]
  12256. + name2text '/usr/..'
  12257. + sed -e 's/ /<SP>/g; s/ /<TAB>/g'
  12258. + tr -d '\n'
  12259. + tr '[:cntrl:]' '?'
  12260. + echo -e '/usr/..'
  12261. + return
  12262. + display --to LOG --type WARNING FILESYSTEM_HIDDEN_DIR_FOUND '?[1m?[38;5;6m/usr/..?[39;49m?[m: cannot open `\033[1m\033[38;5;6m/usr/..\033[39;49m\033[m'\'' (No such file or directory)'
  12263. + WARN_MSG=0
  12264. + NL=0
  12265. + NLAFTER=0
  12266. + LOGINDENT=0
  12267. + SCREENINDENT=0
  12268. + LOGNL=0
  12269. + SCREENNL=0
  12270. + WRITETO=''
  12271. + TYPE=''
  12272. + RESULT=''
  12273. + COLOR=''
  12274. + MSG=''
  12275. + LINE1=''
  12276. + LOGLINE1=''
  12277. + SPACES=''
  12278. + NONL=''
  12279. + DISPLAY_LINE='display --to
  12280. LOG
  12281. --type
  12282. WARNING
  12283. FILESYSTEM_HIDDEN_DIR_FOUND
  12284. ?[1m?[38;5;6m/usr/..?[39;49m?[m: cannot open `\033[1m\033[38;5;6m/usr/..\033[39;49m\033[m'\'' (No such file or directory)'
  12285. + [ 6 -le 0 ]
  12286. + [ 6 -ge 1 ]
  12287. + WRITETO=LOG
  12288. + shift
  12289. + shift
  12290. + [ 4 -ge 1 ]
  12291. + eval echo '$MSG_TYPE_WARNING'
  12292. + echo Warning
  12293. + TYPE=Warning
  12294. + [ -z Warning -a WARNING != PLAIN ]
  12295. + test WARNING = WARNING
  12296. + WARN_MSG=1
  12297. + shift
  12298. + shift
  12299. + [ 2 -ge 1 ]
  12300. + MSG=FILESYSTEM_HIDDEN_DIR_FOUND
  12301. + shift
  12302. + break
  12303. + test 1 -eq 1
  12304. + expr 1 + 1
  12305. + WARNING_COUNT=2
  12306. + [ 0 -eq 1 ]
  12307. + [ 0 -eq 1 ]
  12308. + test LOG = SCREEN -o LOG = SCREEN+LOG
  12309. + WRITETOTTY=0
  12310. + test LOG = LOG -o LOG = SCREEN+LOG
  12311. + WRITETOLOG=1
  12312. + [ 0 -eq 0 -a 1 -eq 0 ]
  12313. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  12314. + test -n Warning
  12315. + NONL=''
  12316. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  12317. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  12318. + [ -n FILESYSTEM_HIDDEN_DIR_FOUND ]
  12319. + grep -a ^FILESYSTEM_HIDDEN_DIR_FOUND: /usr/local/var/lib/rkhunter/db/i18n/en
  12320. + head '-n 1'
  12321. + cut -d: -f2-
  12322. + LINE1='Hidden directory found: $1'
  12323. + [ 0 -eq 1 ]
  12324. + [ -z 'Hidden directory found: $1' ]
  12325. + echo 'Hidden directory found: $1'
  12326. + sed -e 's/`/\\`/g'
  12327. + LINE1='Hidden directory found: $1'
  12328. + test -n 'Hidden directory found: $1'
  12329. + eval 'echo "Hidden directory found: $1" | sed -e '\''s/;/\;/g'\'
  12330. + echo 'Hidden directory found: ?[1m?[38;5;6m/usr/..?[39;49m?[m: cannot open `\033[1m\033[38;5;6m/usr/..\033[39;49m\033[m'\'' (No such file or directory)'
  12331. + sed -e 's/;/\;/g'
  12332. + LINE1='Hidden directory found: ?[1m?[38;5;6m/usr/..?[39;49m?[m: cannot open `\033[1m\033[38;5;6m/usr/..\033[39;49m\033[m'\'' (No such file or directory)'
  12333. + [ 1 -eq 1 ]
  12334. + date '+[%H:%M:%S]'
  12335. + LOGLINE1='[04:22:09]'
  12336. + test 0 -gt 0 -o 0 -eq 1
  12337. + [ -n Warning ]
  12338. + LOGLINE1='[04:22:09] Warning: Hidden directory found: ?[1m?[38;5;6m/usr/..?[39;49m?[m: cannot open `\033[1m\033[38;5;6m/usr/..\033[39;49m\033[m'\'' (No such file or directory)'
  12339. + [ 0 -eq 1 -a 0 -gt 0 ]
  12340. + [ -n '' ]
  12341. + [ 0 -eq 1 -a -n '' ]
  12342. + [ 0 -eq 1 ]
  12343. + [ 0 -eq 1 ]
  12344. + [ 1 -eq 1 ]
  12345. + echo -e '[04:22:09] Warning: Hidden directory found: ?[1m?[38;5;6m/usr/..?[39;49m?[m: cannot open `\033[1m\033[38;5;6m/usr/..\033[39;49m\033[m'\'' (No such file or directory)'
  12346. + [ 1 -eq 1 ]
  12347. + test 0 -eq 1
  12348. + LINE1=1
  12349. + OLDIFS='
  12350. '
  12351. + IFS='
  12352. '
  12353. + grep -a ^FILESYSTEM_HIDDEN_DIR_FOUND: /usr/local/var/lib/rkhunter/db/i18n/en
  12354. + cut -d: -f2-
  12355. + [ 1 -eq 1 ]
  12356. + LINE1=0
  12357. + continue
  12358. + IFS='
  12359. '
  12360. + test 0 -eq 1 -a 0 -eq 1
  12361. + return
  12362. + awk -F: '{ print $NF }'
  12363. + cut -c2-
  12364. + echo '/etc/.: cannot open `\033[1m\033[38;5;6m/etc/.\033[39;49m\033[m'\'' (No such file or directory)'
  12365. + FTYPE='cannot open `\033[1m\033[38;5;6m/etc/.\033[39;49m\033[m'\'' (No such file or directory)'
  12366. + echo '/etc/.: cannot open `\033[1m\033[38;5;6m/etc/.\033[39;49m\033[m'\'' (No such file or directory)'
  12367. + sed -e 's/: [^:]*$//'
  12368. + FNAME='/etc/.'
  12369. + [ 'cannot open `\033[1m\033[38;5;6m/etc/.\033[39;49m\033[m'\'' (No such file or directory)' = directory ]
  12370. + name2text '/etc/.'
  12371. + sed -e 's/ /<SP>/g; s/ /<TAB>/g'
  12372. + tr -d '\n'
  12373. + echo -e '/etc/.'
  12374. + tr '[:cntrl:]' '?'
  12375. + return
  12376. + display --to LOG --type WARNING FILESYSTEM_HIDDEN_DIR_FOUND '?[1m?[38;5;6m/etc/.?[39;49m?[m: cannot open `\033[1m\033[38;5;6m/etc/.\033[39;49m\033[m'\'' (No such file or directory)'
  12377. + WARN_MSG=0
  12378. + NL=0
  12379. + NLAFTER=0
  12380. + LOGINDENT=0
  12381. + SCREENINDENT=0
  12382. + LOGNL=0
  12383. + SCREENNL=0
  12384. + WRITETO=''
  12385. + TYPE=''
  12386. + RESULT=''
  12387. + COLOR=''
  12388. + MSG=''
  12389. + LINE1=''
  12390. + LOGLINE1=''
  12391. + SPACES=''
  12392. + NONL=''
  12393. + DISPLAY_LINE='display --to
  12394. LOG
  12395. --type
  12396. WARNING
  12397. FILESYSTEM_HIDDEN_DIR_FOUND
  12398. ?[1m?[38;5;6m/etc/.?[39;49m?[m: cannot open `\033[1m\033[38;5;6m/etc/.\033[39;49m\033[m'\'' (No such file or directory)'
  12399. + [ 6 -le 0 ]
  12400. + [ 6 -ge 1 ]
  12401. + WRITETO=LOG
  12402. + shift
  12403. + shift
  12404. + [ 4 -ge 1 ]
  12405. + eval echo '$MSG_TYPE_WARNING'
  12406. + echo Warning
  12407. + TYPE=Warning
  12408. + [ -z Warning -a WARNING != PLAIN ]
  12409. + test WARNING = WARNING
  12410. + WARN_MSG=1
  12411. + shift
  12412. + shift
  12413. + [ 2 -ge 1 ]
  12414. + MSG=FILESYSTEM_HIDDEN_DIR_FOUND
  12415. + shift
  12416. + break
  12417. + test 1 -eq 1
  12418. + expr 2 + 1
  12419. + WARNING_COUNT=3
  12420. + [ 0 -eq 1 ]
  12421. + [ 0 -eq 1 ]
  12422. + test LOG = SCREEN -o LOG = SCREEN+LOG
  12423. + WRITETOTTY=0
  12424. + test LOG = LOG -o LOG = SCREEN+LOG
  12425. + WRITETOLOG=1
  12426. + [ 0 -eq 0 -a 1 -eq 0 ]
  12427. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  12428. + test -n Warning
  12429. + NONL=''
  12430. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  12431. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  12432. + [ -n FILESYSTEM_HIDDEN_DIR_FOUND ]
  12433. + head '-n 1'
  12434. + cut -d: -f2-
  12435. + grep -a ^FILESYSTEM_HIDDEN_DIR_FOUND: /usr/local/var/lib/rkhunter/db/i18n/en
  12436. + LINE1='Hidden directory found: $1'
  12437. + [ 0 -eq 1 ]
  12438. + [ -z 'Hidden directory found: $1' ]
  12439. + sed -e 's/`/\\`/g'
  12440. + echo 'Hidden directory found: $1'
  12441. + LINE1='Hidden directory found: $1'
  12442. + test -n 'Hidden directory found: $1'
  12443. + eval 'echo "Hidden directory found: $1" | sed -e '\''s/;/\;/g'\'
  12444. + sed -e 's/;/\;/g'
  12445. + echo 'Hidden directory found: ?[1m?[38;5;6m/etc/.?[39;49m?[m: cannot open `\033[1m\033[38;5;6m/etc/.\033[39;49m\033[m'\'' (No such file or directory)'
  12446. + LINE1='Hidden directory found: ?[1m?[38;5;6m/etc/.?[39;49m?[m: cannot open `\033[1m\033[38;5;6m/etc/.\033[39;49m\033[m'\'' (No such file or directory)'
  12447. + [ 1 -eq 1 ]
  12448. + date '+[%H:%M:%S]'
  12449. + LOGLINE1='[04:22:09]'
  12450. + test 0 -gt 0 -o 0 -eq 1
  12451. + [ -n Warning ]
  12452. + LOGLINE1='[04:22:09] Warning: Hidden directory found: ?[1m?[38;5;6m/etc/.?[39;49m?[m: cannot open `\033[1m\033[38;5;6m/etc/.\033[39;49m\033[m'\'' (No such file or directory)'
  12453. + [ 0 -eq 1 -a 0 -gt 0 ]
  12454. + [ -n '' ]
  12455. + [ 0 -eq 1 -a -n '' ]
  12456. + [ 0 -eq 1 ]
  12457. + [ 0 -eq 1 ]
  12458. + [ 1 -eq 1 ]
  12459. + echo -e '[04:22:09] Warning: Hidden directory found: ?[1m?[38;5;6m/etc/.?[39;49m?[m: cannot open `\033[1m\033[38;5;6m/etc/.\033[39;49m\033[m'\'' (No such file or directory)'
  12460. + [ 1 -eq 1 ]
  12461. + test 0 -eq 1
  12462. + LINE1=1
  12463. + OLDIFS='
  12464. '
  12465. + IFS='
  12466. '
  12467. + cut -d: -f2-
  12468. + grep -a ^FILESYSTEM_HIDDEN_DIR_FOUND: /usr/local/var/lib/rkhunter/db/i18n/en
  12469. + [ 1 -eq 1 ]
  12470. + LINE1=0
  12471. + continue
  12472. + IFS='
  12473. '
  12474. + test 0 -eq 1 -a 0 -eq 1
  12475. + return
  12476. + echo '/etc/..: cannot open `\033[1m\033[38;5;6m/etc/..\033[39;49m\033[m'\'' (No such file or directory)'
  12477. + awk -F: '{ print $NF }'
  12478. + cut -c2-
  12479. + FTYPE='cannot open `\033[1m\033[38;5;6m/etc/..\033[39;49m\033[m'\'' (No such file or directory)'
  12480. + sed -e 's/: [^:]*$//'
  12481. + echo '/etc/..: cannot open `\033[1m\033[38;5;6m/etc/..\033[39;49m\033[m'\'' (No such file or directory)'
  12482. + FNAME='/etc/..'
  12483. + [ 'cannot open `\033[1m\033[38;5;6m/etc/..\033[39;49m\033[m'\'' (No such file or directory)' = directory ]
  12484. + name2text '/etc/..'
  12485. + echo -e '/etc/..'
  12486. + sed -e 's/ /<SP>/g; s/ /<TAB>/g'
  12487. + tr -d '\n'
  12488. + tr '[:cntrl:]' '?'
  12489. + return
  12490. + display --to LOG --type WARNING FILESYSTEM_HIDDEN_DIR_FOUND '?[1m?[38;5;6m/etc/..?[39;49m?[m: cannot open `\033[1m\033[38;5;6m/etc/..\033[39;49m\033[m'\'' (No such file or directory)'
  12491. + WARN_MSG=0
  12492. + NL=0
  12493. + NLAFTER=0
  12494. + LOGINDENT=0
  12495. + SCREENINDENT=0
  12496. + LOGNL=0
  12497. + SCREENNL=0
  12498. + WRITETO=''
  12499. + TYPE=''
  12500. + RESULT=''
  12501. + COLOR=''
  12502. + MSG=''
  12503. + LINE1=''
  12504. + LOGLINE1=''
  12505. + SPACES=''
  12506. + NONL=''
  12507. + DISPLAY_LINE='display --to
  12508. LOG
  12509. --type
  12510. WARNING
  12511. FILESYSTEM_HIDDEN_DIR_FOUND
  12512. ?[1m?[38;5;6m/etc/..?[39;49m?[m: cannot open `\033[1m\033[38;5;6m/etc/..\033[39;49m\033[m'\'' (No such file or directory)'
  12513. + [ 6 -le 0 ]
  12514. + [ 6 -ge 1 ]
  12515. + WRITETO=LOG
  12516. + shift
  12517. + shift
  12518. + [ 4 -ge 1 ]
  12519. + eval echo '$MSG_TYPE_WARNING'
  12520. + echo Warning
  12521. + TYPE=Warning
  12522. + [ -z Warning -a WARNING != PLAIN ]
  12523. + test WARNING = WARNING
  12524. + WARN_MSG=1
  12525. + shift
  12526. + shift
  12527. + [ 2 -ge 1 ]
  12528. + MSG=FILESYSTEM_HIDDEN_DIR_FOUND
  12529. + shift
  12530. + break
  12531. + test 1 -eq 1
  12532. + expr 3 + 1
  12533. + WARNING_COUNT=4
  12534. + [ 0 -eq 1 ]
  12535. + [ 0 -eq 1 ]
  12536. + test LOG = SCREEN -o LOG = SCREEN+LOG
  12537. + WRITETOTTY=0
  12538. + test LOG = LOG -o LOG = SCREEN+LOG
  12539. + WRITETOLOG=1
  12540. + [ 0 -eq 0 -a 1 -eq 0 ]
  12541. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  12542. + test -n Warning
  12543. + NONL=''
  12544. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  12545. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  12546. + [ -n FILESYSTEM_HIDDEN_DIR_FOUND ]
  12547. + grep -a ^FILESYSTEM_HIDDEN_DIR_FOUND: /usr/local/var/lib/rkhunter/db/i18n/en
  12548. + cut -d: -f2-
  12549. + head '-n 1'
  12550. + LINE1='Hidden directory found: $1'
  12551. + [ 0 -eq 1 ]
  12552. + [ -z 'Hidden directory found: $1' ]
  12553. + echo 'Hidden directory found: $1'
  12554. + sed -e 's/`/\\`/g'
  12555. + LINE1='Hidden directory found: $1'
  12556. + test -n 'Hidden directory found: $1'
  12557. + eval 'echo "Hidden directory found: $1" | sed -e '\''s/;/\;/g'\'
  12558. + echo 'Hidden directory found: ?[1m?[38;5;6m/etc/..?[39;49m?[m: cannot open `\033[1m\033[38;5;6m/etc/..\033[39;49m\033[m'\'' (No such file or directory)'
  12559. + sed -e 's/;/\;/g'
  12560. + LINE1='Hidden directory found: ?[1m?[38;5;6m/etc/..?[39;49m?[m: cannot open `\033[1m\033[38;5;6m/etc/..\033[39;49m\033[m'\'' (No such file or directory)'
  12561. + [ 1 -eq 1 ]
  12562. + date '+[%H:%M:%S]'
  12563. + LOGLINE1='[04:22:10]'
  12564. + test 0 -gt 0 -o 0 -eq 1
  12565. + [ -n Warning ]
  12566. + LOGLINE1='[04:22:10] Warning: Hidden directory found: ?[1m?[38;5;6m/etc/..?[39;49m?[m: cannot open `\033[1m\033[38;5;6m/etc/..\033[39;49m\033[m'\'' (No such file or directory)'
  12567. + [ 0 -eq 1 -a 0 -gt 0 ]
  12568. + [ -n '' ]
  12569. + [ 0 -eq 1 -a -n '' ]
  12570. + [ 0 -eq 1 ]
  12571. + [ 0 -eq 1 ]
  12572. + [ 1 -eq 1 ]
  12573. + echo -e '[04:22:10] Warning: Hidden directory found: ?[1m?[38;5;6m/etc/..?[39;49m?[m: cannot open `\033[1m\033[38;5;6m/etc/..\033[39;49m\033[m'\'' (No such file or directory)'
  12574. + [ 1 -eq 1 ]
  12575. + test 0 -eq 1
  12576. + LINE1=1
  12577. + OLDIFS='
  12578. '
  12579. + IFS='
  12580. '
  12581. + grep -a ^FILESYSTEM_HIDDEN_DIR_FOUND: /usr/local/var/lib/rkhunter/db/i18n/en
  12582. + cut -d: -f2-
  12583. + [ 1 -eq 1 ]
  12584. + LINE1=0
  12585. + continue
  12586. + IFS='
  12587. '
  12588. + test 0 -eq 1 -a 0 -eq 1
  12589. + return
  12590. + IFS='
  12591. '
  12592. + FOUNDFILES=''
  12593. + [ -n '' ]
  12594. + display --to LOG --type PLAIN --result SKIPPED --log-indent 2 FILESYSTEM_LOGFILE_MISSING
  12595. + WARN_MSG=0
  12596. + NL=0
  12597. + NLAFTER=0
  12598. + LOGINDENT=0
  12599. + SCREENINDENT=0
  12600. + LOGNL=0
  12601. + SCREENNL=0
  12602. + WRITETO=''
  12603. + TYPE=''
  12604. + RESULT=''
  12605. + COLOR=''
  12606. + MSG=''
  12607. + LINE1=''
  12608. + LOGLINE1=''
  12609. + SPACES=''
  12610. + NONL=''
  12611. + DISPLAY_LINE='display --to LOG --type PLAIN --result SKIPPED --log-indent 2 FILESYSTEM_LOGFILE_MISSING'
  12612. + [ 9 -le 0 ]
  12613. + [ 9 -ge 1 ]
  12614. + WRITETO=LOG
  12615. + shift
  12616. + shift
  12617. + [ 7 -ge 1 ]
  12618. + eval echo '$MSG_TYPE_PLAIN'
  12619. + echo
  12620. + TYPE=''
  12621. + [ -z '' -a PLAIN != PLAIN ]
  12622. + test PLAIN = WARNING
  12623. + shift
  12624. + shift
  12625. + [ 5 -ge 1 ]
  12626. + eval echo '$MSG_RESULT_SKIPPED'
  12627. + echo Skipped
  12628. + RESULT=Skipped
  12629. + [ -z Skipped ]
  12630. + shift
  12631. + shift
  12632. + [ 3 -ge 1 ]
  12633. + LOGINDENT=2
  12634. + [ -z 2 ]
  12635. + grep '^[0-9]*$'
  12636. + echo 2
  12637. + [ -z 2 ]
  12638. + shift
  12639. + shift
  12640. + [ 1 -ge 1 ]
  12641. + MSG=FILESYSTEM_LOGFILE_MISSING
  12642. + shift
  12643. + break
  12644. + test 0 -eq 1
  12645. + [ 0 -eq 1 ]
  12646. + [ 0 -eq 1 ]
  12647. + test LOG = SCREEN -o LOG = SCREEN+LOG
  12648. + WRITETOTTY=0
  12649. + test LOG = LOG -o LOG = SCREEN+LOG
  12650. + WRITETOLOG=1
  12651. + [ 0 -eq 0 -a 1 -eq 0 ]
  12652. + [ 0 -eq 1 -a 1 -eq 1 -a -n Skipped -a -z '' ]
  12653. + test -n ''
  12654. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a Skipped = Whitelisted ]
  12655. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  12656. + [ -n FILESYSTEM_LOGFILE_MISSING ]
  12657. + grep -a ^FILESYSTEM_LOGFILE_MISSING: /usr/local/var/lib/rkhunter/db/i18n/en
  12658. + cut -d: -f2-
  12659. + head -n 1
  12660. + LINE1='Checking for missing log files'
  12661. + [ 0 -eq 1 ]
  12662. + [ -z 'Checking for missing log files' ]
  12663. + echo 'Checking for missing log files'
  12664. + sed -e 's/`/\\`/g'
  12665. + LINE1='Checking for missing log files'
  12666. + test -n 'Checking for missing log files'
  12667. + eval 'echo "Checking for missing log files" | sed -e '\''s/;/\;/g'\'
  12668. + echo 'Checking for missing log files'
  12669. + sed -e 's/;/\;/g'
  12670. + LINE1='Checking for missing log files'
  12671. + [ 1 -eq 1 ]
  12672. + date '+[%H:%M:%S]'
  12673. + LOGLINE1='[04:22:10]'
  12674. + test 0 -gt 0 -o 0 -eq 1
  12675. + [ -n '' ]
  12676. + test 2 -gt 0
  12677. + echo ' '
  12678. + cut -c1-2
  12679. + SPACES=' '
  12680. + LOGLINE1='[04:22:10] Checking for missing log files'
  12681. + [ 0 -eq 1 -a 0 -gt 0 ]
  12682. + [ -n Skipped ]
  12683. + [ 0 -eq 1 ]
  12684. + [ 1 -eq 1 ]
  12685. + echo '[04:22:10] Checking for missing log files'
  12686. + tr -d ' '
  12687. + wc -c
  12688. + LOGLINE1_NUM=44
  12689. + expr 62 - 44
  12690. + NUM_SPACES=18
  12691. + test 18 -lt 1
  12692. + echo ' '
  12693. + cut -c1-18
  12694. + SPACES=' '
  12695. + LOGLINE1='[04:22:10] Checking for missing log files [ Skipped ]'
  12696. + [ 0 -eq 1 ]
  12697. + [ 0 -eq 1 ]
  12698. + [ 1 -eq 1 ]
  12699. + echo -e '[04:22:10] Checking for missing log files [ Skipped ]'
  12700. + [ 0 -eq 1 ]
  12701. + echo '[04:22:10] Checking for missing log files [ Skipped ]'
  12702. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  12703. + [ 0 -eq 1 -a -n '' ]
  12704. + test 0 -eq 1 -a 0 -eq 1
  12705. + return
  12706. + [ -n '' ]
  12707. + display --to LOG --type PLAIN --result SKIPPED --log-indent 2 FILESYSTEM_LOGFILE_EMPTY
  12708. + WARN_MSG=0
  12709. + NL=0
  12710. + NLAFTER=0
  12711. + LOGINDENT=0
  12712. + SCREENINDENT=0
  12713. + LOGNL=0
  12714. + SCREENNL=0
  12715. + WRITETO=''
  12716. + TYPE=''
  12717. + RESULT=''
  12718. + COLOR=''
  12719. + MSG=''
  12720. + LINE1=''
  12721. + LOGLINE1=''
  12722. + SPACES=''
  12723. + NONL=''
  12724. + DISPLAY_LINE='display --to LOG --type PLAIN --result SKIPPED --log-indent 2 FILESYSTEM_LOGFILE_EMPTY'
  12725. + [ 9 -le 0 ]
  12726. + [ 9 -ge 1 ]
  12727. + WRITETO=LOG
  12728. + shift
  12729. + shift
  12730. + [ 7 -ge 1 ]
  12731. + eval echo '$MSG_TYPE_PLAIN'
  12732. + echo
  12733. + TYPE=''
  12734. + [ -z '' -a PLAIN != PLAIN ]
  12735. + test PLAIN = WARNING
  12736. + shift
  12737. + shift
  12738. + [ 5 -ge 1 ]
  12739. + eval echo '$MSG_RESULT_SKIPPED'
  12740. + echo Skipped
  12741. + RESULT=Skipped
  12742. + [ -z Skipped ]
  12743. + shift
  12744. + shift
  12745. + [ 3 -ge 1 ]
  12746. + LOGINDENT=2
  12747. + [ -z 2 ]
  12748. + grep '^[0-9]*$'
  12749. + echo 2
  12750. + [ -z 2 ]
  12751. + shift
  12752. + shift
  12753. + [ 1 -ge 1 ]
  12754. + MSG=FILESYSTEM_LOGFILE_EMPTY
  12755. + shift
  12756. + break
  12757. + test 0 -eq 1
  12758. + [ 0 -eq 1 ]
  12759. + [ 0 -eq 1 ]
  12760. + test LOG = SCREEN -o LOG = SCREEN+LOG
  12761. + WRITETOTTY=0
  12762. + test LOG = LOG -o LOG = SCREEN+LOG
  12763. + WRITETOLOG=1
  12764. + [ 0 -eq 0 -a 1 -eq 0 ]
  12765. + [ 0 -eq 1 -a 1 -eq 1 -a -n Skipped -a -z '' ]
  12766. + test -n ''
  12767. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a Skipped = Whitelisted ]
  12768. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  12769. + [ -n FILESYSTEM_LOGFILE_EMPTY ]
  12770. + grep -a ^FILESYSTEM_LOGFILE_EMPTY: /usr/local/var/lib/rkhunter/db/i18n/en
  12771. + cut -d: -f2-
  12772. + head -n 1
  12773. + LINE1='Checking for empty log files'
  12774. + [ 0 -eq 1 ]
  12775. + [ -z 'Checking for empty log files' ]
  12776. + echo 'Checking for empty log files'
  12777. + sed -e 's/`/\\`/g'
  12778. + LINE1='Checking for empty log files'
  12779. + test -n 'Checking for empty log files'
  12780. + eval 'echo "Checking for empty log files" | sed -e '\''s/;/\;/g'\'
  12781. + echo 'Checking for empty log files'
  12782. + sed -e 's/;/\;/g'
  12783. + LINE1='Checking for empty log files'
  12784. + [ 1 -eq 1 ]
  12785. + date '+[%H:%M:%S]'
  12786. + LOGLINE1='[04:22:10]'
  12787. + test 0 -gt 0 -o 0 -eq 1
  12788. + [ -n '' ]
  12789. + test 2 -gt 0
  12790. + echo ' '
  12791. + cut -c1-2
  12792. + SPACES=' '
  12793. + LOGLINE1='[04:22:10] Checking for empty log files'
  12794. + [ 0 -eq 1 -a 0 -gt 0 ]
  12795. + [ -n Skipped ]
  12796. + [ 0 -eq 1 ]
  12797. + [ 1 -eq 1 ]
  12798. + echo '[04:22:10] Checking for empty log files'
  12799. + tr -d ' '
  12800. + wc -c
  12801. + LOGLINE1_NUM=42
  12802. + expr 62 - 42
  12803. + NUM_SPACES=20
  12804. + test 20 -lt 1
  12805. + echo ' '
  12806. + cut -c1-20
  12807. + SPACES=' '
  12808. + LOGLINE1='[04:22:10] Checking for empty log files [ Skipped ]'
  12809. + [ 0 -eq 1 ]
  12810. + [ 0 -eq 1 ]
  12811. + [ 1 -eq 1 ]
  12812. + echo -e '[04:22:10] Checking for empty log files [ Skipped ]'
  12813. + [ 0 -eq 1 ]
  12814. + echo '[04:22:10] Checking for empty log files [ Skipped ]'
  12815. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  12816. + [ 0 -eq 1 -a -n '' ]
  12817. + test 0 -eq 1 -a 0 -eq 1
  12818. + return
  12819. + return
  12820. + keypresspause
  12821. + [ 1 -eq 0 -a 0 -eq 0 ]
  12822. + return
  12823. + return
  12824. + do_app_checks
  12825. + check_test apps
  12826. + echo ' filesystem local_host '
  12827. + grep ' apps '
  12828. + [ 'filesystem local_host' = all -o -n '' ]
  12829. + return 1
  12830. +
  12831. + display --to LOG --type INFO --nl USER_DISABLED_TEST apps
  12832. + WARN_MSG=0
  12833. + NL=0
  12834. + NLAFTER=0
  12835. + LOGINDENT=0
  12836. + SCREENINDENT=0
  12837. + LOGNL=0
  12838. + SCREENNL=0
  12839. + WRITETO=''
  12840. + TYPE=''
  12841. + RESULT=''
  12842. + COLOR=''
  12843. + MSG=''
  12844. + LINE1=''
  12845. + LOGLINE1=''
  12846. + SPACES=''
  12847. + NONL=''
  12848. + DISPLAY_LINE='display --to LOG --type INFO --nl USER_DISABLED_TEST apps'
  12849. + [ 7 -le 0 ]
  12850. + [ 7 -ge 1 ]
  12851. + WRITETO=LOG
  12852. + shift
  12853. + shift
  12854. + [ 5 -ge 1 ]
  12855. + eval echo '$MSG_TYPE_INFO'
  12856. + echo Info
  12857. + TYPE=Info
  12858. + [ -z Info -a INFO != PLAIN ]
  12859. + test INFO = WARNING
  12860. + shift
  12861. + shift
  12862. + [ 3 -ge 1 ]
  12863. + NL=1
  12864. + shift
  12865. + [ 2 -ge 1 ]
  12866. + MSG=USER_DISABLED_TEST
  12867. + shift
  12868. + break
  12869. + test 0 -eq 1
  12870. + [ 0 -eq 1 ]
  12871. + [ 0 -eq 1 ]
  12872. + test LOG = SCREEN -o LOG = SCREEN+LOG
  12873. + WRITETOTTY=0
  12874. + test LOG = LOG -o LOG = SCREEN+LOG
  12875. + WRITETOLOG=1
  12876. + [ 0 -eq 0 -a 1 -eq 0 ]
  12877. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  12878. + test -n Info
  12879. + NONL=''
  12880. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  12881. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  12882. + [ -n USER_DISABLED_TEST ]
  12883. + grep -a ^USER_DISABLED_TEST: /usr/local/var/lib/rkhunter/db/i18n/en
  12884. + cut -d: -f2-
  12885. + head -n 1
  12886. + LINE1='Test '\''$1'\'' disabled at users request.'
  12887. + [ 0 -eq 1 ]
  12888. + [ -z 'Test '\''$1'\'' disabled at users request.' ]
  12889. + echo 'Test '\''$1'\'' disabled at users request.'
  12890. + sed -e 's/`/\\`/g'
  12891. + LINE1='Test '\''$1'\'' disabled at users request.'
  12892. + test -n 'Test '\''$1'\'' disabled at users request.'
  12893. + eval 'echo "Test '\''$1'\'' disabled at users request." | sed -e '\''s/;/\;/g'\'
  12894. + echo 'Test '\''apps'\'' disabled at users request.'
  12895. + sed -e 's/;/\;/g'
  12896. + LINE1='Test '\''apps'\'' disabled at users request.'
  12897. + [ 1 -eq 1 ]
  12898. + date '+[%H:%M:%S]'
  12899. + LOGLINE1='[04:22:11]'
  12900. + test 1 -gt 0 -o 0 -eq 1
  12901. + echo '[04:22:11]'
  12902. + [ -n Info ]
  12903. + LOGLINE1='[04:22:11] Info: Test '\''apps'\'' disabled at users request.'
  12904. + [ 0 -eq 1 -a 0 -gt 0 ]
  12905. + [ -n '' ]
  12906. + [ 0 -eq 1 -a -n '' ]
  12907. + [ 0 -eq 1 ]
  12908. + [ 0 -eq 1 ]
  12909. + [ 1 -eq 1 ]
  12910. + echo -e '[04:22:11] Info: Test '\''apps'\'' disabled at users request.'
  12911. + [ 0 -eq 1 ]
  12912. + echo '[04:22:11] Info: Test '\''apps'\'' disabled at users request.'
  12913. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  12914. + [ 0 -eq 1 -a -n '' ]
  12915. + test 0 -eq 1 -a 0 -eq 1
  12916. + return
  12917. + return
  12918. + [ 1443954112 -ne 0 ]
  12919. + [ -n '' ]
  12920. + [ 1 -eq 1 ]
  12921. + date +%s
  12922. + ENDTIME=1443954131
  12923. + expr 1443954131 - 1443954112
  12924. + TOTAL_SCANTIME=19
  12925. + expr 19 / 60
  12926. + TOTALMINS=0
  12927. + expr 19 % 60
  12928. + TOTALSECS=19
  12929. + [ 0 -gt 0 ]
  12930. + TOTAL_SCANTIME=''
  12931. + [ 19 -eq 1 ]
  12932. + TOTAL_SCANTIME='19 seconds'
  12933. + RKH_WARN_DISPLYD=0
  12934. + [ 1 -eq 1 ]
  12935. + OLD_NOTTY=0
  12936. + test 0 -eq 1
  12937. + display_check_summary
  12938. + [ 0 -eq 0 -o '(' 0 -eq 1 -a 4 -gt 0 ')' ]
  12939. + RKHTMPVAR=2
  12940. + display --to SCREEN+LOG --type PLAIN --nl 2 SUMMARY_TITLE1
  12941. + WARN_MSG=0
  12942. + NL=0
  12943. + NLAFTER=0
  12944. + LOGINDENT=0
  12945. + SCREENINDENT=0
  12946. + LOGNL=0
  12947. + SCREENNL=0
  12948. + WRITETO=''
  12949. + TYPE=''
  12950. + RESULT=''
  12951. + COLOR=''
  12952. + MSG=''
  12953. + LINE1=''
  12954. + LOGLINE1=''
  12955. + SPACES=''
  12956. + NONL=''
  12957. + DISPLAY_LINE='display --to SCREEN+LOG --type PLAIN --nl 2 SUMMARY_TITLE1'
  12958. + [ 7 -le 0 ]
  12959. + [ 7 -ge 1 ]
  12960. + WRITETO=SCREEN+LOG
  12961. + shift
  12962. + shift
  12963. + [ 5 -ge 1 ]
  12964. + eval echo '$MSG_TYPE_PLAIN'
  12965. + echo
  12966. + TYPE=''
  12967. + [ -z '' -a PLAIN != PLAIN ]
  12968. + test PLAIN = WARNING
  12969. + shift
  12970. + shift
  12971. + [ 3 -ge 1 ]
  12972. + NL=1
  12973. + NL=2
  12974. + shift
  12975. + shift
  12976. + [ 1 -ge 1 ]
  12977. + MSG=SUMMARY_TITLE1
  12978. + shift
  12979. + break
  12980. + test 0 -eq 1
  12981. + [ 0 -eq 1 ]
  12982. + [ 0 -eq 1 ]
  12983. + test SCREEN+LOG = SCREEN -o SCREEN+LOG = SCREEN+LOG
  12984. + WRITETOTTY=1
  12985. + test SCREEN+LOG = LOG -o SCREEN+LOG = SCREEN+LOG
  12986. + WRITETOLOG=1
  12987. + [ 1 -eq 0 -a 1 -eq 0 ]
  12988. + [ 1 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  12989. + test -n ''
  12990. + [ 0 -eq 1 -a 1 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  12991. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  12992. + [ -n SUMMARY_TITLE1 ]
  12993. + head -n 1
  12994. + cut -d: -f2-
  12995. + grep -a ^SUMMARY_TITLE1: /usr/local/var/lib/rkhunter/db/i18n/en
  12996. + LINE1='System checks summary'
  12997. + [ 0 -eq 1 ]
  12998. + [ -z 'System checks summary' ]
  12999. + echo 'System checks summary'
  13000. + sed -e 's/`/\\`/g'
  13001. + LINE1='System checks summary'
  13002. + test -n 'System checks summary'
  13003. + eval 'echo "System checks summary" | sed -e '\''s/;/\;/g'\'
  13004. + echo 'System checks summary'
  13005. + sed -e 's/;/\;/g'
  13006. + LINE1='System checks summary'
  13007. + [ 1 -eq 1 ]
  13008. + date '+[%H:%M:%S]'
  13009. + LOGLINE1='[04:22:11]'
  13010. + test 2 -gt 0 -o 0 -eq 1
  13011. + echo '[04:22:11]'
  13012. + [ -n '' ]
  13013. + test 0 -gt 0
  13014. + LOGLINE1='[04:22:11] System checks summary'
  13015. + [ 1 -eq 1 -a 0 -gt 0 ]
  13016. + [ -n '' ]
  13017. + [ 1 -eq 1 -a -n '' ]
  13018. + [ 0 -eq 1 ]
  13019. + [ 1 -eq 1 ]
  13020. + NLLOOP=2
  13021. + test 2 -gt 0
  13022. + echo ''
  13023.  
  13024. + expr 2 - 1
  13025. + NLLOOP=1
  13026. + test 1 -gt 0
  13027. + echo ''
  13028.  
  13029. + expr 1 - 1
  13030. + NLLOOP=0
  13031. + test 0 -gt 0
  13032. + [ '' = c ]
  13033. + echo -e 'System checks summary'
  13034. System checks summary
  13035. + [ 1 -eq 1 ]
  13036. + echo -e '[04:22:11] System checks summary'
  13037. + [ 0 -eq 1 ]
  13038. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  13039. + echo '[04:22:11] System checks summary'
  13040. + [ 0 -eq 1 -a -n '' ]
  13041. + test 1 -eq 1 -a 0 -eq 1
  13042. + return
  13043. + display --to SCREEN+LOG --type PLAIN SUMMARY_TITLE2
  13044. + WARN_MSG=0
  13045. + NL=0
  13046. + NLAFTER=0
  13047. + LOGINDENT=0
  13048. + SCREENINDENT=0
  13049. + LOGNL=0
  13050. + SCREENNL=0
  13051. + WRITETO=''
  13052. + TYPE=''
  13053. + RESULT=''
  13054. + COLOR=''
  13055. + MSG=''
  13056. + LINE1=''
  13057. + LOGLINE1=''
  13058. + SPACES=''
  13059. + NONL=''
  13060. + DISPLAY_LINE='display --to SCREEN+LOG --type PLAIN SUMMARY_TITLE2'
  13061. + [ 5 -le 0 ]
  13062. + [ 5 -ge 1 ]
  13063. + WRITETO=SCREEN+LOG
  13064. + shift
  13065. + shift
  13066. + [ 3 -ge 1 ]
  13067. + eval echo '$MSG_TYPE_PLAIN'
  13068. + echo
  13069. + TYPE=''
  13070. + [ -z '' -a PLAIN != PLAIN ]
  13071. + test PLAIN = WARNING
  13072. + shift
  13073. + shift
  13074. + [ 1 -ge 1 ]
  13075. + MSG=SUMMARY_TITLE2
  13076. + shift
  13077. + break
  13078. + test 0 -eq 1
  13079. + [ 0 -eq 1 ]
  13080. + [ 0 -eq 1 ]
  13081. + test SCREEN+LOG = SCREEN -o SCREEN+LOG = SCREEN+LOG
  13082. + WRITETOTTY=1
  13083. + test SCREEN+LOG = LOG -o SCREEN+LOG = SCREEN+LOG
  13084. + WRITETOLOG=1
  13085. + [ 1 -eq 0 -a 1 -eq 0 ]
  13086. + [ 1 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  13087. + test -n ''
  13088. + [ 0 -eq 1 -a 1 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  13089. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  13090. + [ -n SUMMARY_TITLE2 ]
  13091. + grep -a ^SUMMARY_TITLE2: /usr/local/var/lib/rkhunter/db/i18n/en
  13092. + head -n 1
  13093. + cut -d: -f2-
  13094. + LINE1======================
  13095. + [ 0 -eq 1 ]
  13096. + [ -z ===================== ]
  13097. + echo =====================
  13098. + sed -e 's/`/\\`/g'
  13099. + LINE1======================
  13100. + test -n =====================
  13101. + eval 'echo "=====================" | sed -e '\''s/;/\;/g'\'
  13102. + echo =====================
  13103. + sed -e 's/;/\;/g'
  13104. + LINE1======================
  13105. + [ 1 -eq 1 ]
  13106. + date '+[%H:%M:%S]'
  13107. + LOGLINE1='[04:22:11]'
  13108. + test 0 -gt 0 -o 0 -eq 1
  13109. + [ -n '' ]
  13110. + test 0 -gt 0
  13111. + LOGLINE1='[04:22:11] ====================='
  13112. + [ 1 -eq 1 -a 0 -gt 0 ]
  13113. + [ -n '' ]
  13114. + [ 1 -eq 1 -a -n '' ]
  13115. + [ 0 -eq 1 ]
  13116. + [ 1 -eq 1 ]
  13117. + NLLOOP=0
  13118. + test 0 -gt 0
  13119. + [ '' = c ]
  13120. + echo -e =====================
  13121. =====================
  13122. + [ 1 -eq 1 ]
  13123. + echo -e '[04:22:11] ====================='
  13124. + [ 0 -eq 1 ]
  13125. + echo '[04:22:11] ====================='
  13126. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  13127. + [ 0 -eq 1 -a -n '' ]
  13128. + test 1 -eq 1 -a 0 -eq 1
  13129. + return
  13130. + display --to SCREEN+LOG --type PLAIN --nl SUMMARY_PROP_SCAN
  13131. + WARN_MSG=0
  13132. + NL=0
  13133. + NLAFTER=0
  13134. + LOGINDENT=0
  13135. + SCREENINDENT=0
  13136. + LOGNL=0
  13137. + SCREENNL=0
  13138. + WRITETO=''
  13139. + TYPE=''
  13140. + RESULT=''
  13141. + COLOR=''
  13142. + MSG=''
  13143. + LINE1=''
  13144. + LOGLINE1=''
  13145. + SPACES=''
  13146. + NONL=''
  13147. + DISPLAY_LINE='display --to SCREEN+LOG --type PLAIN --nl SUMMARY_PROP_SCAN'
  13148. + [ 6 -le 0 ]
  13149. + [ 6 -ge 1 ]
  13150. + WRITETO=SCREEN+LOG
  13151. + shift
  13152. + shift
  13153. + [ 4 -ge 1 ]
  13154. + eval echo '$MSG_TYPE_PLAIN'
  13155. + echo
  13156. + TYPE=''
  13157. + [ -z '' -a PLAIN != PLAIN ]
  13158. + test PLAIN = WARNING
  13159. + shift
  13160. + shift
  13161. + [ 2 -ge 1 ]
  13162. + NL=1
  13163. + shift
  13164. + [ 1 -ge 1 ]
  13165. + MSG=SUMMARY_PROP_SCAN
  13166. + shift
  13167. + break
  13168. + test 0 -eq 1
  13169. + [ 0 -eq 1 ]
  13170. + [ 0 -eq 1 ]
  13171. + test SCREEN+LOG = SCREEN -o SCREEN+LOG = SCREEN+LOG
  13172. + WRITETOTTY=1
  13173. + test SCREEN+LOG = LOG -o SCREEN+LOG = SCREEN+LOG
  13174. + WRITETOLOG=1
  13175. + [ 1 -eq 0 -a 1 -eq 0 ]
  13176. + [ 1 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  13177. + test -n ''
  13178. + [ 0 -eq 1 -a 1 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  13179. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  13180. + [ -n SUMMARY_PROP_SCAN ]
  13181. + head -n 1
  13182. + cut -d: -f2-
  13183. + grep -a ^SUMMARY_PROP_SCAN: /usr/local/var/lib/rkhunter/db/i18n/en
  13184. + LINE1='File properties checks...'
  13185. + [ 0 -eq 1 ]
  13186. + [ -z 'File properties checks...' ]
  13187. + sed -e 's/`/\\`/g'
  13188. + echo 'File properties checks...'
  13189. + LINE1='File properties checks...'
  13190. + test -n 'File properties checks...'
  13191. + eval 'echo "File properties checks..." | sed -e '\''s/;/\;/g'\'
  13192. + sed -e 's/;/\;/g'
  13193. + echo 'File properties checks...'
  13194. + LINE1='File properties checks...'
  13195. + [ 1 -eq 1 ]
  13196. + date '+[%H:%M:%S]'
  13197. + LOGLINE1='[04:22:11]'
  13198. + test 1 -gt 0 -o 0 -eq 1
  13199. + echo '[04:22:11]'
  13200. + [ -n '' ]
  13201. + test 0 -gt 0
  13202. + LOGLINE1='[04:22:11] File properties checks...'
  13203. + [ 1 -eq 1 -a 0 -gt 0 ]
  13204. + [ -n '' ]
  13205. + [ 1 -eq 1 -a -n '' ]
  13206. + [ 0 -eq 1 ]
  13207. + [ 1 -eq 1 ]
  13208. + NLLOOP=1
  13209. + test 1 -gt 0
  13210. + echo ''
  13211.  
  13212. + expr 1 - 1
  13213. + NLLOOP=0
  13214. + test 0 -gt 0
  13215. + [ '' = c ]
  13216. + echo -e 'File properties checks...'
  13217. File properties checks...
  13218. + [ 1 -eq 1 ]
  13219. + echo -e '[04:22:11] File properties checks...'
  13220. + [ 0 -eq 1 ]
  13221. + echo '[04:22:11] File properties checks...'
  13222. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  13223. + [ 0 -eq 1 -a -n '' ]
  13224. + test 1 -eq 1 -a 0 -eq 1
  13225. + return
  13226. + check_test properties
  13227. + echo ' filesystem local_host '
  13228. + grep ' properties '
  13229. + [ 'filesystem local_host' = all -o -n '' ]
  13230. + return 1
  13231. +
  13232. + display --to SCREEN+LOG --type PLAIN --screen-indent 4 SUMMARY_CHKS_SKIPPED
  13233. + WARN_MSG=0
  13234. + NL=0
  13235. + NLAFTER=0
  13236. + LOGINDENT=0
  13237. + SCREENINDENT=0
  13238. + LOGNL=0
  13239. + SCREENNL=0
  13240. + WRITETO=''
  13241. + TYPE=''
  13242. + RESULT=''
  13243. + COLOR=''
  13244. + MSG=''
  13245. + LINE1=''
  13246. + LOGLINE1=''
  13247. + SPACES=''
  13248. + NONL=''
  13249. + DISPLAY_LINE='display --to SCREEN+LOG --type PLAIN --screen-indent 4 SUMMARY_CHKS_SKIPPED'
  13250. + [ 7 -le 0 ]
  13251. + [ 7 -ge 1 ]
  13252. + WRITETO=SCREEN+LOG
  13253. + shift
  13254. + shift
  13255. + [ 5 -ge 1 ]
  13256. + eval echo '$MSG_TYPE_PLAIN'
  13257. + echo
  13258. + TYPE=''
  13259. + [ -z '' -a PLAIN != PLAIN ]
  13260. + test PLAIN = WARNING
  13261. + shift
  13262. + shift
  13263. + [ 3 -ge 1 ]
  13264. + SCREENINDENT=4
  13265. + [ -z 4 ]
  13266. + echo 4
  13267. + grep '^[0-9]*$'
  13268. + [ -z 4 ]
  13269. + shift
  13270. + shift
  13271. + [ 1 -ge 1 ]
  13272. + MSG=SUMMARY_CHKS_SKIPPED
  13273. + shift
  13274. + break
  13275. + test 0 -eq 1
  13276. + [ 0 -eq 1 ]
  13277. + [ 0 -eq 1 ]
  13278. + test SCREEN+LOG = SCREEN -o SCREEN+LOG = SCREEN+LOG
  13279. + WRITETOTTY=1
  13280. + test SCREEN+LOG = LOG -o SCREEN+LOG = SCREEN+LOG
  13281. + WRITETOLOG=1
  13282. + [ 1 -eq 0 -a 1 -eq 0 ]
  13283. + [ 1 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  13284. + test -n ''
  13285. + [ 0 -eq 1 -a 1 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  13286. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  13287. + [ -n SUMMARY_CHKS_SKIPPED ]
  13288. + head -n 1
  13289. + cut -d: -f2-
  13290. + grep -a ^SUMMARY_CHKS_SKIPPED: /usr/local/var/lib/rkhunter/db/i18n/en
  13291. + LINE1='All checks skipped'
  13292. + [ 0 -eq 1 ]
  13293. + [ -z 'All checks skipped' ]
  13294. + echo 'All checks skipped'
  13295. + sed -e 's/`/\\`/g'
  13296. + LINE1='All checks skipped'
  13297. + test -n 'All checks skipped'
  13298. + eval 'echo "All checks skipped" | sed -e '\''s/;/\;/g'\'
  13299. + sed -e 's/;/\;/g'
  13300. + echo 'All checks skipped'
  13301. + LINE1='All checks skipped'
  13302. + [ 1 -eq 1 ]
  13303. + date '+[%H:%M:%S]'
  13304. + LOGLINE1='[04:22:11]'
  13305. + test 0 -gt 0 -o 0 -eq 1
  13306. + [ -n '' ]
  13307. + test 0 -gt 0
  13308. + LOGLINE1='[04:22:11] All checks skipped'
  13309. + [ 1 -eq 1 -a 4 -gt 0 ]
  13310. + echo ' '
  13311. + cut -c1-4
  13312. + SPACES=' '
  13313. + LINE1=' All checks skipped'
  13314. + [ -n '' ]
  13315. + [ 1 -eq 1 -a -n '' ]
  13316. + [ 0 -eq 1 ]
  13317. + [ 1 -eq 1 ]
  13318. + NLLOOP=0
  13319. + test 0 -gt 0
  13320. + [ '' = c ]
  13321. + echo -e ' All checks skipped'
  13322. All checks skipped
  13323. + [ 1 -eq 1 ]
  13324. + echo -e '[04:22:11] All checks skipped'
  13325. + [ 0 -eq 1 ]
  13326. + echo '[04:22:11] All checks skipped'
  13327. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  13328. + [ 0 -eq 1 -a -n '' ]
  13329. + test 1 -eq 1 -a 0 -eq 1
  13330. + return
  13331. + display --to SCREEN+LOG --type PLAIN --nl SUMMARY_RKT_SCAN
  13332. + WARN_MSG=0
  13333. + NL=0
  13334. + NLAFTER=0
  13335. + LOGINDENT=0
  13336. + SCREENINDENT=0
  13337. + LOGNL=0
  13338. + SCREENNL=0
  13339. + WRITETO=''
  13340. + TYPE=''
  13341. + RESULT=''
  13342. + COLOR=''
  13343. + MSG=''
  13344. + LINE1=''
  13345. + LOGLINE1=''
  13346. + SPACES=''
  13347. + NONL=''
  13348. + DISPLAY_LINE='display --to SCREEN+LOG --type PLAIN --nl SUMMARY_RKT_SCAN'
  13349. + [ 6 -le 0 ]
  13350. + [ 6 -ge 1 ]
  13351. + WRITETO=SCREEN+LOG
  13352. + shift
  13353. + shift
  13354. + [ 4 -ge 1 ]
  13355. + eval echo '$MSG_TYPE_PLAIN'
  13356. + echo
  13357. + TYPE=''
  13358. + [ -z '' -a PLAIN != PLAIN ]
  13359. + test PLAIN = WARNING
  13360. + shift
  13361. + shift
  13362. + [ 2 -ge 1 ]
  13363. + NL=1
  13364. + shift
  13365. + [ 1 -ge 1 ]
  13366. + MSG=SUMMARY_RKT_SCAN
  13367. + shift
  13368. + break
  13369. + test 0 -eq 1
  13370. + [ 0 -eq 1 ]
  13371. + [ 0 -eq 1 ]
  13372. + test SCREEN+LOG = SCREEN -o SCREEN+LOG = SCREEN+LOG
  13373. + WRITETOTTY=1
  13374. + test SCREEN+LOG = LOG -o SCREEN+LOG = SCREEN+LOG
  13375. + WRITETOLOG=1
  13376. + [ 1 -eq 0 -a 1 -eq 0 ]
  13377. + [ 1 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  13378. + test -n ''
  13379. + [ 0 -eq 1 -a 1 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  13380. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  13381. + [ -n SUMMARY_RKT_SCAN ]
  13382. + grep -a ^SUMMARY_RKT_SCAN: /usr/local/var/lib/rkhunter/db/i18n/en
  13383. + cut -d: -f2-
  13384. + head -n 1
  13385. + LINE1='Rootkit checks...'
  13386. + [ 0 -eq 1 ]
  13387. + [ -z 'Rootkit checks...' ]
  13388. + echo 'Rootkit checks...'
  13389. + sed -e 's/`/\\`/g'
  13390. + LINE1='Rootkit checks...'
  13391. + test -n 'Rootkit checks...'
  13392. + eval 'echo "Rootkit checks..." | sed -e '\''s/;/\;/g'\'
  13393. + echo 'Rootkit checks...'
  13394. + sed -e 's/;/\;/g'
  13395. + LINE1='Rootkit checks...'
  13396. + [ 1 -eq 1 ]
  13397. + date '+[%H:%M:%S]'
  13398. + LOGLINE1='[04:22:12]'
  13399. + test 1 -gt 0 -o 0 -eq 1
  13400. + echo '[04:22:12]'
  13401. + [ -n '' ]
  13402. + test 0 -gt 0
  13403. + LOGLINE1='[04:22:12] Rootkit checks...'
  13404. + [ 1 -eq 1 -a 0 -gt 0 ]
  13405. + [ -n '' ]
  13406. + [ 1 -eq 1 -a -n '' ]
  13407. + [ 0 -eq 1 ]
  13408. + [ 1 -eq 1 ]
  13409. + NLLOOP=1
  13410. + test 1 -gt 0
  13411. + echo ''
  13412.  
  13413. + expr 1 - 1
  13414. + NLLOOP=0
  13415. + test 0 -gt 0
  13416. + [ '' = c ]
  13417. + echo -e 'Rootkit checks...'
  13418. Rootkit checks...
  13419. + [ 1 -eq 1 ]
  13420. + echo -e '[04:22:12] Rootkit checks...'
  13421. + [ 0 -eq 1 ]
  13422. + echo '[04:22:12] Rootkit checks...'
  13423. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  13424. + [ 0 -eq 1 -a -n '' ]
  13425. + test 1 -eq 1 -a 0 -eq 1
  13426. + return
  13427. + check_test rootkits
  13428. + echo ' filesystem local_host '
  13429. + grep ' rootkits '
  13430. + [ 'filesystem local_host' = all -o -n '' ]
  13431. + return 1
  13432. + check_test startup_malware
  13433. + echo ' filesystem local_host '
  13434. + grep ' startup_malware '
  13435. + [ 'filesystem local_host' = all -o -n '' ]
  13436. + return 1
  13437. +
  13438. + test 0 -gt 0
  13439. + display --to SCREEN+LOG --type PLAIN --screen-indent 4 SUMMARY_CHKS_SKIPPED
  13440. + WARN_MSG=0
  13441. + NL=0
  13442. + NLAFTER=0
  13443. + LOGINDENT=0
  13444. + SCREENINDENT=0
  13445. + LOGNL=0
  13446. + SCREENNL=0
  13447. + WRITETO=''
  13448. + TYPE=''
  13449. + RESULT=''
  13450. + COLOR=''
  13451. + MSG=''
  13452. + LINE1=''
  13453. + LOGLINE1=''
  13454. + SPACES=''
  13455. + NONL=''
  13456. + DISPLAY_LINE='display --to SCREEN+LOG --type PLAIN --screen-indent 4 SUMMARY_CHKS_SKIPPED'
  13457. + [ 7 -le 0 ]
  13458. + [ 7 -ge 1 ]
  13459. + WRITETO=SCREEN+LOG
  13460. + shift
  13461. + shift
  13462. + [ 5 -ge 1 ]
  13463. + eval echo '$MSG_TYPE_PLAIN'
  13464. + echo
  13465. + TYPE=''
  13466. + [ -z '' -a PLAIN != PLAIN ]
  13467. + test PLAIN = WARNING
  13468. + shift
  13469. + shift
  13470. + [ 3 -ge 1 ]
  13471. + SCREENINDENT=4
  13472. + [ -z 4 ]
  13473. + echo 4
  13474. + grep '^[0-9]*$'
  13475. + [ -z 4 ]
  13476. + shift
  13477. + shift
  13478. + [ 1 -ge 1 ]
  13479. + MSG=SUMMARY_CHKS_SKIPPED
  13480. + shift
  13481. + break
  13482. + test 0 -eq 1
  13483. + [ 0 -eq 1 ]
  13484. + [ 0 -eq 1 ]
  13485. + test SCREEN+LOG = SCREEN -o SCREEN+LOG = SCREEN+LOG
  13486. + WRITETOTTY=1
  13487. + test SCREEN+LOG = LOG -o SCREEN+LOG = SCREEN+LOG
  13488. + WRITETOLOG=1
  13489. + [ 1 -eq 0 -a 1 -eq 0 ]
  13490. + [ 1 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  13491. + test -n ''
  13492. + [ 0 -eq 1 -a 1 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  13493. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  13494. + [ -n SUMMARY_CHKS_SKIPPED ]
  13495. + head -n 1
  13496. + cut -d: -f2-
  13497. + grep -a ^SUMMARY_CHKS_SKIPPED: /usr/local/var/lib/rkhunter/db/i18n/en
  13498. + LINE1='All checks skipped'
  13499. + [ 0 -eq 1 ]
  13500. + [ -z 'All checks skipped' ]
  13501. + sed -e 's/`/\\`/g'
  13502. + echo 'All checks skipped'
  13503. + LINE1='All checks skipped'
  13504. + test -n 'All checks skipped'
  13505. + eval 'echo "All checks skipped" | sed -e '\''s/;/\;/g'\'
  13506. + sed -e 's/;/\;/g'
  13507. + echo 'All checks skipped'
  13508. + LINE1='All checks skipped'
  13509. + [ 1 -eq 1 ]
  13510. + date '+[%H:%M:%S]'
  13511. + LOGLINE1='[04:22:12]'
  13512. + test 0 -gt 0 -o 0 -eq 1
  13513. + [ -n '' ]
  13514. + test 0 -gt 0
  13515. + LOGLINE1='[04:22:12] All checks skipped'
  13516. + [ 1 -eq 1 -a 4 -gt 0 ]
  13517. + echo ' '
  13518. + cut -c1-4
  13519. + SPACES=' '
  13520. + LINE1=' All checks skipped'
  13521. + [ -n '' ]
  13522. + [ 1 -eq 1 -a -n '' ]
  13523. + [ 0 -eq 1 ]
  13524. + [ 1 -eq 1 ]
  13525. + NLLOOP=0
  13526. + test 0 -gt 0
  13527. + [ '' = c ]
  13528. + echo -e ' All checks skipped'
  13529. All checks skipped
  13530. + [ 1 -eq 1 ]
  13531. + echo -e '[04:22:12] All checks skipped'
  13532. + [ 0 -eq 1 ]
  13533. + echo '[04:22:12] All checks skipped'
  13534. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  13535. + [ 0 -eq 1 -a -n '' ]
  13536. + test 1 -eq 1 -a 0 -eq 1
  13537. + return
  13538. + display --to SCREEN+LOG --type PLAIN --nl SUMMARY_APPS_SCAN
  13539. + WARN_MSG=0
  13540. + NL=0
  13541. + NLAFTER=0
  13542. + LOGINDENT=0
  13543. + SCREENINDENT=0
  13544. + LOGNL=0
  13545. + SCREENNL=0
  13546. + WRITETO=''
  13547. + TYPE=''
  13548. + RESULT=''
  13549. + COLOR=''
  13550. + MSG=''
  13551. + LINE1=''
  13552. + LOGLINE1=''
  13553. + SPACES=''
  13554. + NONL=''
  13555. + DISPLAY_LINE='display --to SCREEN+LOG --type PLAIN --nl SUMMARY_APPS_SCAN'
  13556. + [ 6 -le 0 ]
  13557. + [ 6 -ge 1 ]
  13558. + WRITETO=SCREEN+LOG
  13559. + shift
  13560. + shift
  13561. + [ 4 -ge 1 ]
  13562. + eval echo '$MSG_TYPE_PLAIN'
  13563. + echo
  13564. + TYPE=''
  13565. + [ -z '' -a PLAIN != PLAIN ]
  13566. + test PLAIN = WARNING
  13567. + shift
  13568. + shift
  13569. + [ 2 -ge 1 ]
  13570. + NL=1
  13571. + shift
  13572. + [ 1 -ge 1 ]
  13573. + MSG=SUMMARY_APPS_SCAN
  13574. + shift
  13575. + break
  13576. + test 0 -eq 1
  13577. + [ 0 -eq 1 ]
  13578. + [ 0 -eq 1 ]
  13579. + test SCREEN+LOG = SCREEN -o SCREEN+LOG = SCREEN+LOG
  13580. + WRITETOTTY=1
  13581. + test SCREEN+LOG = LOG -o SCREEN+LOG = SCREEN+LOG
  13582. + WRITETOLOG=1
  13583. + [ 1 -eq 0 -a 1 -eq 0 ]
  13584. + [ 1 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  13585. + test -n ''
  13586. + [ 0 -eq 1 -a 1 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  13587. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  13588. + [ -n SUMMARY_APPS_SCAN ]
  13589. + grep -a ^SUMMARY_APPS_SCAN: /usr/local/var/lib/rkhunter/db/i18n/en
  13590. + head -n 1
  13591. + cut -d: -f2-
  13592. + LINE1='Applications checks...'
  13593. + [ 0 -eq 1 ]
  13594. + [ -z 'Applications checks...' ]
  13595. + echo 'Applications checks...'
  13596. + sed -e 's/`/\\`/g'
  13597. + LINE1='Applications checks...'
  13598. + test -n 'Applications checks...'
  13599. + eval 'echo "Applications checks..." | sed -e '\''s/;/\;/g'\'
  13600. + echo 'Applications checks...'
  13601. + sed -e 's/;/\;/g'
  13602. + LINE1='Applications checks...'
  13603. + [ 1 -eq 1 ]
  13604. + date '+[%H:%M:%S]'
  13605. + LOGLINE1='[04:22:12]'
  13606. + test 1 -gt 0 -o 0 -eq 1
  13607. + echo '[04:22:12]'
  13608. + [ -n '' ]
  13609. + test 0 -gt 0
  13610. + LOGLINE1='[04:22:12] Applications checks...'
  13611. + [ 1 -eq 1 -a 0 -gt 0 ]
  13612. + [ -n '' ]
  13613. + [ 1 -eq 1 -a -n '' ]
  13614. + [ 0 -eq 1 ]
  13615. + [ 1 -eq 1 ]
  13616. + NLLOOP=1
  13617. + test 1 -gt 0
  13618. + echo ''
  13619.  
  13620. + expr 1 - 1
  13621. + NLLOOP=0
  13622. + test 0 -gt 0
  13623. + [ '' = c ]
  13624. + echo -e 'Applications checks...'
  13625. Applications checks...
  13626. + [ 1 -eq 1 ]
  13627. + echo -e '[04:22:12] Applications checks...'
  13628. + [ 0 -eq 1 ]
  13629. + echo '[04:22:12] Applications checks...'
  13630. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  13631. + [ 0 -eq 1 -a -n '' ]
  13632. + test 1 -eq 1 -a 0 -eq 1
  13633. + return
  13634. + check_test apps
  13635. + echo ' filesystem local_host '
  13636. + grep ' apps '
  13637. + [ 'filesystem local_host' = all -o -n '' ]
  13638. + return 1
  13639. +
  13640. + display --to SCREEN+LOG --type PLAIN --screen-indent 4 SUMMARY_CHKS_SKIPPED
  13641. + WARN_MSG=0
  13642. + NL=0
  13643. + NLAFTER=0
  13644. + LOGINDENT=0
  13645. + SCREENINDENT=0
  13646. + LOGNL=0
  13647. + SCREENNL=0
  13648. + WRITETO=''
  13649. + TYPE=''
  13650. + RESULT=''
  13651. + COLOR=''
  13652. + MSG=''
  13653. + LINE1=''
  13654. + LOGLINE1=''
  13655. + SPACES=''
  13656. + NONL=''
  13657. + DISPLAY_LINE='display --to SCREEN+LOG --type PLAIN --screen-indent 4 SUMMARY_CHKS_SKIPPED'
  13658. + [ 7 -le 0 ]
  13659. + [ 7 -ge 1 ]
  13660. + WRITETO=SCREEN+LOG
  13661. + shift
  13662. + shift
  13663. + [ 5 -ge 1 ]
  13664. + eval echo '$MSG_TYPE_PLAIN'
  13665. + echo
  13666. + TYPE=''
  13667. + [ -z '' -a PLAIN != PLAIN ]
  13668. + test PLAIN = WARNING
  13669. + shift
  13670. + shift
  13671. + [ 3 -ge 1 ]
  13672. + SCREENINDENT=4
  13673. + [ -z 4 ]
  13674. + grep '^[0-9]*$'
  13675. + echo 4
  13676. + [ -z 4 ]
  13677. + shift
  13678. + shift
  13679. + [ 1 -ge 1 ]
  13680. + MSG=SUMMARY_CHKS_SKIPPED
  13681. + shift
  13682. + break
  13683. + test 0 -eq 1
  13684. + [ 0 -eq 1 ]
  13685. + [ 0 -eq 1 ]
  13686. + test SCREEN+LOG = SCREEN -o SCREEN+LOG = SCREEN+LOG
  13687. + WRITETOTTY=1
  13688. + test SCREEN+LOG = LOG -o SCREEN+LOG = SCREEN+LOG
  13689. + WRITETOLOG=1
  13690. + [ 1 -eq 0 -a 1 -eq 0 ]
  13691. + [ 1 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  13692. + test -n ''
  13693. + [ 0 -eq 1 -a 1 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  13694. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  13695. + [ -n SUMMARY_CHKS_SKIPPED ]
  13696. + grep -a ^SUMMARY_CHKS_SKIPPED: /usr/local/var/lib/rkhunter/db/i18n/en
  13697. + head -n 1
  13698. + cut -d: -f2-
  13699. + LINE1='All checks skipped'
  13700. + [ 0 -eq 1 ]
  13701. + [ -z 'All checks skipped' ]
  13702. + echo 'All checks skipped'
  13703. + sed -e 's/`/\\`/g'
  13704. + LINE1='All checks skipped'
  13705. + test -n 'All checks skipped'
  13706. + eval 'echo "All checks skipped" | sed -e '\''s/;/\;/g'\'
  13707. + echo 'All checks skipped'
  13708. + sed -e 's/;/\;/g'
  13709. + LINE1='All checks skipped'
  13710. + [ 1 -eq 1 ]
  13711. + date '+[%H:%M:%S]'
  13712. + LOGLINE1='[04:22:12]'
  13713. + test 0 -gt 0 -o 0 -eq 1
  13714. + [ -n '' ]
  13715. + test 0 -gt 0
  13716. + LOGLINE1='[04:22:12] All checks skipped'
  13717. + [ 1 -eq 1 -a 4 -gt 0 ]
  13718. + cut -c1-4
  13719. + echo ' '
  13720. + SPACES=' '
  13721. + LINE1=' All checks skipped'
  13722. + [ -n '' ]
  13723. + [ 1 -eq 1 -a -n '' ]
  13724. + [ 0 -eq 1 ]
  13725. + [ 1 -eq 1 ]
  13726. + NLLOOP=0
  13727. + test 0 -gt 0
  13728. + [ '' = c ]
  13729. + echo -e ' All checks skipped'
  13730. All checks skipped
  13731. + [ 1 -eq 1 ]
  13732. + echo -e '[04:22:12] All checks skipped'
  13733. + [ 0 -eq 1 ]
  13734. + echo '[04:22:12] All checks skipped'
  13735. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  13736. + [ 0 -eq 1 -a -n '' ]
  13737. + test 1 -eq 1 -a 0 -eq 1
  13738. + return
  13739. + [ 3 -gt 0 ]
  13740. + [ 3 -eq 1 ]
  13741. + [ 3 -eq 2 ]
  13742. + RKHTMPVAR=SCREEN+LOG
  13743. + [ 1443954112 -eq 0 ]
  13744. + display --to SCREEN+LOG --type PLAIN --nl SUMMARY_SCAN_TIME '19 seconds'
  13745. + WARN_MSG=0
  13746. + NL=0
  13747. + NLAFTER=0
  13748. + LOGINDENT=0
  13749. + SCREENINDENT=0
  13750. + LOGNL=0
  13751. + SCREENNL=0
  13752. + WRITETO=''
  13753. + TYPE=''
  13754. + RESULT=''
  13755. + COLOR=''
  13756. + MSG=''
  13757. + LINE1=''
  13758. + LOGLINE1=''
  13759. + SPACES=''
  13760. + NONL=''
  13761. + DISPLAY_LINE='display --to SCREEN+LOG --type PLAIN --nl SUMMARY_SCAN_TIME 19 seconds'
  13762. + [ 7 -le 0 ]
  13763. + [ 7 -ge 1 ]
  13764. + WRITETO=SCREEN+LOG
  13765. + shift
  13766. + shift
  13767. + [ 5 -ge 1 ]
  13768. + eval echo '$MSG_TYPE_PLAIN'
  13769. + echo
  13770. + TYPE=''
  13771. + [ -z '' -a PLAIN != PLAIN ]
  13772. + test PLAIN = WARNING
  13773. + shift
  13774. + shift
  13775. + [ 3 -ge 1 ]
  13776. + NL=1
  13777. + shift
  13778. + [ 2 -ge 1 ]
  13779. + MSG=SUMMARY_SCAN_TIME
  13780. + shift
  13781. + break
  13782. + test 0 -eq 1
  13783. + [ 0 -eq 1 ]
  13784. + [ 0 -eq 1 ]
  13785. + test SCREEN+LOG = SCREEN -o SCREEN+LOG = SCREEN+LOG
  13786. + WRITETOTTY=1
  13787. + test SCREEN+LOG = LOG -o SCREEN+LOG = SCREEN+LOG
  13788. + WRITETOLOG=1
  13789. + [ 1 -eq 0 -a 1 -eq 0 ]
  13790. + [ 1 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  13791. + test -n ''
  13792. + [ 0 -eq 1 -a 1 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  13793. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  13794. + [ -n SUMMARY_SCAN_TIME ]
  13795. + grep -a ^SUMMARY_SCAN_TIME: /usr/local/var/lib/rkhunter/db/i18n/en
  13796. + head -n 1
  13797. + cut -d: -f2-
  13798. + LINE1='The system checks took: $1'
  13799. + [ 0 -eq 1 ]
  13800. + [ -z 'The system checks took: $1' ]
  13801. + echo 'The system checks took: $1'
  13802. + sed -e 's/`/\\`/g'
  13803. + LINE1='The system checks took: $1'
  13804. + test -n 'The system checks took: $1'
  13805. + eval 'echo "The system checks took: $1" | sed -e '\''s/;/\;/g'\'
  13806. + echo 'The system checks took: 19 seconds'
  13807. + sed -e 's/;/\;/g'
  13808. + LINE1='The system checks took: 19 seconds'
  13809. + [ 1 -eq 1 ]
  13810. + date '+[%H:%M:%S]'
  13811. + LOGLINE1='[04:22:13]'
  13812. + test 1 -gt 0 -o 0 -eq 1
  13813. + echo '[04:22:13]'
  13814. + [ -n '' ]
  13815. + test 0 -gt 0
  13816. + LOGLINE1='[04:22:13] The system checks took: 19 seconds'
  13817. + [ 1 -eq 1 -a 0 -gt 0 ]
  13818. + [ -n '' ]
  13819. + [ 1 -eq 1 -a -n '' ]
  13820. + [ 0 -eq 1 ]
  13821. + [ 1 -eq 1 ]
  13822. + NLLOOP=1
  13823. + test 1 -gt 0
  13824. + echo ''
  13825.  
  13826. + expr 1 - 1
  13827. + NLLOOP=0
  13828. + test 0 -gt 0
  13829. + [ '' = c ]
  13830. + echo -e 'The system checks took: 19 seconds'
  13831. The system checks took: 19 seconds
  13832. + [ 1 -eq 1 ]
  13833. + echo -e '[04:22:13] The system checks took: 19 seconds'
  13834. + [ 0 -eq 1 ]
  13835. + echo '[04:22:13] The system checks took: 19 seconds'
  13836. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  13837. + [ 0 -eq 1 -a -n '' ]
  13838. + test 1 -eq 1 -a 0 -eq 1
  13839. + return
  13840. + [ 0 -eq 0 ]
  13841. + display --to SCREEN --type PLAIN --nl --nl-after SUMMARY_LOGFILE /var/log/rkhunter.log
  13842. + WARN_MSG=0
  13843. + NL=0
  13844. + NLAFTER=0
  13845. + LOGINDENT=0
  13846. + SCREENINDENT=0
  13847. + LOGNL=0
  13848. + SCREENNL=0
  13849. + WRITETO=''
  13850. + TYPE=''
  13851. + RESULT=''
  13852. + COLOR=''
  13853. + MSG=''
  13854. + LINE1=''
  13855. + LOGLINE1=''
  13856. + SPACES=''
  13857. + NONL=''
  13858. + DISPLAY_LINE='display --to SCREEN --type PLAIN --nl --nl-after SUMMARY_LOGFILE /var/log/rkhunter.log'
  13859. + [ 8 -le 0 ]
  13860. + [ 8 -ge 1 ]
  13861. + WRITETO=SCREEN
  13862. + shift
  13863. + shift
  13864. + [ 6 -ge 1 ]
  13865. + eval echo '$MSG_TYPE_PLAIN'
  13866. + echo
  13867. + TYPE=''
  13868. + [ -z '' -a PLAIN != PLAIN ]
  13869. + test PLAIN = WARNING
  13870. + shift
  13871. + shift
  13872. + [ 4 -ge 1 ]
  13873. + NL=1
  13874. + shift
  13875. + [ 3 -ge 1 ]
  13876. + NLAFTER=1
  13877. + shift
  13878. + [ 2 -ge 1 ]
  13879. + MSG=SUMMARY_LOGFILE
  13880. + shift
  13881. + break
  13882. + test 0 -eq 1
  13883. + [ 0 -eq 1 ]
  13884. + [ 0 -eq 1 ]
  13885. + test SCREEN = SCREEN -o SCREEN = SCREEN+LOG
  13886. + WRITETOTTY=1
  13887. + test SCREEN = LOG -o SCREEN = SCREEN+LOG
  13888. + WRITETOLOG=0
  13889. + [ 1 -eq 0 -a 0 -eq 0 ]
  13890. + [ 1 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  13891. + test -n ''
  13892. + [ 0 -eq 1 -a 1 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  13893. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  13894. + [ -n SUMMARY_LOGFILE ]
  13895. + grep -a ^SUMMARY_LOGFILE: /usr/local/var/lib/rkhunter/db/i18n/en
  13896. + head -n 1
  13897. + cut -d: -f2-
  13898. + LINE1='All results have been written to the log file: $1'
  13899. + [ 0 -eq 1 ]
  13900. + [ -z 'All results have been written to the log file: $1' ]
  13901. + echo 'All results have been written to the log file: $1'
  13902. + sed -e 's/`/\\`/g'
  13903. + LINE1='All results have been written to the log file: $1'
  13904. + test -n 'All results have been written to the log file: $1'
  13905. + eval 'echo "All results have been written to the log file: $1" | sed -e '\''s/;/\;/g'\'
  13906. + echo 'All results have been written to the log file: /var/log/rkhunter.log'
  13907. + sed -e 's/;/\;/g'
  13908. + LINE1='All results have been written to the log file: /var/log/rkhunter.log'
  13909. + [ 0 -eq 1 ]
  13910. + [ 1 -eq 1 -a 0 -gt 0 ]
  13911. + [ -n '' ]
  13912. + [ 1 -eq 1 -a -n '' ]
  13913. + [ 0 -eq 1 ]
  13914. + [ 1 -eq 1 ]
  13915. + NLLOOP=1
  13916. + test 1 -gt 0
  13917. + echo ''
  13918.  
  13919. + expr 1 - 1
  13920. + NLLOOP=0
  13921. + test 0 -gt 0
  13922. + [ '' = c ]
  13923. + echo -e 'All results have been written to the log file: /var/log/rkhunter.log'
  13924. All results have been written to the log file: /var/log/rkhunter.log
  13925. + [ 0 -eq 1 ]
  13926. + test 1 -eq 1 -a 1 -eq 1
  13927. + echo ''
  13928.  
  13929. + return
  13930. + return
  13931. + [ 0 -eq 0 ]
  13932. + [ 4 -eq 0 ]
  13933. + RKH_WARN_DISPLYD=1
  13934. + display --to SCREEN --type PLAIN CHECK_WARNINGS_FOUND
  13935. + WARN_MSG=0
  13936. + NL=0
  13937. + NLAFTER=0
  13938. + LOGINDENT=0
  13939. + SCREENINDENT=0
  13940. + LOGNL=0
  13941. + SCREENNL=0
  13942. + WRITETO=''
  13943. + TYPE=''
  13944. + RESULT=''
  13945. + COLOR=''
  13946. + MSG=''
  13947. + LINE1=''
  13948. + LOGLINE1=''
  13949. + SPACES=''
  13950. + NONL=''
  13951. + DISPLAY_LINE='display --to SCREEN --type PLAIN CHECK_WARNINGS_FOUND'
  13952. + [ 5 -le 0 ]
  13953. + [ 5 -ge 1 ]
  13954. + WRITETO=SCREEN
  13955. + shift
  13956. + shift
  13957. + [ 3 -ge 1 ]
  13958. + eval echo '$MSG_TYPE_PLAIN'
  13959. + echo
  13960. + TYPE=''
  13961. + [ -z '' -a PLAIN != PLAIN ]
  13962. + test PLAIN = WARNING
  13963. + shift
  13964. + shift
  13965. + [ 1 -ge 1 ]
  13966. + MSG=CHECK_WARNINGS_FOUND
  13967. + shift
  13968. + break
  13969. + test 0 -eq 1
  13970. + [ 0 -eq 1 ]
  13971. + [ 0 -eq 1 ]
  13972. + test SCREEN = SCREEN -o SCREEN = SCREEN+LOG
  13973. + WRITETOTTY=1
  13974. + test SCREEN = LOG -o SCREEN = SCREEN+LOG
  13975. + WRITETOLOG=0
  13976. + [ 1 -eq 0 -a 0 -eq 0 ]
  13977. + [ 1 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  13978. + test -n ''
  13979. + [ 0 -eq 1 -a 1 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  13980. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  13981. + [ -n CHECK_WARNINGS_FOUND ]
  13982. + head -n 1
  13983. + cut -d: -f2-
  13984. + grep -a ^CHECK_WARNINGS_FOUND: /usr/local/var/lib/rkhunter/db/i18n/en
  13985. + LINE1='One or more warnings have been found while checking the system.'
  13986. + [ 0 -eq 1 ]
  13987. + [ -z 'One or more warnings have been found while checking the system.' ]
  13988. + sed -e 's/`/\\`/g'
  13989. + echo 'One or more warnings have been found while checking the system.'
  13990. + LINE1='One or more warnings have been found while checking the system.'
  13991. + test -n 'One or more warnings have been found while checking the system.'
  13992. + eval 'echo "One or more warnings have been found while checking the system." | sed -e '\''s/;/\;/g'\'
  13993. + echo 'One or more warnings have been found while checking the system.'
  13994. + sed -e 's/;/\;/g'
  13995. + LINE1='One or more warnings have been found while checking the system.'
  13996. + [ 0 -eq 1 ]
  13997. + [ 1 -eq 1 -a 0 -gt 0 ]
  13998. + [ -n '' ]
  13999. + [ 1 -eq 1 -a -n '' ]
  14000. + [ 0 -eq 1 ]
  14001. + [ 1 -eq 1 ]
  14002. + NLLOOP=0
  14003. + test 0 -gt 0
  14004. + [ '' = c ]
  14005. + echo -e 'One or more warnings have been found while checking the system.'
  14006. One or more warnings have been found while checking the system.
  14007. + [ 0 -eq 1 ]
  14008. + test 1 -eq 1 -a 0 -eq 1
  14009. + return
  14010. + [ 4 -gt 0 ]
  14011. + [ 0 -eq 1 ]
  14012. + display --to SCREEN --type PLAIN --nl-after CHECK_WARNINGS_FOUND_CHK_LOG /var/log/rkhunter.log
  14013. + WARN_MSG=0
  14014. + NL=0
  14015. + NLAFTER=0
  14016. + LOGINDENT=0
  14017. + SCREENINDENT=0
  14018. + LOGNL=0
  14019. + SCREENNL=0
  14020. + WRITETO=''
  14021. + TYPE=''
  14022. + RESULT=''
  14023. + COLOR=''
  14024. + MSG=''
  14025. + LINE1=''
  14026. + LOGLINE1=''
  14027. + SPACES=''
  14028. + NONL=''
  14029. + DISPLAY_LINE='display --to SCREEN --type PLAIN --nl-after CHECK_WARNINGS_FOUND_CHK_LOG /var/log/rkhunter.log'
  14030. + [ 7 -le 0 ]
  14031. + [ 7 -ge 1 ]
  14032. + WRITETO=SCREEN
  14033. + shift
  14034. + shift
  14035. + [ 5 -ge 1 ]
  14036. + eval echo '$MSG_TYPE_PLAIN'
  14037. + echo
  14038. + TYPE=''
  14039. + [ -z '' -a PLAIN != PLAIN ]
  14040. + test PLAIN = WARNING
  14041. + shift
  14042. + shift
  14043. + [ 3 -ge 1 ]
  14044. + NLAFTER=1
  14045. + shift
  14046. + [ 2 -ge 1 ]
  14047. + MSG=CHECK_WARNINGS_FOUND_CHK_LOG
  14048. + shift
  14049. + break
  14050. + test 0 -eq 1
  14051. + [ 0 -eq 1 ]
  14052. + [ 0 -eq 1 ]
  14053. + test SCREEN = SCREEN -o SCREEN = SCREEN+LOG
  14054. + WRITETOTTY=1
  14055. + test SCREEN = LOG -o SCREEN = SCREEN+LOG
  14056. + WRITETOLOG=0
  14057. + [ 1 -eq 0 -a 0 -eq 0 ]
  14058. + [ 1 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  14059. + test -n ''
  14060. + [ 0 -eq 1 -a 1 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  14061. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  14062. + [ -n CHECK_WARNINGS_FOUND_CHK_LOG ]
  14063. + grep -a ^CHECK_WARNINGS_FOUND_CHK_LOG: /usr/local/var/lib/rkhunter/db/i18n/en
  14064. + cut -d: -f2-
  14065. + head -n 1
  14066. + LINE1='Please check the log file ($1)'
  14067. + [ 0 -eq 1 ]
  14068. + [ -z 'Please check the log file ($1)' ]
  14069. + echo 'Please check the log file ($1)'
  14070. + sed -e 's/`/\\`/g'
  14071. + LINE1='Please check the log file ($1)'
  14072. + test -n 'Please check the log file ($1)'
  14073. + eval 'echo "Please check the log file ($1)" | sed -e '\''s/;/\;/g'\'
  14074. + echo 'Please check the log file (/var/log/rkhunter.log)'
  14075. + sed -e 's/;/\;/g'
  14076. + LINE1='Please check the log file (/var/log/rkhunter.log)'
  14077. + [ 0 -eq 1 ]
  14078. + [ 1 -eq 1 -a 0 -gt 0 ]
  14079. + [ -n '' ]
  14080. + [ 1 -eq 1 -a -n '' ]
  14081. + [ 0 -eq 1 ]
  14082. + [ 1 -eq 1 ]
  14083. + NLLOOP=0
  14084. + test 0 -gt 0
  14085. + [ '' = c ]
  14086. + echo -e 'Please check the log file (/var/log/rkhunter.log)'
  14087. Please check the log file (/var/log/rkhunter.log)
  14088. + [ 0 -eq 1 ]
  14089. + test 1 -eq 1 -a 1 -eq 1
  14090. + echo ''
  14091.  
  14092. + return
  14093. + NOTTY=0
  14094. + [ -n '' ]
  14095. + [ 4 -gt 0 ]
  14096. + [ 0 -eq 1 -a 1 -eq 0 ]
  14097. + [ -n '' ]
  14098. + [ -n '' ]
  14099. + RET_CODE=1
  14100. + return
  14101. + COPIEDLOG=''
  14102. + [ 1 -gt 0 -o 4 -gt 0 ]
  14103. + [ 0 -eq 1 -a 0 -eq 0 ]
  14104. + date
  14105. + display --to LOG --type INFO --nl RKH_ENDDATE 'Sun Oct 4 04:22:13 MDT 2015'
  14106. + WARN_MSG=0
  14107. + NL=0
  14108. + NLAFTER=0
  14109. + LOGINDENT=0
  14110. + SCREENINDENT=0
  14111. + LOGNL=0
  14112. + SCREENNL=0
  14113. + WRITETO=''
  14114. + TYPE=''
  14115. + RESULT=''
  14116. + COLOR=''
  14117. + MSG=''
  14118. + LINE1=''
  14119. + LOGLINE1=''
  14120. + SPACES=''
  14121. + NONL=''
  14122. + DISPLAY_LINE='display --to LOG --type INFO --nl RKH_ENDDATE Sun Oct 4 04:22:13 MDT 2015'
  14123. + [ 7 -le 0 ]
  14124. + [ 7 -ge 1 ]
  14125. + WRITETO=LOG
  14126. + shift
  14127. + shift
  14128. + [ 5 -ge 1 ]
  14129. + eval echo '$MSG_TYPE_INFO'
  14130. + echo Info
  14131. + TYPE=Info
  14132. + [ -z Info -a INFO != PLAIN ]
  14133. + test INFO = WARNING
  14134. + shift
  14135. + shift
  14136. + [ 3 -ge 1 ]
  14137. + NL=1
  14138. + shift
  14139. + [ 2 -ge 1 ]
  14140. + MSG=RKH_ENDDATE
  14141. + shift
  14142. + break
  14143. + test 0 -eq 1
  14144. + [ 0 -eq 1 ]
  14145. + [ 0 -eq 1 ]
  14146. + test LOG = SCREEN -o LOG = SCREEN+LOG
  14147. + WRITETOTTY=0
  14148. + test LOG = LOG -o LOG = SCREEN+LOG
  14149. + WRITETOLOG=1
  14150. + [ 0 -eq 0 -a 1 -eq 0 ]
  14151. + [ 0 -eq 1 -a 1 -eq 1 -a -n '' -a -z '' ]
  14152. + test -n Info
  14153. + NONL=''
  14154. + [ 0 -eq 1 -a 0 -eq 1 -a 1 -eq 1 -a '' = Whitelisted ]
  14155. + LANG_FILE=/usr/local/var/lib/rkhunter/db/i18n/en
  14156. + [ -n RKH_ENDDATE ]
  14157. + grep -a ^RKH_ENDDATE: /usr/local/var/lib/rkhunter/db/i18n/en
  14158. + head -n 1
  14159. + cut -d: -f2-
  14160. + LINE1='End date is $1'
  14161. + [ 0 -eq 1 ]
  14162. + [ -z 'End date is $1' ]
  14163. + sed -e 's/`/\\`/g'
  14164. + echo 'End date is $1'
  14165. + LINE1='End date is $1'
  14166. + test -n 'End date is $1'
  14167. + eval 'echo "End date is $1" | sed -e '\''s/;/\;/g'\'
  14168. + sed -e 's/;/\;/g'
  14169. + echo 'End date is Sun Oct 4 04:22:13 MDT 2015'
  14170. + LINE1='End date is Sun Oct 4 04:22:13 MDT 2015'
  14171. + [ 1 -eq 1 ]
  14172. + date '+[%H:%M:%S]'
  14173. + LOGLINE1='[04:22:13]'
  14174. + test 1 -gt 0 -o 0 -eq 1
  14175. + echo '[04:22:13]'
  14176. + [ -n Info ]
  14177. + LOGLINE1='[04:22:13] Info: End date is Sun Oct 4 04:22:13 MDT 2015'
  14178. + [ 0 -eq 1 -a 0 -gt 0 ]
  14179. + [ -n '' ]
  14180. + [ 0 -eq 1 -a -n '' ]
  14181. + [ 0 -eq 1 ]
  14182. + [ 0 -eq 1 ]
  14183. + [ 1 -eq 1 ]
  14184. + echo -e '[04:22:13] Info: End date is Sun Oct 4 04:22:13 MDT 2015'
  14185. + [ 0 -eq 1 ]
  14186. + grep '^\[[0-9][0-9]:[0-9][0-9]:[0-9][0-9]\] '
  14187. + echo '[04:22:13] Info: End date is Sun Oct 4 04:22:13 MDT 2015'
  14188. + [ 0 -eq 1 -a -n '' ]
  14189. + test 0 -eq 1 -a 0 -eq 1
  14190. + return
  14191. + test -n ''
  14192. + test 0 -eq 1
  14193. + IFS='
  14194. '
  14195. + exit 1
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement