aboutsummaryrefslogtreecommitdiff
path: root/app/forensics/rkhunter/rkhunter.SlackBuild
blob: 6d6c9a2d3368a17c5bc6cfc0d370f533396c56d6 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
#!/bin/bash
#
#  rkhunter.SlackBuild is free software; you can redistribute
#  it and/or modify it under the terms of the GNU General Public
#  License as published by the Free Software Foundation; either
#  version 2 of the License, or any later version.
#
#  rkhunter.SlackBuild is distributed in the hope that it
#  will be useful, but WITHOUT ANY WARRANTY; without even the
#  implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR
#  PURPOSE.  See the GNU General Public License for more details.
#
#  You should have received a copy of the GNU General Public
#  License along with this program; if not, write to the Free
#  Software Foundation, Inc., 59 Temple Place - Suite 330, Boston,
#  MA 02111-1307, USA
#
# SlackBuild for Rootkit Hunter
# http://rkhunter.sourceforge.net/
#
# Author: Luis ( luis at riseup d0t net )
#

# Look for slackbuildrc
if [ -f ~/.slackbuildrc ]; then
  source ~/.slackbuildrc
elif [ -f /etc/slackbuildrc ]; then
  source /etc/slackbuildrc
fi

# Set variables
CWD="$(pwd)"
SRC_NAME="rkhunter"
PKG_NAME="rkhunter"
ARCH=${ARCH:=i486}
SRC_VERSION=${VERSION:=1.3.0}
PKG_VERSION="$(echo "$SRC_VERSION" | tr '[[:blank:]-]' '_')"
BUILD=${BUILD:=1ls}
SRC_DIR=${SRC_DIR:=$CWD}/$PKG_NAME
TMP=${TMP:=/tmp}
PKG=${PKG:=$TMP/package-$PKG_NAME}
REPOS=${REPOS:=$TMP}
PREFIX=${PREFIX:=}
PKG_WORK="$TMP/$SRC_NAME"
CONF_OPTIONS=${CONF_OPTIONS:=}
NUMJOBS=${NUMJOBS:=}

# Set system libraries' path based on $ARCH
if [ "$ARCH" = "x86_64" ]; then
  LIBDIR="$PREFIX/lib64"
else
  LIBDIR="$PREFIX/lib"
fi

# Set error codes (used by createpkg)
ERROR_WGET=31;      ERROR_MAKE=32;      ERROR_INSTALL=33
ERROR_MD5=34;       ERROR_CONF=35;      ERROR_HELP=36
ERROR_TAR=37;       ERROR_MKPKG=38;     ERROR_GPG=39
ERROR_PATCH=40;     ERROR_VCS=41;       ERROR_MKDIR=42

# Clean up any leftovers of previous builds
rm -rf "$PKG_WORK" 2> /dev/null
rm -rf "$PKG" 2> /dev/null

# Create directories if necessary
mkdir -p "$SRC_DIR" || exit $ERROR_MKDIR
mkdir -p "$PKG" || exit $ERROR_MKDIR
mkdir -p "$REPOS" || exit $ERROR_MKDIR
mkdir -p "$PKG_WORK" || exit $ERROR_MKDIR

# Dowload source if necessary
SRC="$SRC_NAME-$SRC_VERSION.tar.gz"
URL="http://downloads.sourceforge.net/rkhunter/$SRC"

if [ ! -s "$SRC_DIR/$SRC" ] || ! gzip -t "$SRC_DIR/$SRC" 2> /dev/null; then
  wget "$URL" -O "$SRC_DIR/$SRC" || exit $ERROR_WGET
fi

# Import minimized signing key from
# http://keyserver.noreply.org/pks/lookup?op=get&search=0xEA5F4CD3A65F5E17
gpg --import << EOKEY || exit $ERROR_GPG
-----BEGIN PGP PUBLIC KEY BLOCK-----

mIsERqMwPQEEAI0vYVqBSHTexjttt9iFOItnJy56vIKnBNaG/PqPMvTY3HHzWfRN
p62YPB+F+htLzfKwUSDVaC0BYP8zl09lzNcTeb5JkUcT/qaSEssdBQFLI2H/7A2y
2HXzkntijiWTLw7YzWk45d8YzJ8SMJMu1CFX26VqgDZJ27hdDEJ7+t97AAQLtC8i
cmtodW50ZXJAaHVzaG1haWwuY29tIiA8cmtodW50ZXJAaHVzaG1haWwuY29tPoiq
BBABAgAUBhUICQoDAgYLCQgHCgQFAkajMD0ACgkQ6l9M06ZfXhdc5QP/ewqGepun
BTAd7K35OpGdbwRBWhGL7hk3Ek0Ai0rHOCJVFHgX6ihzKqcpPLTnBie/QUd7XoV6
3jrwIbrgXADckg3sTKnMgxFowtEgrJgGYtZTPaQEW5bkWrZwSxl/lgYs61yjSsDB
8lBON2tM8/OwkJQtv4WfFQ9xXqs0sRH8DQO5AQsERqMwPQEIAJvaygqO3Z3qYVe+
aff2Zd9Bm7r2JhjcIIjz7ul53MyQF3dxkPrh70Ix3azupdrZvirn5mMa2oC5ZdDr
zIw5c43ztRV4Ia3nFG7hdrDkMmYoUbxnLU0qLhGep/kadPvdLlEVyKvSHKLen5Wd
XPE6iLaTUQj/PuALhJ/Ll6hJyk6KohBV+Y0ZTkmdBp+r/jI4DEQ8HGc0J3tLuzWJ
fZcQNvV/m5UyyDOfmD9rcXkowhhVtMeX5epS3CfskhJzeQfwJnFr5d8Wq76a0FL3
dQLFqLBIZlechSDsfTu1FndjxMDAymR9aMBMPRP/CR3PKI7LN/l1822QQf1pBNne
/JKilMEABAuInAQYAQIABgUCRqMwQAAKCRDqX0zTpl9eFzfEBACJLzcgMUAFYE5F
R8XqRS2zfv13XPaTJD9cs2rut0RgsG7wtUdkXJ52kwM/2MmFkJBahK5jrJoPnZ2U
1xHJ1LgS+xeHtHCxees30lJrMU2uCcqLZtm7MRp/NCVtBeC2615XEQ3wF3nyzJSA
oiiAs08RzKzUAiEhUTJbKiySdp3xSQ==
=OxBn
-----END PGP PUBLIC KEY BLOCK-----
EOKEY

# Dowload source's signature if necessary and check it
if [ ! -s "$SRC_DIR/$SRC.asc" ]; then
  wget "$URL.asc" -O "$SRC_DIR/$SRC.asc" || exit $ERROR_WGET
fi

gpg --verify "$SRC_DIR/$SRC.asc" "$SRC_DIR/$SRC" || exit $ERROR_GPG


# Untar
cd "$PKG_WORK"
tar --no-same-owner --no-same-permissions -xvf "$SRC_DIR/$SRC" || exit $ERROR_TAR
PKG_SRC=`ls -l | awk '/^d/ { print $8 }'`
cd "$PKG_SRC"

# Install
if [ -z "$PREFIX" ]; then
  RPM_BUILD_ROOT="$PKG" \
    ./installer.sh --layout RPM --striproot "$PKG" --install || exit $ERROR_INSTALL
  mv -f "$PKG"/etc/rkhunter.conf "$PKG"/etc/rkhunter.conf.new
  mv -f "$PKG"/usr/local/share/* "$PKG"/usr
  rm -rf "$PKG"/usr/local/share
else
  mkdir -p "$PKG/$PREFIX" || exit $ERROR_MKDIR
  ./installer.sh --layout custom "$PKG/$PREFIX" --striproot "$PKG" --install || exit $ERROR_INSTALL
  mv -f "$PKG/$PREFIX"/etc/rkhunter.conf "$PKG/$PREFIX"/etc/rkhunter.conf.new
  mv -f "$PKG/$PREFIX"/share/* "$PKG"/usr
  rm -rf "$PKG/$PREFIX"/share
  if ! echo "$PATH" | grep -q "$PREFIX"/bin; then
    mkdir -p "$PKG"/usr/local/bin || exit $ERROR_MKDIR
    ln -sf "$PREFIX"/bin/rkhunter "$PKG"/usr/local/bin/rkhunter
  fi
fi

# Compress and link manpages
if [ -d "$PKG"/usr/man ]; then
  ( cd "$PKG"/usr/man
    for manpagedir in $(find . -type d -name "man*") ; do
      ( cd $manpagedir
        for eachpage in $( find . -type l -maxdepth 1) ; do
          ln -s $( readlink $eachpage ).gz $eachpage.gz
          rm $eachpage
        done
        gzip -9 *.?
      )
    done
  )
fi

# Add package description (slack-desc)
mkdir -p "$PKG/install" || exit $ERROR_MKDIR
cat << EODESC > "$PKG/install/slack-desc"
# HOW TO EDIT THIS FILE:
# The "handy ruler" below makes it easier to edit a package description.  Line
# up the first '|' above the ':' following the base package name, and the '|'
# on the right side marks the last column you can put a character in.  You must
# make exactly 11 lines for the formatting to be correct.  It's also
# customary to leave one space after the ':'.

        |-----handy-ruler------------------------------------------------------|
rkhunter: Rootkit Hunter
rkhunter: 
rkhunter: Rootkit Hunter (RKH) is a security monitoring and analyzing tool for
rkhunter: POSIX compliant systems. It checks your computer for the presence of
rkhunter: rootkits and other unwanted tools.
rkhunter: 
rkhunter: For more information, http://rkhunter.sourceforge.net/
rkhunter: 
rkhunter: 
rkhunter: 
rkhunter: 
EODESC

# Add a post-installation script (doinst.sh)
cat << EOSCRIPT > "$PKG/install/doinst.sh"
config() {
  NEW="\$1"
  OLD="\$(dirname \$NEW)/\$(basename \$NEW .new)"
  # If there's no config file by that name, mv it over:
  if [ ! -r \$OLD ]; then
    mv \$NEW \$OLD
  elif [ "\$(cat \$OLD | md5sum)" = "\$(cat \$NEW | md5sum)" ]; then
    # toss the redundant copy
    rm \$NEW
  fi
  # Otherwise, we leave the .new copy for the admin to consider...
}

config $PREFIX/etc/rkhunter.conf.new
EOSCRIPT

# Build the package
cd "$PKG"
makepkg -l y -c n "$REPOS/$PKG_NAME-$PKG_VERSION-$ARCH-$BUILD.tgz" || exit $ERROR_MKPKG

# Delete source and build directories if requested
if [ "$CLEANUP" == "yes" ]; then
  rm -rf "$PKG_WORK" "$PKG"
fi