From owner-freebsd-questions@freebsd.org Fri Feb 21 17:06:02 2020 Return-Path: Delivered-To: freebsd-questions@mailman.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.nyi.freebsd.org (Postfix) with ESMTP id DBC0023C497 for ; Fri, 21 Feb 2020 17:06:02 +0000 (UTC) (envelope-from kremels@kreme.com) Received: from mail.covisp.net (mail.covisp.net [65.121.55.42]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) server-signature RSA-PSS (4096 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 48PHsh6zpHz4Yk5 for ; Fri, 21 Feb 2020 17:06:00 +0000 (UTC) (envelope-from kremels@kreme.com) From: "@lbutlr" Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Subject: Re: FreeBSD equivalent of LMD/Linux Malware Detect? Date: Fri, 21 Feb 2020 10:05:59 -0700 References: <7e2b46d9fd477722ae145abda20ce4e9@kazancci.com> To: FreeBSD In-Reply-To: <7e2b46d9fd477722ae145abda20ce4e9@kazancci.com> Message-Id: <1795D726-491A-475B-810E-067776D22B1F@kreme.com> X-Mailer: Apple Mail (2.3608.60.0.2.5) X-Rspamd-Queue-Id: 48PHsh6zpHz4Yk5 X-Spamd-Bar: + Authentication-Results: mx1.freebsd.org; dkim=none; dmarc=none; spf=pass (mx1.freebsd.org: domain of kremels@kreme.com designates 65.121.55.42 as permitted sender) smtp.mailfrom=kremels@kreme.com X-Spamd-Result: default: False [1.16 / 15.00]; ARC_NA(0.00)[]; NEURAL_HAM_MEDIUM(-0.39)[-0.387,0]; FROM_HAS_DN(0.00)[]; R_SPF_ALLOW(-0.20)[+mx]; MISSING_MIME_VERSION(2.00)[]; MIME_GOOD(-0.10)[text/plain]; MIME_TRACE(0.00)[0:+]; DMARC_NA(0.00)[kreme.com]; RCPT_COUNT_ONE(0.00)[1]; NEURAL_HAM_LONG(-0.98)[-0.981,0]; IP_SCORE(-0.07)[ip: (-0.24), ipnet: 65.112.0.0/12(-0.00), asn: 209(-0.04), country: US(-0.05)]; TO_DN_ALL(0.00)[]; TO_MATCH_ENVRCPT_ALL(0.00)[]; RCVD_COUNT_ZERO(0.00)[0]; RCVD_IN_DNSWL_LOW(-0.10)[42.55.121.65.list.dnswl.org : 127.0.5.1]; R_DKIM_NA(0.00)[]; SUBJECT_ENDS_QUESTION(1.00)[]; ASN(0.00)[asn:209, ipnet:65.112.0.0/12, country:US]; MID_RHS_MATCH_FROM(0.00)[]; FROM_EQ_ENVFROM(0.00)[] X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 21 Feb 2020 17:06:02 -0000 On 21 Feb 2020, at 07:37, =C3=96zg=C3=BCr Kazancci = wrote: > It *somehow* works on FreeBSD 10/11, but not on 12 at all. How does it not work? It installs just fine under 12.1 and the scripts = execute. =EF=A3=BF root@mail ./install.sh ./install.sh: line 48: chattr: command not found Linux Malware Detect v1.6.4 (C) 2002-2019, R-fx Networks (C) 2019, Ryan MacDonald This program may be freely redistributed under the terms of the GNU GPL installation completed to /usr/local/maldetect config file: /usr/local/maldetect/conf.maldet exec file: /usr/local/maldetect/maldet exec link: /usr/local/sbin/maldet exec link: /usr/local/sbin/lmd cron.daily: /etc/cron.daily/maldet imported config options from /usr/local/maldetect.last/conf.maldet maldet(22068): {sigup} performing signature update check... maldet(22068): {sigup} could not determine signature version maldet(22068): {sigup} signature files missing or corrupted, forcing = update... maldet(22068): {sigup} new signature set 202002198018 available maldet(22068): {sigup} downloading = https://cdn.rfxn.com/downloads/maldet-sigpack.tgz maldet(22068): {sigup} downloading = https://cdn.rfxn.com/downloads/maldet-cleanv2.tgz maldet(22068): {sigup} verified md5sum of maldet-sigpack.tgz maldet(22068): {sigup} unpacked and installed maldet-sigpack.tgz maldet(22068): {sigup} verified md5sum of maldet-clean.tgz maldet(22068): {sigup} unpacked and installed maldet-clean.tgz maldet(22068): {sigup} signature set update completed maldet(22068): {sigup} 17027 signatures (14207 MD5 | 2035 HEX | 785 YARA = | 0 USER) =EF=A3=BF root@mail # /usr/local/maldetect/maldet Linux Malware Detect v1.6.4 (C) 2002-2019, R-fx Networks (C) 2019, Ryan MacDonald This program may be freely redistributed under the terms of the GNU GPL = v2 signature set: 202002198018 usage maldet [-h|--help] [-a|--scan-all PATH] [-r|--scan-recent PATH = DAYS] [-f|--file-list PATH] [-i|--include-regex] [-x|--exclude-regex] [-b|--background] [-m|--monitor] [-k|--kill-monitor] = [-c|--checkout] [-q|--quarantine] [-s|--restore] [-n|--clean] [-l|--log] = [-e|--report] [-u|--update-sigs] [-d|--update-ver]