Wrong WEB_CMD leads to error message
Security bugs like CVE-2017-7480 et. al. resulted in commit b3243157, which switched off rkhunter version check and update feature provided by upstream. Nevertheless, the weekly update cron job is still part of Debian rkhunter package and installed by default:
- Provide a safe weekly minimum version check cron job for rkhunter database and fix error introduced by commit b3243157:
- Fix default WEB_CMD setting to switch-off unsafe rkhunter updates
- Provide safe weekly update check to inform system adminsitrators about available upstream rkhunter (database) updates
- New configuration option to operate rkhunter behind an (anonymous) web proxy
This merge request continues to allow system administrators that are willing to take security risks to configure rkhunter to periodically perform rkhunter updates using internal rkhunter update mechanism.