RE: Certifying a RedHat Install
"Michael LaSalvia" <[email protected]>
| Newsgroups | gmane.comp.security.linux |
|---|---|
| Message-ID | <001a01c469e7$9c6c1f70$6401a8c0@rootmybox> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 The base install of rh 9.0 has a vuln in the kernel that a normal user can gain root access. I believe the vuln was bork overflow. I would suggest upgrading the kernel before delivery. Michael LaSalvia LCA, TICSA, CCSA, CSI - -----Original Message----- From: abe [mailto:[email protected]] Sent: Wednesday, July 14, 2004 1:38 PM To: [email protected] Subject: Certifying a RedHat Install My client wants me to certify there are no back doors in the RedHat 9 server we are going to deliver. It's a base RH9 install with a few extra RPM's, like Guarddog. Question is what's the best way for us to certify this? * rpm -Va ? * A global md5 on each file? Also, what's the best way to minimize liability if they are hacked? I don't want to get sued because the were negligent. Thanks, Abe -----BEGIN PGP SIGNATURE----- Version: PGPfreeware 6.5.8 for non-commercial use <http://www.pgp.com> iQA/AwUBQPWiSdKAGcNwMOHTEQJpXwCeJywd4Xipzz+eF8NddFIkWfkmSf8AnRTG zygHmTq5XTPsolbVLCMp5FD5 =BMA/ -----END PGP SIGNATURE-----