RE: Certifying a RedHat Install

"Michael LaSalvia" <[email protected]>
Newsgroups gmane.comp.security.linux
Message-ID <001a01c469e7$9c6c1f70$6401a8c0@rootmybox>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

The base install of rh 9.0 has a vuln in the kernel that a normal
user can gain root access. I believe the vuln was bork overflow. I
would suggest upgrading the kernel before delivery.

Michael LaSalvia
LCA, TICSA, CCSA, CSI


- -----Original Message-----
From: abe [mailto:[email protected]] 
Sent: Wednesday, July 14, 2004 1:38 PM
To: [email protected]
Subject: Certifying a RedHat Install

My client wants me to certify there are no back doors in the RedHat 9
server we are going to deliver.  It's a base RH9 install with a few 
extra RPM's, like Guarddog.

Question is what's the best way for us to certify this?
*  rpm -Va ?
*  A global md5 on each file?

Also, what's the best way to minimize liability if they are hacked? 
I 
don't want to get sued because the were negligent.

Thanks,

Abe




-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 6.5.8 for non-commercial use <http://www.pgp.com>

iQA/AwUBQPWiSdKAGcNwMOHTEQJpXwCeJywd4Xipzz+eF8NddFIkWfkmSf8AnRTG
zygHmTq5XTPsolbVLCMp5FD5
=BMA/
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.