Re: securing a unix system - suggestions on checking for intrusions
Robin Paulson <[email protected]>
| Newsgroups | gmane.org.user-groups.linux.new-zealand.general |
|---|---|
| Message-ID | <[email protected]> |
On Thu, 06 Oct 2011 13:32:29 +1300, Robin Sheat wrote: > Op donderdag 06-10-2011 om 12:53 uur [tijdzone +1300], schreef Robin > Paulson: >> Unfortunately there is no known way of verifying this on >> Debian-based >> systems." > > Apt checks the sigs of the repo and the packages when you install > from > it, and whinges mightily if they don't match a known key. > > I'm not totally sure what that snippet is doing, but it looks like > it's > seeing that there's sig on packages that are already installed, which > I > don't see the point of. i would guess to check for suspicious files that have replaced files from the repo? i.e. ensuring you've still got the exact binary installed that you want/should have? -- robin http://bumblepuppy.org/blog/?p=237 - government bill to remove basic human rights in NZ _______________________________________________ NZLUG mailing list [email protected] http://www.linux.net.nz/cgi-bin/mailman/listinfo/nzlug