Re: securing a unix system - suggestions on checking for intrusions

Robin Paulson <[email protected]>
Newsgroups gmane.org.user-groups.linux.new-zealand.general
Message-ID <[email protected]>
 On Thu, 06 Oct 2011 13:32:29 +1300, Robin Sheat wrote:
> Op donderdag 06-10-2011 om 12:53 uur [tijdzone +1300], schreef Robin
> Paulson:
>>     Unfortunately there is no known way of verifying this on
>>  Debian-based
>>     systems."
>
> Apt checks the sigs of the repo and the packages when you install 
> from
> it, and whinges mightily if they don't match a known key.
>
> I'm not totally sure what that snippet is doing, but it looks like 
> it's
> seeing that there's sig on packages that are already installed, which 
> I
> don't see the point of.

 i would guess to check for suspicious files that have replaced files 
 from the repo? i.e. ensuring you've still got the exact binary installed 
 that you want/should have?

-- 
 robin

 http://bumblepuppy.org/blog/?p=237 - government bill to remove basic 
 human rights in NZ

_______________________________________________
NZLUG mailing list [email protected]
http://www.linux.net.nz/cgi-bin/mailman/listinfo/nzlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.