Re: securing a unix system - suggestions on checking for intrusions
Bryan Baldwin <[email protected]>
| Newsgroups | gmane.org.user-groups.linux.new-zealand.general |
|---|---|
| Message-ID | <[email protected]> |
On 6/10/2011 3:00 PM, Robin Paulson wrote: > On Thu, 06 Oct 2011 14:54:56 +1300, Robin Sheat wrote: >>> i would guess to check for suspicious files that have replaced files >>> from the repo? i.e. ensuring you've still got the exact binary >>> installed >>> that you want/should have? >> >> But, is it checking the sigs on the binaries, or just that the RPM you >> installed was fine? > > i think the latter > >> Actually, if every manifest contains the hash of each installed file, >> and that manifest is signed, then it would be useful to verify the >> integrity of those aspects of the system. >> >> But I don't think it's doing that. > > me neither. any suggestions on software/script to do the former, i.e. > check every file? > Something like this could help. http://www.tripwire.org/ http://en.wikipedia.org/wiki/Open_Source_Tripwire _______________________________________________ NZLUG mailing list [email protected] http://www.linux.net.nz/cgi-bin/mailman/listinfo/nzlug