Re: securing a unix system - suggestions on checking for intrusions
Robin Paulson <[email protected]>
| Newsgroups | gmane.org.user-groups.linux.new-zealand.general |
|---|---|
| Message-ID | <[email protected]> |
On Thu, 06 Oct 2011 15:29:43 +1300, [email protected] wrote: >>> Something like this could help. >>> >>> http://www.tripwire.org/ >>> >>> http://en.wikipedia.org/wiki/Open_Source_Tripwire >> >> excellent, i'll give it a whirl. but it brings up this question: >> is there anything to check the tripwire database, to ensure it >> hasn't >> been tampered with? > > Sounds like a Russian doll problem to me. Any check you can do will > need a check on itself and so on... > > You could be reasonably sure by taking a sha1 hash of the tripwire > database when your system is in a known good state and storing it on > another system (encrypted if necessary). sorry, i should confess i was kind of having fun. we are always inside the matrix, etc. thanks for the suggestion, though. that is a solution, i could always email it somewhere else each time the hash is created. or if the database is not too large, email that somewhere -- robin http://bumblepuppy.org/blog/?p=237 - government bill to remove basic human rights in NZ _______________________________________________ NZLUG mailing list [email protected] http://www.linux.net.nz/cgi-bin/mailman/listinfo/nzlug