Re: securing a unix system - suggestions on checking for intrusions

Robin Paulson <[email protected]>
Newsgroups gmane.org.user-groups.linux.new-zealand.general
Message-ID <[email protected]>
 On Thu, 06 Oct 2011 15:29:43 +1300, [email protected] wrote:
>>> Something like this could help.
>>>
>>> http://www.tripwire.org/
>>>
>>> http://en.wikipedia.org/wiki/Open_Source_Tripwire
>>
>> excellent, i'll give it a whirl. but it brings up this question:
>> is there anything to check the tripwire database, to ensure it 
>> hasn't
>> been tampered with?
>
> Sounds like a Russian doll problem to me. Any check you can do will
> need a check on itself and so on...
>
> You could be reasonably sure by taking a sha1 hash of the tripwire
> database when your system is in a known good state and storing it on
> another system (encrypted if necessary).

 sorry, i should confess i was kind of having fun. we are always inside 
 the matrix, etc.

 thanks for the suggestion, though. that is a solution, i could always 
 email it somewhere else each time the hash is created. or if the 
 database is not too large, email that somewhere

-- 
 robin

 http://bumblepuppy.org/blog/?p=237 - government bill to remove basic 
 human rights in NZ

_______________________________________________
NZLUG mailing list [email protected]
http://www.linux.net.nz/cgi-bin/mailman/listinfo/nzlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.