Re: securing a unix system - suggestions on checking for intrusions
Cliff Pratt <[email protected]>
| Newsgroups | gmane.org.user-groups.linux.new-zealand.general |
|---|---|
| Message-ID | <[email protected]> |
On 06/10/11 15:09, Bryan Baldwin wrote: > On 6/10/2011 3:00 PM, Robin Paulson wrote: >> On Thu, 06 Oct 2011 14:54:56 +1300, Robin Sheat wrote: >>>> i would guess to check for suspicious files that have replaced files >>>> from the repo? i.e. ensuring you've still got the exact binary >>>> installed >>>> that you want/should have? >>> >>> But, is it checking the sigs on the binaries, or just that the RPM you >>> installed was fine? >> >> i think the latter >> >>> Actually, if every manifest contains the hash of each installed file, >>> and that manifest is signed, then it would be useful to verify the >>> integrity of those aspects of the system. >>> >>> But I don't think it's doing that. >> >> me neither. any suggestions on software/script to do the former, i.e. >> check every file? >> > > Something like this could help. > > http://www.tripwire.org/ > > http://en.wikipedia.org/wiki/Open_Source_Tripwire > I don't see the point of tripwire and the like. It's shutting the stable door after the horse has bolted. It's far better to stop the files being changed in the first place. Cheers, Cliff _______________________________________________ NZLUG mailing list [email protected] http://www.linux.net.nz/cgi-bin/mailman/listinfo/nzlug