Re: securing a unix system - suggestions on checking for intrusions

Robin Sheat <[email protected]>
Newsgroups gmane.org.user-groups.linux.new-zealand.general
Message-ID <1317948386.11495.47.camel@zarathud>
Op vrijdag 07-10-2011 om 10:37 uur [tijdzone +1300], schreef Jim
Cheetham:
> Of course a smart attacker will change the checksum after they patch
> the associated binary; to prevent this the checksum files need to be
> signed with the same keys as the packages, which isn't happening, so
> the results of this are potentially less useful than the rpm
> equivalent (which I haven't investigated). 

Were I said attacker, I'd put my key into the 'trusted keys' store and
resign the things I changed with that.

Robin.

_______________________________________________
NZLUG mailing list [email protected]
http://www.linux.net.nz/cgi-bin/mailman/listinfo/nzlug
signature.asc (application/pgp-signature, 198 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iEYEARECAAYFAk6OS9kACgkQFNNkhamc622YRQCePsKq0341KyQl9c00aK9q6YHW
2EQAmwQVHV2MDSHOjvvMMzx/qs9Eq7mF
=pURM
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.