1 |
> On Thu, Mar 25, 2004 at 12:46:25PM -0600, Andrew Gaffney wrote: |
2 |
> > I've come up with a quick n' dirty Perl script to use portage's MD5s in a |
3 |
> > tripwire fashion. |
4 |
> > |
5 |
> Didn't you know about qpkg? qpkg already does this, qpkg -c checks mtime |
6 |
> and md5sum for all packages. With -v it will list the exact files that |
7 |
> mismatch.. The only thing that's lacking is checking the integrity of |
8 |
> the md5sums themselves with some kind of signature. |
9 |
> |
10 |
> Regards, |
11 |
> |
12 |
> Michel Wilson. |
13 |
|
14 |
What about qpkq being compromised itself. As I understand it, in |
15 |
tripwire, cryptographic keys are used for the policy file. |
16 |
|
17 |
Couldn't an attacker mess around with which files qpkq scans? |
18 |
|
19 |
Tom |
20 |
|
21 |
|
22 |
-- |
23 |
gentoo-security@g.o mailing list |