Gentoo Archives: gentoo-security

From: Heikki Levanto <heikki@×××.dk>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] Built in integrity?
Date: Tue, 10 Feb 2004 09:40:59
Message-Id: 20040210094034.GB13825@lsd.dk
In Reply to: Re: [gentoo-security] Built in integrity? by Christian Schwede
1 On Tue, Feb 10, 2004 at 01:51:51AM +0100, Christian Schwede wrote:
2 >
3 > Right. But this still isn't that useful - for watching binary files it's
4 > ok, but you wouldn't recognize changes to config files etc.
5
6 I am using a homegrown script that mails all sorts of important
7 snapshots to another server. MD5's of executables, list of setuids,
8 config files, etc. Some every hour, some every night.
9
10 The receiving server compares all these mails to their previous
11 versions, and alerts me to any differences.
12
13 After some tuning and tweaking, there are still several false alarms
14 every day, but I have learned to read them and discard most of them as
15 harmless.
16
17 I think it is important that the "correct" values are on a different
18 machine, so that they should be safe under eventual attack. Of course I
19 see that a qualified attacker could modify the mail script to always
20 send the same "correct" mails, but then I would nt get any false
21 alarms... He can't know how much differences I expect.
22
23 I am not sharing the scripts, as they are easy to write, and need to be
24 customized to every installation. But the idea is hereby given freely
25 for anyone to use.
26
27 --
28 Heikki Levanto LSD - Levanto Software Development <heikki@×××.dk>
29
30
31 --
32 gentoo-security@g.o mailing list