Note: Due to technical difficulties, the Archives are currently not up to date.
GMANE provides an alternative service for most mailing lists. c.f. bug 424647
List Archive: gentoo-security
> Should it really be this difficult to get something like tripwire to work properly? Gentoo
> needs a custom tripwire-ish program that can take advantage of portage's MD5SUM's and
> mtime's on all installed files. A scanner could even be added to portage as a FEATURE.
> While a program like this wouldn't catch intrusions involving non-portage-installed data
> files, it would catch any replaced/modified binaries/scripts. Although, there would need
> to be a configuration option to disable warnings on files in /etc since those are usually
> modified after they are installed by portage. Or even better, there could be an option to
> the program that would scan for changes in /etc and update portage's MD5SUM of the files.
What's the difference between tripwire's file signature's, and portage's
md5sum's and mtime's?
Tom
--
gentoo-security@g.o mailing list
|
|