Gentoo Archives: gentoo-hardened

From: lists@×××.org
To: gentoo-hardened@g.o
Subject: Re: [gentoo-hardened] Just joined, normallly would lurk, but...
Date: Tue, 11 Mar 2003 21:37:40
Message-Id: Pine.LNX.4.53.0303111634330.28046@nautilus.m8y.org
In Reply to: Re: [gentoo-hardened] Just joined, normallly would lurk, but... by Alain Penders
1 Yes, I used tripwire before. Although all it does is warn. I like the idea of blocking.
2 Also, it merely tracks executables, it does not permit signed access to certain operations.
3 This method they gave has its problems. No code signatures, only tracks single system call, apparently hardcoded passphrase (even if hashed), but unlike tripwire where it'd be up to *me* to notice the breakin based on the report, their system is more about preventing certain rights in the first place.
4
5 This is very interesting to me as I like giving people accounts on my machine, and something like rbash simply doesn't cut it.
6 For large systems, the ability to tightly restrict user rights would be very cool.
7
8 ----------------------------------------
9 Free Mickey!
10 http://randomfoo.net/oscon/2002/lessig/
11 My key: http://m8y.org/keys.html
12
13 On Tue, 11 Mar 2003, Alain Penders wrote:
14 > There's a whole company based around this: http://www.tripwire.com/
15 >
16 > tripwire is a standard part of most linux distributions these days, and we're
17 > looking at adding tripwire-like functionality into portage.
18 >
19 > As for the paper... had the authors been familiar with tripwire, they might
20 > have described some other security risks related to their implementation. :)
21 >
22 > Alain
23 >
24 > --
25 > gentoo-hardened@g.o mailing list
26 >
27 >
28
29 --
30 gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] Just joined, normallly would lurk, but... Alain Penders <alain@g.o>