Gentoo Archives: gentoo-security

From: Andrea Barisani <lcars@g.o>
To: Andrew Gaffney <agaffney@×××××××××××.com>
Cc: gentoo-security@l.g.o
Subject: Re: [gentoo-security] tripwire-ish portage scanner
Date: Fri, 26 Mar 2004 00:06:52
Message-Id: 20040326000631.GR20380@sole.infis.univ.trieste.it
In Reply to: Re: [gentoo-security] tripwire-ish portage scanner by Andrew Gaffney
1 On Thu, Mar 25, 2004 at 06:01:55PM -0600, Andrew Gaffney wrote:
2 > >
3 > >
4 > >I suggest that you look at samhain:
5 > >
6 > >http://la-samhna.de/samhain
7 > >
8 > >It's an excellent file integrity and host-based intrusion detection system
9 > >with advanced features that solves the "chicken-and-egg" problem along with
10 > >other cool gizmos :).
11 >
12 > From the site:
13 >
14 > Support for a stealth mode of operation
15 >
16 > Is there a way to make a process not show up in 'ps' output?
17
18 Yes, there is a kernel module that allows you to do that. You can also
19 automatically change the name of the binary and related paths.
20
21
22 --
23 Andrea Barisani <lcars@g.o> .*.
24 Gentoo Linux Infrastructure Developer V
25 ( )
26 GPG-Key 0x864C9B9E http://dev.gentoo.org/~lcars/pubkey.asc ( )
27 0A76 074A 02CD E989 CE7F AC3F DA47 578E 864C 9B9E ^^_^^
28
29 --
30 gentoo-security@g.o mailing list