Gentoo Archives: gentoo-security

From: Tom Hosiawa <tomek32@××××××.com>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] tripwire policy generator
Date: Thu, 25 Mar 2004 22:35:47
Message-Id: 1080236109.10506.4.camel@newton.tomek.ca
In Reply to: Re: [gentoo-security] tripwire policy generator by Andrew Gaffney
1 > Should it really be this difficult to get something like tripwire to work properly? Gentoo
2 > needs a custom tripwire-ish program that can take advantage of portage's MD5SUM's and
3 > mtime's on all installed files. A scanner could even be added to portage as a FEATURE.
4 > While a program like this wouldn't catch intrusions involving non-portage-installed data
5 > files, it would catch any replaced/modified binaries/scripts. Although, there would need
6 > to be a configuration option to disable warnings on files in /etc since those are usually
7 > modified after they are installed by portage. Or even better, there could be an option to
8 > the program that would scan for changes in /etc and update portage's MD5SUM of the files.
9
10 What's the difference between tripwire's file signature's, and portage's
11 md5sum's and mtime's?
12
13 Tom
14
15
16 --
17 gentoo-security@g.o mailing list

Replies

Subject Author
Re: [gentoo-security] tripwire policy generator Michel Wilson <michel@×××××××.net>
Re: [gentoo-security] tripwire policy generator Andrew Gaffney <agaffney@×××××××××××.com>