1 |
> Should it really be this difficult to get something like tripwire to work properly? Gentoo |
2 |
> needs a custom tripwire-ish program that can take advantage of portage's MD5SUM's and |
3 |
> mtime's on all installed files. A scanner could even be added to portage as a FEATURE. |
4 |
> While a program like this wouldn't catch intrusions involving non-portage-installed data |
5 |
> files, it would catch any replaced/modified binaries/scripts. Although, there would need |
6 |
> to be a configuration option to disable warnings on files in /etc since those are usually |
7 |
> modified after they are installed by portage. Or even better, there could be an option to |
8 |
> the program that would scan for changes in /etc and update portage's MD5SUM of the files. |
9 |
|
10 |
What's the difference between tripwire's file signature's, and portage's |
11 |
md5sum's and mtime's? |
12 |
|
13 |
Tom |
14 |
|
15 |
|
16 |
-- |
17 |
gentoo-security@g.o mailing list |