Gentoo Archives: gentoo-security

From: Andrew Gaffney <agaffney@×××××××××××.com>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] tripwire-ish portage scanner
Date: Thu, 25 Mar 2004 20:05:23
Message-Id: 40633B21.8070701@skylineaero.com
In Reply to: Re: [gentoo-security] tripwire-ish portage scanner by Tom Hosiawa
1 Tom Hosiawa wrote:
2 >>On Thu, Mar 25, 2004 at 12:46:25PM -0600, Andrew Gaffney wrote:
3 >>
4 >>>I've come up with a quick n' dirty Perl script to use portage's MD5s in a
5 >>>tripwire fashion.
6 >>>
7 >>
8 >>Didn't you know about qpkg? qpkg already does this, qpkg -c checks mtime
9 >>and md5sum for all packages. With -v it will list the exact files that
10 >>mismatch.. The only thing that's lacking is checking the integrity of
11 >>the md5sums themselves with some kind of signature.
12 >>
13 >>Regards,
14 >>
15 >>Michel Wilson.
16 >
17 >
18 > What about qpkq being compromised itself. As I understand it, in
19 > tripwire, cryptographic keys are used for the policy file.
20 >
21 > Couldn't an attacker mess around with which files qpkq scans?
22
23 That's another good reason for a customer portage-integrated solution.
24
25 --
26 Andrew Gaffney
27 Network Administrator
28 Skyline Aeronautics, LLC.
29 636-357-1548
30
31
32 --
33 gentoo-security@g.o mailing list

Replies

Subject Author
Re: [gentoo-security] tripwire-ish portage scanner Mark Guertin <guertin@××××××××××××××.com>
Re: [gentoo-security] tripwire-ish portage scanner Michel Wilson <michel@×××××××.net>