Gentoo Archives: gentoo-security

From: Andrew Gaffney <agaffney@×××××××××××.com>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] tripwire policy generator
Date: Thu, 25 Mar 2004 22:57:06
Message-Id: 40636363.9040900@skylineaero.com
In Reply to: Re: [gentoo-security] tripwire policy generator by Tom Hosiawa
1 Tom Hosiawa wrote:
2 >>Should it really be this difficult to get something like tripwire to work properly? Gentoo
3 >>needs a custom tripwire-ish program that can take advantage of portage's MD5SUM's and
4 >>mtime's on all installed files. A scanner could even be added to portage as a FEATURE.
5 >>While a program like this wouldn't catch intrusions involving non-portage-installed data
6 >>files, it would catch any replaced/modified binaries/scripts. Although, there would need
7 >>to be a configuration option to disable warnings on files in /etc since those are usually
8 >>modified after they are installed by portage. Or even better, there could be an option to
9 >>the program that would scan for changes in /etc and update portage's MD5SUM of the files.
10 >
11 >
12 > What's the difference between tripwire's file signature's, and portage's
13 > md5sum's and mtime's?
14
15 Portage's MD5SUM's and mtime's are updated when the system is updated. One less step.
16
17 --
18 Andrew Gaffney
19 Network Administrator
20 Skyline Aeronautics, LLC.
21 636-357-1548
22
23
24 --
25 gentoo-security@g.o mailing list