1 |
Tom Hosiawa wrote: |
2 |
>>Should it really be this difficult to get something like tripwire to work properly? Gentoo |
3 |
>>needs a custom tripwire-ish program that can take advantage of portage's MD5SUM's and |
4 |
>>mtime's on all installed files. A scanner could even be added to portage as a FEATURE. |
5 |
>>While a program like this wouldn't catch intrusions involving non-portage-installed data |
6 |
>>files, it would catch any replaced/modified binaries/scripts. Although, there would need |
7 |
>>to be a configuration option to disable warnings on files in /etc since those are usually |
8 |
>>modified after they are installed by portage. Or even better, there could be an option to |
9 |
>>the program that would scan for changes in /etc and update portage's MD5SUM of the files. |
10 |
> |
11 |
> |
12 |
> What's the difference between tripwire's file signature's, and portage's |
13 |
> md5sum's and mtime's? |
14 |
|
15 |
Portage's MD5SUM's and mtime's are updated when the system is updated. One less step. |
16 |
|
17 |
-- |
18 |
Andrew Gaffney |
19 |
Network Administrator |
20 |
Skyline Aeronautics, LLC. |
21 |
636-357-1548 |
22 |
|
23 |
|
24 |
-- |
25 |
gentoo-security@g.o mailing list |