Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
 Post subject:
PostPosted: Wed Sep 28, 2011 6:24 pm 
Offline
Senior Member

Joined: Mon Dec 07, 2009 6:46 am
Posts: 331
Lesson to use an intrusion detection system like Aide or Tripwire. Personally I use Aide, and I also keep it's db checksum independently (the script mails it to me on each build) so I can check if Aide itself has been compromised.

This alone can prevent such problems in the future as the system will (should, at least) show all the files that have changed and should not have. Naturally, those files that SHOULD change, like logs etc..., shouldn't be covered by Aide. But at least it can cover the most important ones like /bin, /sbin, /usr/sbin, /etc and perhaps some files in /var (like package manager's). Update Aide DB on each system update, program (de)installation or config change.


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group