System Integrity checker
Posted: 28 Mar 2008, 14:40
Many moons ago I wrote a set of scripts much like csf. I am glad great minds think alike
I know this is a tricky one, but one improvement I would like to see is a way to set up a set of files which the System Integrity check will restore if they are modified.
For instance, sshd, ps, etc...
Last year, one of my servers was compromised but I caught it immediately (thanks to csf!) however, it was late at night and there was a good chance I would not have caught it until the next morning. I got an email about sshd being replaced along with a few other commands.
the packages in question would have to be excluded from system updates (up2date, upcp, etc...) but this would provide a healing option
Another suggestion would be perhaps to use dnotify or inotify for monitoring these files which would provide more of an instantaneous trigger.
Just my 2 cents
--
George
I know this is a tricky one, but one improvement I would like to see is a way to set up a set of files which the System Integrity check will restore if they are modified.
For instance, sshd, ps, etc...
Last year, one of my servers was compromised but I caught it immediately (thanks to csf!) however, it was late at night and there was a good chance I would not have caught it until the next morning. I got an email about sshd being replaced along with a few other commands.
the packages in question would have to be excluded from system updates (up2date, upcp, etc...) but this would provide a healing option
Another suggestion would be perhaps to use dnotify or inotify for monitoring these files which would provide more of an instantaneous trigger.
Just my 2 cents
--
George