Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.security > #6118

Re: What is the best free HIDS for Debian

Path csiph.com!aioe.org!bofh.it!news.nic.it!robomod
From Michael Lazin <microlaser@gmail.com>
Newsgroups linux.debian.security
Subject Re: What is the best free HIDS for Debian
Date Mon, 09 May 2022 12:50:01 +0200
Message-ID <El97H-ej1J-1@gated-at.bofh.it> (permalink)
References <EiJ7H-cKEs-3@gated-at.bofh.it> <Ejlwl-d9mK-1@gated-at.bofh.it> <Ek6EV-dDUf-5@gated-at.bofh.it> <Ek6Yh-dEgS-3@gated-at.bofh.it> <EkQRr-e7eu-5@gated-at.bofh.it> <EkQRr-e7eu-3@gated-at.bofh.it> <EkTPj-e92s-19@gated-at.bofh.it> <EkU8F-e98w-5@gated-at.bofh.it> <EkV4K-e9Go-9@gated-at.bofh.it> <EkXzz-ebew-3@gated-at.bofh.it> <EkY2C-eboV-5@gated-at.bofh.it> <El6CR-ehI2-1@gated-at.bofh.it>
X-Original-To debian-security@lists.debian.org
X-Mailbox-Line From debian-security-request@lists.debian.org Mon May 9 10:42:47 2022
Old-Return-Path <microlaser@gmail.com>
X-Amavis-Spam-Status No, score=-3.609 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, BODY_8BITS=1.5, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FOURLA=0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=2, LDO_WHITELIST=-5, RCVD_IN_DNSWL_NONE=-0.0001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=no autolearn_force=no
X-Policyd-Weight using cached result; rate: -5.5
X-Gm-Message-State AOAM531J8ONganPAO0q30RPjm9sDhMAsqFHnVW3FAAw/2fshEex6SMBI OF8suPHggdwMP9/8cqUh3G32lyGXPaaL58SdE2hUS19n
X-Google-SMTP-Source ABdhPJx9VNgbLFmlz7tL/CgvA2mO8eI97X8/bkBdJ+zXXA/WiwFUb2ra9UkZy/aJ2NP/vlGxj9mGO1cyoRBdMZuCBS0=
X-Received by 2002:a17:906:6a14:b0:6f4:78b8:39e7 with SMTP id qw20-20020a1709066a1400b006f478b839e7mr13698995ejc.309.1652092951717; Mon, 09 May 2022 03:42:31 -0700 (PDT)
MIME-Version 1.0
Content-Type multipart/alternative; boundary="00000000000085e9f605de91dd08"
X-Mailing-List <debian-security@lists.debian.org> archive/latest/29270
List-ID <debian-security.lists.debian.org>
List-URL <https://lists.debian.org/debian-security/>
List-Archive https://lists.debian.org/msgid-search/CALdcr8faAD5xZbnGHiUK6DPT-GfhTmbb3xHQ67yeSW53xrPUvw@mail.gmail.com
Approved robomod@news.nic.it
Lines 108
Organization linux.* mail to news gateway
Sender robomod@news.nic.it
X-Original-Date Mon, 9 May 2022 06:42:20 -0400
X-Original-Message-ID <CALdcr8faAD5xZbnGHiUK6DPT-GfhTmbb3xHQ67yeSW53xrPUvw@mail.gmail.com>
X-Original-References <62701ec7$0$18715$426a34cc@news.free.fr> <627260e6$0$24819$426a74cc@news.free.fr> <7848bfca-3955-dd96-3aff-f454d1e28315@elstel.org> <42898050-0dea-3cfb-3462-0a58452182e5@elstel.org> <Ek6Yh-dEgS-3@gated-at.bofh.it> <6277d936$0$22287$426a74cc@news.free.fr> <CALdcr8d8tq49E2+UE1khcb5YKKJP+FWTiLtnObQ7L5+afFJwxg@mail.gmail.com> <3269f6ada90bb33d1a672932ff4afc82@elstel.org> <baf40c33ad6fdd6ba4e24ee09fee972b@elstel.org> <CALdcr8dyg8uGCzfpFCrOEb8d8+38y8Cu3F+5MdY8oQPAARZSiw@mail.gmail.com> <YnhIxd8lAT27VqEd@vandradlabs.com.au> <2f7f912c-e001-a32c-ca99-5eeb2c4a981a@elstel.org>
Xref csiph.com linux.debian.security:6118

Show key headers only | View raw


[Multipart message — attachments visible in raw view] - view raw

This supports the use of rkhunter and running it once on first install but
you can manually find file changes systematically by becoming root and
going to the top level directory and running “find -ctime 1”, “find -ctime
-2” etc ad infinitum until you find all files that may have been
compromised.  This method will not find deleted files so some expertise in
the Linux file system is necessary when not using rkhunter.

Thanks,

Michael Lazin

On Mon,May 9, 2022 at 4:04 AM Elmar Stellnberger <estellnb@elstel.org>
wrote:

> Am 09.05.22 um 00:48 schrieb Tomasz Ciolek:
> > 5. have we eliminated other causes of file mismatch - bad/incomplete
> > updates, corrupted HDD, bad RAM, user error ?
>
>    If exactly such files have been changed where there is reason to
> manipulate them for a rootkit then one shall assume unequivocally that
> there is a rootkit installed. With bad RAM you get a system crash and
> with a physically bad hard disk you get filesystem errors on fsck, none
> of which you get with a rootkit where only certain files have been
> manipulated intentionally. A broken update could theoretically result in
> a singleton file of half the size. Usually running programs keep to use
> the old version of the file under Linux while newly issued open
> operations on the same file name will use the file as replaced by an
> update. A file of half the size would however result in an unusable
> program, none of which you would usually observe with a rootkit.
>
> Elmar
>
> --
Michael Lazin

.. τὸ γὰρ αὐτὸ νοεῖν ἐστίν τε καὶ εἶναι.

Back to linux.debian.security | Previous | NextPrevious in thread | Next in thread | Find similar


Thread

What is the best free HIDS for Debian Sylvain <ssecherre@free.fr> - 2022-05-02 20:40 +0200
  Re: What is the best free HIDS for Debian Hannes von Haugwitz <hannes@vonhaugwitz.com> - 2022-05-02 21:00 +0200
  Re: What is the best free HIDS for Debian "Dave P." <dprowseus@gmail.com> - 2022-05-02 21:10 +0200
  Re: What is the best free HIDS for Debian Gianluca Gabrielli <ggabrielli@suse.de> - 2022-05-02 21:10 +0200
  Re: What is the best free HIDS for Debian "Darren S." <phatbuckett@gmail.com> - 2022-05-02 21:50 +0200
  Re: What is the best free HIDS for Debian mlnl <mlnl@mailbox.org> - 2022-05-03 06:30 +0200
  Re: What is the best free HIDS for Debian Sylvain <ssecherre@free.fr> - 2022-05-03 14:40 +0200
    Re: What is the best free HIDS for Debian Jonathan Hutchins <hutchins@tarcanfel.org> - 2022-05-03 15:10 +0200
      Re: What is the best free HIDS for Debian Elmar Stellnberger <estellnb@elstel.org> - 2022-05-03 15:30 +0200
    Re: What is the best free HIDS for Debian Marc Haber <mh+debian-security@zugschlus.de> - 2022-05-04 10:10 +0200
  Re: What is the best free HIDS for Debian Sylvain <ssecherre@free.fr> - 2022-05-04 13:40 +0200
    Re: What is the best free HIDS for Debian Elmar Stellnberger <estellnb@elstel.org> - 2022-05-06 16:00 +0200
      Re: What is the best free HIDS for Debian Elmar Stellnberger <estellnb@elstel.org> - 2022-05-06 16:20 +0200
        Re: What is the best free HIDS for Debian Sylvain <ssecherre@free.fr> - 2022-05-08 17:20 +0200
          Re: What is the best free HIDS for Debian Michael Lazin <microlaser@gmail.com> - 2022-05-08 20:30 +0200
            Re: What is the best free HIDS for Debian estellnb@elstel.org - 2022-05-08 20:50 +0200
              Re: What is the best free HIDS for Debian Michael Lazin <microlaser@gmail.com> - 2022-05-08 20:50 +0200
                Re: What is the best free HIDS for Debian estellnb@elstel.org - 2022-05-08 21:20 +0200
              Re: What is the best free HIDS for Debian estellnb@elstel.org - 2022-05-08 21:50 +0200
                Re: What is the best free HIDS for Debian Michael Lazin <microlaser@gmail.com> - 2022-05-09 00:30 +0200
                Re: What is the best free HIDS for Debian Tomasz Ciolek <tmc@vandradlabs.com.au> - 2022-05-09 01:00 +0200
                Re: What is the best free HIDS for Debian Elmar Stellnberger <estellnb@elstel.org> - 2022-05-09 10:10 +0200
                Re: What is the best free HIDS for Debian Michael Lazin <microlaser@gmail.com> - 2022-05-09 12:50 +0200
                Re: What is the best free HIDS for Debian tmc@vandradlabs.com.au - 2022-05-09 13:40 +0200
                Re: What is the best free HIDS for Debian Elmar Stellnberger <estellnb@elstel.org> - 2022-05-09 14:00 +0200
                Re: What is the best free HIDS for Debian Tomasz Ciolek <tmc@vandradlabs.com.au> - 2022-05-09 15:30 +0200
        Re: What is the best free HIDS for Debian Elmar Stellnberger <estellnb@elstel.org> - 2022-05-08 20:30 +0200
        Re: What is the best free HIDS for Debian Elmar Stellnberger <estellnb@elstel.org> - 2022-05-08 20:30 +0200
        Re: What is the best free HIDS for Debian Elmar Stellnberger <estellnb@elstel.org> - 2022-05-08 20:40 +0200
          Re: What is the best free HIDS for Debian Sylvain <ssecherre@free.fr> - 2022-05-13 16:30 +0200
            Re: What is the best free HIDS for Debian Sylvain <ssecherre@free.fr> - 2022-05-16 12:00 +0200
              Re: What is the best free HIDS for Debian Elmar Stellnberger <estellnb@elstel.org> - 2022-05-16 13:10 +0200
              Re: What is the best free HIDS for Debian Elmar Stellnberger <estellnb@elstel.org> - 2022-05-17 12:00 +0200
      Re: What is the best free HIDS for Debian Vitaly Krasheninnikov <iam@krushik.ru> - 2022-05-10 05:40 +0200
        Re: What is the best free HIDS for Debian Richard van den Berg <richard@vdberg.org> - 2022-05-10 08:40 +0200
      Re: What is the best free HIDS for Debian Elmar Stellnberger <estellnb@elstel.org> - 2022-05-11 17:50 +0200

csiph-web