[Date Prev][Date Next] [Thread Prev][Thread Next]
[Thread Index]
[Date Index]
[Author Index]
Re: what to use instead of tripwire?t
- From: Alan Cox <alan redhat com>
- To: fedora-test-list redhat com
- Subject: Re: what to use instead of tripwire?t
- Date: Sun, 12 Oct 2003 15:37:42 -0400 (EDT)
> For that matter, it can be easily bypassed by a modified RPM database or
> binary.
> It's a useful check against corruption, but probably not skilled &
> determined deliberate modification.
Just like tripwire.
Short of physically powercycling, verifying the BIOS and device ROM
checksums match, inspecting the hardware for modifications and trusting
the device vendors you don't get far.
The signed tripwire database for example is worthless unless you boot
off a trusted kernel to process it using only trusted binaries.
[Date Prev][Date Next] [Thread Prev][Thread Next]
[Thread Index]
[Date Index]
[Author Index]