Re: mtree vs tripwire

From: Adrian Filipi (adrian+freebsd-security_at_ubergeeks.com)
Date: 01/16/04

  • Next message: Lowell Gilbert: "Re: mtree vs tripwire"
    Date: Fri, 16 Jan 2004 01:09:16 -0500 (EST)
    To: D J Hawkey Jr <hawkeyd@visi.com>
    
    

    On Wed, 14 Jan 2004, D J Hawkey Jr wrote:

    > On Jan 14, at 07:09 PM, Jesper Louis Andersen wrote:
    > >
    > > > This might seem really naive, but can mtree be used effectively as
    > > > a native-to-core-OS tripwire equivalent? Would it be as efficient in
    > > > terms of time-to-run and resource requirements?
    > >
    > > Pro: distributed with base
    > > Con: Only available for *BSD architectures as far as my knowledge goes.
    >
    > I'm aware of both, yes; hence my question. FreeBSD is all I'm dealing
    > with, where my question is concerned.
    >
    > Is your reply from personal experience, or is it the same "Hey, it
    > could..." as is my question? If the former, would you elaborate on the
    > implementation details?
    >
    > Thanks,
    > Dave

            The company I just left makes a security appliance, and we
    developed an mtree-based IDS. As others have mentioned, raw mtree and diff
    as-is leaves a lot to be desired. It's just not very conveneint.

            That being said, its works great now that we wrapped it all up in
    some wrapper scripts.

            Adrian

    --
    [ adrian@ubergeeks.com ]
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    

  • Next message: Lowell Gilbert: "Re: mtree vs tripwire"

    Relevant Pages

    • Re: mtree vs tripwire
      ... D J Hawkey Jr writes: ... FreeBSD is all I'm dealing ... Mtree works as well if not slightly better ...
      (FreeBSD-Security)
    • Re: freebsd router with cable modem
      ... I mean do I need to setup ppp in freebsd just ... like the way of dealing with connecting ADSL service? ... I'm unable to get to my own box due to network changes by my ISP (until I ... I just followed the "FreeBSD handbook" section on www.freebsd.org. ...
      (comp.unix.bsd.freebsd.misc)
    • Re: GCC does not support lrint ?
      ... > It appears there is no lrint-family of functions in FreeBSD ... >, but unless you're dealing with longs, rint() should ...
      (comp.unix.bsd.freebsd.misc)
    • Re: Opinion please on quick and dirty
      ... zope installed and running on your FreeBSD box. ... Adding instructions for howto do this with portupgrade would be helpful, ... e.g. dealing with the 'make instance'. ... Ian Tegebo ...
      (freebsd-questions)