Re: aide or tripwire

From: Brian Cervenka (focus-linux@tracking.zerobelow.org)
Date: 12/21/01


Date: Thu, 20 Dec 2001 16:53:12 -0800 (PST)
From: Brian Cervenka <focus-linux@tracking.zerobelow.org>
To: rdicaire@ardynet.com


> If it can be set, it can be unset. On a CDROM its on a read only
> filesystem.

Keep in mind, though, that some vulnerabilities only allow things like to
overwrite a file that is root writable, or to append to a file -- not all
vulns allow code execution directly. chattr would have helped in this
case.

Also, if they can turn off chattr +i, what's to stop them from doing
something like mounting a loopback device that looks like a cd-rom?

Also, you need to keep your entire tripwire binaries on that cd-rom, so
that they can not be trojaned to look at a different database.

Also, you need to keep your entire os on a cd-rom so that it can not be
trojaned to run a different binary.

This is all about mitigating risks...you're not going to eliminate them.
The chattr thing can help in some circumstances, so its not entirely
useless. But, yeah, it's probably a good idea to keep the database on
cd-rom.

--brian



Relevant Pages

  • Re: Translating my genealogy CD-ROM
    ... Denis Beauregard wrote: ... I published recently the French version of my database on a CD-ROM ... I read software that I only had to have some autorun ...
    (soc.genealogy.computing)
  • Re: Translating my genealogy CD-ROM
    ... I published recently the French version of my database on a CD-ROM ... I read software that I only had to have some autorun ... you can make the CD autorun with a simple batch file. ...
    (soc.genealogy.computing)
  • Re: Translating my genealogy CD-ROM
    ... Denis Beauregard wrote: ... I published recently the French version of my database on a CD-ROM ... There are instructions at http://www.softwarepatch.com/tips/autorun.html for autorunning. ...
    (soc.genealogy.computing)
  • Re: [Info-Ingres] createdb -r flag
    ... introduced in 2.5 I think and is a way to e.g. distribute a database on ... Let's take the CD-ROM example. ... to have the same version of Ingres installed. ... Createdb -rcdrom_loc sales_demo ...
    (comp.databases.ingres)
  • Re: Translating my genealogy CD-ROM
    ... I published recently the French version of my database on a CD-ROM ... I read software that I only had to have some autorun ... a start command in Windows 98 SE. ...
    (soc.genealogy.computing)