Re: Certifying a RedHat Install

From: Zow (zow_at_llnl.gov)
Date: 07/15/04

  • Next message: Peter Koinange: "Re: Certifying a RedHat Install"
    To: "corey" <Corey.Hart@synopsys.com>
    Date: Thu, 15 Jul 2004 14:02:08 -0700
    
    

    > Yeah you can an rpm -Va, but who the hell installs a root =
    > kit, backdoor, etc via an rpm?

    Actually, in the case of a naive/stupid attacker, an rpm -Va will catch them
    as it will detect that a binary such as /bin/ls doesn't match the one
    installed from that rpm. Putting aside for the moment the fact that most any
    attacker (even script kiddies) will use a rootkit that will return the proper
    checksum, this brings up an interesting attack scenero: if the attacker does
    install their new tools via an rpm, the rpm -Va will NOT catch it, because
    now the files match the package they're installed from!

    The important thing to keep in mind here is that rpm's verify functionality
    was designed to detect random or accidental corruption or deletion of files,
    not malicious activity.

    Terry
    #include <stdDisclaimer.hh>


  • Next message: Peter Koinange: "Re: Certifying a RedHat Install"

    Relevant Pages

    • Re: Why does this happen?
      ... options to telnetd have changed (I have never heard of the -L altlogin ... But have you thought about how the attacker might have gotten in? ... Making sure you have a good rpm, ... to see all the suid root and suig files. ...
      (alt.os.linux)
    • Re: RPM aware rootkits?
      ... Just create a modified rpm and install it instead of the first one. ... > involve replacing some binaries. ... package but not the signed extracted contents. ... meant to be more of a "did I change anything" than a "did an attacker ...
      (Focus-Linux)
    • Re: Dependencies
      ... Should you install it or no? ... RPM is just a low-level tool that does one thing and that one ... If getting the GPG keys causes you heartburn, ... > To stay in the RPM subject, Apache give keys for their tarball versions. ...
      (linux.redhat)
    • Re: Three newbie questions!
      ... You can see the main groups, then the applications ... Until you get to know the names of applications, it is best to use RPM ... You normally find a README, an INSTALL, and a doc ... If you have installed any libraries, then you must run the following ...
      (comp.os.linux.setup)
    • FW: [SLE] YaST Online Update Problem
      ... >>update one of the rpms manually to see if rpm will give you a better error ... >SuSE to try to apply one of the patches? ... >I've always used YaST for Online Updates and for installing new packages. ... Not only that, but at the end of the install, it ...
      (SuSE)