Re: Linux hardening

From: Glynn Clements (glynn_at_gclements.plus.com)
Date: 08/26/05

  • Next message: Glynn Clements: "Re: Xvfb Question"
    Date: Fri, 26 Aug 2005 22:47:50 +0100
    To: infosec@norwich.edu
    
    

    Norwich University - Information Security wrote:

    > Since we're talking about Linux hardening...
    >
    > What do folks suggest as far as files that should be monitored with
    > integrity checking tools? Obviously, tmp files and other frequently
    > changed files are out of the question, and it is also impractical to do
    > checking on all other files. Does anyone have a best practices list or
    > suggestions of what files are critical to monitor with integrity checking?

    Anything in: bin boot dev etc lib opt sbin usr

    although you can exclude stuff like documentation from /usr.

    You can exclude most of: home mnt proc root tmp var

    Although sometimes services live under /home (e.g. /home/httpd), in
    which case you might need to monitor such directories.

    -- 
    Glynn Clements <glynn@gclements.plus.com>
    

  • Next message: Glynn Clements: "Re: Xvfb Question"

    Relevant Pages

    • Re: Linux hardening
      ... tmp files and other frequently ... suggestions of what files are critical to monitor with integrity checking? ... Chief Information Security Officer ...
      (Focus-Linux)
    • Re: Monitor doesnt always turn on.
      ... Make sure your video card's integrity is intact. ... problem at work with my monitor. ... >> one from the AGP video card. ...
      (microsoft.public.windowsxp.help_and_support)
    • [opensuse] Monitor timeout
      ... I did something...don't ask me what...and now my moniter shuts off before the ... screensave kicks on....I'd really like the monitor to not shut off.. ... The integrity of the output is dependent on the integrity of the input ...
      (SuSE)
    • Re: Controlling Pc From Server?
      ... > libpcap to monitor the packets being sent and received, ... > taking care to exclude the local subnet (or your reporting will be ... > skewed as packets sent to the monitoring server will also be included!). ...
      (comp.lang.python)