Re: library/executable image
From: Fabrice MARIE (fabrice@fma.homelinux.com)
Date: 03/24/03
- Previous message: Jose Nazario: "Re: Detecting abnormal behaviour"
- In reply to: Adrian S: "library/executable image"
- Next in thread: Adam Gilmore: "RE: library/executable image"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: Fabrice MARIE <fabrice@fma.homelinux.com> To: Adrian S <hotelectron@hotmail.com>, vuln-dev@securityfocus.com Date: Mon, 24 Mar 2003 14:00:23 +0800
On Monday 24 March 2003 01:47, Adrian S wrote:
> Hi,
> Other than identifying the path & PID, what is the other proactive way
> to detect unauthorised execution of library/executable image ?
On Linux, install RSBAC: http://www.rsbac.org/
You can _enforce_ and/or _detect_ it's up to you.
On other unix, they have similar stuff.
Have a nice day,
Fabrice.
--
Fabrice MARIE
"Silly hacker, root is for administrators"
-Unknown
- Previous message: Jose Nazario: "Re: Detecting abnormal behaviour"
- In reply to: Adrian S: "library/executable image"
- Next in thread: Adam Gilmore: "RE: library/executable image"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|