3 ms·
just a note: intelligent exploiters hide their files inside of yours, so the -mtime is useless in many cases, they will set the mtime of their upload to match t
by eonw 10y ago
just a note: intelligent exploiters hide their files inside of yours, so the -mtime is useless in many cases, they will set the mtime of their upload to match the rest of the folder they hide in.
command history is also easy to alter if you know what you are doing.
- porker 10y agoSo the only way to detect exploits is to scan the server regularly and log the mtime and the file size, and look for changed files that shouldn't have changed? Re the command history, is there any way around them wiping it - e.g. piping all .bash_history entries to an append-only store?
- spdustin 10y agoRootKit Hunter [0] works pretty well on most distros to check hashes on files and other potential problems. You can also use a global bash configuration that would log all commands [1] entered into any bash shell to a central log, which could be shipped off-server simultaneously. [0]: http://rkhunter.sourceforge.net http://rkhunter.sourceforge.net [1]: http://askubuntu.com/questions/93566/how-to-log-all-bash-commands-by-all-users-on-a-server http://askubuntu.com/questions/93566/how-to-log-all-bash-com...
- uxp 10y agoDoes RKHunter scan userspace for mtimes? I haven't used it in years, so I'm honestly curious. Back when I did, it was customary to install it side-by-side with Tripwire, which essentially does only that; scan userspace and categorically log changed files based on a configurable severity depending on location (eg, /root/ is high, /var/log/messages is low)
- spdustin 10y agoThey really serve two different functions. Tripwire and similar tools like aide (I use aide now rather than tripwire, but that's my personal preference, I'm not an infosec domain expert) are file integrity checkers that check files for property changes (including mtime). Tuning out false alarms can result in an admin just turning off the reporting functions of the tools, that's the downside as I understand it. However, rkhunter has additional logic to specifically seek out rootkits and malware-like behavior, and is more specifically targeted to system file modifications. Combining it with unhide (to compare actual processes running with those visible from userspace) provides a reasonable assurance that nothing nefarious is going on. They're all part of a spectrum, however. I use scanners like aide alongside rkhunter as well, but I'm the sort of guy that will spend a day tuning the config of aide to avoid constant false alarms.
- emcrazyone 10y agoyes, excellent point, agree. I run the scan regardless in case I'm dealing with the non-intelligent exploiter type ;)
- eonw 10y agogood point as well. might as well run every bit of security you can, helps stop the "script kiddies" and lower quality automated stuff.