2 ms·
This goes back to the problem of maintaining your own whitelist, though. The problem is that maintaining your own whitelist is a lot of work. For example, if yo
by HD142245b 10y ago
This goes back to the problem of maintaining your own whitelist, though. The problem is that maintaining your own whitelist is a lot of work. For example, if you update your system, but don't update your rkhunter database, your next report is totally inaccurate.
I just want a solution where I can boot up any system from a live CD, and inspect an existing installation, based on an external verified database.
- stevekemp 10y agoEven if you paid for access to a list of known-good binaries you would still need to have your own local list. e.g. Malicious exploit drops in /etc/cron.d/botnet. You might also feel safe if you have "good" copy of bash, but your version matched a checksum from pre-shellshock. Really making the list is easy, you could do it yourself, or you could pay somebody to give you one, but it doesn't solve the problem because you'll still have local changes you need to flag/whitelist/update.
- HD142245b 10y agoWell, I'm not denying that config-file trojans exist, but whitelisting all executables massively reduces the haystack. Thx for the tips.