LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Debian
User Name
Password
Debian This forum is for the discussion of Debian Linux.

Notices


Reply
  Search this Thread
Old 02-04-2010, 06:17 PM   #1
rickshawed
LQ Newbie
 
Registered: Feb 2010
Posts: 4

Rep: Reputation: 0
Compromised packages?


I'm wondering if there's a way to verify the integrity of installed packages/programs against official repos. I did an update via synaptic about a week ago and it asked me to upgrade several packages such as login, su, passwd, groupadd, useradd, lastlog, and several others. Right away I was concerned about this, but I figured it's via synaptic, must be safe.

Well now it's a week later and I'm trying to find some "last updated" info for these packages, changlelogs, whatever, to verify that they were indeed official releases/updates, and I'm coming up empty.

Is there something I can do to verify that these files and my system are still intact?
 
Old 02-04-2010, 06:42 PM   #2
craigevil
Senior Member
 
Registered: Apr 2005
Location: OZ
Distribution: Debian Sid/RPIOS
Posts: 4,884
Blog Entries: 28

Rep: Reputation: 533Reputation: 533Reputation: 533Reputation: 533Reputation: 533Reputation: 533
apt-cache policy packagename

You probably want debsums.

debsums - tool for verification of installed package files against MD5 checksums

Packages update all the time, as long as you aren't using a bunch of 3rd party repos you are fine. A little paranoia goes a long way.
 
Old 02-04-2010, 07:56 PM   #3
rickshawed
LQ Newbie
 
Registered: Feb 2010
Posts: 4

Original Poster
Rep: Reputation: 0
Quote:
Originally Posted by craigevil View Post
You probably want debsums.
thank you, this was just what I was looking for.

one question though. if it checks against locally stored files wouldn't it be simple to fake?

Quote:
A little paranoia goes a long way.
no joke. linux does that to me though. especially when I see files like su passwd and login being changed. and even more so when I can't verify that there was an update released in documentation anywhere.
 
Old 02-04-2010, 09:27 PM   #4
Dutch Master
Senior Member
 
Registered: Dec 2005
Posts: 1,686

Rep: Reputation: 124Reputation: 124
Debian, and basically all other distro's, have ways of verifying the contents of the packages on their servers. If one is compromised it'll be noted quickly and the server will be taken off-line immediately. Find and read the Debian security list to learn about untrusted servers. There where cases in the past, but not recent, to my knowledge.

PS: dev's are the worst documentation writers
 
Old 02-04-2010, 09:40 PM   #5
kurtdriver
Member
 
Registered: May 2005
Location: Vancouver, Canada
Distribution: Fedora 18, Puppy Linux, various others
Posts: 107

Rep: Reputation: 15
There isn't a GPG signature?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Compromised? Jukas Linux - Security 6 12-06-2006 07:16 PM
Compromised ? ./2[1].6.12 DaveQB Linux - Security 4 10-10-2006 06:47 PM
Compromised??? redice Linux - Security 5 02-25-2006 01:14 PM
Compromised? I can't tell. Chuck23 Linux - Security 11 02-15-2005 07:33 AM
Am I compromised? dripter Linux - Security 5 01-27-2004 12:31 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Debian

All times are GMT -5. The time now is 01:45 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration