LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-17-2018, 06:09 AM   #1
qrange
Senior Member
 
Registered: Jul 2006
Location: Belgrade, Yugoslavia
Distribution: Debian stable/testing, amd64
Posts: 1,063

Rep: Reputation: 47
check hashsums


is there some bootable live USB that could check shasums of all installed debian system executables?
 
Old 04-17-2018, 11:24 PM   #2
AwesomeMachine
LQ Guru
 
Registered: Jan 2005
Location: USA and Italy
Distribution: Debian testing/sid; OpenSuSE; Fedora; Mint
Posts: 5,524

Rep: Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015
The problem is the program wouldn't know what the hashsums are supposed to be. There would be no way to know if the files were changed. If you install tripwire on installation, that gives you a good snapshot. But after an incident occurs it's too late.

Last edited by AwesomeMachine; 04-17-2018 at 11:25 PM.
 
1 members found this post helpful.
Old 04-18-2018, 05:48 AM   #3
qrange
Senior Member
 
Registered: Jul 2006
Location: Belgrade, Yugoslavia
Distribution: Debian stable/testing, amd64
Posts: 1,063

Original Poster
Rep: Reputation: 47
I see, but I'd have to update that tripwire on each apt upgrade?
Assuming there's a lot of people using latest Debian stable amd64, couldn't someone make a list of hashes at least for basic, 'startup-sequence' executables?

Or perhaps, we could run a script from LiveCD that would:

-inspect installed debian and give a list of all packages.
-download again those packages, extract them one-by-one, create a hashsum list, delete them.
-compare sums

?

edit: it would be simpler if packages were distributed with such lists for executables inside, imho.

Last edited by qrange; 04-18-2018 at 06:25 AM.
 
Old 04-18-2018, 06:55 AM   #4
pan64
LQ Addict
 
Registered: Mar 2012
Location: Hungary
Distribution: debian/ubuntu/suse ...
Posts: 22,071

Rep: Reputation: 7364Reputation: 7364Reputation: 7364Reputation: 7364Reputation: 7364Reputation: 7364Reputation: 7364Reputation: 7364Reputation: 7364Reputation: 7364Reputation: 7364
do you mean something like this: http://xpt.sourceforge.net/techdocs/...ntegrityCheck/ ?
 
1 members found this post helpful.
Old 04-19-2018, 07:09 AM   #5
qrange
Senior Member
 
Registered: Jul 2006
Location: Belgrade, Yugoslavia
Distribution: Debian stable/testing, amd64
Posts: 1,063

Original Poster
Rep: Reputation: 47
yes, it helps, thanks.
I have also found 'cruft', its very useful.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LFS 8.1: Binutils make -k check failed at Makefile line 2174 'do-check' OedipusR3x Linux From Scratch 3 03-04-2018 06:24 PM
[SOLVED] problem with 6.9glibc make -k check 2>&1 | tee glibc-check-log bhismnarayan Linux From Scratch 3 10-01-2010 08:51 AM
problem with 6.9glibc make -k check 2>&1 | tee glibc-check-log bhismnarayan Linux From Scratch 1 09-30-2010 03:04 PM
Partition check, check double check Vincentius Linux - General 0 12-25-2004 05:47 AM
Boot disk; check. CD in drive; check. Doesn't work; check. Hal DamnSmallLinux 7 02-04-2004 02:10 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:23 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration