LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-02-2018, 04:55 PM   #1
qrange
Senior Member
 
Registered: Jul 2006
Location: Belgrade, Yugoslavia
Distribution: Debian stable/testing, amd64
Posts: 1,061

Rep: Reputation: 47
virustotal


virustotal seems like a nice 'project' but its not, well, completely free/opensource.
Could we have a bootable iso that would check 'common' (not user compiled) binaries in given partition, create a list of sha256 or similar hashes, and upload it on some public server? there it could be compared with other users, and give us some 'evaluation' of security. just like virustotal but in more 'opensource' way?

something like 'cruft' for debian, but that would check hashsums.

There are no guarantees that repositories are 'clean' but it would help?

Last edited by qrange; 05-02-2018 at 04:58 PM.
 
Old 05-03-2018, 01:06 PM   #2
_roman_
Member
 
Registered: Dec 2017
Location: _Austro_Bavaria_
Distribution: gentoo / linux mint
Posts: 433

Rep: Reputation: 29
afaik any decent package manager checks for checksum.

gentoo has now some sort of checksum for the repros when you sync.
and gentoo has for ages checksum on patches and the stuff you download in the distfiles

I'd ditch outdated debian when they are not able to do basic tasks like software tree and download verifications. read what the guy who wrote xscreensaver wrote on his homepage about debian for example
 
Old 05-04-2018, 08:15 AM   #3
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
https://en.wikipedia.org/wiki/Open_Source_Tripwire may help

virustotal is not a "project"
Launched in June 2004
 
Old 05-10-2018, 01:58 PM   #4
dave@burn-it.co.uk
Member
 
Registered: Sep 2011
Distribution: Puppy
Posts: 601

Rep: Reputation: 172Reputation: 172
This is just my opinion.
I tried Virus Total and after a very short time removed all traces of it.
I found it and the company to be very intrusive.
I still get emails from them after 6 months "begging" me to give them a second try.
 
Old 05-11-2018, 12:02 PM   #5
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Quote:
Originally Posted by qrange View Post
something like 'cruft' for debian, but that would check hashsums.
Code:
sudo dpkg -V
 
Old 05-11-2018, 12:11 PM   #6
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
installed?
How? from where?
 
Old 05-12-2018, 05:48 AM   #7
qrange
Senior Member
 
Registered: Jul 2006
Location: Belgrade, Yugoslavia
Distribution: Debian stable/testing, amd64
Posts: 1,061

Original Poster
Rep: Reputation: 47
thanks Habitual,
but that uses md5, also if someone managed to modify elf, he could do the same with local md5sum?
anyway, I've started collecting hashes myself:

https://www.linuxquestions.org/quest...in-4175629080/
 
Old 05-12-2018, 10:52 AM   #8
_roman_
Member
 
Registered: Dec 2017
Location: _Austro_Bavaria_
Distribution: gentoo / linux mint
Posts: 433

Rep: Reputation: 29
gentoo has since a few weeks now checksum enabled for the portage tree also. not only for the patches and downloads which was the case for ages.

--

forget about md5, md5 can be easily spoofed. it is not secure for quite a while.

when you want to be sure, use at least 3 or 5 different checksum algorithm on the same file
 
Old 05-12-2018, 05:15 PM   #9
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Try https://www.rfxn.com/projects/linux-malware-detect/

Not bootable. No public "submit" for 'evaluation' of security.
 
Old 05-13-2018, 06:33 AM   #10
dave@burn-it.co.uk
Member
 
Registered: Sep 2011
Distribution: Puppy
Posts: 601

Rep: Reputation: 172Reputation: 172
It is intended to be installed and run for REAL TIME monitoring.
Just add it to your own bootable recovery media. They probably don't want to force a different distribution on you.

Are you just looking for excuses NOT to run a virus checker???
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Google's VirusTotal puts Linux malware under the spotlight LXer Syndicated Linux News 0 11-12-2014 01:20 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:44 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration