Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 10 Dec 1996 09:52:01 -0500
From:      Garrett Wollman <wollman@lcs.mit.edu>
To:        Brian Tao <taob@io.org>
Cc:        freebsd-security@freebsd.org
Subject:   Re: URGENT: Packet sniffer found on my system
Message-ID:  <9612101452.AA21942@halloran-eldar.lcs.mit.edu>
In-Reply-To: <Pine.BSF.3.95.961210014357.1328E-100000@nap.io.org>
References:  <199612100639.WAA00847@salsa.gv.ssi1.com> <Pine.BSF.3.95.961210014357.1328E-100000@nap.io.org>

next in thread | previous in thread | raw e-mail | index | archive | help
<<On Tue, 10 Dec 1996 01:54:34 -0500 (EST), Brian Tao <taob@io.org> said:

>     One of these days I'm going to set up cops or tripwire to do this
> for me on a regular basis.  Heck, maybe even mtree, since it seems
> like it can do that sort of stuff...

In fact, recent distributions should come with all the mtree files you
need to perform this sort of check.  Look for the `distname.mtree'
files in the distribution directories.  You can even have mtree
screech about files which are there but are not present in the
profile.

Be aware that some files (like init) exist in different versions in
different distributions, so there are going to be some false alarms.

-GAWollman

--
Garrett A. Wollman   | O Siem / We are all family / O Siem / We're all the same
wollman@lcs.mit.edu  | O Siem / The fires of freedom 
Opinions not those of| Dance in the burning flame
MIT, LCS, ANA, or NSA|                     - Susan Aglukark and Chad Irschick



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?9612101452.AA21942>