[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Problem with AIDE



    Since I upgraded my Woody servers to Sarge AIDE has started 
to give strange results - but not always. But sometimes it show 
that some files have been added to /lib, /bin or /sbin directory - 
but those files existed there before (when running aide --update).

Like:

added:/sbin/e2fsck
added:/sbin/fsck.ext2
added:/sbin/fsck.ext3

    All those directorys are mitored with AIDE rule 
Binlib = p+i+n+u+g+s+b+m+c+md5+sha1
Same rule is used for /usr/bin and /usr/lib directory's also - but 
there are no anomalies.
    There aren't any other signs of problem that would indicate 
intrusion.

-- 
Virgo Pärna 
virgo.parna@mail.ee



Reply to: