Tripwire and /proc
The amount of data that tripwire reports on /proc is a bit overwhelming,
and strikes me as not particularly useful most of the time. After all,
most of the info in the root of /proc is PID info, so while certain
system processes shouldn't change all that often, most of the stuff in
there is pretty dynamic.
Since there doesn't appear to be a way to specify wildcards in
tripwire/stable uptodate 2.3.1.2.0-4, it seems like having 30k+ lines
similar to:
/proc/32768 -> $(SEC_INVARIANT) (recurse = 0) ;
is the best way to minimize this sort of info, although it slows down
tripwire tremendously. Is there a better way to do it, and is there
actually any value in recursing into PID directories in /proc that I'm
overlooking?
--
Re-Interpreting Historic Miracles with SED #141: %s/water/wine/g
Reply to: