LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-03-2001, 11:48 AM   #1
WurlyBurly
LQ Newbie
 
Registered: Jul 2001
Posts: 1

Rep: Reputation: 0
Question Tripwire Reports Changes I Don't Understand


Hello-

I have tripwire running daily. Sunday's report showed some file changes and additions I don't recognize, but it is a recently installed box (RH7.1), and I am new to this so I was wondering if anyone else has seen these and knows what they are- or if I should be worried. Also, the machine supposedly was untouched over the weekend, so I don't understand why Saturday's tripwire report is clean, but Sunday has system changes.

Here is the relavant part of the report:

* System boot changes severity:100 added:11 removed:0 modified:11

Added:
"/var/log/messages.1"
"/var/log/secure.1"
"/var/log/maillog.1"
"/var/log/spooler.1"
"/var/log/boot.log.1"
"/var/log/cron.1"
"/var/log/kernel.1"
"/var/log/syslog.1"
"/var/log/loginlog.1"
"/var/log/xferlog.1"
"/var/log/wtmp.1"

Modified:
"/var/log/boot.log"
"/var/log/cron"
"/var/log/kernel"
"/var/log/loginlog"
"/var/log/maillog"
"/var/log/messages"
"/var/log/secure"
"/var/log/spooler"
"/var/log/syslog"
"/var/log/wtmp"
"/var/log/xferlog"


Any help would be appreciated. Are these files supposed to be there? Why would they show up as modified/added on Sunday?
 
Old 07-03-2001, 04:38 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
This comes from rotating logs by logrotate, which will backup a log sequentially and touch a new logfile. This pretty much fsck's over the previously stored signatures.

A solution could be to exclude all logfiles from examination except wtmp. These logfiles even tho some might be security related are not tampered the way wtmp/utmp are when someone wants to cover up gaining root.
Wtmp could be checked IMO with chkwtmp from chrootkit.

If you want to hold on to full coverage examination another strategy could be running different signature databases on different filesystem selections at different times.

HTH

Last edited by unSpawn; 07-03-2001 at 05:00 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Bug reports, using them microsoft/linux Debian 1 10-12-2005 07:22 AM
reports on 10.rc2? freychef Slackware 18 06-23-2004 09:27 PM
tripwire reports /usr/sbin/tripwire changed alfaalfabeta Linux - Security 5 07-22-2003 05:52 PM
Log Reports chaoticanuck Linux - Security 1 12-12-2002 02:13 PM
dsl reports tied2 Linux - General 3 08-04-2002 03:31 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:17 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration