<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AIDE (software integrity app) &amp;amp; mtime question in Operating System - Linux</title>
    <link>https://community.hpe.com/t5/operating-system-linux/aide-software-integrity-app-amp-mtime-question/m-p/5088687#M49372</link>
    <description>It's probably "prelink". It adds some information to executables and libraries to speed up loading. Read "man prelink" for a more detailed description.&lt;BR /&gt;&lt;BR /&gt;When using AIDE or tripwire, you'll generally want to run the prelinking manually after each update or software installation, and *only then* acknowledge the changes in the integrity application. Or if your server's workload does not involve starting a lot of processes frequently, you might choose to disable the prelink system.&lt;BR /&gt;&lt;BR /&gt;MK</description>
    <pubDate>Tue, 22 Jan 2008 08:01:19 GMT</pubDate>
    <dc:creator>Matti_Kurkela</dc:creator>
    <dc:date>2008-01-22T08:01:19Z</dc:date>
    <item>
      <title>AIDE (software integrity app) &amp; mtime question</title>
      <link>https://community.hpe.com/t5/operating-system-linux/aide-software-integrity-app-amp-mtime-question/m-p/5088686#M49371</link>
      <description>Hello everyone,&lt;BR /&gt;&lt;BR /&gt;We run RHEL4 on our ProLiant BL20p G3 servers and I'm playing-with/evaluatiing  AIDE (software integrity app similar to tripwire) in order to install it on some new servers during the next weeks.&lt;BR /&gt;&lt;BR /&gt;I've been tweaking the configuration file and I've been running it for a couple of days. I run the "check" every night but last night I got a warning about 3 directories: they're mtime changed. I'm 100% sure my system wasn't hacked (as it is offline). I just found out that the modification time in these directories is the same as the time the scripts in /etc/cron.daily run. The directories were:&lt;BR /&gt;&lt;BR /&gt;/usr/lib64&lt;BR /&gt;/usr/bin&lt;BR /&gt;/lib64&lt;BR /&gt;&lt;BR /&gt;Does anyone knows what script on /etc/cron.daily might change mtime in these directories? A script could "touch" these files  in order to change the mtime on purpose (don't see why) or a file could be removed or added from these directories (very unlikely). I did a search for new files in these directories but none were found.&lt;BR /&gt;&lt;BR /&gt;I could just remove the check for mtime in these directories but I don't think it would be wise.&lt;BR /&gt;&lt;BR /&gt;Thanks in advance,&lt;BR /&gt;Jorge</description>
      <pubDate>Fri, 18 Jan 2008 15:16:50 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/aide-software-integrity-app-amp-mtime-question/m-p/5088686#M49371</guid>
      <dc:creator>Jorge Fabregas</dc:creator>
      <dc:date>2008-01-18T15:16:50Z</dc:date>
    </item>
    <item>
      <title>Re: AIDE (software integrity app) &amp; mtime question</title>
      <link>https://community.hpe.com/t5/operating-system-linux/aide-software-integrity-app-amp-mtime-question/m-p/5088687#M49372</link>
      <description>It's probably "prelink". It adds some information to executables and libraries to speed up loading. Read "man prelink" for a more detailed description.&lt;BR /&gt;&lt;BR /&gt;When using AIDE or tripwire, you'll generally want to run the prelinking manually after each update or software installation, and *only then* acknowledge the changes in the integrity application. Or if your server's workload does not involve starting a lot of processes frequently, you might choose to disable the prelink system.&lt;BR /&gt;&lt;BR /&gt;MK</description>
      <pubDate>Tue, 22 Jan 2008 08:01:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/aide-software-integrity-app-amp-mtime-question/m-p/5088687#M49372</guid>
      <dc:creator>Matti_Kurkela</dc:creator>
      <dc:date>2008-01-22T08:01:19Z</dc:date>
    </item>
    <item>
      <title>Re: AIDE (software integrity app) &amp; mtime question</title>
      <link>https://community.hpe.com/t5/operating-system-linux/aide-software-integrity-app-amp-mtime-question/m-p/5088688#M49373</link>
      <description>Thanks Matti. Right on. Prelink was indeed. Thanks also for the tip. I'll do that (run prelink manually after update and THEN recreate the AIDE database).&lt;BR /&gt;&lt;BR /&gt;All the best,&lt;BR /&gt;Jorge</description>
      <pubDate>Wed, 23 Jan 2008 13:43:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/aide-software-integrity-app-amp-mtime-question/m-p/5088688#M49373</guid>
      <dc:creator>Jorge Fabregas</dc:creator>
      <dc:date>2008-01-23T13:43:41Z</dc:date>
    </item>
  </channel>
</rss>

