- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - Linux
- >
- AIDE (software integrity app) & mtime question
Operating System - Linux
1822143
Members
3555
Online
109640
Solutions
Forums
Categories
Company
Local Language
юдл
back
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Forums
Discussions
юдл
back
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Blogs
Information
Community
Resources
Community Language
Language
Forums
Blogs
Go to solution
Topic Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-18-2008 07:16 AM
тАО01-18-2008 07:16 AM
Hello everyone,
We run RHEL4 on our ProLiant BL20p G3 servers and I'm playing-with/evaluatiing AIDE (software integrity app similar to tripwire) in order to install it on some new servers during the next weeks.
I've been tweaking the configuration file and I've been running it for a couple of days. I run the "check" every night but last night I got a warning about 3 directories: they're mtime changed. I'm 100% sure my system wasn't hacked (as it is offline). I just found out that the modification time in these directories is the same as the time the scripts in /etc/cron.daily run. The directories were:
/usr/lib64
/usr/bin
/lib64
Does anyone knows what script on /etc/cron.daily might change mtime in these directories? A script could "touch" these files in order to change the mtime on purpose (don't see why) or a file could be removed or added from these directories (very unlikely). I did a search for new files in these directories but none were found.
I could just remove the check for mtime in these directories but I don't think it would be wise.
Thanks in advance,
Jorge
We run RHEL4 on our ProLiant BL20p G3 servers and I'm playing-with/evaluatiing AIDE (software integrity app similar to tripwire) in order to install it on some new servers during the next weeks.
I've been tweaking the configuration file and I've been running it for a couple of days. I run the "check" every night but last night I got a warning about 3 directories: they're mtime changed. I'm 100% sure my system wasn't hacked (as it is offline). I just found out that the modification time in these directories is the same as the time the scripts in /etc/cron.daily run. The directories were:
/usr/lib64
/usr/bin
/lib64
Does anyone knows what script on /etc/cron.daily might change mtime in these directories? A script could "touch" these files in order to change the mtime on purpose (don't see why) or a file could be removed or added from these directories (very unlikely). I did a search for new files in these directories but none were found.
I could just remove the check for mtime in these directories but I don't think it would be wise.
Thanks in advance,
Jorge
Solved! Go to Solution.
2 REPLIES 2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-22-2008 12:01 AM
тАО01-22-2008 12:01 AM
Solution
It's probably "prelink". It adds some information to executables and libraries to speed up loading. Read "man prelink" for a more detailed description.
When using AIDE or tripwire, you'll generally want to run the prelinking manually after each update or software installation, and *only then* acknowledge the changes in the integrity application. Or if your server's workload does not involve starting a lot of processes frequently, you might choose to disable the prelink system.
MK
When using AIDE or tripwire, you'll generally want to run the prelinking manually after each update or software installation, and *only then* acknowledge the changes in the integrity application. Or if your server's workload does not involve starting a lot of processes frequently, you might choose to disable the prelink system.
MK
MK
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-23-2008 05:43 AM
тАО01-23-2008 05:43 AM
Re: AIDE (software integrity app) & mtime question
Thanks Matti. Right on. Prelink was indeed. Thanks also for the tip. I'll do that (run prelink manually after update and THEN recreate the AIDE database).
All the best,
Jorge
All the best,
Jorge
The opinions expressed above are the personal opinions of the authors, not of Hewlett Packard Enterprise. By using this site, you accept the Terms of Use and Rules of Participation.
Company
Learn About
News and Events
Support
© Copyright 2025 Hewlett Packard Enterprise Development LP