From owner-freebsd-security@FreeBSD.ORG Tue Jan 20 15:19:25 2004 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 1E10B16A4CE for ; Tue, 20 Jan 2004 15:19:25 -0800 (PST) Received: from mail.seekingfire.com (coyote.seekingfire.com [24.72.10.212]) by mx1.FreeBSD.org (Postfix) with ESMTP id E0C2343D53 for ; Tue, 20 Jan 2004 15:19:19 -0800 (PST) (envelope-from tillman@seekingfire.com) Received: by mail.seekingfire.com (Postfix, from userid 500) id E4CC46E; Tue, 20 Jan 2004 17:19:18 -0600 (CST) Date: Tue, 20 Jan 2004 17:19:18 -0600 From: Tillman Hodgson To: security at FreeBSD Message-ID: <20040120231918.GS24105@seekingfire.com> References: <20040114134215.GA21307@sheol.localdomain> <20040114180931.GA17074@miracle.mongers.org> <20040114182154.GA22444@sheol.localdomain> <20040114182755.GX50342@horsey.gshapiro.net> <44oet5mivk.fsf@be-well.ilk.org> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="FK65GREB+Evh/hTL" Content-Disposition: inline In-Reply-To: <44oet5mivk.fsf@be-well.ilk.org> X-Habeas-SWE-1: winter into spring X-Habeas-SWE-2: brightly anticipated X-Habeas-SWE-3: like Habeas SWE (tm) X-Habeas-SWE-4: Copyright 2002 Habeas (tm) X-Habeas-SWE-5: Sender Warranted Email (SWE) (tm). The sender of this X-Habeas-SWE-6: email in exchange for a license for this Habeas X-Habeas-SWE-7: warrant mark warrants that this is a Habeas Compliant X-Habeas-SWE-8: Message (HCM) and not spam. Please report use of this X-Habeas-SWE-9: mark in spam to . X-GPG-Key-ID: 828AFC7B X-GPG-Fingerprint: 5584 14BA C9EB 1524 0E68 F543 0F0A 7FBC 828A FC7B X-GPG-Key: http://www.seekingfire.com/gpg_key.asc X-Urban-Legend: There is lots of hidden information in headers User-Agent: Mutt/1.5.5.1i Subject: Re: mtree vs tripwire X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 20 Jan 2004 23:19:25 -0000 --FK65GREB+Evh/hTL Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Thu, Jan 15, 2004 at 08:38:55AM -0500, Lowell Gilbert wrote: > Gregory Neil Shapiro writes: > > I use: > >=20 > > mtree -K sha1digest -c -X mtree.exclude -p / > mtree.out > > Although I am sure there is a better way to do it with mtree, to > > see if something has changed, I repeat the process and diff the > > output. >=20 > That would be=20 > mtree < mtree.out > to have mtree do it itself. I just now tried this: [root@athena ~/landmine]# ls -l total 41746 -rw-r--r-- 1 root wheel 46 Jan 20 14:58 mtree.exclude -rw-r--r-- 1 root wheel 42713965 Jan 20 16:19 mtree.out [root@athena ~/landmine]# mtree < mtree.out mtree: line 270131: unknown keyword Burg I'm fairly certain that that's not the intended result ;-) That line, BTW, is just a file name with a space in it: link=3D/opt/SC3U/buildings/Den Burg Bruges.bld Am I missing somethign fairly simple? -T --=20 "Getting a SCSI chain working is perfectly simple if you remember that there must be exactly three terminations: one on one end of the cable, one on the far end, and the goat, terminated over the SCSI chain with a silver-handled knife whilst burning *black* candles." - Anthony DeBoer --FK65GREB+Evh/hTL Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (FreeBSD) iD8DBQFADbd2Dwp/vIKK/HsRAuYyAJ4uV3PNxZFMS2Lhv2GzKmS3HPxp1ACbBiru pM1YL6Y8pMSgp3n/2BV2ibw= =/8hv -----END PGP SIGNATURE----- --FK65GREB+Evh/hTL--