From owner-freebsd-security@FreeBSD.ORG Wed Jan 14 10:49:12 2004 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id B22E316A4CE for ; Wed, 14 Jan 2004 10:49:12 -0800 (PST) Received: from conn.mc.mpls.visi.com (conn.mc.mpls.visi.com [208.42.156.2]) by mx1.FreeBSD.org (Postfix) with ESMTP id 6FDCF43D1F for ; Wed, 14 Jan 2004 10:49:09 -0800 (PST) (envelope-from hawkeyd@visi.com) Received: from sheol.localdomain (hawkeyd-fw.dsl.visi.com [208.42.101.193]) by conn.mc.mpls.visi.com (Postfix) with ESMTP id 6955A8946; Wed, 14 Jan 2004 12:49:08 -0600 (CST) Received: (from hawkeyd@localhost) by sheol.localdomain (8.11.6p2/8.11.6) id i0EIn7N22945; Wed, 14 Jan 2004 12:49:07 -0600 (CST) (envelope-from hawkeyd) X-Spam-Policy: http://www.visi.com/~hawkeyd/index.html#mail Date: Wed, 14 Jan 2004 12:49:07 -0600 From: D J Hawkey Jr To: Andrew Kenneth Milton Message-ID: <20040114184907.GA22901@sheol.localdomain> References: <20040114134215.GA21307@sheol.localdomain> <20040114180931.GA17074@miracle.mongers.org> <20040114182154.GA22444@sheol.localdomain> <20040114183850.GM57209@zeus.theinternet.com.au> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20040114183850.GM57209@zeus.theinternet.com.au> User-Agent: Mutt/1.4.1i cc: security at FreeBSD Subject: Re: mtree vs tripwire X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: hawkeyd@visi.com List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 14 Jan 2004 18:49:12 -0000 On Jan 15, at 05:38 AM, Andrew Kenneth Milton wrote: > > The manpage for mtree has an example... The 4.5-REL man page has a "suggestion", where using it as an IDS is concerned; that's what spurred my post. I'm looking for insights as to "fleshing it out"; I can't imagine that it's as straightforward as it appears - though it just might be, based on other replys. :-) Dave -- ______________________ ______________________ \__________________ \ D. J. HAWKEY JR. / __________________/ \________________/\ hawkeyd@visi.com /\________________/ http://www.visi.com/~hawkeyd/