From owner-freebsd-security@FreeBSD.ORG Wed Jan 14 10:27:57 2004 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 8150216A4CE for ; Wed, 14 Jan 2004 10:27:57 -0800 (PST) Received: from horsey.gshapiro.net (horsey.gshapiro.net [64.105.95.154]) by mx1.FreeBSD.org (Postfix) with ESMTP id 691A743D6B for ; Wed, 14 Jan 2004 10:27:56 -0800 (PST) (envelope-from gshapiro@gshapiro.net) Received: from horsey.gshapiro.net (localhost [127.0.0.1]) id i0EIRtEO031126 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Wed, 14 Jan 2004 10:27:55 -0800 (PST) Received: (from gshapiro@localhost)i0EIRtX2031125; Wed, 14 Jan 2004 10:27:55 -0800 (PST) Date: Wed, 14 Jan 2004 10:27:55 -0800 From: Gregory Neil Shapiro To: D J Hawkey Jr Message-ID: <20040114182755.GX50342@horsey.gshapiro.net> References: <20040114134215.GA21307@sheol.localdomain> <20040114180931.GA17074@miracle.mongers.org> <20040114182154.GA22444@sheol.localdomain> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20040114182154.GA22444@sheol.localdomain> User-Agent: Mutt/1.5.5.1i X-Mailman-Approved-At: Thu, 15 Jan 2004 02:56:02 -0800 cc: security at FreeBSD Subject: Re: mtree vs tripwire X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 14 Jan 2004 18:27:57 -0000 > Is your reply from personal experience, or is it the same "Hey, it > could..." as is my question? If the former, would you elaborate on the > implementation details? I use: mtree -K sha1digest -c -X mtree.exclude -p / > mtree.out where mtree.exclude is: ./home ./mnt ./proc ./tmp ./var/account ./var/backups ./var/db ./var/imap ./var/lock ./var/log ./var/mail ./var/run ./var/spool ./var/tmp Although I am sure there is a better way to do it with mtree, to see if something has changed, I repeat the process and diff the output.