<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: CentOS 5 and aide</title>
	<atom:link href="http://www.bofh-hunter.com/2008/04/10/centos-5-and-aide/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.bofh-hunter.com/2008/04/10/centos-5-and-aide/</link>
	<description>Admin Spotting for Fun and Profit</description>
	<lastBuildDate>Fri, 16 Jul 2010 09:41:46 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: toro</title>
		<link>http://www.bofh-hunter.com/2008/04/10/centos-5-and-aide/comment-page-1/#comment-282</link>
		<dc:creator>toro</dc:creator>
		<pubDate>Tue, 25 May 2010 22:17:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.bofh-hunter.com/2007/12/04/centos-5-and-aide/#comment-282</guid>
		<description>how to disable prelink on centos is described here:

http://www.linuxquestions.org/questions/linux-security-4/aide-prelink-issues-584646/</description>
		<content:encoded><![CDATA[<p>how to disable prelink on centos is described here:</p>
<p><a href="http://www.linuxquestions.org/questions/linux-security-4/aide-prelink-issues-584646/" rel="nofollow">http://www.linuxquestions.org/questions/linux-security-4/aide-prelink-issues-584646/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: seo</title>
		<link>http://www.bofh-hunter.com/2008/04/10/centos-5-and-aide/comment-page-1/#comment-277</link>
		<dc:creator>seo</dc:creator>
		<pubDate>Thu, 11 Mar 2010 14:58:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.bofh-hunter.com/2007/12/04/centos-5-and-aide/#comment-277</guid>
		<description>I agree with the prelinking. For the cron job, don&#039;t forget to check whether &#039;root&#039; can execute the job. Also, is it possible to just get the changes in the email and not the entire database?</description>
		<content:encoded><![CDATA[<p>I agree with the prelinking. For the cron job, don&#8217;t forget to check whether &#8216;root&#8217; can execute the job. Also, is it possible to just get the changes in the email and not the entire database?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ceejay</title>
		<link>http://www.bofh-hunter.com/2008/04/10/centos-5-and-aide/comment-page-1/#comment-253</link>
		<dc:creator>Ceejay</dc:creator>
		<pubDate>Thu, 24 Sep 2009 07:30:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.bofh-hunter.com/2007/12/04/centos-5-and-aide/#comment-253</guid>
		<description>I agree with Tomas Rudén. Prelink creates a lot of false alarms.</description>
		<content:encoded><![CDATA[<p>I agree with Tomas Rudén. Prelink creates a lot of false alarms.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anon</title>
		<link>http://www.bofh-hunter.com/2008/04/10/centos-5-and-aide/comment-page-1/#comment-236</link>
		<dc:creator>Anon</dc:creator>
		<pubDate>Wed, 26 Aug 2009 21:56:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.bofh-hunter.com/2007/12/04/centos-5-and-aide/#comment-236</guid>
		<description>Just change the cron location from weekly to daily, as well as the text of the con script</description>
		<content:encoded><![CDATA[<p>Just change the cron location from weekly to daily, as well as the text of the con script</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Annand</title>
		<link>http://www.bofh-hunter.com/2008/04/10/centos-5-and-aide/comment-page-1/#comment-234</link>
		<dc:creator>Annand</dc:creator>
		<pubDate>Mon, 24 Aug 2009 14:36:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.bofh-hunter.com/2007/12/04/centos-5-and-aide/#comment-234</guid>
		<description>Great article.  I am trying it out.  How can I set it to get daily emails instead of weekly?</description>
		<content:encoded><![CDATA[<p>Great article.  I am trying it out.  How can I set it to get daily emails instead of weekly?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tomas Rudén</title>
		<link>http://www.bofh-hunter.com/2008/04/10/centos-5-and-aide/comment-page-1/#comment-189</link>
		<dc:creator>Tomas Rudén</dc:creator>
		<pubDate>Thu, 14 May 2009 09:15:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.bofh-hunter.com/2007/12/04/centos-5-and-aide/#comment-189</guid>
		<description>It is worth mentioning that Aide doesn&#039;t work well together with prelink. Since prelink modifies several bins and libs on a regular basis you will get a lot of false alarms that you have to check.

I have decided to turn off prelink but I&#039;m curious to know if there are other solutions.</description>
		<content:encoded><![CDATA[<p>It is worth mentioning that Aide doesn&#8217;t work well together with prelink. Since prelink modifies several bins and libs on a regular basis you will get a lot of false alarms that you have to check.</p>
<p>I have decided to turn off prelink but I&#8217;m curious to know if there are other solutions.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jim Perrin</title>
		<link>http://www.bofh-hunter.com/2008/04/10/centos-5-and-aide/comment-page-1/#comment-126</link>
		<dc:creator>Jim Perrin</dc:creator>
		<pubDate>Tue, 13 Jan 2009 18:50:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.bofh-hunter.com/2007/12/04/centos-5-and-aide/#comment-126</guid>
		<description>Aide is updating the database, however it&#039;s a little unclear by default exactly what&#039;s going on. You don&#039;t need to worry about database_new. It&#039;s database_out that&#039;s messing with you here.

When you run aide --update, it generates a new aide.db.new.gz file, and compares it against aide.db.gz, just like --check does. The catch is that it&#039;s aide.db.gz that&#039;s used for validation. You must manually move the aide.db.new.gz to aide.db.gz after you update. Setting database_new won&#039;t change this, and aide --update will throw a fit if  database and database_out have the same values. This is tricky to most folks, and caught me off guard at first until I noticed the timestamps on the file changing when I was screaming at --update</description>
		<content:encoded><![CDATA[<p>Aide is updating the database, however it&#8217;s a little unclear by default exactly what&#8217;s going on. You don&#8217;t need to worry about database_new. It&#8217;s database_out that&#8217;s messing with you here.</p>
<p>When you run aide &#8211;update, it generates a new aide.db.new.gz file, and compares it against aide.db.gz, just like &#8211;check does. The catch is that it&#8217;s aide.db.gz that&#8217;s used for validation. You must manually move the aide.db.new.gz to aide.db.gz after you update. Setting database_new won&#8217;t change this, and aide &#8211;update will throw a fit if  database and database_out have the same values. This is tricky to most folks, and caught me off guard at first until I noticed the timestamps on the file changing when I was screaming at &#8211;update</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: brian</title>
		<link>http://www.bofh-hunter.com/2008/04/10/centos-5-and-aide/comment-page-1/#comment-121</link>
		<dc:creator>brian</dc:creator>
		<pubDate>Sat, 10 Jan 2009 00:17:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.bofh-hunter.com/2007/12/04/centos-5-and-aide/#comment-121</guid>
		<description>Great article, found it just as I was going to install tripwire.

I&#039;m running into an issue though... I cannot get --update to update the database.  It just complains that it found some changes.  My config file contains both the &quot;database&quot; and the &quot;database_new&quot; parameters.

What am I missing?  Thanks</description>
		<content:encoded><![CDATA[<p>Great article, found it just as I was going to install tripwire.</p>
<p>I&#8217;m running into an issue though&#8230; I cannot get &#8211;update to update the database.  It just complains that it found some changes.  My config file contains both the &#8220;database&#8221; and the &#8220;database_new&#8221; parameters.</p>
<p>What am I missing?  Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jon Norwood</title>
		<link>http://www.bofh-hunter.com/2008/04/10/centos-5-and-aide/comment-page-1/#comment-107</link>
		<dc:creator>Jon Norwood</dc:creator>
		<pubDate>Wed, 31 Dec 2008 19:24:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.bofh-hunter.com/2007/12/04/centos-5-and-aide/#comment-107</guid>
		<description>Thanks for this article - you saved me a ton of time!</description>
		<content:encoded><![CDATA[<p>Thanks for this article &#8211; you saved me a ton of time!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jeffatrackaid</title>
		<link>http://www.bofh-hunter.com/2008/04/10/centos-5-and-aide/comment-page-1/#comment-51</link>
		<dc:creator>jeffatrackaid</dc:creator>
		<pubDate>Sun, 04 May 2008 23:57:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.bofh-hunter.com/2007/12/04/centos-5-and-aide/#comment-51</guid>
		<description>1. Don&#039;t forget /dev/shm. I make it noexec,nosuid as well.

3. Chkrootkit is good but I also like rkhunter
http://www.rootkit.nl/

5. PHP: Disable functions. I disable some functions in PHP when possible. Especially things like exec, system, etc.

6. wget/curl/fetch tools. When possible we set these to 700 and owned by root.  If end-users need wget I create a &quot;uwget&quot;. This prevents many of the bot-type attacks.  Not great but helpful on shared hosting boxes with 100&#039;s of sites managed by the end users.</description>
		<content:encoded><![CDATA[<p>1. Don&#8217;t forget /dev/shm. I make it noexec,nosuid as well.</p>
<p>3. Chkrootkit is good but I also like rkhunter<br />
<a href="http://www.rootkit.nl/" rel="nofollow">http://www.rootkit.nl/</a></p>
<p>5. PHP: Disable functions. I disable some functions in PHP when possible. Especially things like exec, system, etc.</p>
<p>6. wget/curl/fetch tools. When possible we set these to 700 and owned by root.  If end-users need wget I create a &#8220;uwget&#8221;. This prevents many of the bot-type attacks.  Not great but helpful on shared hosting boxes with 100&#8242;s of sites managed by the end users.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
