Re: OS binaries integrity check

From: Adams Kevin J (kevin.adams@PHS.COM)
Date: Fri Feb 13 2004 - 14:02:11 EST


I know it's not as good as Tripwire or TCB (which has to be installed
initially at build), but lppchk -c will:

"Performs a checksum operation on the FileList items and verifies that the
checksum and the file size are consistent with the SWVPD database."

I've never tried to fool it, so I don't know how good it is, but it may be
useful.

Kevin Adams
PacifiCare Behavioral Health
Principal Systems Analyst
AIX CATE

-----Original Message-----
From: IBM AIX Discussion List [mailto:aix-l@Princeton.EDU]On Behalf Of
Bill Verzal
Sent: Friday, February 13, 2004 10:51 AM
To: aix-l@Princeton.EDU
Subject: Re: [aix-l] OS binaries integrity check

TCB
--------------------------------------------------------

"If everything is coming your way, then you are in the wrong lane"

Bill Verzal
AIX Administrator, Komatsu America
(847) 970-3726 - direct
(847) 970-4184 - fax

             "Fette, Gustavo"
             <gustavo.fette@ED
             S.COM> To
             Sent by: IBM AIX aix-l@Princeton.EDU
             Discussion List cc
             <aix-l@Princeton.
             EDU> Subject
                                       OS binaries integrity check

             02/13/2004 12:38
             PM

             Please respond to
                  IBM AIX
              Discussion List
             <aix-l@Princeton.
                   EDU>

Hello:
                Does anyone know about a free tool to check the integrity
of the binaries of my system?

I mean, some kind of tools that run against ie: ls, shutdown, etc give me a
hash that I can have to compare with a new hash ie every month...

Thanks in advance.

Regards,

Gustavo Fette
MMH - GOSD
EDS Argentina
Arias 1851 - Buenos Aires
Phone: +54 11 4704-3403
Mobile: +54 9 11 5110-2325

This electronic message transmission, including any attachments, contains
information from PacifiCare Health Systems Inc. which may be confidential or
privileged. The information is intended to be for the use of the individual or
entity named above. If you are not the intended recipient, be aware that any
disclosure, copying, distribution or use of the contents of this information
is prohibited.
If you have received this electronic transmission in error, please notify the
sender immediately by a "reply to sender only" message and destroy all
electronic and hard copies of the communication, including attachments.



This archive was generated by hypermail 2.1.7 : Wed Apr 09 2008 - 22:17:36 EDT