F-SECURE ANTI-VIRUS LINUX SERVER SECURITY Administrator's Manual page 169

Hide thumbs Also See for ANTI-VIRUS LINUX SERVER SECURITY:
Table of Contents

Advertisement

So even if inode data is changed Hash might be same (touch
on a file will change inode data) however IF hash is changed
and inode data is still same then file contents has been modi-
fied and it's mtime set back to what it was with utime() (man 2
utime).
If --show-details is specified, then deviations against baseline
are reported as follows
[Note] ( RA) /bin/ls Hash does not match
baselined hash
[Note] ( RA) /bin/ls inode information
does not match baselined data
mode:uid:gid:len:mtime
81ed:0:0:31936:1096007887
e2c2f03d5460690211fa497592543371
81ed:0:0:31940:1096388689
08c4eae2cf02c4214ba48cb89197aa66
If no deviations are found and --show-all is also specified
then following will be reported
[
(81ed:0:0:620676:1077202297)
baseline action reports
When --baseline is specified the integrity checker will recalcu-
hash
OK
]
(
CHAPTER F
Old
Now
RA)
/bin/ls
167

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents