[Aide] Permission denied when scanning readable directory below unreadable directory

2012-07-05 Thread Keith Constable
the same with /home. It chokes because it can't list the contents of /home. Is there a way to make this work, short of asking the sysadmin to change the perms on /home? Regards, Keith Constable ___ Aide mailing list Aide@cs.tut.fi https

Re: [Aide] Permission denied when scanning readable directory below unreadable directory

2012-07-06 Thread Keith Constable
On Fri, Jul 6, 2012 at 4:08 AM, Hannes von Haugwitz han...@vonhaugwitz.com wrote: Hello, For the time being you can use the current git snapshot [0] and use the new root_prefix option... This. This is the solution to my problem. Thanks. Regards, Keith Constable

Re: [Aide] AIDE + Apache 2.2 reload Problem

2012-08-29 Thread Keith Constable
On Tue, Aug 28, 2012 at 4:27 AM, Daniel Gerne daniel.ge...@googlemail.com wrote: Hello, we want to use AIDE on our webservers running apache 2.2. To manage the logs we use logrotate on the apache logs. As far as I know it is best practice to do a reload on rotate for apache logs so apache

Re: [Aide] AIDE + Apache 2.2 reload Problem

2012-08-30 Thread Keith Constable
On Thu, Aug 30, 2012 at 4:23 AM, Daniel Gerne daniel.ge...@googlemail.com wrote: Dear Keith, thank you for support. We are running SLES 11 SP1. AIDE is installed from its package manager. Httpd is also installed from its package manager. So far we know that AIDE recognizes a change in both

Re: [Aide] WARNING: Old db contains a file that shouldn't be there, run --init or --update

2012-10-05 Thread Keith Constable
Matt, What are you trying to do when this message appears and what aide command line are you using? Could you paste your aide.conf (sensitive parts redacted, if you wish)? Best, Keith Constable On Fri, Oct 5, 2012 at 9:16 AM, matthew.langtho...@stfc.ac.uk wrote: Hello list, i keep

Re: [Aide] Aide init

2012-10-22 Thread Keith Constable
On 22 Oct 2012, at 7:12 PM, ncalsmitty1369 ncalsmitty1...@gmail.com wrote: Hi, I am having a problem initializing my aide installation on a xen Debian squeeze domU. I have installed and configured aide many times across debian etch/lenny/squeeze and have not had the problem detailed

Re: [Aide] libgcrypt error

2012-10-26 Thread Keith Constable
that, rather than one packaged in 2007. Best regards, Keith Constable [1] http://aide.git.sourceforge.net/git/gitweb.cgi?p=aide/aide;a=blob;f=README;hb=HEAD smime.p7s Description: S/MIME cryptographic signature ___ Aide mailing list Aide@cs.tut.fi https

Re: [Aide] /run/aide

2012-11-05 Thread Keith Constable
includes in the AIDE package. Best of luck, Keith Constable smime.p7s Description: S/MIME cryptographic signature ___ Aide mailing list Aide@cs.tut.fi https://mailman.cs.tut.fi/mailman/listinfo/aide

Re: [Aide] question about dealing with expected files

2013-03-19 Thread Keith Constable
: It is generally a good idea to write the most general rules last. Try rearranging the rules like so: !/var/log/sa/sa[0-9][0-9]$ !/var/log/sa/sar[0-9][0-9]$ /var/log/sa NORMAL Be specific first and broad later. Regards, Keith Constable

Re: [Aide] Implementation and configuration question.

2013-05-24 Thread Keith Constable
A cursory search suggests http://splunk-base.splunk.com/apps/22366/pci-app-creative-commons-version Regards, Keith Constable smime.p7s Description: S/MIME cryptographic signature ___ Aide mailing list Aide@cs.tut.fi https://mailman.cs.tut.fi/mailman

Re: [Aide] Can I get a list of files aide is scanning?

2013-06-17 Thread Keith Constable
Dave, No worries. One might assume the file is some binary database, unless they have a reason to check. Mine's not even gzipped. Regards, Keith Constable On Jun 17, 2013, at 12:14 PM, Dave Shevett shev...@pobox.com wrote: On 6/17/13 12:09 PM, Keith Constable wrote: Dave, The aide

Re: [Aide] syntax error when trying to run aide

2013-08-28 Thread Keith Constable
added the /etc/selinux rule as you have claimed. Are you certain you added it? Regards, Keith Constable smime.p7s Description: S/MIME cryptographic signature ___ Aide mailing list Aide@cs.tut.fi https://mailman.cs.tut.fi/mailman/listinfo/aide

Re: [Aide] AIDE configuration taking too long

2013-08-28 Thread Keith Constable
anywhere near that long on such little data. If I were in your shoes, I would try running aide with the -V231 argument. It turns on just enough verbosity to show you what files it's working on without being overwhelming. You can go up to -V255 if you feel you need more info. Regards, Keith Constable

Re: [Aide] AIDE configuration taking too long

2013-08-28 Thread Keith Constable
not necessarily improve your security. Be careful not to include so many frequently changing files that it generates a report that's too long. You're more likely to miss that one important change if you have to sift through a mountain of unimportant ones. Regards, Keith Constable smime.p7s

Re: [Aide] AIDE configuration taking too long

2013-08-29 Thread Keith Constable
of the entire content of the drive, not the device file itself). http://aide.sourceforge.net/stable/manual.html#config Did running aide with the verbose option show if it was getting stuck on any particular file? Regards, Keith Constable ___ Aide

Re: [Aide] install using centos rpm

2014-03-13 Thread Keith Constable
James, Generally speaking, when a package build system complains about a missing library, it is looking for the -devel version of it. You may want to check the CentOS packaging system for a zlib-devel and libcrypt-devel or something similar. Regards, Keith Constable On 13 Mar 2014, at 12

Re: [Aide] install using centos rpm

2014-03-14 Thread Keith Constable
to install the -devel package for any other libraries the configure script complains about. Regards, Keith Constable On Mar 14, 2014, at 10:36 AM, Yunker, James M CIV NUWC NWPT james.yun...@navy.mil wrote: I think that I did not make something clear and that I should clear it up

Re: [Aide] wildcard in aide.conf?

2014-04-24 Thread Keith Constable
Julien, Be certain that your most specific rules are on top and most generic on bottom. For example !/home/.*/Downloads needs to be higher in the list than /home Regards, Keith Constable On Wed, Apr 23, 2014 at 11:02 PM, Julien T julien@gmail.com wrote: Hello, I'm reviewing my aide

Re: [Aide] AIDE and Wordpress? Constant wp-content changes? Is it normal?

2015-05-01 Thread Keith Constable
? Bear in mind that Wordpress has automatic update features, so some unexpected changes may occur. Regards, Keith Constable ___ Aide mailing list Aide@cs.tut.fi https://mailman.cs.tut.fi/mailman/listinfo/aide

Re: [Aide] Renaming aide.db.new cause false positives

2015-05-12 Thread Keith Constable
, Keith Constable ___ Aide mailing list Aide@cs.tut.fi https://mailman.cs.tut.fi/mailman/listinfo/aide

Re: [Aide] Need help with AIDE configuration

2016-04-22 Thread Keith Constable
ance to inject some file in a website, I want to see > it. But he won't probably modify the AIDE database from himself. > > Cordialement, > > Jérôme LILLE | Responsable Agence > i...@lije-creative.com > <javascript:_e(%7B%7D,'cvml','i...@lije-creative.com');> | +33 7 7