manan shah wrote:
home/mshah/ps md5+sha1+rmd160
You probably want to start the line with a / like this:
/home/mshah/ps md5+sha1+rmd160
Are you getting any error messages when running aide?
Sincerely,
Richard van den Berg
linked aide
executable on a read-only medium too.
Sincerely,
Richard van den Berg
in db_readline_file 310
@@end_db
Is this a bug, feature, something else?
That is a bug in the latest official release. It has been fixed in the
CVS version.
Sincerely,
Richard van den Berg
like to move this project to sourceforge.net or another open source
platform so development can move forward.
This is a request for your comments.
Sincerely,
Richard van den Berg
Zac DeLesDernier wrote:
0 0 * * * /mnt/cdrom/aide echo no differences found
That works too of course. :-) Pipe, logical and, it's more of the same.
Sincerely,
Richard van den Berg
when a system does not
have vsnprintf() natively.
Sincerely,
Richard van den Berg
[EMAIL PROTECTED] wrote:
In article [EMAIL PROTECTED] you write:
Got the following errors with aide v0.9 on solaris:
This has been discussed before.
And it has already been fixed in the CVS version of aide. See
http://sourceforge.net/projects/aide/
Sincerely,
Richard van den Berg
Paananen Osmo wrote:
It seems that at least somebody uses aide:
http://lists.debian.org/debian-announce/debian-announce-2003/msg3.html
Thanks for the link. I added a news item to the sourceforge projectpage.
Richard
. This is bad, very bad. Most
likely you installed your system or some patches with the system clock
set to a time in the future.
To fix this you can:
- reinstall your system with the system clock set to a current time
- touch all the files that aide complains about
Sincerely,
Richard van den Berg
--enable-static=yes and build
aide as usual, it will be statically linked. You can verify the dynamic
dependencies using ldd aide when you have build it.
Sincerely,
Richard van den Berg
? Are all the other values the same (size, mod time,
etc) ?
Sincerely,
Richard van den Berg
the aide config.log file.)
Sincerely,
Richard van den Berg
___
Aide mailing list
[EMAIL PROTECTED]
https://mailman.cs.tut.fi/mailman/listinfo/aide
I found a portable vsnprintf at http://www.ijs.si/software/snprintf/
That must be the problem. You have vsnprintf() but it is not C99
compliant. I'll try to add an extra check for this in the configure script
for the next release.
Thanks,
Richard van den Berg
level (which is 5).
I applied it to CVS.
Sincerely,
Richard van den Berg
___
Aide mailing list
[EMAIL PROTECTED]
https://mailman.cs.tut.fi/mailman/listinfo/aide
can tell.
This happens during a --check as well? Please use the patch that Pablo
posted (should be in tomorrows snapshot). I'm very interested to see
which attribute has changed.
Sincerely,
Richard van den Berg
___
Aide mailing list
[EMAIL PROTECTED
On Sat, November 6, 2004 12:55, Virolainen Pablo said:
Only small problem. When you are tired you will make some errors. This
time | was replased with (I wanted to do bitwise or not bitwise and
like I typed).
Fixed in CVS, thanks.
Richard van den Berg
you. You
can always use the CVS snapshot, which includes a configure script.
Sincerely,
Richard van den Berg
___
Aide mailing list
[EMAIL PROTECTED]
https://mailman.cs.tut.fi/mailman/listinfo/aide
:///etc/aide/aide.db.new
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
the output of aide.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
1.0) is due, and should be released soon.
If you experience problems with aide 0.10, please try the CVS version.
If the problem persists, please report it on sf.net using the available
tools.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide
as expected. (This is a bug in aide 0.10.)
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
. This should now be conf_lex2.o from
conf_lex2.c (which includes conf_lex.c).
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
[EMAIL PROTECTED] wrote:
Richard, when is the CVS version going to be released?
When I fix all the bugs. ;-) I know it's long overdue, but I need to
find the time to make a proper release (and do extensive testing).
Sincerely,
Richard van den Berg
with the errors attached.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
recommend the current CVS version over aide 0.10.
If your problems persist, let us know.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
does not support this. Since the aide.db is a line oriented
text file, it can easily be scripted though.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
: Cannot allocate memory
That is pretty weird. Can you send the output of ulimit -a of that
account? I am wondering if there are any restrictions on the memory usage.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https
. This is the code from do_md.c that fails:
#ifdef HAVE_O_NOATIME
int filedes=open(line-filename,O_RDONLY|O_NOATIME);
#else
int filedes=open(line-filename,O_RDONLY);
#endif
Pretty straight forward, really.
Sincerely,
Richard van den Berg
___
Aide mailing
details about your setup? OS, kernel
version, filesystem type, mount flags. Please be as verbose as possible.
Since the O_NOATIME is a new feature in Linux (and aide), it would be
nice to know its limitations.
Sincerely,
Richard van den Berg
___
Aide mailing
,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
, if
it is there, it will be used. At least the configure of aide tests if
files can be opened using this flag.
The fix to retry when opening with O_NOATIME fails (suggested by Pablo)
should work around this. So please try aide 0.11-rc2 when it is released.
Sincerely,
Richard van den Berg
names as well.
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
[EMAIL PROTECTED] wrote:
The -c switch in the last bzip2.
I tried this before, and now again. But this does not change anything.
It should. How did you manage to get aide to output the aide.db on
stderr in the first place?
Sincerely,
Richard van den Berg
bzip2 example to the contrib directory, thanks. If anyone
can make a verfied test case with a pgp script as well, I'll add that
one too.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo
, mmap is used. Are the hashes completely different, or are
they just stored differently (byte order, etc)?
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
Marc Haber wrote:
Unfortunately, I seem to have broken things, my aide now segfaults.
Can you confirm that the segfault is caused by your patch? If so, I'll
hold off on applying it. I took a quick look at it, but can't find any
potential problems.
Sincerely,
Richard van den Berg
van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
I just uploaded aide 0.11-rc2 to http://sourceforge.net/projects/aide/
Please test it, and provide feedback through the SF bug tracker or this
list. If you found bugs in 0.11-rc1 please test 0.11-rc2 and see if they
are properly solved.
Sincerely,
Richard van den Berg
is hosting..
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
Virolainen Pablo wrote:
Thanks for the help (config-file,core and binary). The Bug was where I
suspected. The new patch should fix that problem.
This last patch has been applied to CVS, and is included it today's
daily snapshot.
Thanks,
Richard van den Berg
use
in this function)
make[2]: *** [gen_list.o] Error 1
Please post a patch against the current CVS or aide 0.11-rc2.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
Virolainen Pablo wrote:
Ok. Lets try again.
Much better. :-) I applied this patch to CVS and todays daily snapshot.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
Marc Haber wrote:
this patch seems to restore the old behavior. Please consider applying
it to CVS.
It looks like Pablo changed a bit too much when trying to make the rule
matches more logical. I just applied your patch, thanks.
Sincerely,
Richard van den Berg
.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
to the administrator to see what output
--update produces (i.e. what has changed), and then manually replace the
aide.db with the aide.db.new. The next run of aide will then report any
changes made since the last run. You can adopt this strategy if you like it.
Sincerely,
Richard van den Berg
in the update report.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
directory as gpg2_check.sh and gpg2_update.sh. Thanks for the
contribution.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
.html
Aide does not allow regexes in the directory part of a selection rule.
The reason for this, is that aide uses that path information to decide
which directories to recurse into. Only the file part is a full featured
regex.
Sincerely,
Richard van den Berg
might support full regexes in the
directory component as well..
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
with database_new as well?
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
that might give you a hint. If the file is set to be world
writable however, it would be a wild guess.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
Vincent Danen wrote:
Attached is a patch that fixes a few layout issues in the aide.conf.5
manpage.
Applied to CVS, thanks.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
Vincent Danen wrote:
I find the output of aide --help to be extremely hard to read, so the
attached patch makes it much easier to read and condenses it somewhat
(more in style with other programs' --help output).
It looks much cleaner now, thanks. Applied to CVS.
Sincerely,
Richard van den
solved.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
of config.log (the one about unsigned
short). Or send the while config.log (compressed) when you are not sure.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
systems and cygwin
* Open files with O_NOATIME on supported Linux systems
* Added I/ANF/ARF directives
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
rotating log files by inode number.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
a but at http://sf.net/projects/aide ).
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
aide.conf file. Can you send it?
/usr/bin/aide: line 9: 24848 Segmentation fault /usr/bin/aide.real $@
That looks like a bug of some sort. Please use gdb to run aide (or on
the core file) and send the backtrace (bt).
Sincerely,
Richard van den Berg
to /usr/local/includes/mutils ?
You can always try a previous mhash version. The 0.8.x versions don't
have as many problems as the 0.9.x releases have had.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi
,
Richard van den Berg
PS: do not forget to Cc the list when replying
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
release.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
0x000c in ?? ()
Previous frame identical to this frame (corrupt stack?)
(gdb)
So either aide.real is not build with debugging enabled, or the stack is
completely corrupted. I am not a gdb expert.. can someone else please
comment?
Sincerely,
Richard van den Berg
+g+s+m+c+md5
So this includes c for ctime. R is a default group that is created in
the c-code, even when it is not mentioned in the aide.conf file. It's
better to define your custom group using base elements. Try defining
NORMAL as:
NORMAL = p+i+n+u+g+s+m+md5+b+sha1
Sincerely,
Richard van den
not be the
case.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
Will recurse for --check but not for --init. I've found the problem for
this in the code, but I am not sure what I will break by fixing this
issue. For now, using equal rules is the way to go.
Is anyone else seeing this behavior?
Yes, I can confirm this.
Sincerely,
Richard van den Berg
doesn't..
# make
make: *** No targets specified and no makefile found. Stop.
please could you help me?
The Makefile should be created by configure. Please check config.log for
a hint of what went wrong.
Sincerely,
Richard van den Berg
___
Aide
Fredrik Söderblom wrote:
I've just submitted a fix for this rather odd behaviour from mmap()
on HP-UX, see patch 1474555
Thanks a lot. I've added it to CVS.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https
=HEAD
Look for the section named Understanding Aide rule matching.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
change like it is expected to.
Are you sure you did an --init after you changed the aide.conf file? If
so, please change the /etc/passwd file again (touch should be enough)
and send the output of aide -V255 --check.
Sincerely,
Richard van den Berg
___
Aide
make sure that you are only updating
attributes as a result from changes you made to the aide.conf and not
other changes perhaps made by an intruder.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman
pointer.
In the current situation, does --init work? If so, try using this new
database and see if --update will still seg fault when changes are made
on the system.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https
Thanks for the additional gdb output. What compiler (type and version)
are you using? I doubt this is an aide bug.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
when linking.
Modify the line that looks like
$(LINK) $(aide_LDFLAGS) $(aide_OBJECTS) $(aide_LDADD) $(LIBS)
to read:
$(LINK) $(aide_LDFLAGS) $(aide_OBJECTS) $(aide_LDADD) $(LIBS) ${PSQLLIB}
Let me know if that works.
Sincerely,
Richard van den Berg
the --disable-static configure option that is
present in the CVS version.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
the config.h file?
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
. Pretty strange that this did not show
up on other OSses.
I'll apply the patch as soon as the sourceforge CVS is back up.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
Randy Brown wrote:
If things are OK, we don't want an email. Is there a silent
option, or a way to suppress that message with AIDE?
The standard Looks okay message is printed with verbosity level 5 or
greater. So use aide -V4 or lower to suppress it.
Sincerely,
Richard van den Berg
Randy Brown wrote:
Using -V4 would I still get messages if something were changed, added,
removed?
Yes, the summary of changes is at verbosity level 0 (they are always
printed). The details of the changes is at level 2.
Sincerely,
Richard van den Berg
. A gdb backtrace should help in locating the
problem. Please do not use aide 0.10, it is known to cause segfaults in
various situations.
Since your problem is with --compare, you can send the 2 databases so I
can troubleshoot this locally on my system.
Sincerely,
Richard van den Berg
with your SourceForge id, you will be kept informed if and
when this is implemented.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
already have a rule for / in your conf, exclude /home by:
!/home
You might have to play a bit with the order of those lines to get it
right. My first guess would be:
/ R
!/home
/home/path/to/dir1 R
/home/path/to/dir2 R
Sincerely,
Richard van den Berg
Pablo Virolainen wrote:
On Mon, 30 Jan 2006, Richard van den Berg wrote:
Pablo Virolainen wrote:
It could be usefull to have some file attributes to be printed in the
report even if they haven't changed (like UID/GID, permissions?). It
could
be handled with special rule like
/?group_id=86976atid=581579
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
for the aide.conf on toots are the same
as on ovh. IIRC running aide --compare still takes into account the
selection rules in the aide.conf file.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo
the MD5 and SHA1 for the whole
file again, and so on. Of course this only makes sense for ever growing
files. I am not sure if the event log is limited in size (if so, the
first n bytes will change over time).
Sincerely,
Richard van den Berg
___
Aide mailing
it run under cygwin. NTFS should have a
similar concept like inodes. I know it also supports hard links, so the
chances are good that under cygwin these attributes are mapped to their
NTFS equivalent.
Sincerely,
Richard van den Berg
___
Aide mailing list
Robert V. Coward/CTR/OSAGWI wrote:
Has the ability to add:
report_url=mailto:[EMAIL PROTECTED]
to the aide.conf file been added in this last release.
No, it has not. It is easy to script this however.
Sincerely,
Richard van den Berg
___
Aide
be LOG_LOCAL1. So the aide.conf line should read:
Report_url=syslog:LOG_LOCAL1
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
/?group_id=86976atid=581579
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
conf_yacc.y
a3810155367ef91d2c54767551134e58 conf_yacc.y
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
with aide.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
Robert V. Coward/CTR/OSAGWI wrote:
I am having the same problem.
If bison does not give any errors, but also does not created the
requested conf_yacc.c it definitely has a problem. Try a newer version
of bison.
Sincerely,
Richard van den Berg
than the file size in the aide.db.
running: aide-0.10 on Solaris-9 Sparc.
You should really upgrade to aide 0.12. Many bugs have been fixed since
version 0.10.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https
0.13 so others will also benefit
from the changes you made.
Sincerely,
Richard van den Berg
___
Aide mailing list
Aide@cs.tut.fi
https://mailman.cs.tut.fi/mailman/listinfo/aide
James Antill wrote:
Given the timestamp, I'd guess it's prelink changing the binary.
Prelink? Aide should not be compiled as a dynamic linked binary! Use the
defaults, and let it link statically.
Sincerely,
Richard van den Berg
___
Aide mailing list
it
afterwards so that /dev/null is replaced by the path of your aide.db
file. Then use it to check for changes in aide.db and all attributes
should be reported as changed. Or am I missing something obvious here?
Sincerely,
Richard van den Berg
___
Aide mailing
1 - 100 of 224 matches
Mail list logo