Hi everybody,
   I was discussing some security issues wit my colleagues. And we
found interresting issue. How is guaranteed integrity of Ossec itself?
Can Ossec somehow discover, that an attacker will replace Ossec with
modified application. Modified Ossec will report during syscheck scan
same size, modification times, checksums, etc. as had original version
of Ossec application. Is there any internal mechanism howto prevent or
discover described situation?

   Jakub

Reply via email to