Forums

Resolved
0 votes
Greetings,

When an automatic update occurs AIDE triggers reports that checksums, inodes and posix file attrs have changed on files. Shouldn't there be some sort of coordination between automatic updates and AIDE analysis? It makes updates appear to be exploits.

Thanks,

--Jeff
Friday, December 06 2019, 06:32 PM
Share this post:
Responses (2)
  • Accepted Answer

    Friday, December 06 2019, 07:15 PM - #Permalink
    Resolved
    0 votes
    Interesting thought. I have no idea how easy it is to implement. Also, what is a rogue package brings in some valid dependencies?
    The reply is currently minimized Show
  • Accepted Answer

    Friday, December 06 2019, 07:50 PM - #Permalink
    Resolved
    0 votes
    Valid point. I'll go back to my original assertion. If the automatic updates created and driven by ClearOS, the packages are ClearOS and AIDE is a part of ClearOS you would think that a ClearOS auto update function wouldn't trigger a security alert in ClearOS.
    The reply is currently minimized Show
Your Reply