AIDE
AIDE 是稽核LINUX 上系統異動的情況,包含權限異動也都可以查到。
最後修改日期:2014/2/20
基本使用:
1. 首次使用時輸入 aide --init
輸出的資料檔為:/var/lib/aide/,記得要換名稱、否則日後比對時會找不到基準到。
# aide --check AIDE found differences between database and filesystem!! Start timestamp: 2014-01-05 08:03:47 Summary: Total number of files: 39240 Added files: 0 Removed files: 0 Changed files: 20 --------------------------------------------------- Changed files: --------------------------------------------------- changed: /usr/sbin changed: /usr/libexec changed: /usr/libexec/gcc/x86_64-redhat-linux/4.4.4 changed: /usr/libexec/getconf changed: /usr/libexec/polkit-1 changed: /usr/libexec/utempter changed: /usr/libexec/awk changed: /usr/bin changed: /usr/lib64 changed: /usr/lib64/pm-utils/bin changed: /usr/lib64/nss/unsupported-tools changed: /usr/lib64/sa changed: /usr/lib64/perl5/CORE changed: /root changed: /root/.viminfo changed: /lib/udev changed: /bin changed: /lib64 changed: /lib64/dbus-1 changed: /sbin -------------------------------------------------- Detailed information about changes: --------------------------------------------------- Directory: /usr/sbin Mtime : 2014-01-05 08:00:49 , 2014-01-05 08:01:20 Ctime : 2014-01-05 08:00:49 , 2014-01-05 08:01:20 Directory: /usr/libexec Mtime : 2014-01-05 08:00:49 , 2014-01-05 08:01:21 Ctime : 2014-01-05 08:00:49 , 2014-01-05 08:01:21 Directory: /usr/libexec/gcc/x86_64-redhat-linux/4.4.4 Mtime : 2014-01-05 08:00:49 , 2014-01-05 08:01:21 Ctime : 2014-01-05 08:00:49 , 2014-01-05 08:01:21 Directory: /usr/libexec/getconf Mtime : 2014-01-05 08:00:49 , 2014-01-05 08:01:21 Ctime : 2014-01-05 08:00:49 , 2014-01-05 08:01:21 Directory: /usr/libexec/polkit-1 Mtime : 2014-01-05 08:00:50 , 2014-01-05 08:01:21 Ctime : 2014-01-05 08:00:50 , 2014-01-05 08:01:21 Directory: /usr/libexec/utempter Mtime : 2014-01-05 08:00:50 , 2014-01-05 08:01:21 Ctime : 2014-01-05 08:00:50 , 2014-01-05 08:01:21 Directory: /usr/libexec/awk Mtime : 2014-01-05 08:00:50 , 2014-01-05 08:01:21 Ctime : 2014-01-05 08:00:50 , 2014-01-05 08:01:21 Directory: /usr/bin Mtime : 2014-01-05 08:00:57 , 2014-01-05 08:01:29 Ctime : 2014-01-05 08:00:57 , 2014-01-05 08:01:29 Directory: /usr/lib64 Mtime : 2014-01-05 08:01:09 , 2014-01-05 08:01:42 Ctime : 2014-01-05 08:01:09 , 2014-01-05 08:01:42 Directory: /usr/lib64/pm-utils/bin Mtime : 2014-01-05 08:01:09 , 2014-01-05 08:01:42 Ctime : 2014-01-05 08:01:09 , 2014-01-05 08:01:42 Directory: /usr/lib64/nss/unsupported-tools Mtime : 2014-01-05 08:01:09 , 2014-01-05 08:01:42 Ctime : 2014-01-05 08:01:09 , 2014-01-05 08:01:42 Directory: /usr/lib64/sa Mtime : 2014-01-05 08:01:10 , 2014-01-05 08:01:43 Ctime : 2014-01-05 08:01:10 , 2014-01-05 08:01:43 Directory: /usr/lib64/perl5/CORE Mtime : 2014-01-05 08:01:10 , 2014-01-05 08:01:44 Ctime : 2014-01-05 08:01:10 , 2014-01-05 08:01:44 Directory: /root Mtime : 2014-01-05 07:59:25 , 2014-01-05 08:03:45 Ctime : 2014-01-05 07:59:25 , 2014-01-05 08:03:45 File: /root/.viminfo Inode : 267392 , 267393 Directory: /lib/udev Mtime : 2014-01-05 08:01:14 , 2014-01-05 08:01:48 Ctime : 2014-01-05 08:01:14 , 2014-01-05 08:01:48 Directory: /bin Mtime : 2014-01-05 08:01:15 , 2014-01-05 08:01:49 Ctime : 2014-01-05 08:01:15 , 2014-01-05 08:01:49 Directory: /lib64 Mtime : 2014-01-05 08:01:16 , 2014-01-05 08:01:50 Ctime : 2014-01-05 08:01:16 , 2014-01-05 08:01:50 Directory: /lib64/dbus-1 Mtime : 2014-01-05 08:01:16 , 2014-01-05 08:01:50 Ctime : 2014-01-05 08:01:16 , 2014-01-05 08:01:50 Directory: /sbin Mtime : 2014-01-05 08:01:18 , 2014-01-05 08:01:52 Ctime : 2014-01-05 08:01:18 , 2014-01-05 08:01:52 |
預設情況下,每次比對都會把一些正常的東西給列出來如下:
這是因為prelink 的關係,請參考:這裡修改即可。
1. vi /etc/sysconfig/prelink 把PRELINK=yes 改成PRELINK=no
2. 以root 身份運行 /etc/cron.daily/prelink
後面就會正常了。
留言