Welcome to Linux Forums! With a comprehensive Linux Forum, information on various types of Linux software and many Linux Reviews articles, we have all the knowledge you need a click away, or accessible via our knowledgeable members.
Write an article for LinuxForums Today! Win Great Prizes!
AIDE found differences between database and files in dev directory!!
Hi,
AIDE found differences between database and files in dev directory!!
I am almost sure that it wasn't a hack. How could the ctime of some files in dev be changed? What program could do that?
As far as I know: The ctime--change time--is the time when changes were made to the file or directory's inode (owner, permissions, etc.).
All files that were changed represent devices that I am not using (sound, scanner, mic, usb). This is a server without graphical interface installed, locked in a room (no one had physical access yesterday at 15:55:36) and no one has tried to access/install there devices.
The ctime of all files was changed at the same time (2005-06-28 15:55:36 ). I also don�t know why the old ctime was 2005-06-21 15:16:24. Nothing special happened on 2005-06-21 15:16:24 but AIDE wasn�t installed on 2005-06-21 15:16:24 so I couldn�t notice that.
Open Source Security Myths Dispelled Dispel the five major myths surrounding Open Source Security and gain the tools necessary to make a truly informed decision for your IT organization subscribe
InformationWeek InformationWeek is the only newsweekly you'll need to stay on top of the latest developments in information technology. subscribe