<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Catch website file changes with AIDE</title>
	<atom:link href="http://ocaoimh.ie/catch-website-file-changes-with-aide/feed/" rel="self" type="application/rss+xml" />
	<link>http://ocaoimh.ie/catch-website-file-changes-with-aide/</link>
	<description>Look what I found today!</description>
	<lastBuildDate>Wed, 17 Mar 2010 19:05:48 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: SEO</title>
		<link>http://ocaoimh.ie/catch-website-file-changes-with-aide/comment-page-1/#comment-673523</link>
		<dc:creator>SEO</dc:creator>
		<pubDate>Mon, 15 Mar 2010 15:59:40 +0000</pubDate>
		<guid isPermaLink="false">http://ocaoimh.ie/?p=89493743#comment-673523</guid>
		<description>The problem with CentOs is that if you run a cron, it will email you the entire database in addition to the changed files etc. Also, the directory /etc/default/aide isn&#039;t there, so how to set COPYNEWDB to yes?

Anyone knows how to get this working on CentOs?

Thanks!</description>
		<content:encoded><![CDATA[<p>The problem with CentOs is that if you run a cron, it will email you the entire database in addition to the changed files etc. Also, the directory /etc/default/aide isn&#8217;t there, so how to set COPYNEWDB to yes?</p>
<p>Anyone knows how to get this working on CentOs?</p>
<p>Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: whoo</title>
		<link>http://ocaoimh.ie/catch-website-file-changes-with-aide/comment-page-1/#comment-652557</link>
		<dc:creator>whoo</dc:creator>
		<pubDate>Tue, 15 Jul 2008 02:39:38 +0000</pubDate>
		<guid isPermaLink="false">http://ocaoimh.ie/?p=89493743#comment-652557</guid>
		<description>md5mon does something similar, if not identical. Ive been using it for a while.

http://freshmeat.net/projects/md5mon/</description>
		<content:encoded><![CDATA[<p>md5mon does something similar, if not identical. Ive been using it for a while.</p>
<p><a href="http://freshmeat.net/projects/md5mon/" rel="nofollow">http://freshmeat.net/projects/md5mon/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Roni</title>
		<link>http://ocaoimh.ie/catch-website-file-changes-with-aide/comment-page-1/#comment-651527</link>
		<dc:creator>Roni</dc:creator>
		<pubDate>Thu, 19 Jun 2008 06:07:37 +0000</pubDate>
		<guid isPermaLink="false">http://ocaoimh.ie/?p=89493743#comment-651527</guid>
		<description>As you said &quot;If your site is on a shared hosting account then you’re out of luck&quot;

I think some one must provide features brought to by AIDE into an  easier manner. I didn&#039;t think I was harder, but I use shared hosting :-)</description>
		<content:encoded><![CDATA[<p>As you said &#8220;If your site is on a shared hosting account then you’re out of luck&#8221;</p>
<p>I think some one must provide features brought to by AIDE into an  easier manner. I didn&#8217;t think I was harder, but I use shared hosting <img src='http://ocaoimh.ie/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Альтернативщики опротестовали дотации &#34;Почте России&#34; - ComNews.ru</title>
		<link>http://ocaoimh.ie/catch-website-file-changes-with-aide/comment-page-1/#comment-651501</link>
		<dc:creator>Альтернативщики опротестовали дотации &#34;Почте России&#34; - ComNews.ru</dc:creator>
		<pubDate>Wed, 18 Jun 2008 01:06:43 +0000</pubDate>
		<guid isPermaLink="false">http://ocaoimh.ie/?p=89493743#comment-651501</guid>
		<description>[...] Catch website file changes with AIDE [...]</description>
		<content:encoded><![CDATA[<p>[...] Catch website file changes with AIDE [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Donnacha</title>
		<link>http://ocaoimh.ie/catch-website-file-changes-with-aide/comment-page-1/#comment-651489</link>
		<dc:creator>Donnacha</dc:creator>
		<pubDate>Tue, 17 Jun 2008 14:02:07 +0000</pubDate>
		<guid isPermaLink="false">http://ocaoimh.ie/?p=89493743#comment-651489</guid>
		<description>@Kate, I found this article which suggests that it&#039;s extremely simple:

http://www.bofh-hunter.com/2008/04/10/centos-5-and-aide/

... but I haven&#039;t actually got around to implementing it on any of my CentOS systems yet.</description>
		<content:encoded><![CDATA[<p>@Kate, I found this article which suggests that it&#8217;s extremely simple:</p>
<p><a href="http://www.bofh-hunter.com/2008/04/10/centos-5-and-aide/" rel="nofollow">http://www.bofh-hunter.com/2008/04/10/centos-5-and-aide/</a></p>
<p>&#8230; but I haven&#8217;t actually got around to implementing it on any of my CentOS systems yet.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kate</title>
		<link>http://ocaoimh.ie/catch-website-file-changes-with-aide/comment-page-1/#comment-651482</link>
		<dc:creator>Kate</dc:creator>
		<pubDate>Tue, 17 Jun 2008 04:36:20 +0000</pubDate>
		<guid isPermaLink="false">http://ocaoimh.ie/?p=89493743#comment-651482</guid>
		<description>Is AIDE available for CentOS or Redhat system? I want to try it in CentOS/Redhat system</description>
		<content:encoded><![CDATA[<p>Is AIDE available for CentOS or Redhat system? I want to try it in CentOS/Redhat system</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress file monitoring at Mostly Harmless</title>
		<link>http://ocaoimh.ie/catch-website-file-changes-with-aide/comment-page-1/#comment-651480</link>
		<dc:creator>WordPress file monitoring at Mostly Harmless</dc:creator>
		<pubDate>Tue, 17 Jun 2008 03:18:00 +0000</pubDate>
		<guid isPermaLink="false">http://ocaoimh.ie/?p=89493743#comment-651480</guid>
		<description>[...] Donncha provided a page that covers the issue succinctly and today he added another post on setting up aide.  His two posts are good and anyone considering monitoring their WordPress files for modification [...]</description>
		<content:encoded><![CDATA[<p>[...] Donncha provided a page that covers the issue succinctly and today he added another post on setting up aide.  His two posts are good and anyone considering monitoring their WordPress files for modification [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Donncha</title>
		<link>http://ocaoimh.ie/catch-website-file-changes-with-aide/comment-page-1/#comment-651473</link>
		<dc:creator>Donncha</dc:creator>
		<pubDate>Mon, 16 Jun 2008 20:45:00 +0000</pubDate>
		<guid isPermaLink="false">http://ocaoimh.ie/?p=89493743#comment-651473</guid>
		<description>Donnacha - unfortunately it might have a lot of privacy issues as POST requests include usernames and passwords.
It&#039;s probably hard, but not impossible, to see a hack attempt in progress. A central db might be useful but it would require a lot of resources.</description>
		<content:encoded><![CDATA[<p>Donnacha &#8211; unfortunately it might have a lot of privacy issues as POST requests include usernames and passwords.<br />
It&#8217;s probably hard, but not impossible, to see a hack attempt in progress. A central db might be useful but it would require a lot of resources.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Donnacha</title>
		<link>http://ocaoimh.ie/catch-website-file-changes-with-aide/comment-page-1/#comment-651469</link>
		<dc:creator>Donnacha</dc:creator>
		<pubDate>Mon, 16 Jun 2008 20:08:55 +0000</pubDate>
		<guid isPermaLink="false">http://ocaoimh.ie/?p=89493743#comment-651469</guid>
		<description>Hmmm, I&#039;m thinking it would be really useful if, aswell as having a plugin email the admin, if the emails were also CC&#039;d to a central server that could treat them as incoming reports, track the trends and, then, when another rash of attacks hits, could send additional warning emails to people whose emails seemed to indicate a likely attack.

Donncha, is something like that ever likely to be instituted or does Automattic tend to be more hands-off, culturally?</description>
		<content:encoded><![CDATA[<p>Hmmm, I&#8217;m thinking it would be really useful if, aswell as having a plugin email the admin, if the emails were also CC&#8217;d to a central server that could treat them as incoming reports, track the trends and, then, when another rash of attacks hits, could send additional warning emails to people whose emails seemed to indicate a likely attack.</p>
<p>Donncha, is something like that ever likely to be instituted or does Automattic tend to be more hands-off, culturally?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Donncha</title>
		<link>http://ocaoimh.ie/catch-website-file-changes-with-aide/comment-page-1/#comment-651468</link>
		<dc:creator>Donncha</dc:creator>
		<pubDate>Mon, 16 Jun 2008 19:59:39 +0000</pubDate>
		<guid isPermaLink="false">http://ocaoimh.ie/?p=89493743#comment-651468</guid>
		<description>Piggy - it&#039;s similar, but AIDE goes further.

First of all, AIDE has a database of file checksums. It runs md5 and various other checksum algorithms on the files you list, and uses that checksum to figure out what files have changed. The plugin above simply checks the file modification time which can be easily spoofed using touch().

Second, AIDE has to be run as root (well, you could install it in a home directory as an ordinary user too, but I digress) which offers some protection against the database being compromised by the webserver user. Even if a PHP application recorded md5 checksums of all it&#039;s files, you could never trust the database because it would have to be owned by the webserver and therefore at risk of being modified by a hacker.

That said, if you can&#039;t install AIDE, then you should use a plugin like that. It would be really nice if it emailed the administrator once every 24 hours with a list of changed files.</description>
		<content:encoded><![CDATA[<p>Piggy &#8211; it&#8217;s similar, but AIDE goes further.</p>
<p>First of all, AIDE has a database of file checksums. It runs md5 and various other checksum algorithms on the files you list, and uses that checksum to figure out what files have changed. The plugin above simply checks the file modification time which can be easily spoofed using touch().</p>
<p>Second, AIDE has to be run as root (well, you could install it in a home directory as an ordinary user too, but I digress) which offers some protection against the database being compromised by the webserver user. Even if a PHP application recorded md5 checksums of all it&#8217;s files, you could never trust the database because it would have to be owned by the webserver and therefore at risk of being modified by a hacker.</p>
<p>That said, if you can&#8217;t install AIDE, then you should use a plugin like that. It would be really nice if it emailed the administrator once every 24 hours with a list of changed files.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
