Re: Script to System Check Integrity against Debian Package Repository

2013-09-18 Thread adrelanos
Török Edwin: > On 09/17/2013 09:45 PM, adrelanos wrote: >> Situation: >> >> * You have a Debian machine, which might be compromised by a backdoor >> due to a targeted attack. You don't know and want to make sure it's not. >> For example, a server or a client internet machine. > > Why not just rein

Re: Script to System Check Integrity against Debian Package Repository

2013-09-18 Thread adrelanos
Paul Wise: > On Wed, Sep 18, 2013 at 9:36 AM, Török Edwin wrote: > >> Why not just reinstall from a trusted source, then restore /etc, /home and >> /var from backups >> and audit the changes introduced by that only? > > That is a slightly short-sighted way to do it; if you restore from > scratch

AUTO: Thomas Sinka ist außer Haus (Rückkehr am 01.10.2013)

2013-09-18 Thread tsinka
Ich bin bis 01.10.2013 abwesend Bitte wenden Sie sich in dringenden Fällen an Frau Langenfeld: anna-meta.langenf...@it-choice.de, Tel. 0721 85 006-0 Vielen Dank! Hinweis: Dies ist eine automatische Antwort auf Ihre Nachricht "[SECURITY] [DSA 2756-1] wireshark security update" gesendet am 13.09

AUTO: Thomas Sinka ist außer Haus (Rückkehr am 01.10.2013)

2013-09-18 Thread tsinka
Ich bin bis 01.10.2013 abwesend Bitte wenden Sie sich in dringenden Fällen an Frau Langenfeld: anna-meta.langenf...@it-choice.de, Tel. 0721 85 006-0 Vielen Dank! Hinweis: Dies ist eine automatische Antwort auf Ihre Nachricht "[SECURITY] [DSA 2756-1] wireshark security update" gesendet am 13.09

Re: Script to System Check Integrity against Debian Package Repository

2013-09-18 Thread Timo Juhani Lindfors
adrelanos writes: > * No code within the untrusted system must be required to be executed in > order for the check, since no code inside the vm image is trusted while > testing. How about using https://github.com/devstructure/blueprint? -- To UNSUBSCRIBE, email to debian-security-requ...@lists

Re: Script to System Check Integrity against Debian Package Repository

2013-09-18 Thread Paul Wise
On Wed, Sep 18, 2013 at 9:36 AM, Török Edwin wrote: > Why not just reinstall from a trusted source, then restore /etc, /home and > /var from backups > and audit the changes introduced by that only? That is a slightly short-sighted way to do it; if you restore from scratch without doing any foren

Re: Script to System Check Integrity against Debian Package Repository

2013-09-18 Thread Török Edwin
On 09/17/2013 09:45 PM, adrelanos wrote: > Situation: > > * You have a Debian machine, which might be compromised by a backdoor > due to a targeted attack. You don't know and want to make sure it's not. > For example, a server or a client internet machine. Why not just reinstall from a trusted so