ืืืืืขืจ ืื ืึธื ืืืื ืคืื ืืขื ืงืืจืก
AIDE ืฉืืืื ืคึฟืึทืจ "ืึทืืืึทื ืกืืจืืข ืื ืืจืืกืืึธื ืืขืืขืงืฉืึทื ืกืืืืืืข" ืืื ืืื ืืืื ืขืจ ืคืื ืื ืืขืจืกื ืคืึธืืงืก ืกืืกืืขืืขื ืคึฟืึทืจ ืืึธื ืืืึธืจืื ื ืขื ืืขืจืื ืืขื ืืื ืืื ืืงืก-ืืืืืจื ืึธืคึผืขืจืืืืื ื ืกืืกืืขืืขื. AIDE ืืื ืืขื ืืฆื ืฆื ืืึทืฉืืฆื ืงืขืื ืืึทืืืืึทืจืข, ืืืืจืืกืขืก ืืื ืืขืืขืงื ืึทื ืึธืืขืจืืืื ืึทืงืืืืืืืขืื. ืฆื ืืึทืฉืืขืืืงื ืืขืงืข ืึธืจื ืืืขืืงืืึทื ืืื ืืขืืขืงื ืื ืืจืืืฉืึทื ื, AIDE ืงืจืืืืฅ ืึท ืืึทืืึทืืืืก ืคืื ืืขืงืข ืืื ืคึฟืึธืจืืึทืฆืืข ืืื ืงืึทืืคึผืขืจื ืื ืงืจืึทื ื ืฉืืึทื ืคืื ืื ืกืืกืืขื ืืื ืืขื ืืึทืืึทืืืืก. AIDE ืืขืืคึผืก ืฆื ืจืขืืืฆืืจื ืื ืกืึทืืึทื ืฅ ืืืกืคืึธืจืฉืื ื ืฆืืื ืืืจื ืคืึธืืงืืกืื ื ืืืืฃ ืืขืงืขืก ืืืึธืก ืืขื ืขื ืืึทืืึทืคืืื.
AIDE ืคึฟืขืึดืงืืืื:
- ืฉืืืฆื ืคืึทืจืฉืืื ืืขืงืข ืึทืืจืืืืืฅ, ืึทืจืืึทื ืืขืจืขืื ื: ืืขืงืข ืืืคึผ, ืื ืึธืืข, ืืื, ืืื, ืคึผืขืจืืืฉืึทื ื, ื ืืืขืจ ืคืื ืคึฟืึทืจืืื ืืื ืืขื, ืืืืืข, ืงืืืืข ืืื ืฆืืื.
- ืฉืืืฆื ืคึฟืึทืจ Gzip ืงืึทืืคึผืจืขืฉืึทื, SELinux, XAttrs, Posix ACL ืืื ืืขืงืข ืกืืกืืขื ืึทืืจืืืืืฅ.
- ืฉืืืฆื ืคืึทืจืฉืืื ืึทืืืขืจืืืึทืื ืึทืจืืึทื ืืขืจืขืื ื md5, sha1, sha256, sha512, rmd160, crc32, ืขืืง.
- ืฉืืงื ื ืึธืืืึทืคืึทืงืืืฉืึทื ื ืืืจื ืืืืฆืคึผืึธืกื.
ืืื ืืขื ืึทืจืืืงื, ืืืจ ืืืขืื ืงืืงื ืืื ืืื ืฆื ืื ืกืืึทืืืจื ืืื ื ืืฆื AIDE ืคึฟืึทืจ ืื ืืจืืืฉืึทื ืืืืขืงืฉืึทื ืืืืฃ CentOS 8.
ืคึผืจืืจืขืงืืืึทืืึทืฅ
- ืกืขืจืืืืจืขืจ ืคืืืกื ืืืง CentOS 8, ืืื ืืคึผืืืช 2 ืืืืืืืื ืคืื ืืึทืจืึทื.
- ืืืึธืจืฆื ืึทืงืกืขืก
ืืขืืื ื ืกืืึทืจืืขื
ืขืก ืืื ืจืขืงืึทืืขื ืืื ืฆื ืืขืจืืืึทื ืืืงื ืื ืกืืกืืขื ืขืจืฉืืขืจ. ืฆื ืืึธื ืืึธืก, ืืืืคื ืื ืคืืืืขื ืืข ืืึทืคึฟืขื.
dnf update -y
ื ืึธื ืึทืคึผืืืืืื ื, ืจืืกืืึทืจื ืืืื ืกืืกืืขื ืคึฟืึทืจ ืื ืขื ืืขืจืื ืืขื ืฆื ื ืขืืขื ืืืืจืงืื ื.
ืื ืกืืึทืืืจื AIDE
AIDE ืืื ืื ืืืฆื ืืื ืื ืคืขืืืงืืึทื CentOS 8 ืจืืคึผืึทืืึทืืึธืจื. ืืืจ ืงืขื ืขื ืืืืื ืื ืกืืึทืืืจื ืขืก ืืืจื ืืืืคื ืื ืคืืืืขื ืืข ืืึทืคึฟืขื:
dnf install aide -y
ืึทืืึธื ืื ืื ืกืืึทืืืจืื ื ืืื ืืึทื ืฅ, ืืืจ ืงืขื ืขื ืืขื ืื AIDE ืืืขืจืกืืข ืืื ืื ืคืืืืขื ืืข ืืึทืคึฟืขื:
aide --version
ืืืจ ืืึธื ืืขื ืื ืคืืืืขื ืืข:
Aide 0.16
Compiled with the following options:
WITH_MMAP
WITH_PCRE
WITH_POSIX_ACL
WITH_SELINUX
WITH_XATTR
WITH_E2FSATTRS
WITH_LSTAT64
WITH_READDIR64
WITH_ZLIB
WITH_CURL
WITH_GCRYPT
WITH_AUDIT
CONFIG_FILE = "/etc/aide.conf"
ืื ืืืฆื ืึธืคึผืฆืืขืก aide
ืงืขื ืขื ืืืื ืืขืืขื ืืื ืืืื:
aide --help
ืงืจืืืืืื ื ืืื ืื ืืืืึทืืืืื ื ืื ืืึทืืึทืืืืก
ืืขืจ ืขืจืฉืืขืจ ืืึทื ืืืจ ืืึทืจืคึฟื ืฆื ืืึธื ื ืึธื ืื ืกืืึธืืื ื AIDE ืืื ืฆื ืื ืืฉืึทืืืื ืขืก. ืื ืืืืึทืืืืึทืืืึธื ืืืฉืืืื ืคืื ืงืจืืืืืื ื ืึท ืืึทืืึทืืืืก (ืกื ืึทืคึผืฉืึธื) ืคืื ืึทืืข ืืขืงืขืก ืืื ืืืจืขืงืืขืจืื ืืืืฃ ืื ืกืขืจืืืขืจ.
ืฆื ืื ืืฉืึทืืืื ืื ืืึทืืึทืืืืก, ืืืืคื ืื ืคืืืืขื ืืข ืืึทืคึฟืขื:
aide --init
ืืืจ ืืึธื ืืขื ืื ืคืืืืขื ืืข:
Start timestamp: 2020-01-16 03:03:19 -0500 (AIDE 0.16)
AIDE initialized database at /var/lib/aide/aide.db.new.gz
Number of entries: 49472
---------------------------------------------------
The attributes of the (uncompressed) database(s):
---------------------------------------------------
/var/lib/aide/aide.db.new.gz
MD5 : 4N79P7hPE2uxJJ1o7na9sA==
SHA1 : Ic2XBj50MKiPd1UGrtcUk4LGs0M=
RMD160 : rHMMy5WwHVb9TGUc+TBHFHsPCrk=
TIGER : vkb2bvB1r7DbT3n6d1qYVfDzrNCzTkI0
SHA256 : tW3KmjcDef2gNXYqnOPT1l0gDFd0tBh9
xWXT2iaEHgQ=
SHA512 : VPMRQnz72+JRgNQhL16dxQC9c+GiYB8g
uZp6uZNqTvTdxw+w/IYDSanTtt/fEkiI
nDw6lgDNI/ls2esijukliQ==
End timestamp: 2020-01-16 03:03:44 -0500 (run time: 0m 25s)
ืืขืจ ืืืืื ืืึทืคึฟืขื ืืืขื ืฉืึทืคึฟื ืึท ื ืืึทืข ืืึทืืึทืืืืก aide.db.new.gz
ืืื ืืขื ืงืึทืืึทืืึธื /var/lib/aide
. ืขืก ืงืขื ืขื ืืืื ืืขืืขื ืืื ืื ืคืืืืขื ืืข ืืึทืคึฟืขื:
ls -l /var/lib/aide
ืืขืจ ืจืขืืืืืึทื:
total 2800
-rw------- 1 root root 2863809 Jan 16 03:03 aide.db.new.gz
AIDE ืืืขื ื ืืฉื ื ืืฆื ืืขื ื ืืึทืข ืืึทืืึทืืืืก ืืขืงืข ืืื ืขืก ืืื ืจืื ืืืื ืฆื aide.db.gz
. ืืึธืก ืงืขื ืืืื ืืขืืื ืืื ืืืื:
mv /var/lib/aide/aide.db.new.gz /var/lib/aide/aide.db.gz
ืขืก ืืื ืจืขืงืึทืืขื ืืื ืฆื ืืขืจืืืึทื ืืืงื ืืขื ืืึทืืึทืืืืก ืคึผืืจืืึทืืืงืื ืฆื ืขื ืฉืืจ ืึทื ืขื ืืขืจืื ืืขื ืืขื ืขื ืจืขืื ืืึธื ืืืึธืจืขื.
ืืืจ ืงืขื ืขื ืืืืฉื ืืขื ืึธืจื ืคืื ืื ืืึทืืึทืืืืก ืืืจื ืืฉืึทื ืืื ื ืืขื ืคึผืึทืจืึทืืขืืขืจ DBDIR
ืืื ืืขืงืข /etc/aide.conf
.
ืคืืืกื ืืืง ืึท ืืืขืจืงืืงื
AIDE ืืื ืืืฆื ืืจืืื ืฆื ื ืืฆื ืื ื ืืึทืข ืืึทืืึทืืืืก. ืืืืคื ืื ืขืจืฉืืขืจ AIDE ืืฉืขืง ืึธื ืงืืื ืขื ืืขืจืื ืืขื:
aide --check
ืืขื ืืึทืคึฟืขื ืืืขื ื ืขืืขื ืขืืืขืืข ืืึธื ืฆื ืคืึทืจืขื ืืืงื ืืืคึผืขื ืืื ื ืืืืฃ ืื ืืจืืืก ืคืื ืืืื ืืขืงืข ืกืืกืืขื ืืื ืื ืกืืืข ืคืื โโืืึทืจืึทื ืืืืฃ ืืืื ืกืขืจืืืขืจ. ืึทืืึธื ืื ืืืขืจืงืืงื ืืื ืืึทื ืฅ, ืืืจ ืืึธื ืืขื ืื ืคืืืืขื ืืข:
Start timestamp: 2020-01-16 03:05:07 -0500 (AIDE 0.16)
AIDE found NO differences between database and filesystem. Looks okay!!
ืื ืืืืื ืจืขืืืืืึทื ืืืื ืึทื ืึทืืข ืืขืงืขืก ืืื ืืืืจืขืงืืขืจืื ืืืืึทืื ืื AIDE ืืึทืืึทืืืืก.
ืืขืกืืื ื AIDE
ืืืจื ืคืขืืืงืืึทื, AIDE ืงืขื ื ืืฉื ืฉืคึผืืจ ืื ืคืขืืืงืืึทื ืึทืคึผืึทืืฉื ืืืึธืจืฆื ืืืขืืืืืึทืืขืจ /var/www/html.
ืืึธืืืจ ืงืึทื ืคืืืืขืจ AIDE ืฆื ืืขื ืขืก. ืฆื ืืึธื ืืึธืก, ืืืจ ืืึทืจืคึฟื ืฆื ืืืืฉื ืื ืืขืงืข /etc/aide.conf
.
nano /etc/aide.conf
ืืืื ืืืืื ืฉืืจื "/root/CONTENT_EX"
following:
/var/www/html/ CONTENT_EX
ืืืืึทืืขืจ, ืฉืึทืคึฟื ืึท ืืขืงืข aide.txt
ืืื ืืขื ืงืึทืืึทืืึธื /var/www/html/
ื ืืฆื ืื ืคืืืืขื ืืข ืืึทืคึฟืขื:
echo "Test AIDE" > /var/www/html/aide.txt
ืืืฆื ืืืืคื ืื AIDE ืืฉืขืง ืืื ืืึทืื ืืืืขืจ ืึทื ืื ืืืฉืืคื ืืขืงืข ืืื ืืืืขืงืืึทื.
aide --check
ืืืจ ืืึธื ืืขื ืื ืคืืืืขื ืืข:
Start timestamp: 2020-01-16 03:09:40 -0500 (AIDE 0.16)
AIDE found differences between database and filesystem!!
Summary:
Total number of entries: 49475
Added entries: 1
Removed entries: 0
Changed entries: 0
---------------------------------------------------
Added entries:
---------------------------------------------------
f++++++++++++++++: /var/www/html/aide.txt
ืืืจ ืืขื ืึทื ืื ืืืฉืืคื ืืขืงืข ืืื ืืืืขืงืืึทื aide.txt
.
ื ืึธื ืึทื ืึทืืืืืื ื ืื ืืืืขืงืืึทื ืขื ืืขืจืื ืืขื, ืืขืจืืืึทื ืืืงื ืื AIDE ืืึทืืึทืืืืก.
aide --update
ื ืึธื ืื ืืขืจืืืึทื ืืืงื ืืืจ ืืืขื ืืขื ืื ืคืืืืขื ืืข:
Start timestamp: 2020-01-16 03:10:41 -0500 (AIDE 0.16)
AIDE found differences between database and filesystem!!
New AIDE database written to /var/lib/aide/aide.db.new.gz
Summary:
Total number of entries: 49475
Added entries: 1
Removed entries: 0
Changed entries: 0
---------------------------------------------------
Added entries:
---------------------------------------------------
f++++++++++++++++: /var/www/html/aide.txt
ืืขืจ ืืืืื ืืึทืคึฟืขื ืืืขื ืฉืึทืคึฟื ืึท ื ืืึทืข ืืึทืืึทืืืืก aide.db.new.gz
ืืื ืืขื ืงืึทืืึทืืึธื
/var/lib/aide/
ืืืจ ืงืขื ืขื ืืขื ืขืก ืืื ืื ืคืืืืขื ืืข ืืึทืคึฟืขื:
ls -l /var/lib/aide/
ืืขืจ ืจืขืืืืืึทื:
total 5600
-rw------- 1 root root 2864012 Jan 16 03:09 aide.db.gz
-rw------- 1 root root 2864100 Jan 16 03:11 aide.db.new.gz
ืืืฆื ืจืขื ืึทืืข ืื ื ืืึทืข ืืึทืืึทืืืืก ืืืืืขืจ ืึทืืื ืึทื AIDE ื ืืฆื ืื ื ืืึทืข ืืึทืืึทืืืืก ืฆื ืฉืคึผืืจ ืืืืึทืืขืจ ืขื ืืขืจืื ืืขื. ืืืจ ืงืขื ืขื ืจืขื ืึทืืข ืขืก ืืื ืืืื:
mv /var/lib/aide/aide.db.new.gz /var/lib/aide/aide.db.gz
ืืืืคื ืื ืืฉืขืง ืืืืืขืจ ืฆื ืขื ืฉืืจ ืึทื AIDE ืืื ื ืืฆื ืื ื ืืึทืข ืืึทืืึทืืืืก:
aide --check
ืืืจ ืืึธื ืืขื ืื ืคืืืืขื ืืข:
Start timestamp: 2020-01-16 03:12:29 -0500 (AIDE 0.16)
AIDE found NO differences between database and filesystem. Looks okay!!
ืืืจ ืึธืืึทืืืื ืื ืืฉืขืง
ืขืก ืืื ืึท ืืืืข ืืขืืึทื ืง ืฆื ืืืืคื ืึทื AIDE ืืฉืขืง ืืขืืขืจ ืืึธื ืืื ืคึผืึธืกื ืืขื ืืึทืจืืื. ืืขื ืคึผืจืึธืฆืขืก ืงืขื ืขื ืืืื ืึธืืึทืืืืืื ืืื Cron.
nano /etc/crontab
ืฆื ืืืืคื ืื AIDE ืืฉืขืง ืืขืืขืจ ืืึธื ืืืึท 10:15, ืืืืื ืื ืคืืืืขื ืืข ืฉืืจื ืฆื ืื ืกืืฃ ืคืื ืืขืจ ืืขืงืข:
15 10 * * * root /usr/sbin/aide --check
AIDE ืืืขื ืืืฆื ืืขืื ืฆื ืืืืกื ืืืจ ืืืจื ืคึผืึธืกื. ืืืจ ืงืขื ื ืงืึธื ืืจืึธืืืจื ืืืื ืคึผืึธืกื ืืื ืื ืคืืืืขื ืืข ืืึทืคึฟืขื:
tail -f /var/mail/root
ืื AIDE ืงืืึธืฅ ืงืขื ืขื ืืืื ืืืืื ืืื ืื ืคืืืืขื ืืข ืืึทืคึฟืขื:
tail -f /var/log/aide/aide.log
ืกืึธืฃ
ืืื ืืขื ืึทืจืืืงื, ืืืจ ืืขืืขืจื ื ืืื ืฆื ื ืืฆื AIDE ืฆื ืืขืืขืงื ืืขืงืข ืขื ืืขืจืื ืืขื ืืื ืืืขื ืืืคืืฆืืจื ืึทื ืึธืืขืจืืืื ืกืขืจืืืขืจ ืึทืงืกืขืก. ืคึฟืึทืจ ื ืึธื ืกืขืืืื ืืก, ืืืจ ืงืขื ืขื ืจืขืืึทืืืจื ืื /etc/aide.conf ืงืึทื ืคืืืืขืจืืืฉืึทื ืืขืงืข. ืคึฟืึทืจ ืืืืขืจืืืื ืกืืืืช, ืขืก ืืื ืจืขืงืึทืืขื ืืื ืฆื ืงืจืึธื ืื ืืึทืืึทืืืืก ืืื ืงืึทื ืคืืืืขืจืืืฉืึทื ืืขืงืข ืืืืฃ ืืืืขื ืขื-ืืืืื ืืืืืึท. ืืขืจ ืืื ืคึฟืึธืจืืึทืฆืืข ืงืขื ืขื ืืืื ืืขืคึฟืื ืขื ืืื ืื ืืึทืงืืืืขื ืืืืฉืึทื
ืืงืืจ: www.habr.com