Red Hat LINUX 7.2 - OFFICIAL LINUX CUSTOMIZATION GUIDE Guida di Installazione Pagina 154

  • Scaricare
  • Aggiungi ai miei manuali
  • Stampa
  • Pagina
    / 282
  • Indice
  • SEGNALIBRI
  • Valutato. / 5. Basato su recensioni clienti
Vedere la pagina 153
154 Chapter 12. Installing and Configuring Tripwire
12.9.1. Using twprint to View the Tripwire Database
You can also use twprint to view the entire database or information about selected files in the
Tripwire database. This is useful for seeing just how much information Tripwire is tracking on your
system.
To view the entire Tripwire database, type this command:
/usr/sbin/twprint -m d --print-dbfile | less
This command will generate a large amount of output, with the first few lines appearing similar to
this:
Tripwire(R) 2.3.0 Database
Database generated by: root
Database generated on: Tue Jan 9 13:56:42 2001
Database last updated on: Tue Jan 9 16:19:34 2001
=================================================================
Database Summary:
=================================================================
Host name: some.host.com
Host IP address: 10.0.0.1
Host ID: None
Policy file used: /etc/tripwire/tw.pol
Configuration file used: /etc/tripwire/tw.cfg
Database file used: /var/lib/tripwire/some.host.com.twd
Command line used: /usr/sbin/tripwire --init
=================================================================
Object Summary:
=================================================================
-----------------------------------------------------------------
# Section: Unix File System
-----------------------------------------------------------------
Mode UID Size Modify Time
------ ---------- ---------- ----------
/
drwxr-xr-x root (0) XXX XXXXXXXXXXXXXXXXX
/bin
drwxr-xr-x root (0) 4096 Mon Jan 8 08:20:45 2001
/bin/arch
-rwxr-xr-x root (0) 2844 Tue Dec 12 05:51:35 2000
/bin/ash
-rwxr-xr-x root (0) 64860 Thu Dec 7 22:35:05 2000
/bin/ash.static
-rwxr-xr-x root (0) 405576 Thu Dec 7 22:35:05 2000
To see information about a particular file that Tripwire is tracking, such as /etc/hosts, type a
different twprint command:
/usr/sbin/twprint -m d --print-dbfile /etc/hosts
The result will look similar to this:
Object name: /etc/hosts
Property: Value:
Vedere la pagina 153
1 2 ... 149 150 151 152 153 154 155 156 157 158 159 ... 281 282

Commenti su questo manuale

Nessun commento