The script lived above the web root, so they'd have to escape that to tamper with it, and was generated by another script.
Saved me a couple of times since, well worth the 15 minutes I spent on setting it up.
The script lived above the web root, so they'd have to escape that to tamper with it, and was generated by another script.
Saved me a couple of times since, well worth the 15 minutes I spent on setting it up.
As I recall, they recommended putting the expected values on a floppy disk and setting the ‘write protect’ tab, so the checksums couldn’t be changed.
The alternative (tho not practical in many cases) would be RO media like RW-DVD.
If tinkering with OSSEC one of the first steps should be to configure whitelisting for IP ranges and CIDR blocks used by your company, SNAT addresses and bastion IP's so that someone does not lock everyone out. It does a lot more than checksums.
[1] - https://www.ossec.net/
Though yes, two USB ports would definitely work; it's just that the concept might be better served by providing two different connectors (e.g. USB-A & USB-C), as is common nowadays.
Had some drawbacks compared to using offline media of course, but in day to day operation on an air-gapped network it had its uses.
Also worth knowing is the "-V" (for very parameter) of rpm.
[1] https://docs.redhat.com/en/documentation/red_hat_enterprise_...
Wait, how often does your Wordpress site get successfully hacked like that?
One time the hosting provider got compromised, FTP server exploit IIRC, they ran a recursive search and replace from root directory of the server.
Back around 2010, there were security vulnerabilities in WordPress or its popular plugins almost every month.