--- aide.conf~ 2007-07-23 10:35:11.000000000 -0600 +++ aide.conf 2007-07-22 12:45:26.000000000 -0600 @@ -1,7 +1,7 @@ # AIDE conf -database=file:/var/lib/aide/aide.db -database_out=file:/var/lib/aide/aide.db.new +database=file:/floppy/aide.db +database_out=file:/root/aide/aide.db.new # Change this to "no" or remove it to not gzip output # (only useful on systems with few CPU cycles to spare) @@ -35,10 +35,10 @@ # Defines formerly set here have been moved to /etc/default/aide. # Custom rules -Binlib = p+i+n+u+g+s+b+m+c+md5+sha1 +Binlib = p+i+n+u+g+s+b+md5+sha1 ConfFiles = p+i+n+u+g+s+b+m+c+md5+sha1 Logs = p+i+n+u+g+S -Devices = p+i+n+u+g+s+b+c+md5+sha1 +Devices = p+n+u+g+s+b+md5+sha1 Databases = p+n+u+g StaticDir = p+i+n+u+g ManPages = p+i+n+u+g+s+b+m+c+md5+sha1 @@ -46,7 +46,8 @@ # Next decide what directories/files you want in the database # Kernel, system map, etc. -=/boot$ Binlib +/boot Binlib +!/boot/grub/default # Binaries /bin Binlib /sbin Binlib @@ -55,18 +56,20 @@ /usr/local/bin Binlib /usr/local/sbin Binlib /usr/games Binlib +/opt Binlib # Libraries /lib Binlib +!/lib/init/rw /usr/lib Binlib /usr/local/lib Binlib # Log files -=/var/log$ StaticDir -!/var/log/ksymoops -/var/log/aide/aide.log(.[0-9])?(.gz)? Databases -/var/log/aide/error.log(.[0-9])?(.gz)? Databases -/var/log/setuid.changes(.[0-9])?(.gz)? Databases -!/var/log/aide -/var/log Logs +#=/var/log$ StaticDir +#!/var/log/ksymoops +#/var/log/aide/aide.log(.[0-9])?(.gz)? Databases +#/var/log/aide/error.log(.[0-9])?(.gz)? Databases +#/var/log/setuid.changes(.[0-9])?(.gz)? Databases +#!/var/log/aide +#/var/log Logs # Devices !/dev/pts # If you get spurious warnings about being unable to mmap() /dev/cpu/mtrr, @@ -93,10 +96,16 @@ #/var/spool/anacron/cron.weekly Databases #/var/spool/cron Databases #/var/spool/cron/crontabs Databases +/etc/cron.d Databases +/etc/cron.daily Databases +/etc/cron.hourly Databases +/etc/cron.monthly Databases +/etc/cron.weekly Databases +/etc/crontab Databases # manpages can be trojaned, especially depending on *roff implementation #/usr/man ManPages -#/usr/share/man ManPages +/usr/share/man ManPages #/usr/local/man ManPages # docs @@ -111,5 +120,5 @@ #/usr/local/src L # Check headers for same -#/usr/include L -#/usr/local/include L +/usr/include L +/usr/local/include L