Hi,
how about a pidfile attribute that makes a file get reported if it contains more than one line of digits only? That way we could protect pidfiles.
A more generalistic approach would be a function of aide that compares every line of a (potentially compressed) file with a given regexp, that way we could validate /etc/passwd and log files. A maximum size could also be nice.
Greetings
marc
Hi,
how about a pidfile attribute that makes a file get reported if it contains more than one line of digits only? That way we could protect pidfiles.
A more generalistic approach would be a function of aide that compares every line of a (potentially compressed) file with a given regexp, that way we could validate /etc/passwd and log files. A maximum size could also be nice.
Greetings
marc