|
@@ -8045,6 +8045,12 @@ function intrusion_detection {
|
8045
|
8045
|
sed -i 's|/proc.*||g' /etc/tripwire/twpol.txt
|
8046
|
8046
|
# Don't report log changes
|
8047
|
8047
|
sed -i 's|/var/log.*||g' /etc/tripwire/twpol.txt
|
|
8048
|
+ # Ignore /etc/tripwire
|
|
8049
|
+ if ! grep -q "!/etc/tripwire" /etc/tripwire/twpol.txt; then
|
|
8050
|
+ sed -i '\|/etc\t\t->.*|a\ !/etc/tripwire;' /etc/tripwire/twpol.txt
|
|
8051
|
+ fi
|
|
8052
|
+ # Avoid logging the changed database
|
|
8053
|
+ sed -i 's|$(TWETC)/tw.pol.*||g' /etc/tripwire/twpol.txt
|
8048
|
8054
|
reset-tripwire
|
8049
|
8055
|
|
8050
|
8056
|
echo 'intrusion_detection' >> $COMPLETION_FILE
|