cd ../notes

TIL ·

Ask the package manager what changed on disk

Every package manager already stores checksums for the files it installed, which turns “has anything been modified since installation?” into one command instead of a filesystem-wide hunt:

bash
dpkg --verify               # Debian, Ubuntu
rpm -Va                      # Fedora, RHEL
pacman -Qkk                  # Arch

All three speak the same output dialect: a field of check results, . where a check passed and ? where it could not be performed, a letter where one failed — 5 for a digest mismatch, M for mode, S for size, T for mtime — then c if the file is a conffile.

text
??5?????? c /etc/ssh/sshd_config
S.5....T.  c /etc/php.ini

The first line is dpkg being precise about itself: it functionally checks digests and nothing else, so every other position is ?. It is also a conffile, the one file in that directory you expect to differ because somebody edited it on purpose. Skip conffiles first, and only care about T when nothing else changed. rpm compares size, mode, owner and mtime too, so rpm -V --nomtime --nosize narrows it to the digest comparison, which is usually what you want when triaging.

None of them can find files that nobody owns. rpm -Va walks the package database, so a new binary dropped in /usr/local/bin is invisible to it; dnf repocheck --unowned-files walks the filesystem instead and reports those separately. That direction of travel is the one that finds attacker-planted files.

Two limits worth stating plainly. pacman -Qkk checks against the package’s mtree file, which records size, mode and mtime but no checksum — a file patched in place with its length and timestamp restored passes. And all of these compare against the local database, so an attacker with root can rewrite a binary together with the database entry that vouches for it and none of this notices. That gap is what file-integrity monitoring with an off-host baseline belongs to: AIDE, Tripwire, or a scheduled rpm -Va whose output you ship somewhere else, alongside package signature verification. Either way, run it on a timer — the signal is the diff from yesterday, not today’s output.