Integrity protection A.I.D.E

Hello,

following question:

It is possible to create a package with A.I.D.E.:slight_smile:

AIDE (Advanced Intrusion Detection Environment), developed in C, monitors program and configuration files for changes. It calculates their checksum using six different hash methods (to prevent collisions) and detects changes to timestamps, permissions, and ownership. AIDE also recognizes if files have been added or removed.

Best christmas wishes. :slight_smile:

keep in mind there's no guarantee your router's clock is in sync with the rest of the world.

Huh? Are you using OpenWrt?

Please connect to your OpenWrt device using ssh and copy the output of the following commands and post it here using the "Preformatted text </> " button (red circle; this works best in the 'Markdown' composer view in the blue oval):

Screenshot 2025-10-20 at 8.14.14 PM

Remember to redact passwords, VPN keys, MAC addresses and any public IP addresses you may have:

ubus call system board

From v25 (and snaphost for a while) you have apk audit to track checksums.

To be frank, either a hash is good enough (and in practice, even just md5 would do) - or not. Raising this as an advantage puts the rest of the claims into quite some doubt and makes it more sound like snakeoil than anything else. (And yes, there'd be a lot to be said about "monitors program and configuration files for changes" as well, because if I can change those, I can just as well replace AIDE with a 2-line script mimicking AIDE's output to claim that everything is fine).

3 Likes

Hold on, look here:

It seems that in 26 years of intensive development, it reached the heady heights of version 0.19.2 in 2025.
Fast work /s :man_tipping_hand:

Wen v1? :nerd_face:

Seriously though @icehunter Do have a Happy Christmas :santa_claus: