Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
anti hacker tools like tripwire
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
Ozymandias
Tux's lil' helper
Tux's lil' helper


Joined: 10 Apr 2002
Posts: 81
Location: Netherlands

PostPosted: Fri Jul 05, 2002 12:05 am    Post subject: anti hacker tools like tripwire Reply with quote

Hi there,

I run a gentoo server, but would like to have something like tripwire and a log reporter. What should I use?

greetz Ozy
Back to top
View user's profile Send private message
delta407
Bodhisattva
Bodhisattva


Joined: 23 Apr 2002
Posts: 2876
Location: Chicago, IL

PostPosted: Fri Jul 05, 2002 12:08 am    Post subject: Reply with quote

Why not use tripwire?
_________________
I don't believe in witty sigs.
Back to top
View user's profile Send private message
Nitro
Bodhisattva
Bodhisattva


Joined: 08 Apr 2002
Posts: 661
Location: San Francisco

PostPosted: Fri Jul 05, 2002 12:19 am    Post subject: Reply with quote

Try running snort + ACID. Snort is an IDS (intrustion detection system) and ACID shows the snort logs in a readable form. :)

Snort: http://www.snort.org/
ACID: http://acidlab.sourceforge.net/

It isn't just an install and be done. You have to read the results, and edit the rules. If I say '/bin/bash' (whoops I just said it huh?) snort will log that it is a WEB-MISC bash expoit. Oh well, if someone hammers the heck outta your server you will see that too. :)
_________________
- Kyle Manna

Please, please SEARCH before posting.

There are three kinds of people in the world: those who can count, and those who can't.
Back to top
View user's profile Send private message
Ozymandias
Tux's lil' helper
Tux's lil' helper


Joined: 10 Apr 2002
Posts: 81
Location: Netherlands

PostPosted: Fri Jul 05, 2002 12:50 am    Post subject: Reply with quote

I looked into snort a while ago, it looks a bit extensive for my use, but maybe I'll give it a try.

greetz ozy
Back to top
View user's profile Send private message
elcesar
n00b
n00b


Joined: 11 Jul 2002
Posts: 16

PostPosted: Tue Jul 16, 2002 6:43 am    Post subject: Re: anti hacker tools like tripwire Reply with quote

Ozymandias wrote:
Hi there,

I run a gentoo server, but would like to have something like tripwire and a log reporter. What should I use?

greetz Ozy



As a log reporter y suggest you to use "metalog" replacing your old syslog. It's regular expresion search through the log files will do what you want.
Back to top
View user's profile Send private message
Xor
Tux's lil' helper
Tux's lil' helper


Joined: 07 Jul 2002
Posts: 144

PostPosted: Tue Jul 16, 2002 9:39 am    Post subject: Reply with quote

[quote="delta407"]Why not use tripwire?[/quote]

seems tripwire is finally gpl :)... anyway... aide is also quite good :)
Back to top
View user's profile Send private message
Chris W
l33t
l33t


Joined: 25 Jun 2002
Posts: 972
Location: Brisbane, Australia

PostPosted: Tue Jul 16, 2002 10:26 am    Post subject: Reply with quote

For a not-quite-GPL option you could also look at PureSecure from Demarc.

It requires registration to download and is free (beer) for home use. Makes use of MySql, Apache, perl and snort, and produces pretty WWW pages from them.
_________________
Cheers,
Chris W
"Common sense: The collection of prejudices acquired by age 18." -- Einstein
Back to top
View user's profile Send private message
argent
n00b
n00b


Joined: 15 Aug 2002
Posts: 1
Location: Akron, Ohio

PostPosted: Thu Aug 15, 2002 1:30 am    Post subject: Reply with quote

Well, on the subject of IDS's....
There are two kinds, Network IDS (or NIDS) like snort, etc. And there are Host IDS (or HIDS) like Tripwire.

NIDS are good for logging hack attempts against your network, like syn-attacks, or Code Red attacks. But they won't tell you if your host has been compromised.

HIDS are good to tell if any files have been modified on your system, which *could* tell you if your system may have been hacked. But they won't tell you if anyone's trying to get in.

So, you need to figure out what you want to watch for, and choose accordingly.

argent
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum