LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-01-2015, 06:25 AM   #1
pompado
LQ Newbie
 
Registered: Sep 2008
Posts: 12

Rep: Reputation: 0
Complete & Simple Guide to install Tripwire!


Hello - i install this on Ubuntu and think this guide also work with Debian.
The guide explain how to install and configurate Tripwire on your system.
And also explain how to save the Tripwire database on removable media.

I can not programming but succed to install Tripwire - so can you even if you don't have coding skills :-)

TRIPWIRE

Tripwire is a "intrusion detection system" ... this means that Tripwire don't prevent an intrusion, but it will notice if it has happen.
It works like this; Tripwire sign each file with a specific algorithm or key number on your operating system and save all the information on a database.
So if some one change of modifie any file, then Tripwire will notice this change, so no one can break into your computer without you being aware of that.

So each file gets a uniq id and if some one hack into your system Tripwire will notice the change with some critical files being modified.
The great thing with this guide is that in the end i will explain how you install the Tripwire database on removable media.
This means that if you get an intrusion - so cant they modifie or hack your Tripwire - it is safe and secure.

THE FIRST PART OF THE INSTALLATION


First you need to have a new installation from scratch, so you know that your operating system has not been temporized with.
Now you can connect to internet and install Tripwire.

Code:
sudo apt-get update
Code:
sudo apt-get install tripwire
Now when you run Tripwire installation it will ask you at the beginning to configuration email option.
Then you should pick "internetsystem" ...

http://i59.tinypic.com/2vazcix.jpg

After that it will ask you to add what kind of email you use.
Like hotmail.com or gmail.com

http://i58.tinypic.com/x3cm0j.png

After this Tripwire will ask you if you want to install two secure keys.
The site key and the local key.

You should answer yes and continue doing so true the hole installation process.
It is a good idea if you have prepared your self with two good key phrases.
Two good passwords.
 
Old 06-01-2015, 05:45 PM   #2
ButterflyMelissa
Senior Member
 
Registered: Nov 2007
Location: Somewhere on my hard drive...
Distribution: Manjaro
Posts: 2,766
Blog Entries: 23

Rep: Reputation: 411Reputation: 411Reputation: 411Reputation: 411Reputation: 411
hey, thanks for this info
all security tips are welcome
 
Old 06-02-2015, 06:08 AM   #3
displace
Member
 
Registered: Jan 2013
Location: EU
Distribution: Debian
Posts: 268

Rep: Reputation: 25
Is Tripwire still a thing today? I hear many people recommend AIDE over Tripwire.

~dis
 
Old 06-06-2015, 05:20 AM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by displace View Post
Is Tripwire still a thing today?
Well maybe if my concerns posted here (first paragraph) no longer apply?.. (Not holding my breath.)


Quote:
Originally Posted by displace View Post
I hear many people recommend AIDE over Tripwire.
AIDE or Samhain, and always as part of an appropriate set of measures.
 
1 members found this post helpful.
Old 06-08-2015, 09:10 AM   #5
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
The whole shebang is at http://ubuntuforums.org/showthread.php?t=2235300
 
Old 06-11-2015, 12:18 AM   #6
displace
Member
 
Registered: Jan 2013
Location: EU
Distribution: Debian
Posts: 268

Rep: Reputation: 25
Quote:
Originally Posted by unSpawn View Post
AIDE or Samhain, and always as part of an appropriate set of measures.
I haven't heard about Samhain before. How does it compare to AIDE?

On a side note, do you perhaps know, if any of these tools are also capable of monitoring custom disk sectors i.e. the first 2048 sectors of the HDD where the boot loader is located? How about the contents of the bios chip? I normally do this by hand and I'm looking for a way to automate it.

~dis
 
Old 06-11-2015, 07:51 PM   #7
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by displace View Post
I haven't heard about Samhain before. How does it compare to AIDE?
- Daemon vs cron jobbed task,
- Can use inotify,
- Can be centrally managed (server - client paradigm),
- Can encrypt config,
- Can obfuscate own process argv[0],
- much, much more: please check documentation.


Quote:
Originally Posted by displace View Post
On a side note, do you perhaps know, if any of these tools are also capable of monitoring custom disk sectors (..) How about the contents of the bios chip?
None do.
 
Old 01-23-2016, 03:44 AM   #8
pompado
LQ Newbie
 
Registered: Sep 2008
Posts: 12

Original Poster
Rep: Reputation: 0
Quote:
Originally Posted by Habitual View Post
Hello i was going to post the hole howto - but something got wrong with forum text input - thanks for sharing the link to my Tripwire Howto.
What i like is that you can install the Tripwire database on removable media.

Cheers
 
Old 01-23-2016, 04:23 AM   #9
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by pompado View Post
Hello i was going to post the hole howto - but something got wrong with forum text input
If you want to you can submit your article and we'll post it in the HOWTO section.
 
Old 01-23-2016, 10:01 AM   #10
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Quote:
Originally Posted by pompado View Post
Hello i was going to post the hole howto - but something got wrong with forum text input - thanks for sharing the link to my Tripwire Howto.
What i like is that you can install the Tripwire database on removable media.

Cheers
Good Stuff, Maynard.
I have it bookmarked and I tend to keep those for years.
 
Old 01-24-2016, 02:49 AM   #11
pompado
LQ Newbie
 
Registered: Sep 2008
Posts: 12

Original Poster
Rep: Reputation: 0
Hello, i would like to add two HOWTO in the HOWTO section, but i can not find the HOWTO section?
I would like to add Logwatch & Tripwire.

Cheers
 
Old 01-24-2016, 03:47 PM   #12
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Right side menu: Write for LQ: LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
 
Old 01-25-2016, 09:54 PM   #13
JockVSJock
Senior Member
 
Registered: Jan 2004
Posts: 1,420
Blog Entries: 4

Rep: Reputation: 164Reputation: 164
I thought Tripwire was commercial software only.

Didn't realize there is an open source version: http://sourceforge.net/projects/tripwire/
 
Old 01-26-2016, 12:44 AM   #14
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
...that has been left completely unmaintained for the past 5 years.
 
Old 01-26-2016, 05:51 AM   #15
JockVSJock
Senior Member
 
Registered: Jan 2004
Posts: 1,420
Blog Entries: 4

Rep: Reputation: 164Reputation: 164
Quote:
Originally Posted by unSpawn View Post
...that has been left completely unmaintained for the past 5 years.
Exactly!

OP failed to note that in the original post and the documentation that he/she linked too. Why even post this?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Wanted: simple driver install guide Blasphemous Linux - Newbie 2 02-24-2012 10:34 AM
LXer: How-To: Install Latest Firefox in Ubuntu - Complete Guide LXer Syndicated Linux News 0 07-16-2009 09:00 AM
LXer: Complete Aspire One Install Guide for Ubuntu Netbook Remix in English LXer Syndicated Linux News 0 05-03-2009 12:10 PM
tripwire (simple and effective) ridertech Linux - Security 1 02-12-2004 01:06 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:21 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration