Linux - SecurityThis forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.
Notices
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
Sorry for asking these newbie questions. I have configured a firewall on Mandrake 9.1 (guarddog at the moment will change for smoothwall when the 9.2 is released or iptables if I have the time to study the howtos) which seems to work fine. But I want to know if its working so I think an intrusion detection system would be appropriate. The question is which one. I've heard about several such as portsentry, lids, grsecurity and snort. But which one would be easy and still do the job. I just want to see what's up; if anyone is port scanning and if so does the firewall work.
Snort www.snort.org is a great host/network instrusion detection system.
You also might want to look at AIDE, an alternative to Tripwire. This is a host based content integrity system. Lets you know if you important files have been modified or replaced by trojans.
No. IMNSHO you need network intrusion detection system (Snort) *and* a filesystem integrity checker (Aide, Samhain, tripwire) to cover it. The "problem" is a filesystem integrity checker should best be installed after installing the OS, and before connecting it to a network to have some guarantee wrt the state of the system.
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.