LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-18-2002, 02:34 PM   #1
Stormproof
LQ Newbie
 
Registered: Aug 2002
Location: Slackware, KS
Distribution: Slackware
Posts: 12

Rep: Reputation: 0
Intrusion Detection System (ids)


Does any one know of an easy to install IDS for linux that has a GUI?

If any of you guys need help setting up a linux firewall with a cable modem,

let me know!
I have built tons of them for people and showed them how!
 
Old 08-18-2002, 04:15 PM   #2
turnip
Member
 
Registered: Jul 2002
Posts: 143

Rep: Reputation: 15
Snort+acid is very very nice. Also, snort can log to a postgre or mysql database. You can then write some php to pull all the data from the db and display it on a page.

I actually already have some php scripts written for them. if you are interested....

Then their is http://www.demarc.com

Demarc is really nice, and cake to install, you just need a machine w/o a web+sql server because the default install drops them in for you. It's not free for commercial use though..
 
Old 08-18-2002, 04:54 PM   #3
Stormproof
LQ Newbie
 
Registered: Aug 2002
Location: Slackware, KS
Distribution: Slackware
Posts: 12

Original Poster
Rep: Reputation: 0
Thanks for all of your help. I will go download them now.
 
Old 08-19-2002, 07:40 PM   #4
Stormproof
LQ Newbie
 
Registered: Aug 2002
Location: Slackware, KS
Distribution: Slackware
Posts: 12

Original Poster
Rep: Reputation: 0
Is Big Brother anygood !!
 
Old 08-19-2002, 08:01 PM   #5
jeremy
root
 
Registered: Jun 2000
Distribution: Debian, Red Hat, Slackware, Fedora, Ubuntu
Posts: 13,602

Rep: Reputation: 4084Reputation: 4084Reputation: 4084Reputation: 4084Reputation: 4084Reputation: 4084Reputation: 4084Reputation: 4084Reputation: 4084Reputation: 4084Reputation: 4084
If you are talking about the BB that can be found at http://www.bb4.com then yes it is very good. It's not an IDS though, it's a network monitoring system.

--jeremy
 
Old 08-20-2002, 09:14 PM   #6
neo77777
LQ Addict
 
Registered: Dec 2001
Location: Brooklyn, NY
Distribution: *NIX
Posts: 3,704

Rep: Reputation: 56
turnip thanks for the link to demarc's puresecure, it works great. I was setup in less than 20 mins.
Regards, neo

Last edited by neo77777; 08-20-2002 at 09:22 PM.
 
Old 08-21-2002, 05:35 PM   #7
marvc
Member
 
Registered: Aug 2002
Location: GA
Posts: 59

Rep: Reputation: 15
To piggyback on this discussion. I'm looking for the same solution for my home network that consists of a w2k server and linux server ver7.3 also w/dsl. I attempted to install the win version of puresecure on my w2k web server running apache/mysql & php. the install went good until I went to start the service. Afterwards it gave me the following:
PureSecure Installation and Setup complete.
You will need to map the following virtual paths to their installation paths in your IIS webserver before you can login to the PureSecure Console:
/Demarc -> c:\PureSecure\console\cgi
/dm_images -> c:\PureSecure\console\images

/Demarc should have "Scripts and Exectubales" enabled, but *no* "Read" permission.
/dm_images should have "Read" permissions, but no "Execute" permissions.

The first problem is that I'm running Apache instead of IIS, and all of those services are stopped. So I'm assuming I'll need to modify the httpd.conf file, but I'm not how to.

Can anyone assist with this? Since I wasn't using the linux server as a web server I wasn't sure about installing it there. So I placed it on my web server, which just happens to be w2k. Anyone know if running this on a standalone linux server that won't be running as a web server will be a problem?

Any response is appreciated...
 
Old 08-22-2002, 08:48 AM   #8
neo77777
LQ Addict
 
Registered: Dec 2001
Location: Brooklyn, NY
Distribution: *NIX
Posts: 3,704

Rep: Reputation: 56
Sorry mate, can't help you on this one, I installed puresecure on linux side, I did what I was told to do - removed my current apache (backed up everything of course), removed MySQL ( I didn't even used that before, it was there for "later" use), ran ./configure script for PureSecire, it installed everything, upgraded openssl - it tends to install openssl version which is a little bit outdated, and now I have a fully functional (almost) IDS, gotta work some rules for snort though - whenever I go on the net and fire up my browser to surf the net I am getting a port scan alert in my logs telling me that my IP has port scanned whoever I point my browser to, LQ, etc.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
intrusion detection system aparna Linux - General 4 01-02-2006 09:30 AM
intrusion detection system aparna Linux - General 2 12-31-2005 01:03 AM
Intrusion Detection System On Linux AmitC Linux - Networking 1 10-19-2004 03:34 AM
Network Intrusion Detection System WarlockofVirgo Linux - Security 1 08-08-2004 10:36 PM
Network Intrusion Detection System SaTaN Programming 6 11-26-2003 11:22 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:37 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration