LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-26-2005, 10:33 AM   #1
ddaas
Member
 
Registered: Oct 2004
Location: Romania
Distribution: Ubuntu server, FreeBsd
Posts: 474

Rep: Reputation: 30
tripwire vs. aide


hi,
I have to install a new server computer and I don't know which is better Tripwire or AIDE?

I can’t say that I had nice experience with tripwire until now. I have never installed AIDE.


What do you think?
What do you prefer?


ddaas
 
Old 05-26-2005, 03:46 PM   #2
iceman47
Senior Member
 
Registered: Oct 2002
Location: Belgium
Distribution: Debian, Free/OpenBSD
Posts: 1,123

Rep: Reputation: 47
Take your pick, I'll take aide anytime.
 
Old 05-27-2005, 02:15 AM   #3
ddaas
Member
 
Registered: Oct 2004
Location: Romania
Distribution: Ubuntu server, FreeBsd
Posts: 474

Original Poster
Rep: Reputation: 30
Can you explain a little why?
 
Old 05-27-2005, 03:56 AM   #4
iceman47
Senior Member
 
Registered: Oct 2002
Location: Belgium
Distribution: Debian, Free/OpenBSD
Posts: 1,123

Rep: Reputation: 47
I've used it for years, am very happy with it and does it's job faster than tripwire.
Tripwire supports signed databases but imo it's a bad idea to leave the db on the machine itself so
my aide db's get stored on an encrypted FS on another machine so I don't need tripwire's extended feature(s).
 
Old 05-27-2005, 08:36 AM   #5
TruckStuff
Member
 
Registered: Apr 2002
Posts: 498

Rep: Reputation: 30
I'll vote for tripwire for almost the exact same reasons. Its easy to use once you get the hang of it. Its very secure compared to aide (encrypted DB, etc.). Plus I couldn't get aide to install the last time I was setting up a server. Let me rephrase: I couldn't get aide working. It installed then segfaulted everytime I tried to run it.
 
Old 06-01-2005, 01:58 PM   #6
Atrocity
Member
 
Registered: Nov 2002
Location: Hell
Distribution: FreeBSD, Slackware
Posts: 308

Rep: Reputation: 30
I am am also interested in using one of these tools on a hony pot I am building so any info suggestions or tutorial links would be helpfull
 
Old 06-01-2005, 05:44 PM   #7
Ephracis
Senior Member
 
Registered: Sep 2004
Location: Sweden
Distribution: Ubuntu, Debian
Posts: 1,109

Rep: Reputation: 50
I first tried tripwire but as for TruckStuff (he could not get aide working), I could not get tripwire working. I would not even install, it broke at compile time and then I tried aide and it worked out fine. It is easy to set up and I am not sure if I will try tripwire anytime soon, since I have not seen any problems with aide yet.
 
Old 06-02-2005, 03:02 AM   #8
ddaas
Member
 
Registered: Oct 2004
Location: Romania
Distribution: Ubuntu server, FreeBsd
Posts: 474

Original Poster
Rep: Reputation: 30
I have installed aide very easy and works just fine. Making Tripwire working took me a long time and a lot of nerves.
The configuration of tripwire is more difficult as the config of aide and not so clear.
The only advantage of tripwire is that it encrypts its database and config file.
I can do it by myself with gpg and a script with less that 5 lines and I get aide encrypted. Or I could take it offside/ro media.

So I vote for aide.
 
Old 06-02-2005, 09:23 AM   #9
TruckStuff
Member
 
Registered: Apr 2002
Posts: 498

Rep: Reputation: 30
Quote:
Originally posted by Ephracis
I first tried tripwire but as for TruckStuff (he could not get aide working), I could not get tripwire working. I would not even install, it broke at compile time and then I tried aide and it worked out fine.
Did you use the tripwire source from tripwire.org? That package hasn't been maintained very well and it breaks an almost every modern system. Paul Herman has taken up the tripwire source and adapted it to modern *nix systems. The package is called tripwire-portable and can be found here.
 
Old 06-02-2005, 10:07 AM   #10
Ephracis
Senior Member
 
Registered: Sep 2004
Location: Sweden
Distribution: Ubuntu, Debian
Posts: 1,109

Rep: Reputation: 50
Thanks TruckStuff, I will check on that later. I do not know but guess it was from tripwire.org, I get almost all of my packages from freshmeat.net. :P
 
Old 06-02-2005, 01:31 PM   #11
Atrocity
Member
 
Registered: Nov 2002
Location: Hell
Distribution: FreeBSD, Slackware
Posts: 308

Rep: Reputation: 30
So I am guessing that aide is a better solution ?
 
Old 06-02-2005, 02:22 PM   #12
Ephracis
Senior Member
 
Registered: Sep 2004
Location: Sweden
Distribution: Ubuntu, Debian
Posts: 1,109

Rep: Reputation: 50
Actually, this is like with distros: you can only know if you test them yourself.
 
Old 06-03-2005, 11:43 AM   #13
Atrocity
Member
 
Registered: Nov 2002
Location: Hell
Distribution: FreeBSD, Slackware
Posts: 308

Rep: Reputation: 30
HaHa sounds good, I will give that a try
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
how to configure Aide? moonloader Linux - Software 5 08-18-2004 07:24 PM
How to burn AIDE to a CD? Jiggy Linux - Software 5 11-23-2003 01:21 AM
aide conf f1uke Linux - Security 1 07-29-2003 07:38 PM
tripwire reports /usr/sbin/tripwire changed alfaalfabeta Linux - Security 5 07-22-2003 05:52 PM
aide cuckoopint Linux - Security 3 04-22-2003 02:50 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:34 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration