LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-12-2004, 08:00 PM   #1
Tyir
Member
 
Registered: Sep 2003
Distribution: Slackware 9.1 with fluxbox
Posts: 259

Rep: Reputation: 30
Basic set up of snort and tripwire


I got ssh set up on my home computer, and in the post I made about it someone said I should install snort and something like tripwire..
I am installing snort now, and i was looking at the documentation, and it all seemed very somfusing for a security newb like me.
Does anyone know and basic guide for them, or any tips for someone who has no idea what he's doing?

Thanks
 
Old 02-16-2004, 03:47 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Does anyone know and basic guide for them, or any tips for someone who has no idea what he's doing?
Basic docs are in the tarball or at Snort.org. Basically you install the app, insert your network and interface details in the config, tweak the rulesets to comment out stuff that's either CPU intensive or services you don't run and update the rulesets regularly. Make sure you process the logs regularly to make use of Snort as an early warning system for your network/systems. If you want blocking capabilities it's possible to add third party apps that react by adding blocking rules to your fw like Guardian. If you need GUI level logcollection, sensor management and such look for stuff like ACID, Midas, Sguil SPADE or Demarc. IIRC Webmin also has a GUI for Snort. One alternative I know for Snort is Prelude, but I haven't tested that one.

Don't ask me about tripwire, I turned to Aide yrs ago as it's much easier to deploy. One alternative you might want to look at is Samhain.

More nfo about IDS'es and host integrity scanners at the LQ FAQ: Security references, post #3.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Help with my snort rule set PixelCloud Linux - Security 1 07-17-2004 01:35 PM
Installing basic snort ElementNine Linux - Security 1 10-04-2003 02:34 AM
tripwire reports /usr/sbin/tripwire changed alfaalfabeta Linux - Security 5 07-22-2003 05:52 PM
Trying to get a basic server set up in Redhat 8 joecuba Linux - Software 9 02-17-2003 04:00 PM
Need basic help to set up Mail Server RH8 melmore Linux - Networking 3 12-16-2002 06:47 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:18 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration