Re: Been hacked

From: Newsbox (newsbox_at_customers-of-adelphia.org)
Date: 11/15/03

  • Next message: /dev/rob0: "Re: Been hacked"
    Date: Fri, 14 Nov 2003 18:00:25 -0500
    
    

    On Fri, 14 Nov 2003 14:35:47 -0500, jim_patterson wrote:

    > On Fri, 14 Nov 2003 18:30:28 +0000, Dale Dellutri wrote:
    >
    >> On Fri, 14 Nov 2003 16:27:46 GMT, Jim Patterson
    >> <jim_patterson@comcast.net> wrote:
    >>>...
    >>> Is there a program out there that will monitor a system and indicate
    >>> immediately if someone is modifying files? Low cost?
    >>
    >> Tripwire. It's free, included with RedHat 9 (probably others).
    >>
    >> Don't know if you can set it for immediate notification, but certainly
    >> daily, and probably more often if set up correctly.
    > tripwire is the monitoring program that was removed. on a RH9 system. So
    > i'm looking for something that will alert me immediately to what is
    > going on.
     
    snort

    But snort does not monitor your filesystem, it monitors your network
    traffic. However, snort is real-time, wheras tripwire is scheduled. If
    you want tripwire, you can get it online. Look around.

    And if your system is hacked, disconnect it from the network !!


  • Next message: /dev/rob0: "Re: Been hacked"

    Relevant Pages

    • Re: Info HIDS
      ... Snort will provide the kind of monitoring you are asking about. ... be configured to monitor an entire network, and output logs in tcp dump, ... >configure an HIDS (tripwire) to get intrusion's information about a Web ...
      (Security-Basics)
    • Re: Linux/*nix open source IDS
      ... Snort is my personal favorite. ... AFAIK Tripwire is more a "System File ... IDS" which creates a hash of files and compares to check for differences. ... sort of critiques they have received. ...
      (Focus-IDS)
    • Re: Detecting File Alteration
      ... monitoring within an Active Directory environment. ... > Tripwire is awfully expensive for a small company... ... EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE ... The NSA has designated Norwich University a center of Academic Excellence ...
      (Security-Basics)
    • Re: snort or tripwire, which is best?
      ... > For a relative novice using Mandriva linux, which would be better, snort ... for me to install and configure on my system? ... your network interface while tripwire scans your filesystems. ...
      (comp.os.linux.security)
    • Re: snort or tripwire, which is best?
      ... >> your network interface while tripwire scans your filesystems. ... > So snort will not log or notify me if a system file is ... intruder has a chance to alter that system file. ...
      (comp.os.linux.security)