Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
PostPosted: Mon Mar 28, 2005 11:02 pm 
Offline
Senior Member
User avatar

Joined: Tue Jan 04, 2005 7:32 am
Posts: 277
Website: http://www.betadome.com/
Location: Ă…lesund, Norway
Skype: neonnero
Twitter: neonnero
I came across this article, which is worth a read if you want to know what to do when your Linux server is hacked:
http://security.linux.com/security/05/0 ... tml?tid=35

The article references two IDS tools, Tripwire and chkrootkit. I know for a fact that both exist in the Gentoo portage repository, and only chkrootkit of the two is available from the Debian APT repository.

Latest versions of both, as well as more detailed information about the two tools, can be found here:

http://www.chkrootkit.org/
http://www.tripwire.org/


Top
   
 Post subject: Tripwire
PostPosted: Tue Mar 29, 2005 4:36 am 
Offline
Senior Member
User avatar

Joined: Wed Mar 17, 2004 4:11 pm
Posts: 554
Website: http://www.unixtastic.com
Location: Europe
Tripwire isn't in debian because it isn't free ( as in freedom. )
If you are using debian integrit does more or less the same thing.

Mounting noexec,ro where possible is also a simple but good idea.


Top
   
 Post subject:
PostPosted: Tue Mar 29, 2005 12:20 pm 
Offline
Linode Staff
User avatar

Joined: Fri Oct 17, 2003 12:38 am
Posts: 287
Location: Dr Wierd's Lab, South Jersey Shore
sednet is correct, if one wants tripwire on Debian, you can add the non-free category and get tripwire.


Top
   
 Post subject:
PostPosted: Wed Mar 30, 2005 3:55 pm 
Offline
Senior Member
User avatar

Joined: Fri Aug 15, 2003 2:15 pm
Posts: 111
Website: http://fubegra.net/
Another useful approach is to use RIBS to back your Linode up to a local directory, and have it email its reports to you. Any file that gets modified will be picked up by rsync and listed in the report, and you will still have access to older versions.

_________________
Bus error (passengers dumped)


Top
   
 Post subject:
PostPosted: Sat Apr 02, 2005 5:24 am 
Offline
Senior Member

Joined: Sat Jun 05, 2004 12:49 am
Posts: 333
Erm, the tripwire package is in main but it's non-us not non-free since after all the package in debian *is* based off of the GPL sources :)

Package: tripwire
Priority: optional
Section: non-US
Installed-Size: 6564
<snip some stuff here>
Filename: pool/non-US/main/t/tripwire/tripwire_2.3.1.2-6.1_i386.deb


Top
   
 Post subject:
PostPosted: Sat Apr 02, 2005 12:12 pm 
Offline
Linode Staff
User avatar

Joined: Fri Oct 17, 2003 12:38 am
Posts: 287
Location: Dr Wierd's Lab, South Jersey Shore
Overlord, thanks for the corrections. I didn't bother to check beyond seeing that it was apt-getable ;)


Top
   
 Post subject:
PostPosted: Sun Apr 03, 2005 12:16 am 
Offline
Senior Member

Joined: Sat Jun 05, 2004 12:49 am
Posts: 333
it used to be in non-free untill teh tripwire ppl released a GPL version which replaced what was in debian so it was moved :)


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group