Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
PostPosted: Sat Nov 06, 2010 2:49 am 
Offline
Senior Newbie

Joined: Wed Nov 03, 2010 1:50 am
Posts: 12
I tried but failed to install LIDS on Debian,so I have to find a replacement.


I'm not sure,but LIDS wont be the ONLY IDS system that works on Kernel level,so Any IDS tool similar to LIDS? even better ones?

BTW,LIDS sucks,bad documents,bad support...........absofuckinglutely a nigntmare


Top
   
 Post subject:
PostPosted: Tue Nov 23, 2010 4:43 pm 
Offline

Joined: Tue Nov 23, 2010 4:34 pm
Posts: 1
The common recommended ones are:

Tripwire (Payed) - http://www.tripwire.com/
AIDE (Free) - http://aide.sourceforge.net/

However, if you're running a web server, some say it is to resource intensive. It *might* be better to have a CRON job run rkhunter (http://www.rootkit.nl/) or chkroot (http://www.chkrootkit.org/) and have the original system hashes stored on a separate system.

I asked a similar question not so long ago on server fault. Hopefully some of the tips there can help you:
http://serverfault.com/questions/202112 ... y-overkill

I am a newbie in this area as well, so hopefully someone can be more informative!

Best of luck!


Last edited by azampagl on Tue Nov 23, 2010 5:26 pm, edited 1 time in total.

Top
   
 Post subject:
PostPosted: Tue Nov 23, 2010 4:51 pm 
Offline
Senior Newbie

Joined: Wed Nov 03, 2010 1:50 am
Posts: 12
Thanks a lot+ a lot +a lot.
as far as I know, LIDS can protect the kernel but TripWire cannot.

I guess,if you use LIDS,it's impossible to install a rootkit into your system,it cannot be really hacked.
if you use TripWire instead,you can find the system has been hacked if it does,but then you also have to reinstall the OS.


am I right?


BTW,is it really necessary to disable the password authentication of SSH? the length of my root password is 40,Isn't that safe enough?


Top
   
 Post subject:
PostPosted: Tue Nov 23, 2010 8:22 pm 
Offline
Senior Member

Joined: Mon Jul 05, 2010 5:13 pm
Posts: 392
decbin wrote:
BTW,is it really necessary to disable the password authentication of SSH? the length of my root password is 40,Isn't that safe enough?


Once configured, key auth is much simpler to use. It's more portable, less dependent on your memory, and also many, many times more secure.


Top
   
 Post subject:
PostPosted: Wed Nov 24, 2010 10:06 am 
Offline
Senior Member
User avatar

Joined: Tue May 26, 2009 3:29 pm
Posts: 1691
Location: Montreal, QC
akerl wrote:
It's more portable, less dependent on your memory, and also many, many times more secure.


Let me know how I can log on from a random remote machine without carrying around a USB stick with my key on it and I'll agree that it's more portable. Until then, key-only auth is uselessly restrictive since it prevents me from logging in without carrying storage media around with me at all times.


Top
   
 Post subject:
PostPosted: Wed Nov 24, 2010 11:06 am 
Offline
Senior Member

Joined: Sun Mar 07, 2010 7:47 pm
Posts: 1970
Website: http://www.rwky.net
Location: Earth
Guspaz wrote:
akerl wrote:
It's more portable, less dependent on your memory, and also many, many times more secure.


Let me know how I can log on from a random remote machine without carrying around a USB stick with my key on it and I'll agree that it's more portable. Until then, key-only auth is uselessly restrictive since it prevents me from logging in without carrying storage media around with me at all times.


And that's why I'm grateful for lish!

_________________
Paid support
How to ask for help
1. Give details of your problem
2. Post any errors
3. Post relevant logs.
4. Don't hide details i.e. your domain, it just makes things harder
5. Be polite or you'll be eaten by a grue


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 6 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group