<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Open Source Tripwire now available on HPUX Internet Express 7.0 in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/open-source-tripwire-now-available-on-hpux-internet-express-7-0/m-p/3819023#M739338</link>
    <description>That is great - that means I don't have to buy anymore licenses for the commercial version. &lt;BR /&gt;&lt;BR /&gt;Question thogh - what is different between the commercial and open source one?&lt;BR /&gt;&lt;BR /&gt;Rgds...Geoff</description>
    <pubDate>Fri, 10 Nov 2006 13:30:04 GMT</pubDate>
    <dc:creator>Geoff Wild</dc:creator>
    <dc:date>2006-11-10T13:30:04Z</dc:date>
    <item>
      <title>Open Source Tripwire now available on HPUX Internet Express 7.0</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/open-source-tripwire-now-available-on-hpux-internet-express-7-0/m-p/3819017#M739332</link>
      <description>&lt;!--!*#--&gt;Read Before Installing (RBI)&lt;BR /&gt;&lt;A href="http://docs.hp.com/en/internet.html#Internet%20Express" target="_blank"&gt;http://docs.hp.com/en/internet.html#Internet%20Express&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;11iv &lt;BR /&gt;&lt;A href="http://h20293.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=HPUXIEXP1111" target="_blank"&gt;http://h20293.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=HPUXIEXP1111&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;11iv2&lt;BR /&gt;&lt;A href="http://h20293.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=HPUXIEXP1123" target="_blank"&gt;http://h20293.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=HPUXIEXP1123&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;The RBI mentions you must install PHSS_28871 in order for tripwire to work.&lt;BR /&gt;&lt;BR /&gt;We would like to gauge customer demand for an HP fully supported file integrity checker.</description>
      <pubDate>Thu, 06 Jul 2006 14:43:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/open-source-tripwire-now-available-on-hpux-internet-express-7-0/m-p/3819017#M739332</guid>
      <dc:creator>Pierre Pasturel</dc:creator>
      <dc:date>2006-07-06T14:43:03Z</dc:date>
    </item>
    <item>
      <title>Re: Open Source Tripwire now available on HPUX Internet Express 7.0</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/open-source-tripwire-now-available-on-hpux-internet-express-7-0/m-p/3819018#M739333</link>
      <description>Pierre,&lt;BR /&gt;&lt;BR /&gt;If I had anything to say about it, I'd put in every machine. It is a great tool.&lt;BR /&gt;&lt;BR /&gt;Customer demand will be high. Lots of people try to get it to work.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Thu, 06 Jul 2006 15:54:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/open-source-tripwire-now-available-on-hpux-internet-express-7-0/m-p/3819018#M739333</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2006-07-06T15:54:24Z</dc:date>
    </item>
    <item>
      <title>Re: Open Source Tripwire now available on HPUX Internet Express 7.0</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/open-source-tripwire-now-available-on-hpux-internet-express-7-0/m-p/3819019#M739334</link>
      <description>Lots of questions in these forums about how to do something like tripwire.&lt;BR /&gt;&lt;BR /&gt;A very worthwhile tool!&lt;BR /&gt;&lt;BR /&gt;Everybody, this is a "gotta have it" utility.</description>
      <pubDate>Thu, 06 Jul 2006 16:10:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/open-source-tripwire-now-available-on-hpux-internet-express-7-0/m-p/3819019#M739334</guid>
      <dc:creator>Rick Garland</dc:creator>
      <dc:date>2006-07-06T16:10:54Z</dc:date>
    </item>
    <item>
      <title>Re: Open Source Tripwire now available on HPUX Internet Express 7.0</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/open-source-tripwire-now-available-on-hpux-internet-express-7-0/m-p/3819020#M739335</link>
      <description>Excellent! This will save me the trouble of having to do the builds from source.</description>
      <pubDate>Thu, 06 Jul 2006 17:13:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/open-source-tripwire-now-available-on-hpux-internet-express-7-0/m-p/3819020#M739335</guid>
      <dc:creator>A. Clay Stephenson</dc:creator>
      <dc:date>2006-07-06T17:13:08Z</dc:date>
    </item>
    <item>
      <title>Re: Open Source Tripwire now available on HPUX Internet Express 7.0</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/open-source-tripwire-now-available-on-hpux-internet-express-7-0/m-p/3819021#M739336</link>
      <description>Hi,&lt;BR /&gt;anybody has a sample policy file for hp-ux 11.11 to share?</description>
      <pubDate>Fri, 10 Nov 2006 12:14:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/open-source-tripwire-now-available-on-hpux-internet-express-7-0/m-p/3819021#M739336</guid>
      <dc:creator>paolo barila</dc:creator>
      <dc:date>2006-11-10T12:14:56Z</dc:date>
    </item>
    <item>
      <title>Re: Open Source Tripwire now available on HPUX Internet Express 7.0</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/open-source-tripwire-now-available-on-hpux-internet-express-7-0/m-p/3819022#M739337</link>
      <description>Really Good news!!&lt;BR /&gt;Many thanks&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;All the best&lt;BR /&gt;Victor</description>
      <pubDate>Fri, 10 Nov 2006 12:21:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/open-source-tripwire-now-available-on-hpux-internet-express-7-0/m-p/3819022#M739337</guid>
      <dc:creator>Victor BERRIDGE</dc:creator>
      <dc:date>2006-11-10T12:21:00Z</dc:date>
    </item>
    <item>
      <title>Re: Open Source Tripwire now available on HPUX Internet Express 7.0</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/open-source-tripwire-now-available-on-hpux-internet-express-7-0/m-p/3819023#M739338</link>
      <description>That is great - that means I don't have to buy anymore licenses for the commercial version. &lt;BR /&gt;&lt;BR /&gt;Question thogh - what is different between the commercial and open source one?&lt;BR /&gt;&lt;BR /&gt;Rgds...Geoff</description>
      <pubDate>Fri, 10 Nov 2006 13:30:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/open-source-tripwire-now-available-on-hpux-internet-express-7-0/m-p/3819023#M739338</guid>
      <dc:creator>Geoff Wild</dc:creator>
      <dc:date>2006-11-10T13:30:04Z</dc:date>
    </item>
    <item>
      <title>Re: Open Source Tripwire now available on HPUX Internet Express 7.0</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/open-source-tripwire-now-available-on-hpux-internet-express-7-0/m-p/3819024#M739339</link>
      <description>There is one tool that has been conspicuously absent from Internet Express:&lt;BR /&gt; &lt;BR /&gt;lsof&lt;BR /&gt; &lt;BR /&gt;Since fuser is hopelessly broken, it seems like a very useful candidate for this package. For example:&lt;BR /&gt; &lt;BR /&gt;fuser /opt&lt;BR /&gt;lsof /opt</description>
      <pubDate>Fri, 10 Nov 2006 18:43:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/open-source-tripwire-now-available-on-hpux-internet-express-7-0/m-p/3819024#M739339</guid>
      <dc:creator>Bill Hassell</dc:creator>
      <dc:date>2006-11-10T18:43:04Z</dc:date>
    </item>
    <item>
      <title>Re: Open Source Tripwire now available on HPUX Internet Express 7.0</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/open-source-tripwire-now-available-on-hpux-internet-express-7-0/m-p/3819025#M739340</link>
      <description>What does Tripwire do?&lt;BR /&gt;&lt;BR /&gt;Planning very soon to use HIDS... essentially to monitor changes to configuration files and direcotories. Is Tripwire better than HIDS or are they vastly different?&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 10 Nov 2006 21:49:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/open-source-tripwire-now-available-on-hpux-internet-express-7-0/m-p/3819025#M739340</guid>
      <dc:creator>Alzhy</dc:creator>
      <dc:date>2006-11-10T21:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: Open Source Tripwire now available on HPUX Internet Express 7.0</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/open-source-tripwire-now-available-on-hpux-internet-express-7-0/m-p/3819026#M739341</link>
      <description>&lt;!--!*#--&gt;Hi Nelson -&lt;BR /&gt;&lt;BR /&gt;File integrity checkers (like tripwire), HIDS, NIDS. HIPS, and NIPS and other security solutions all complement each other. You can find some useful definitions at: &lt;A href="http://www.networkintrusion.co.uk/ids.htm" target="_blank"&gt;http://www.networkintrusion.co.uk/ids.htm&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;I think Tripwire's CTO's posting that you can find at &lt;A href="http://archives.neohapsis.com/archives/sf/ids/2000-q4/0071.html" target="_blank"&gt;http://archives.neohapsis.com/archives/sf/ids/2000-q4/0071.html&lt;/A&gt;   provides a good summary of what file integrity checkers like tripwire and host intrusion detection systems like HIDS can do:&lt;BR /&gt;&lt;BR /&gt;"To roll up in one sentence, I view IDS as early warning detection, and integrity as damage assessment and recovery. I use both, because both are essential."&lt;BR /&gt;&lt;BR /&gt;As a simplification, within host intrusion detection, there are two main classes of HIDS (anomaly detection &amp;amp; misuse detection).  The problem is that those words can mean different things to different people.  Our&lt;BR /&gt;HPUX HIDS could be seen as doing both anomaly detection (we can flag things that don't normally happen) and misuse detection (we detect things like unauthorized file modifications or unauthorized access&lt;BR /&gt;attempts, such as repeated failed logins/su attempts to become a privileged user).   But we don't do system or application profiling, so we can't call ourselves a true anomaly detector.&lt;BR /&gt;&lt;BR /&gt;We take the approach of monitoring for attempts to exploit certain Unix vulnerabilities. See &lt;A href="http://h20293.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=HPUX-HIDS#threats_monitored" target="_blank"&gt;http://h20293.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=HPUX-HIDS#threats_monitored&lt;/A&gt;  for the list.&lt;BR /&gt;&lt;BR /&gt;Here is how I would break them down:&lt;BR /&gt;&lt;BR /&gt;Tripwire&lt;BR /&gt;- Runs in batch mode (e.g., typically daily runs, more frequently for small set of critical files)&lt;BR /&gt;- Establishes a known "good" state (requires persistent database)&lt;BR /&gt;- Discovers state changes (changes in file contents and in file attributes)&lt;BR /&gt;- Rollback feature: provides mechanism to either manually or automatically recover from undesired file changes and restore files back to known "good" state.&lt;BR /&gt;- Open source version (but no rollback feature, no central management, basic reporting)&lt;BR /&gt;- Commercial version (Server/Enterprise Tripwire) (has central management,&lt;BR /&gt;rollback/change control, GUI, Enterprise version supports network devices). See &lt;A href="http://www.tripwire.com/products/enterprise/ost/" target="_blank"&gt;http://www.tripwire.com/products/enterprise/ost/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;HPUX Host IDS&lt;BR /&gt;- Real-time detection, not batch mode&lt;BR /&gt;- Detects the exploitation of certain vulnerabilities, not just file modification&lt;BR /&gt;     - Unauthorized File Modification (critical files, log files, non-owned files)&lt;BR /&gt;     - Creation of privileged files (setuid and privileged world-writable files)&lt;BR /&gt;     - Poorly written privileged programs (buffer overflow, race condition)&lt;BR /&gt;     - Weak password and/or unauthorized access (logins/logouts)&lt;BR /&gt;     - Password Guessing (failed logins, failed su attempts)&lt;BR /&gt;- Does not perform real-time file integrity checks due to performance impact of frequently calculating file content signatures on either a large number of files and/or large-sized files. Does detect file creations, deletions and truncations in real-time.&lt;BR /&gt;- Complements Tripwire by providing early detection/warning&lt;BR /&gt;- Can detect signs of attack as the attack is unfolding (e.g., detects when critical file opened for modification before file is modified)&lt;BR /&gt;- OpenView Operations (OVO) integration by providing HIDS SPI from free download gallery.&lt;BR /&gt;- Supports response framework for customized responses to alerts (e.g., forward alerts by email, kill offending process, restore file to good state, integration with other management solutions)&lt;BR /&gt;- Comes with preconfigured surveillance schedules for out-of-the-box detection &lt;BR /&gt;- Supported by HP&lt;BR /&gt;- Free download&lt;BR /&gt;&lt;BR /&gt;Pierre&lt;BR /&gt;</description>
      <pubDate>Mon, 13 Nov 2006 15:03:48 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/open-source-tripwire-now-available-on-hpux-internet-express-7-0/m-p/3819026#M739341</guid>
      <dc:creator>Pierre Pasturel</dc:creator>
      <dc:date>2006-11-13T15:03:48Z</dc:date>
    </item>
    <item>
      <title>Re: Open Source Tripwire now available on HPUX Internet Express 7.0</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/open-source-tripwire-now-available-on-hpux-internet-express-7-0/m-p/3819027#M739342</link>
      <description>Hi pierre,&lt;BR /&gt;do you have a TRIPWIRE sample policy file for hp-ux 11.11 to share with us?&lt;BR /&gt;</description>
      <pubDate>Tue, 14 Nov 2006 04:11:48 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/open-source-tripwire-now-available-on-hpux-internet-express-7-0/m-p/3819027#M739342</guid>
      <dc:creator>paolo barila</dc:creator>
      <dc:date>2006-11-14T04:11:48Z</dc:date>
    </item>
  </channel>
</rss>

