<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ids for linux in Operating System - Linux</title>
    <link>https://community.hpe.com/t5/operating-system-linux/ids-for-linux/m-p/3450488#M86663</link>
    <description>Personally I don't think you can go wrong with Snort.&lt;BR /&gt;&lt;BR /&gt;I also use Sguil (sguil.sourceforge.net) for monitoring it.</description>
    <pubDate>Sat, 01 Jan 2005 09:26:25 GMT</pubDate>
    <dc:creator>Steven Coutts_1</dc:creator>
    <dc:date>2005-01-01T09:26:25Z</dc:date>
    <item>
      <title>ids for linux</title>
      <link>https://community.hpe.com/t5/operating-system-linux/ids-for-linux/m-p/3450478#M86653</link>
      <description>hi all,&lt;BR /&gt;is there any free ids for linux, other than snort ?&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;Maaz</description>
      <pubDate>Sun, 26 Dec 2004 14:35:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/ids-for-linux/m-p/3450478#M86653</guid>
      <dc:creator>Maaz</dc:creator>
      <dc:date>2004-12-26T14:35:21Z</dc:date>
    </item>
    <item>
      <title>Re: ids for linux</title>
      <link>https://community.hpe.com/t5/operating-system-linux/ids-for-linux/m-p/3450479#M86654</link>
      <description>Check out labrea (&lt;A href="http://labrea.sf.net/)" target="_blank"&gt;http://labrea.sf.net/)&lt;/A&gt; and Prelude.  There are many file integrity checking tools too.</description>
      <pubDate>Sun, 26 Dec 2004 23:30:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/ids-for-linux/m-p/3450479#M86654</guid>
      <dc:creator>Ragu_3</dc:creator>
      <dc:date>2004-12-26T23:30:28Z</dc:date>
    </item>
    <item>
      <title>Re: ids for linux</title>
      <link>https://community.hpe.com/t5/operating-system-linux/ids-for-linux/m-p/3450480#M86655</link>
      <description>Hello,&lt;BR /&gt;&lt;BR /&gt;depends on what you want to operate your IDS to work on? Network? &lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.snort.org/" target="_blank"&gt;http://www.snort.org/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Host? Perhaps samhain is a solution for you:&lt;BR /&gt;&lt;A href="http://la-samhna.de/samhain/" target="_blank"&gt;http://la-samhna.de/samhain/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Best wishes</description>
      <pubDate>Mon, 27 Dec 2004 04:02:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/ids-for-linux/m-p/3450480#M86655</guid>
      <dc:creator>Oliver Schwank</dc:creator>
      <dc:date>2004-12-27T04:02:30Z</dc:date>
    </item>
    <item>
      <title>Re: ids for linux</title>
      <link>https://community.hpe.com/t5/operating-system-linux/ids-for-linux/m-p/3450481#M86656</link>
      <description>you do not like snort ?</description>
      <pubDate>Mon, 27 Dec 2004 04:07:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/ids-for-linux/m-p/3450481#M86656</guid>
      <dc:creator>Ivajlo Yanakiev</dc:creator>
      <dc:date>2004-12-27T04:07:27Z</dc:date>
    </item>
    <item>
      <title>Re: ids for linux</title>
      <link>https://community.hpe.com/t5/operating-system-linux/ids-for-linux/m-p/3450482#M86657</link>
      <description>Snort is the most popular and has really good support.  If your having problems getting it installed, I have a kickscript script for installing ES 3.0 and a Bash script for installing all of the necessary packages. It took me 2 days to get it to work but I can get a new box with Snort,PHP, ACiD &amp;amp; MySQL backend up and running within 60 minutes or so. Doing all the steps by hand takes an easily 4+ hours. Let me know if your interested.. &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.linuxtech.cc" target="_blank"&gt;www.linuxtech.cc&lt;/A&gt;</description>
      <pubDate>Mon, 27 Dec 2004 17:15:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/ids-for-linux/m-p/3450482#M86657</guid>
      <dc:creator>Don_89</dc:creator>
      <dc:date>2004-12-27T17:15:39Z</dc:date>
    </item>
    <item>
      <title>Re: ids for linux</title>
      <link>https://community.hpe.com/t5/operating-system-linux/ids-for-linux/m-p/3450483#M86658</link>
      <description>Where I can get this scripts ?</description>
      <pubDate>Tue, 28 Dec 2004 03:52:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/ids-for-linux/m-p/3450483#M86658</guid>
      <dc:creator>Ivajlo Yanakiev</dc:creator>
      <dc:date>2004-12-28T03:52:17Z</dc:date>
    </item>
    <item>
      <title>Re: ids for linux</title>
      <link>https://community.hpe.com/t5/operating-system-linux/ids-for-linux/m-p/3450484#M86659</link>
      <description>Many Thanks Dear Ragu&lt;BR /&gt;Nice Help from Dear Oliver Schwank&lt;BR /&gt;&lt;BR /&gt;I m eagerly looking forward for the script from Don&lt;BR /&gt;&lt;BR /&gt;and Dear Ivajlo Yanakiev, i am working on snort, and want some other tool, also.&lt;BR /&gt;&lt;BR /&gt;Nice help&lt;BR /&gt;Thanks to all&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;Maaz</description>
      <pubDate>Tue, 28 Dec 2004 14:10:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/ids-for-linux/m-p/3450484#M86659</guid>
      <dc:creator>Maaz</dc:creator>
      <dc:date>2004-12-28T14:10:24Z</dc:date>
    </item>
    <item>
      <title>Re: ids for linux</title>
      <link>https://community.hpe.com/t5/operating-system-linux/ids-for-linux/m-p/3450485#M86660</link>
      <description>Ok, &lt;BR /&gt;&lt;BR /&gt;Sorry for the late reply. I haven't ran the script in awhile and I just wanted to make sure it still works.. &lt;BR /&gt;&lt;BR /&gt;Goto my website and grab the two files listed in the directory. &lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.linuxtech.cc/snort" target="_blank"&gt;www.linuxtech.cc/snort&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;The first file (snort.cfg) is a kickstart script for ES 3.0. It will probably work for 2.1 also but I haven't tried.  You'll need to change a few things like the NFS server where you do your installs from. Also, the disk partitions are setup for 'sda' (VMware). If this was a HP box with a RAID controller, you would use 'cciss/c0d0' , if using IDE, then use 'hda'. This script isn't too critical, if you install from CD, just make sure NOT to install Apache, MySql or PHP. BTW, the root PW is -&amp;gt; payday &lt;BR /&gt;&lt;BR /&gt;The second file (snort.tar.gz) is a tar of various packages needed for a complete Snort install with ACiD frontend and MySql backend. The install-script goes through all the setup steps which are descriped in this document. &lt;A href="http://www.internetsecurityguru.com/documents/snort_acid_rhws3.pdf" target="_blank"&gt;http://www.internetsecurityguru.com/documents/snort_acid_rhws3.pdf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Once the OS is up &amp;amp; running; &lt;BR /&gt;&lt;BR /&gt;1) mkdir /root/snort&lt;BR /&gt;2) copy the snort.tar.gz file into /root/snort&lt;BR /&gt;3) tar zxvf snort.tar.gz&lt;BR /&gt;4) run ./install-script &lt;BR /&gt;(this takes about 20mins. depending on CPU power) &lt;BR /&gt;5) When the script completes, it will say "Snort up &amp;amp; running!" &lt;BR /&gt;6) Next you'll need to extend the Snort DB to support ACID, point yor broswer to the IDS box; http://snortip/acid and click the 'Setup' link. This will extended the DB. &lt;BR /&gt;&lt;BR /&gt;7) Goto URL http://snortip/acid  ; you should see the ACID frontend. Snort is offically running.. &lt;BR /&gt;&lt;BR /&gt;Let me know how things progress..</description>
      <pubDate>Tue, 28 Dec 2004 16:41:51 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/ids-for-linux/m-p/3450485#M86660</guid>
      <dc:creator>Don_89</dc:creator>
      <dc:date>2004-12-28T16:41:51Z</dc:date>
    </item>
    <item>
      <title>Re: ids for linux</title>
      <link>https://community.hpe.com/t5/operating-system-linux/ids-for-linux/m-p/3450486#M86661</link>
      <description>Hi  don,&lt;BR /&gt;I can't install this now but I plane to do it.&lt;BR /&gt;tnks &lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 29 Dec 2004 07:47:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/ids-for-linux/m-p/3450486#M86661</guid>
      <dc:creator>Ivajlo Yanakiev</dc:creator>
      <dc:date>2004-12-29T07:47:07Z</dc:date>
    </item>
    <item>
      <title>Re: ids for linux</title>
      <link>https://community.hpe.com/t5/operating-system-linux/ids-for-linux/m-p/3450487#M86662</link>
      <description>Here are some more links you might want to check:&lt;BR /&gt;&lt;BR /&gt;Tripwire -- &lt;A href="http://www.tripwire.org/" target="_blank"&gt;http://www.tripwire.org/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;yafic -- Yet Another File Integrity Checker:&lt;BR /&gt;&lt;A href="http://www.philosophysw.com/software/yafic/" target="_blank"&gt;http://www.philosophysw.com/software/yafic/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;integrit -- &lt;A href="http://integrit.sourceforge.net/" target="_blank"&gt;http://integrit.sourceforge.net/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;AIDE (Advanced Intrusion Detection Environment) -- &lt;A href="http://www.cs.tut.fi/%7Erammer/aide.html" target="_blank"&gt;http://www.cs.tut.fi/%7Erammer/aide.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;HTH,&lt;BR /&gt;Ross</description>
      <pubDate>Wed, 29 Dec 2004 18:47:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/ids-for-linux/m-p/3450487#M86662</guid>
      <dc:creator>Ross Minkov</dc:creator>
      <dc:date>2004-12-29T18:47:41Z</dc:date>
    </item>
    <item>
      <title>Re: ids for linux</title>
      <link>https://community.hpe.com/t5/operating-system-linux/ids-for-linux/m-p/3450488#M86663</link>
      <description>Personally I don't think you can go wrong with Snort.&lt;BR /&gt;&lt;BR /&gt;I also use Sguil (sguil.sourceforge.net) for monitoring it.</description>
      <pubDate>Sat, 01 Jan 2005 09:26:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/ids-for-linux/m-p/3450488#M86663</guid>
      <dc:creator>Steven Coutts_1</dc:creator>
      <dc:date>2005-01-01T09:26:25Z</dc:date>
    </item>
  </channel>
</rss>

