- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Open Source Tripwire now available on HPUX Interne...
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО07-06-2006 07:43 AM
тАО07-06-2006 07:43 AM
Open Source Tripwire now available on HPUX Internet Express 7.0
http://docs.hp.com/en/internet.html#Internet%20Express
11iv
http://h20293.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=HPUXIEXP1111
11iv2
http://h20293.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=HPUXIEXP1123
The RBI mentions you must install PHSS_28871 in order for tripwire to work.
We would like to gauge customer demand for an HP fully supported file integrity checker.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО07-06-2006 08:54 AM
тАО07-06-2006 08:54 AM
Re: Open Source Tripwire now available on HPUX Internet Express 7.0
If I had anything to say about it, I'd put in every machine. It is a great tool.
Customer demand will be high. Lots of people try to get it to work.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО07-06-2006 09:10 AM
тАО07-06-2006 09:10 AM
Re: Open Source Tripwire now available on HPUX Internet Express 7.0
A very worthwhile tool!
Everybody, this is a "gotta have it" utility.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО07-06-2006 10:13 AM
тАО07-06-2006 10:13 AM
Re: Open Source Tripwire now available on HPUX Internet Express 7.0
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-10-2006 04:14 AM
тАО11-10-2006 04:14 AM
Re: Open Source Tripwire now available on HPUX Internet Express 7.0
anybody has a sample policy file for hp-ux 11.11 to share?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-10-2006 04:21 AM
тАО11-10-2006 04:21 AM
Re: Open Source Tripwire now available on HPUX Internet Express 7.0
Many thanks
All the best
Victor
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-10-2006 05:30 AM
тАО11-10-2006 05:30 AM
Re: Open Source Tripwire now available on HPUX Internet Express 7.0
Question thogh - what is different between the commercial and open source one?
Rgds...Geoff
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-10-2006 10:43 AM
тАО11-10-2006 10:43 AM
Re: Open Source Tripwire now available on HPUX Internet Express 7.0
lsof
Since fuser is hopelessly broken, it seems like a very useful candidate for this package. For example:
fuser /opt
lsof /opt
Bill Hassell, sysadmin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-10-2006 01:49 PM
тАО11-10-2006 01:49 PM
Re: Open Source Tripwire now available on HPUX Internet Express 7.0
Planning very soon to use HIDS... essentially to monitor changes to configuration files and direcotories. Is Tripwire better than HIDS or are they vastly different?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-13-2006 07:03 AM
тАО11-13-2006 07:03 AM
Re: Open Source Tripwire now available on HPUX Internet Express 7.0
File integrity checkers (like tripwire), HIDS, NIDS. HIPS, and NIPS and other security solutions all complement each other. You can find some useful definitions at: http://www.networkintrusion.co.uk/ids.htm
I think Tripwire's CTO's posting that you can find at http://archives.neohapsis.com/archives/sf/ids/2000-q4/0071.html provides a good summary of what file integrity checkers like tripwire and host intrusion detection systems like HIDS can do:
"To roll up in one sentence, I view IDS as early warning detection, and integrity as damage assessment and recovery. I use both, because both are essential."
As a simplification, within host intrusion detection, there are two main classes of HIDS (anomaly detection & misuse detection). The problem is that those words can mean different things to different people. Our
HPUX HIDS could be seen as doing both anomaly detection (we can flag things that don't normally happen) and misuse detection (we detect things like unauthorized file modifications or unauthorized access
attempts, such as repeated failed logins/su attempts to become a privileged user). But we don't do system or application profiling, so we can't call ourselves a true anomaly detector.
We take the approach of monitoring for attempts to exploit certain Unix vulnerabilities. See http://h20293.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=HPUX-HIDS#threats_monitored for the list.
Here is how I would break them down:
Tripwire
- Runs in batch mode (e.g., typically daily runs, more frequently for small set of critical files)
- Establishes a known "good" state (requires persistent database)
- Discovers state changes (changes in file contents and in file attributes)
- Rollback feature: provides mechanism to either manually or automatically recover from undesired file changes and restore files back to known "good" state.
- Open source version (but no rollback feature, no central management, basic reporting)
- Commercial version (Server/Enterprise Tripwire) (has central management,
rollback/change control, GUI, Enterprise version supports network devices). See http://www.tripwire.com/products/enterprise/ost/
HPUX Host IDS
- Real-time detection, not batch mode
- Detects the exploitation of certain vulnerabilities, not just file modification
- Unauthorized File Modification (critical files, log files, non-owned files)
- Creation of privileged files (setuid and privileged world-writable files)
- Poorly written privileged programs (buffer overflow, race condition)
- Weak password and/or unauthorized access (logins/logouts)
- Password Guessing (failed logins, failed su attempts)
- Does not perform real-time file integrity checks due to performance impact of frequently calculating file content signatures on either a large number of files and/or large-sized files. Does detect file creations, deletions and truncations in real-time.
- Complements Tripwire by providing early detection/warning
- Can detect signs of attack as the attack is unfolding (e.g., detects when critical file opened for modification before file is modified)
- OpenView Operations (OVO) integration by providing HIDS SPI from free download gallery.
- Supports response framework for customized responses to alerts (e.g., forward alerts by email, kill offending process, restore file to good state, integration with other management solutions)
- Comes with preconfigured surveillance schedules for out-of-the-box detection
- Supported by HP
- Free download
Pierre
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-13-2006 08:11 PM
тАО11-13-2006 08:11 PM
Re: Open Source Tripwire now available on HPUX Internet Express 7.0
do you have a TRIPWIRE sample policy file for hp-ux 11.11 to share with us?