What is Tripwire?
Tripwire is a form intrusion detection system (IDS) that helps you keep tabs on the integrity of the files on your computer. Quite simply it will help identify files or modifications made to your system in the event someone compromised your system.
How does Tripwire work?
Tripwire works on a pretty easy to understand concept. Basically, when you install Tripwire on your linux box you tell it to scan your system and create a database of checksums and information. Once you have a good reference point or database setup, you then scan your system on a regular basis for modifications to your file system.
Why would I want run a file system integrity software?
If you have ever had your system compromised by a cracker, it's an extremely frustrating time. You never know what they have done, where they have been, or what files they have modified or installed. This type of application helps in the recovery process. Quite often crackers will installed a group of applications on your system called a rootkit. A rootkit overwrites many of your commonly used system files to help hide the tracks of the cracker, or leave a backdoor on your system so he can return at a later date. Often the types of files modified are ones such as ps and netstat. By installing their own version of applications like these they can hide the fact there is additional daemons and processes running the background.
How do I put Tripwire to practical use?
Tripwire can be configured to send you e-mails at a set time interval via Sendmail or SMTP. On small systems it wouldn't be unreasonable to have your system checked several times a day and have Tripwire e-mail you the results. If you don't want the results e-mailed you can store the information in a file for later review. I believe it is a handy tool to have the logs e-mailed to you, so a problem can be quickly identified.
Thought Tripwire won't protect you from hackers, it will help you identify the level of which your system has been compromised and if scanned at regular time intervals should help you reduce the amount of time for which your system has been compromised. If your system has been broken in to, then the best thing to do is isolate the machine from the network and rebuilt it from know good backups and try to determine the method of entry.
Ken Dennis
http://kendennis-rss.homeip.net/
Microsoft CRM is CRM application, maintained and supported by Microsoft... Read More
Have you ever noticed that when you look at your... Read More
Great Plains Integration Manager scripting and translation - overview for... Read More
Microsoft Business Solutions CRM proved to be reliable solution in... Read More
Not every software testing project can or should be automated.... Read More
What is IRC?IRC is Internet Relay Chat. It is a... Read More
Manufacturing in the USA is far away down from mid... Read More
Internet worms. Is your PC infected?If your computer has become... Read More
Need software to record your voice, streaming audio or musical... Read More
As of now - Great Plains Dynamics/eEnterprise is transformed/renamed into... Read More
Are you a whiz at calculating financial information? Not the... Read More
Finally, you have some time to personalize your desktop with... Read More
Now that spyware is the single most dangerous threat to... Read More
Microsoft Client Relation Management system (Microsoft CRM) and Microsoft RMS... Read More
Usually, the easiest way to tell you have spyware is... Read More
When Great Plains Software was designing and developing Great Plains... Read More
Looking at all the ads which promise to get rid... Read More
Considering whether or not your software company should hire a... Read More
What is Spyware?Spyware monitors your surfing habits and sends the... Read More
Background: For many organizations like ours, the interim target of... Read More
Here is some free software tools to help you build... Read More
How to delete the user? This is the first problem... Read More
IBM Lotus Domino or Microsoft Exchange?The severe competition continues for... Read More
Follow the steps below to quickly design, generate, and deploy... Read More
Looks like Microsoft Great Plains becomes more and more popular,... Read More
house cleaning company Bannockburn ..Just when you thought you were Web savvy, one more... Read More
2005 ? Back to the Future.What does the future hold?... Read More
Microsoft Business Solutions Great Plains, former Great Plains Software Dynamics... Read More
Fundraising software lets you connect with donors in a way... Read More
How would you like to prevent spyware and adware from... Read More
Mapping Software Improves Data VisualizationFrom the outset, it is important... Read More
What is Tripwire?Tripwire is a form intrusion detection system (IDS)... Read More
Microsoft Business Solutions Great Plains has I'd say end user... Read More
It is really interesting that a bug can create problem... Read More
If you use Microsoft Outlook (or similar applications) for e-mailing,... Read More
For those who still don't know, Microsoft Publisher helps computer... Read More
Microsoft Business Solutions Great Plains is very generic accounting application... Read More
IntroductionPHP can be used for a lot of different things,... Read More
In the previous ISDN article, we looked at how and... Read More
Handling character strings in Java is supported through two final... Read More
ERP Consulting industry is on the way to serve clients... Read More
Preventive Maintenance (PM) is defined as scheduled work done on... Read More
Microsoft Great Plains, former Great Plains Software Dynamics, eEnterprise has... Read More
ERP is the acronym of Enterprise Resource Planning. Multi-module ERP... Read More
MSN messenger is a pretty cool invention. I mean I'm... Read More
Spyware and Adware infest over 90 percent of computers in... Read More
As you probably know, when Microsoft purchased Great Plains Software... Read More
We'll give you non formal view, based on our consulting... Read More
Our company, Novaprof Inc., developed unique software - DB Integration.... Read More
The US House of Representatives has recently passed the "Spy... Read More
Software |