Re: [CentOS] Intrusion Detection

2010-03-05 Thread Dan Burkland
> -Original Message- > From: centos-boun...@centos.org [mailto:centos-boun...@centos.org] On > Behalf Of Nux > Sent: Friday, March 05, 2010 1:51 PM > To: centos@centos.org > Subject: Re: [CentOS] Intrusion Detection > > On Thu, 4 Mar 2010, Dan Burkland wrote: >

Re: [CentOS] Intrusion Detection

2010-03-05 Thread Nux
On Thu, 4 Mar 2010, Dan Burkland wrote: Hello all, I have been exploring the various intrusion detection systems available for the Linux platform and was wondering what ones you all would recommend? I have used AIDE before and while it is extremely easy to setup, it does not support the abil

Re: [CentOS] Intrusion Detection

2010-03-04 Thread Bazy
On Fri, Mar 5, 2010 at 12:02 AM, Dan Burkland wrote: > Hello all, > > I have been exploring the various intrusion detection systems available for > the Linux platform and was wondering what ones you all would recommend? I > have used AIDE before and while it is extremely easy to setup, it does n

Re: [CentOS] Intrusion Detection

2010-03-04 Thread Rajagopal Swaminathan
Greetings, On Fri, Mar 5, 2010 at 3:32 AM, Dan Burkland wrote: > Hello all, > > I have been exploring the various intrusion detection systems available for > the Linux platform and was wondering what ones you all would recommend? I > have used AIDE before and while it is extremely easy to setup

Re: [CentOS] Intrusion Detection

2010-03-04 Thread Rob Kampen
Dan Burkland wrote: Hello all, I have been exploring the various intrusion detection systems available for the Linux platform and was wondering what ones you all would recommend? I have used AIDE before and while it is extremely easy to setup, it does not support the ability to send alerts as

Re: [CentOS] Intrusion Detection

2010-03-04 Thread Mike McCarty
Jim Perrin wrote: > On Thu, Mar 4, 2010 at 5:02 PM, Dan Burkland wrote: >> Hello all, >> >> I have been exploring the various intrusion detection systems >> available for the Linux platform and was wondering what ones you >> all would recommend? I have used AIDE before and while it is >> extremely

Re: [CentOS] Intrusion Detection

2010-03-04 Thread Aleksey Tsalolikhin
On Thu, Mar 4, 2010 at 2:02 PM, Dan Burkland wrote: > Hello all, > > I have been exploring the various intrusion detection systems available for > the Linux platform and was wondering what ones you all would recommend? I > have used AIDE before and while it is extremely easy to setup, it does no

Re: [CentOS] Intrusion Detection

2010-03-04 Thread Jim Perrin
On Thu, Mar 4, 2010 at 5:02 PM, Dan Burkland wrote: > Hello all, > > I have been exploring the various intrusion detection systems available for > the Linux platform and was wondering what ones you all would recommend? I > have used AIDE before and while it is extremely easy to setup, it does no

Re: [CentOS] Intrusion Detection

2010-03-04 Thread Ron Loftin
On Thu, 2010-03-04 at 16:02 -0600, Dan Burkland wrote: > Hello all, > > I have been exploring the various intrusion detection systems available for > the Linux platform and was wondering what ones you all would recommend? I > have used AIDE before and while it is extremely easy to setup, it doe

[CentOS] Intrusion Detection

2010-03-04 Thread Dan Burkland
Hello all, I have been exploring the various intrusion detection systems available for the Linux platform and was wondering what ones you all would recommend? I have used AIDE before and while it is extremely easy to setup, it does not support the ability to send alerts as files are changed (al

Re: [CentOS] Intrusion Detection Systems

2007-09-30 Thread Les Bell
John Hinton <[EMAIL PROTECTED]> wrote: >> I did look at snort and actually some people run both snort and OSSEC. I don't remember the reasons. << Simply put, they're different things. Snort is a network IDS which examines network traffic packets, looking for the signatures of various attacks. OS

Re: [CentOS] Intrusion Detection Systems

2007-09-30 Thread John Hinton
Lanny Marcus wrote: On 27 September 2007, John Hinton <[EMAIL PROTECTED]> wrote: Message: 50 Date: Thu, 27 Sep 2007 03:13:00 -0400 WOW! I just did an install of OSSEC on a couple of servers and so far I'm very impressed. First, the installation was as good as anything John: Sounds li

Re: [CentOS] Intrusion Detection Systems

2007-09-30 Thread Lanny Marcus
On 27 September 2007, John Hinton <[EMAIL PROTECTED]> wrote: > Message: 50 > Date: Thu, 27 Sep 2007 03:13:00 -0400 > > WOW! I just did an install of OSSEC on a couple of servers and so far > I'm very impressed. First, the installation was as good as anything John: Sounds like you are very please

Re: [CentOS] Intrusion Detection Systems

2007-09-27 Thread John Hinton
Stephen John Smoogen wrote: On 9/26/07, John Hinton <[EMAIL PROTECTED]> wrote: Situation: We are providing hosting services. I've grown tired of the various kiddie scripts/dictionary attacks on various services. The latest has been against vsftpd, on systems that I can't easily control vs. p

Re: [CentOS] Intrusion Detection Systems

2007-09-26 Thread Stephen John Smoogen
On 9/26/07, John Hinton <[EMAIL PROTECTED]> wrote: > Situation: We are providing hosting services. > > I've grown tired of the various kiddie scripts/dictionary attacks on > various services. The latest has been against vsftpd, on systems that I > can't easily control vs. putting strict limits on s

Re: [CentOS] Intrusion Detection Systems

2007-09-26 Thread Mark D. Foster
John Hinton wrote: > ... > There does seem to be flexibility among these three systems in having > the ability to monitor just about any log system and take action based > on failed logins for instance. > > So, whats the word from the list? Pros cons or other directions? I've always been rather fon

[CentOS] Intrusion Detection Systems

2007-09-26 Thread John Hinton
Situation: We are providing hosting services. I've grown tired of the various kiddie scripts/dictionary attacks on various services. The latest has been against vsftpd, on systems that I can't easily control vs. putting strict limits on ssh. We simply have too many users entering from too many