LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   Linux - Security (https://www.linuxquestions.org/questions/linux-security-4/)
-   -   Complete & Simple Guide to install Tripwire! (https://www.linuxquestions.org/questions/linux-security-4/complete-and-simple-guide-to-install-tripwire-4175544152/)

pompado 06-01-2015 06:25 AM

Complete & Simple Guide to install Tripwire!
 
Hello - i install this on Ubuntu and think this guide also work with Debian.
The guide explain how to install and configurate Tripwire on your system.
And also explain how to save the Tripwire database on removable media.

I can not programming but succed to install Tripwire - so can you even if you don't have coding skills :-)

TRIPWIRE

Tripwire is a "intrusion detection system" ... this means that Tripwire don't prevent an intrusion, but it will notice if it has happen.
It works like this; Tripwire sign each file with a specific algorithm or key number on your operating system and save all the information on a database.
So if some one change of modifie any file, then Tripwire will notice this change, so no one can break into your computer without you being aware of that.

So each file gets a uniq id and if some one hack into your system Tripwire will notice the change with some critical files being modified.
The great thing with this guide is that in the end i will explain how you install the Tripwire database on removable media.
This means that if you get an intrusion - so cant they modifie or hack your Tripwire - it is safe and secure.

THE FIRST PART OF THE INSTALLATION


First you need to have a new installation from scratch, so you know that your operating system has not been temporized with.
Now you can connect to internet and install Tripwire.

Code:

sudo apt-get update
Code:

sudo apt-get install tripwire
Now when you run Tripwire installation it will ask you at the beginning to configuration email option.
Then you should pick "internetsystem" ...

http://i59.tinypic.com/2vazcix.jpg

After that it will ask you to add what kind of email you use.
Like hotmail.com or gmail.com

http://i58.tinypic.com/x3cm0j.png

After this Tripwire will ask you if you want to install two secure keys.
The site key and the local key.

You should answer yes and continue doing so true the hole installation process.
It is a good idea if you have prepared your self with two good key phrases.
Two good passwords.

ButterflyMelissa 06-01-2015 05:45 PM

hey, thanks for this info :)
all security tips are welcome

displace 06-02-2015 06:08 AM

Is Tripwire still a thing today? I hear many people recommend AIDE over Tripwire.

~dis

unSpawn 06-06-2015 05:20 AM

Quote:

Originally Posted by displace (Post 5370947)
Is Tripwire still a thing today?

Well maybe if my concerns posted here (first paragraph) no longer apply?.. (Not holding my breath.)


Quote:

Originally Posted by displace (Post 5370947)
I hear many people recommend AIDE over Tripwire.

AIDE or Samhain, and always as part of an appropriate set of measures.

Habitual 06-08-2015 09:10 AM

The whole shebang is at http://ubuntuforums.org/showthread.php?t=2235300

displace 06-11-2015 12:18 AM

Quote:

Originally Posted by unSpawn (Post 5373024)
AIDE or Samhain, and always as part of an appropriate set of measures.

I haven't heard about Samhain before. How does it compare to AIDE?

On a side note, do you perhaps know, if any of these tools are also capable of monitoring custom disk sectors i.e. the first 2048 sectors of the HDD where the boot loader is located? How about the contents of the bios chip? I normally do this by hand and I'm looking for a way to automate it.

~dis

unSpawn 06-11-2015 07:51 PM

Quote:

Originally Posted by displace (Post 5375424)
I haven't heard about Samhain before. How does it compare to AIDE?

- Daemon vs cron jobbed task,
- Can use inotify,
- Can be centrally managed (server - client paradigm),
- Can encrypt config,
- Can obfuscate own process argv[0],
- much, much more: please check documentation.


Quote:

Originally Posted by displace (Post 5375424)
On a side note, do you perhaps know, if any of these tools are also capable of monitoring custom disk sectors (..) How about the contents of the bios chip?

None do.

pompado 01-23-2016 03:44 AM

Quote:

Originally Posted by Habitual (Post 5373994)

Hello i was going to post the hole howto - but something got wrong with forum text input - thanks for sharing the link to my Tripwire Howto.
What i like is that you can install the Tripwire database on removable media.

Cheers

unSpawn 01-23-2016 04:23 AM

Quote:

Originally Posted by pompado (Post 5486146)
Hello i was going to post the hole howto - but something got wrong with forum text input

If you want to you can submit your article and we'll post it in the HOWTO section.

Habitual 01-23-2016 10:01 AM

Quote:

Originally Posted by pompado (Post 5486146)
Hello i was going to post the hole howto - but something got wrong with forum text input - thanks for sharing the link to my Tripwire Howto.
What i like is that you can install the Tripwire database on removable media.

Cheers

Good Stuff, Maynard.
I have it bookmarked and I tend to keep those for years.

pompado 01-24-2016 02:49 AM

Hello, i would like to add two HOWTO in the HOWTO section, but i can not find the HOWTO section?
I would like to add Logwatch & Tripwire.

Cheers

unSpawn 01-24-2016 03:47 PM

Right side menu: Write for LQ: LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.

JockVSJock 01-25-2016 09:54 PM

I thought Tripwire was commercial software only.

Didn't realize there is an open source version: http://sourceforge.net/projects/tripwire/

unSpawn 01-26-2016 12:44 AM

...that has been left completely unmaintained for the past 5 years.

JockVSJock 01-26-2016 05:51 AM

Quote:

Originally Posted by unSpawn (Post 5487429)
...that has been left completely unmaintained for the past 5 years.

Exactly!

OP failed to note that in the original post and the documentation that he/she linked too. Why even post this?


All times are GMT -5. The time now is 03:06 PM.