Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




firewall-wizards logo Firewall Wizards mailing list archives

Re: FW: OK, I've been hacked, now what?
From: Crispin Cowan <crispin () cse ogi edu>
Date: Fri, 14 May 1999 00:03:23 -0700

kevin.sheldrake () baedsl co uk wrote:

I assume that Tripwire tracks changes to files.  How does it
distinguish between normal,
everyday system usage and unauthorised access?

It has a heuristic for files that are "likely" to change (joe.user's
mailbox) and files that are "unlikely" to change (the login
executable).  It then gives you a report of the "surprising" file
changes, and you get to decide whether you care.  Naturally, this is
configurable.


Is it available
for NT Server 4, NT
Workstation 4, DEC Unix, Solaris?

Yes, yes, probably, and yes:  http://www.tripwiresecurity.com/

Crispin
-----
 Crispin Cowan, Research Assistant Professor of Computer Science, OGI
    NEW:  Protect Your Linux Host with StackGuard'd Programs  :FREE
       http://www.cse.ogi.edu/DISC/projects/immunix/StackGuard/

                 Support Justice:  Boycott Windows 98






  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]