Re: [CentOS] AIDE or OSSEC on CentOS 5.4 x86_64?

2009-11-30 Thread Karanbir Singh
Hi Ian, On 11/30/2009 01:07 AM, Ian Forde wrote: I still want to see the changes, but it would be nice to see the ones I authorized through the update service to be partitioned off from the ones that seem to have no reasonable explanation. Seems to be that a yum plugin could be written that

Re: [CentOS] AIDE or OSSEC on CentOS 5.4 x86_64?

2009-11-29 Thread Rob Kampen
David McGuffey wrote: Starting with a fresh load and after I finish hardening the load following the Center for Internet Security (CIS) guidance, I'm wondering whether AIDE or OSSEC would be a better intrusion detection system. I installed AIDE and did a quick test of AIDE and after

Re: [CentOS] AIDE or OSSEC on CentOS 5.4 x86_64?

2009-11-29 Thread drew einhorn
On Sun, Nov 29, 2009 at 7:55 AM, Rob Kampen rkam...@kampensonline.comwrote: David McGuffey wrote: Starting with a fresh load and after I finish hardening the load following the Center for Internet Security (CIS) guidance, I'm wondering whether AIDE or OSSEC would be a better intrusion

Re: [CentOS] AIDE or OSSEC on CentOS 5.4 x86_64?

2009-11-29 Thread Brian Mathis
On Sun, Nov 29, 2009 at 9:55 AM, Rob Kampen rkam...@kampensonline.com wrote: David McGuffey wrote: Starting with a fresh load and after I finish hardening the load following the Center for Internet Security (CIS) guidance, I'm wondering whether AIDE or OSSEC would be a better intrusion

Re: [CentOS] AIDE or OSSEC on CentOS 5.4 x86_64?

2009-11-29 Thread John Horne
On Sat, 2009-11-28 at 18:57 -0500, David McGuffey wrote: Starting with a fresh load and after I finish hardening the load following the Center for Internet Security (CIS) guidance, I'm wondering whether AIDE or OSSEC would be a better intrusion detection system. I installed AIDE and did a

Re: [CentOS] AIDE or OSSEC on CentOS 5.4 x86_64?

2009-11-29 Thread David McGuffey
On Sun, 2009-11-29 at 20:31 +, John Horne wrote: On Sat, 2009-11-28 at 18:57 -0500, David McGuffey wrote: Starting with a fresh load and after I finish hardening the load following the Center for Internet Security (CIS) guidance, I'm wondering whether AIDE or OSSEC would be a better

Re: [CentOS] AIDE or OSSEC on CentOS 5.4 x86_64?

2009-11-29 Thread Ian Forde
On Nov 29, 2009, at 3:52 PM, David McGuffey davidmcguf...@verizon.net wrote: On Sun, 2009-11-29 at 20:31 +, John Horne wrote: On Sat, 2009-11-28 at 18:57 -0500, David McGuffey wrote: Starting with a fresh load and after I finish hardening the load following the Center for Internet

Re: [CentOS] AIDE or OSSEC on CentOS 5.4 x86_64?

2009-11-29 Thread Brian Mathis
On Sun, Nov 29, 2009 at 6:52 PM, David McGuffey davidmcguf...@verizon.net wrote: On Sun, 2009-11-29 at 20:31 +, John Horne wrote: On Sat, 2009-11-28 at 18:57 -0500, David McGuffey wrote: Starting with a fresh load and after I finish hardening the load following the Center for Internet

[CentOS] AIDE or OSSEC on CentOS 5.4 x86_64?

2009-11-28 Thread David McGuffey
Starting with a fresh load and after I finish hardening the load following the Center for Internet Security (CIS) guidance, I'm wondering whether AIDE or OSSEC would be a better intrusion detection system. I installed AIDE and did a quick test of AIDE and after initializing the db and applying

Re: [CentOS] AIDE or OSSEC on CentOS 5.4 x86_64?

2009-11-28 Thread Alan Sparks
David McGuffey wrote: Seems to me that any IDS must be tied to the yum update process so that one is not dealing with hundreds/thousands of changes that were brought in by a yum update that I choose to apply. Is OSSEC any less noisy? Nope. -Alan

Re: [CentOS] AIDE or OSSEC on CentOS 5.4 x86_64?

2009-11-28 Thread mark
David McGuffey wrote: Starting with a fresh load and after I finish hardening the load following the Center for Internet Security (CIS) guidance, I'm wondering whether AIDE or OSSEC would be a better intrusion detection system. snip We've just started with OSSEC at work. I'm told they'd tried

Re: [CentOS] AIDE or OSSEC on CentOS 5.4 x86_64?

2009-11-28 Thread Brian Mathis
On Sat, Nov 28, 2009 at 6:57 PM, David McGuffey davidmcguf...@verizon.net wrote: Starting with a fresh load and after I finish hardening the load following the Center for Internet Security (CIS) guidance, I'm wondering whether AIDE or OSSEC would be a better intrusion detection system. I