Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 12 of 12
  1. #1
    BANNED
    Join Date
    Feb 2002
    Posts
    656

    Default What kind of Intrusion Detection System is appropriate for a web server?

    What kind of Intrusion Detection System is appropriate for a web server?

    Has anyone caught an intruder?

  2. #2
    Member
    Join Date
    Jan 2004
    Posts
    227

    Default Snort

    Check out "Snort", might need google to find it

  3. #3
    BANNED
    Join Date
    Feb 2002
    Posts
    656

    Default

    I downloaded that, please briefly describe how you use it on your web server.

  4. #4
    Member
    Join Date
    Jan 2004
    Posts
    227

    Default

    Read the FAQ
    It looks for stuff that is not normal

  5. #5
    Member
    Join Date
    Apr 2003
    Location
    Lewisville, Tx
    Posts
    968

    Default

    If you don't understand the included documents I recommend going to someone like Ryan at http://www.rfxnetworks.com and having them install it and other security applications. I believe Rack911 is another good alternative for these services also.
    Kris
    NCServ, LLC.
    WebHosting - Dedicated Servers - Colocation
    sales@ncerv.com

  6. #6
    BANNED
    Join Date
    Jun 2003
    Posts
    293

    Default

    I would like to point out that IDS systems are not very useful if they are run on the same host they are to protect. IDS systems are much better of if they either sit in a network or on the bastion host. So do not expect too much in terms of security.

  7. #7
    Member
    Join Date
    Jan 2004
    Posts
    81

    Default

    Originally posted by kris1351
    If you don't understand the included documents I recommend going to someone like Ryan at http://www.rfxnetworks.com and having them install it and other security applications. I believe Rack911 is another good alternative for these services also.
    Brute Force Detection from RFX Networks is great, and that URL provided step-by-step guide how to install it yourself.. FREE.

    CHKROOTKIT will be useful for determing if a root kit has been placed on your server giving unwanted access to hackers/crackers.

    And for more basic CPanel Security there are a few more how-tos there that should be done to CPanel and general webservers as well.

    If you personally need help, or find a how-to lacking CONTACT ME! I will help you fix your problem, and FIX the how-to!!!

  8. #8
    Member
    Join Date
    Nov 2002
    Posts
    124

    Default

    Originally posted by cyberspirit
    I would like to point out that IDS systems are not very useful if they are run on the same host they are to protect. IDS systems are much better of if they either sit in a network or on the bastion host. So do not expect too much in terms of security.
    This is definitely true. The best setup is to use a ethernet tap upstream of your boxes that you monitor. That said...

    Host-based IDS is better than no IDS at all, and can be a good edition to a well layered security strategy. Since lots of folks nowadays don't colo, host-based is often the only solution (short of buying more services from their DC).

    -David

  9. #9
    Member
    Join Date
    Jan 2004
    Posts
    227

    Default

    @ servermatrix you can rexuest how they setup your servers... so for $55 you could run an IDS< plus a $50 moving charge

  10. #10
    BANNED
    Join Date
    Feb 2002
    Posts
    656

    Default

    What is /etc/apf?

    I don't have that.

    How do i get it? I am assuming its a firewall of some sort.

    Add any IP address that you want to be ignored from the rules.
    If your server provider is doing monitoring add their IP(s) here.
    Since you need these IPs open in APF as well you cancopy the IPs you used in APF
    Type: pico -w /etc/apf/allow_hosts.rules
    Then scroll down to the bottom and copy those IPs (drag mouse over that's it)
    Press: CTRL-X

  11. #11
    Member
    Join Date
    Jul 2002
    Location
    Canada
    Posts
    675

    Default

    Abe,

    /etc/apf refers that you have the APF firewall installed on your server. For a full install guide please read this: http://www.webhostgear.com/61.html
    Upload Guardian 2.0 - Sign up for our early beta
    ServerProgress - Server security, consulting and assistance

  12. #12
    BANNED
    Join Date
    Feb 2002
    Posts
    656

    Default

    What is better Snort or LIDS and why?
    What is better Snort or LIDS and why? Is snort compiled into the kernel?

    What are gresecurity and pax? http://pax.grsecurity.net/
    Can you use those together with Snort and lids?

Similar Threads & Tags
Similar threads

  1. PHP-Intrusion Detection System
    By MiCR0 in forum cPanel Developers
    Replies: 3
    Last Post: 07-25-2009, 10:35 PM
  2. Intrusion Detection cpanel
    By liang3391 in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 06-17-2009, 09:27 AM
  3. What is a good intrusion detection system I can use for my cpanel server?
    By BianchiDude in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 12-14-2007, 08:46 PM
  4. Is this the right kind of program for a Realty web site?
    By Brayton17 in forum Database Discussions
    Replies: 6
    Last Post: 11-16-2006, 12:17 PM
  5. AIDE - Advanced Intrusion Detection Environment
    By sh4ka in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 09-06-2005, 05:32 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube