Categories

Intrusion Detection Software Upgrade

Posted: 8:49am Thursday November 30 2006

Category: Security

The ol' (open source) Tripwire was getting long on the tooth (and it doesn't run under RHEL4/SL4) so I recently rolled out AIDE. It's pretty much a drop in replacement for Tripwire--at least I was able to write a script to munge it's output into Tripwire style output so our existing IDS and meta file integrity checking systems don't need upgrading.


Arghh!

Posted: 5:00pm Friday October 21 2005

Category: Security

One of the internal UW-HEP servers was compromised today. Fortunately, our intrusion detection system altered me--rather alerted me--to the problem about seven minutes after the break-in. Those hackers are, just, just "bastard people". Anyway, today was spent upgrading said server.


Digitally Signed Messages

Posted: 5:00pm Monday June 06 2005

Categories: Mail, Security

Effective immediately, all important emails regarding UW-HEP computing will be digitally signed: they will have a MIME attachment (PGP.sig) that contains a PGP signature, and a URL telling you where to find the appropriate public PGP key.


Compromised Mac

Posted: 5:00pm Tuesday May 24 2005

Category: Security

One of our OS-X Mac systems was broken into recently. The intruders installed two suspect software packages: "Energy Mech" (an IRC bot) was installed in /var/tmp/www and "psyBNC" (also IRC software) was installed in /var/tmp/nsmail. The resulting IRC chatter caused the system to be blackholed by the campus IT folks. Joy.


Acceptable Use

Posted: 5:00pm Thursday March 03 2005

Category: Security

I sent a message around today reminding everyone that the UW-HEP computing facilities are subject to the University of Wisconsin's Acceptable Use Policy...

http://www.doit.wisc.edu/security/policies/appropriate_use.asp

Please be mindful of these facts:

- you may not use the UW-HEP computing facilities to violate State or federal laws.

- you may not use the UW-HEP computing facilities to share unauthorized copyrighted materials

- you must exercise reasonable care to insure that others cannot use your account(s)

- you may not share your password(s) with anyone


Compromised Account

Posted: 5:00pm Friday February 18 2005

Category: Security

A couple of user accounts where compromised recently. The intruders ran running some sort of IRC (internet relay chat) proxy software. Fortunately our systems rely on AFS authentification and thus don't house individual passwords.


Search

Other Links