<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="FeedCreator 1.8" -->
<?xml-stylesheet href="https://wiki.itadmins.net/lib/exe/css.php?s=feed" type="text/css"?>
<rdf:RDF
    xmlns="http://purl.org/rss/1.0/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
    xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel rdf:about="https://wiki.itadmins.net/feed.php">
        <title>Chucks notes and stuff - security</title>
        <description></description>
        <link>https://wiki.itadmins.net/</link>
        <image rdf:resource="https://wiki.itadmins.net/lib/exe/fetch.php?media=wiki:dokuwiki.svg" />
       <dc:date>2026-05-23T10:54:06+00:00</dc:date>
        <items>
            <rdf:Seq>
                <rdf:li rdf:resource="https://wiki.itadmins.net/doku.php?id=security:centralized_tripwire&amp;rev=1582539361&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.itadmins.net/doku.php?id=security:communityid_openid&amp;rev=1582539361&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.itadmins.net/doku.php?id=security:iptables&amp;rev=1582539361&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.itadmins.net/doku.php?id=security:iwatch&amp;rev=1582539361&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.itadmins.net/doku.php?id=security:logcheck&amp;rev=1582539361&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.itadmins.net/doku.php?id=security:opnsense&amp;rev=1775661950&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.itadmins.net/doku.php?id=security:rkhunter&amp;rev=1582539361&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.itadmins.net/doku.php?id=security:server_solution&amp;rev=1582539361&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.itadmins.net/doku.php?id=security:siemonster-suricata&amp;rev=1775654007&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.itadmins.net/doku.php?id=security:tiger&amp;rev=1582539361&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.itadmins.net/doku.php?id=security:tripwire&amp;rev=1582539361&amp;do=diff"/>
            </rdf:Seq>
        </items>
    </channel>
    <image rdf:about="https://wiki.itadmins.net/lib/exe/fetch.php?media=wiki:dokuwiki.svg">
        <title>Chucks notes and stuff</title>
        <link>https://wiki.itadmins.net/</link>
        <url>https://wiki.itadmins.net/lib/exe/fetch.php?media=wiki:dokuwiki.svg</url>
    </image>
    <item rdf:about="https://wiki.itadmins.net/doku.php?id=security:centralized_tripwire&amp;rev=1582539361&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2020-02-24T10:16:01+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>centralized_tripwire</title>
        <link>https://wiki.itadmins.net/doku.php?id=security:centralized_tripwire&amp;rev=1582539361&amp;do=diff</link>
        <description>Centralized Intrusion Detection Using Tripwire

;#;
Large portions of this text was originally published by: Yunliang Yu &lt;yu@math.duke.edu&gt; from Duke University
my changes are published here for reference only and is a work in progress to bring this up to date.
;#;

Summary:</description>
    </item>
    <item rdf:about="https://wiki.itadmins.net/doku.php?id=security:communityid_openid&amp;rev=1582539361&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2020-02-24T10:16:01+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>communityid_openid</title>
        <link>https://wiki.itadmins.net/doku.php?id=security:communityid_openid&amp;rev=1582539361&amp;do=diff</link>
        <description>How to install Community-ID 2.0.0 RC3

The official site of Community-ID (Offline) New official site of Community-ID offers a series of simple tutorials for installation of the service but as of version 2.0.0 the installation process has changed a bit. This little howto is constructed from a tutorial that was based on the original tutorial modified and translating it into Spanish (by</description>
    </item>
    <item rdf:about="https://wiki.itadmins.net/doku.php?id=security:iptables&amp;rev=1582539361&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2020-02-24T10:16:01+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>iptables</title>
        <link>https://wiki.itadmins.net/doku.php?id=security:iptables&amp;rev=1582539361&amp;do=diff</link>
        <description>IPTables Tweeks

ICMP Redirecting

This error was driving me nuts for a while:


Jan 29 15:11:45 zcn1 kernel: host 10.1.0.52/if5 ignores redirects for 10.1.0.51 to 10.1.0.51.
Jan 29 15:21:45 zcn1 kernel: host 10.1.0.52/if5 ignores redirects for 10.1.0.51 to 10.1.0.51.
Jan 29 15:31:45 zcn1 kernel: host 10.1.0.52/if5 ignores redirects for 10.1.0.51 to 10.1.0.51.
Jan 29 15:41:45 zcn1 kernel: host 10.1.0.52/if5 ignores redirects for 10.1.0.51 to 10.1.0.51.
Jan 29 15:51:45 zcn1 kernel: host 10.1.0.52…</description>
    </item>
    <item rdf:about="https://wiki.itadmins.net/doku.php?id=security:iwatch&amp;rev=1582539361&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2020-02-24T10:16:01+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>iwatch</title>
        <link>https://wiki.itadmins.net/doku.php?id=security:iwatch&amp;rev=1582539361&amp;do=diff</link>
        <description>IWatch

With the introduction of IWatch things start to really get interesting in the world of live security monitoring. Unfortunately the documentation is VERY poor in one area.

Generally you can watch a directory and send notifications as soon as anything happens, and you can monitor processes and get notified as soon as a process dies or you can monitor a log file and get notified when something with the file happens. For example, let&#039;s monitor the /etc directory recursively for any changes:</description>
    </item>
    <item rdf:about="https://wiki.itadmins.net/doku.php?id=security:logcheck&amp;rev=1582539361&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2020-02-24T10:16:01+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>logcheck</title>
        <link>https://wiki.itadmins.net/doku.php?id=security:logcheck&amp;rev=1582539361&amp;do=diff</link>
        <description>Logcheck Tweeks

RSyslogd

The rsyslogd syslog entries as follows will cause the default install of logcheck to trip:


Sep 18 06:25:01 zcn1 kernel: imklog 3.18.6, log source = /proc/kmsg started.
Sep 18 06:25:01 zcn1 rsyslogd: [origin software=&quot;rsyslogd&quot; swVersion=&quot;3.18.6&quot; x-pid=&quot;2097&quot; x-info=&quot;http://www.rsyslog.com&quot;] restart</description>
    </item>
    <item rdf:about="https://wiki.itadmins.net/doku.php?id=security:opnsense&amp;rev=1775661950&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2026-04-08T15:25:50+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>opnsense</title>
        <link>https://wiki.itadmins.net/doku.php?id=security:opnsense&amp;rev=1775661950&amp;do=diff</link>
        <description>OPNSense Extras

Rollback to previous stable version

This will rollback a production system to the last good version of OPNSense while keeping all configs.

sh /usr/local/sbin/opnsense-bootstrap

Search for package from cli

pkg search packagename

Install package from cli</description>
    </item>
    <item rdf:about="https://wiki.itadmins.net/doku.php?id=security:rkhunter&amp;rev=1582539361&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2020-02-24T10:16:01+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>rkhunter</title>
        <link>https://wiki.itadmins.net/doku.php?id=security:rkhunter&amp;rev=1582539361&amp;do=diff</link>
        <description>RootKit Hunter (rkhunter) tips

Missing Kernel modules warning

For those of you getting the following warning on Debian systems:


Warning: The kernel modules directory &#039;/lib/modules&#039; is missing or empty.


This is due to the fact that your kernel does support modules but there are none actually on the system and so rkhunter thinks there MAY be a problem.  To get rid of the warning simple edit /etc/rkhunter.conf and change:</description>
    </item>
    <item rdf:about="https://wiki.itadmins.net/doku.php?id=security:server_solution&amp;rev=1582539361&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2020-02-24T10:16:01+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>server_solution</title>
        <link>https://wiki.itadmins.net/doku.php?id=security:server_solution&amp;rev=1582539361&amp;do=diff</link>
        <description>Server Solution 1

Overview

	*  Log analysis/monitoring: Logdog/Logsurfer+/Logwatch
	*  Rootkit/bot monitoring: rkhunter + chkrootkit
	*  Preemptive Firewalling: Denyhosts
	*  HIDS:
		*  Tripwire &amp; AIDE
		*  Tripwire w/ tripwire monitoring &amp; centralized control (OSSIM server)</description>
    </item>
    <item rdf:about="https://wiki.itadmins.net/doku.php?id=security:siemonster-suricata&amp;rev=1775654007&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2026-04-08T13:13:27+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>siemonster-suricata</title>
        <link>https://wiki.itadmins.net/doku.php?id=security:siemonster-suricata&amp;rev=1775654007&amp;do=diff</link>
        <description>Siemonster Suricata Integration

	*  UPDATE 1: Uploaded correct Logstash configs..
	*  UPDATE 2: Uploaded corrected Logstash Suricata Stats template.

After using OSSIM for years I was excited to hear about the release of Siemonster. Performance of the Community Edition of OSSIM is, and always was, a major problem for me.</description>
    </item>
    <item rdf:about="https://wiki.itadmins.net/doku.php?id=security:tiger&amp;rev=1582539361&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2020-02-24T10:16:01+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>tiger</title>
        <link>https://wiki.itadmins.net/doku.php?id=security:tiger&amp;rev=1582539361&amp;do=diff</link>
        <description>Tiger Scanner

cgroup FS warnings

I have a few servers running Tiger that were installed before I took over the IT Department where I work. These servers also run LXC and use the cgroup “filesystem” type and thus Tiger has a problem whenever it runs it&#039;s checks throwing the following error and thus making Cron send a mail about the situation:</description>
    </item>
    <item rdf:about="https://wiki.itadmins.net/doku.php?id=security:tripwire&amp;rev=1582539361&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2020-02-24T10:16:01+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>tripwire</title>
        <link>https://wiki.itadmins.net/doku.php?id=security:tripwire&amp;rev=1582539361&amp;do=diff</link>
        <description>Tripwire

1. Install Tripwire

apt-get install tripwire

	*  Site passphrase will secure the tw.cfg tripwire configuration file and tw.pol tripwire policy file. You have to assign a site passphrase even for a single instance tripwire.
	*  Local passphrase will protect tripwire database and report files.</description>
    </item>
</rdf:RDF>
