home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!ukma!darwin.sura.net!jvnc.net!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: spaf@cs.purdue.EDU (Gene Spafford)
- Newsgroups: comp.virus
- Subject: Tripwire release (UNIX)
- Message-ID: <0018.9211101922.AA06969@barnabas.cert.org>
- Date: 3 Nov 92 22:14:09 GMT
- Sender: virus-l@lehigh.edu
- Lines: 57
- Approved: news@netnews.cc.lehigh.edu
-
- This is to announce the first public release of "Tripwire."
-
- Tripwire is an integrity-monitor for Unix systems. It uses several
- checksum/signature routines to detect changes to files, as well as
- monitoring selected items of system-maintained information. The
- system also monitors for changes in permissions, links, and sizes of
- files and directories. It can be made to detect additions or
- deletions of files from watched directories.
-
- The configuration of Tripwire is such that the system/security
- administrator can easily specify files and directories to be monitored
- or to be excluded from monitoring, and to specify files which are
- allowed limited changes without generating a warning. Tripwire can
- also be configured with customized signature routines for
- site-specific checks.
-
- Tripwire, once installed on a clean system, can detect changes from
- intruder activity, unauthorized modification of files to introduce
- backdoor or logic-bomb code, (if any were to exist) virus activity in
- the Unix environment.
-
- Tripwire is provided as source code with documentation. The system,
- as delivered, performs no changes to system files and does not require
- root privilege to run (in the general case). The code has been
- beta-tested in a form close to that of this release at over 100 sites
- world-wide. Tripwire should work on almost any version of Unix, from
- Xenix on 80386-based machines to Cray and ETA-10 supercomputers.
-
- Tripwire may be used without charge, but it may not be sold or
- modified for sale. Tripwire was written as a project under the
- auspices of the COAST Project at Purdue University. The primary
- author was Gene Kim, with the aid and under the direction of Gene
- Spafford (COAST director).
-
- Copies of the Tripwire distribution may be ftp'd from
- ftp.cs.purdue.edu from the directory pub/spaf/COAST/Tripwire. The
- distribution is available as a compressed tar file, and as
- uncompressed shar kits. The shar kit form of Tripwire version 1.0
- will also be posted to comp.sources.unix on the Usenet. No mailserver
- access currently exists for distribution, although we expect some
- archive sites with such mechanisms will eventually provide access.
-
- Questions, comments, complaints, bugfixes, etc may be directed to:
- genek@mentor.cc.purdue.edu (Gene Kim)
- spaf@cs.purdue.edu (Gene Spafford)
-
- 3 November 1992
-
- [Moderator's note: Did you choose that date on purpose, Spaf? Some
- VIRUS-L readers may remember the historical significance of November
- 3rd...]
-
- - --
- Gene Spafford
- Software Engineering Research Center & Dept. of Computer Sciences
- Purdue University, W. Lafayette IN 47907-1398
- Internet: spaf@cs.purdue.edu phone: (317) 494-7825
-