FiberOptix
March 16th, 2009, 11:34 PM
Hey all,
I've been working on my snort configuration for a little while now and would like to start using it soon, same goes for ossec-hids. However, despite the fact that these appear to be wonderful tools I'm not crazy about setting up mysql and apache services on a stand-alone laptop just to be able to use BASE and OSSEC-HIDS.
Is there any way to use this great tools without the overhead? Maybe I'm crazy but even if I firewall these services and move them to some non-standard high level ports I still find the cost almost equal to the potential gain.
I've been working on my snort configuration for a little while now and would like to start using it soon, same goes for ossec-hids. However, despite the fact that these appear to be wonderful tools I'm not crazy about setting up mysql and apache services on a stand-alone laptop just to be able to use BASE and OSSEC-HIDS.
Is there any way to use this great tools without the overhead? Maybe I'm crazy but even if I firewall these services and move them to some non-standard high level ports I still find the cost almost equal to the potential gain.