SlideShare una empresa de Scribd logo
1 de 14
Open Source Tools for the Systems Administrator
Charles Profitt
Why Have Tools?

Sf
Hp
Why Open Source?

Ba

Ss
Cu
Four Tools

Ca

Nm
nmap

Cacti

Os
Ossec

Rt

RackTables
●

Ca

●
●

Cacti is a complete frontend to RRDTool, it stores all of the necessary
information to create graphs and populate them with data in a MySQL database.
The frontend is completely PHP driven. Along with being able to maintain
Graphs, Data Sources, and Round Robin Archives in a database, cacti handles
the data gathering. There is also SNMP support for those used to creating traffic
graphs with MRTG.
Ability to add templates and custom scripts
Maintain historical data and display it visually to vendors and management

Nm
nmap

Cacti

Os
Ossec

Rt

RackTables
Ca
Cacti
●

Os
Ossec

●
●
●

OSSEC is a scalable, multi-platform, open source Host-based Intrusion
Detection System (HIDS). It has a powerful correlation and analysis engine,
integrating log analysis, file integrity checking, Windows registry monitoring,
centralized policy enforcement, rootkit detection, real-time alerting and active
response. It runs on most operating systems, including Linux, OpenBSD,
FreeBSD, MacOS, Solaris and Windows.
Maintains logs beyond what is feasible for Windows to store
Makes searching logs from multiple servers much easier
Alerts can be setup for specific events and customized to go to individuals
responsible
Os
Ossec
Os
Ossec
●

Nm

●
●
●

Nmap ("Network Mapper") is a free and open source (license) utility for
network discovery and security auditing. Many systems and network
administrators also find it useful for tasks such as network inventory, managing
service upgrade schedules, and monitoring host or service uptime. It was
designed to rapidly scan large networks, but works fine against single hosts.
Establish baselines for servers and desktops.
Find intrusions
Ensure compliance

nmap

Nmap scan report for xxx.xxx.xxx.xxx
Host is up (0.0011s latency).
Not shown: 999 closed ports
PORT STATE SERVICE
23/tcp open telnet
Device type: router|WAP
Running: Cisco IOS 12.X
OS details: Cisco 836, 1751, 1841, or 2800 router (IOS 12.4 - 15.0), Cisco Aironet
AIR-AP1141N WAP (IOS 12.4)
Nm
nmap

Nmap scan report for esx01.pcsd.monroe.edu (10.120.254.61)
Host is up (0.00044s latency).
Not shown: 992 filtered ports
PORT STATE SERVICE
80/tcp open http
427/tcp open svrloc
443/tcp open https
902/tcp open iss-realsecure
5988/tcp closed unknown
5989/tcp open unknown
8000/tcp open http-alt
8100/tcp open unknown
Device type: general purpose|storage-misc|specialized
Running (JUST GUESSING) : FreeBSD 7.X|8.X|6.X|5.X|5.x (92%), VMware ESX Server
3.X|4.X (90%), Crestron 2-Series (88%), Mirapoint embedded (87%)
Aggressive OS guesses: FreeBSD 7.0-RELEASE-p1 - 8.0-CURRENT (92%), FreeNAS
0.686 (FreeBSD 6.2-RELEASE) or VMware ESXi Server 3.0 - 4.0 (90%), FreeBSD 5.2.1RELEASE (90%), FreeBSD 5.4 or 5.5 (x86) (90%), FreeNAS 0.69.2 (FreeBSD 6.3STABLE - 6.4-RELEASE) (90%), FreeBSD 7.1-RELEASE (90%), FreeBSD 8.0-BETA2 8.0-RC2 (89%), FreeBSD 7.0-CURRENT (pre-release) (89%), FreeBSD 7.0-RELEASE-p2 7.1-PRERELEASE (89%), FreeBSD 7.2-STABLE (89%)
No exact OS matches for host (test conditions non-ideal).
●

●
●

Rt

RackTables

●
●
●

Racktables is a nifty and robust solution for data center and server room asset
management. It helps document hardware assets, network addresses, space in
racks, networks configuration and much much more!
Document your servers both physical and virtual
Document networks
Generate reports
Maintain visual diagrams of rack placement
Embed Cacti graphs
●
●
●
●

Rt

RackTables

●
●
●

Drill down
Filter
Front, middle and back rack slots
Automated rack slots (42 - default)
Warranty dates
Support contact information
Asset management data
Questions

?

?
?

?

Más contenido relacionado

Similar a Open Source Tools for the Systems Administrator

breed_python_tx_redacted
breed_python_tx_redactedbreed_python_tx_redacted
breed_python_tx_redacted
Ryan Breed
 
IRATI: an open source RINA implementation for Linux/OS
IRATI: an open source RINA implementation for Linux/OSIRATI: an open source RINA implementation for Linux/OS
IRATI: an open source RINA implementation for Linux/OS
ICT PRISTINE
 
10 years in Network Protocol testing L2 L3 L4-L7 Tcl Python Manual and Automa...
10 years in Network Protocol testing L2 L3 L4-L7 Tcl Python Manual and Automa...10 years in Network Protocol testing L2 L3 L4-L7 Tcl Python Manual and Automa...
10 years in Network Protocol testing L2 L3 L4-L7 Tcl Python Manual and Automa...
Mullaiselvan Mohan
 
Splunk app for stream
Splunk app for stream Splunk app for stream
Splunk app for stream
csching
 

Similar a Open Source Tools for the Systems Administrator (20)

breed_python_tx_redacted
breed_python_tx_redactedbreed_python_tx_redacted
breed_python_tx_redacted
 
an_introduction_to_network_analyzers_new.ppt
an_introduction_to_network_analyzers_new.pptan_introduction_to_network_analyzers_new.ppt
an_introduction_to_network_analyzers_new.ppt
 
NetFlow Monitoring for Cyber Threat Defense
NetFlow Monitoring for Cyber Threat DefenseNetFlow Monitoring for Cyber Threat Defense
NetFlow Monitoring for Cyber Threat Defense
 
wireshark.pdf
wireshark.pdfwireshark.pdf
wireshark.pdf
 
Crypt tech technical-presales
Crypt tech technical-presalesCrypt tech technical-presales
Crypt tech technical-presales
 
project_docs
project_docsproject_docs
project_docs
 
Snabbflow: A Scalable IPFIX exporter
Snabbflow: A Scalable IPFIX exporterSnabbflow: A Scalable IPFIX exporter
Snabbflow: A Scalable IPFIX exporter
 
D. Fast, Simple User-Space Network Functions with Snabb (RIPE 77)
D. Fast, Simple User-Space Network Functions with Snabb (RIPE 77)D. Fast, Simple User-Space Network Functions with Snabb (RIPE 77)
D. Fast, Simple User-Space Network Functions with Snabb (RIPE 77)
 
Cisco Stealtwatch
Cisco StealtwatchCisco Stealtwatch
Cisco Stealtwatch
 
NkSIP: The Erlang SIP application server
NkSIP: The Erlang SIP application serverNkSIP: The Erlang SIP application server
NkSIP: The Erlang SIP application server
 
Dimitri Bellini - Monitoring Large Multi-Site Data Environment
Dimitri Bellini - Monitoring Large Multi-Site Data EnvironmentDimitri Bellini - Monitoring Large Multi-Site Data Environment
Dimitri Bellini - Monitoring Large Multi-Site Data Environment
 
IRATI: an open source RINA implementation for Linux/OS
IRATI: an open source RINA implementation for Linux/OSIRATI: an open source RINA implementation for Linux/OS
IRATI: an open source RINA implementation for Linux/OS
 
10 years in Network Protocol testing L2 L3 L4-L7 Tcl Python Manual and Automa...
10 years in Network Protocol testing L2 L3 L4-L7 Tcl Python Manual and Automa...10 years in Network Protocol testing L2 L3 L4-L7 Tcl Python Manual and Automa...
10 years in Network Protocol testing L2 L3 L4-L7 Tcl Python Manual and Automa...
 
Leverage the Network to Detect and Manage Threats
Leverage the Network to Detect and Manage ThreatsLeverage the Network to Detect and Manage Threats
Leverage the Network to Detect and Manage Threats
 
2014 carlos gzlez florido nksip the erlang sip application server
2014 carlos gzlez florido nksip the erlang sip application server2014 carlos gzlez florido nksip the erlang sip application server
2014 carlos gzlez florido nksip the erlang sip application server
 
MMIX Peering Forum and MMNOG 2020: Packet Analysis for Network Security
MMIX Peering Forum and MMNOG 2020: Packet Analysis for Network SecurityMMIX Peering Forum and MMNOG 2020: Packet Analysis for Network Security
MMIX Peering Forum and MMNOG 2020: Packet Analysis for Network Security
 
Network Security and Visibility through NetFlow
Network Security and Visibility through NetFlowNetwork Security and Visibility through NetFlow
Network Security and Visibility through NetFlow
 
Splunk app for stream
Splunk app for stream Splunk app for stream
Splunk app for stream
 
OpManager - Technical overview
OpManager - Technical overviewOpManager - Technical overview
OpManager - Technical overview
 
Low cost multi-sensor IDS system
Low cost multi-sensor IDS systemLow cost multi-sensor IDS system
Low cost multi-sensor IDS system
 

Más de Charles Profitt (6)

Ed tech 2009
Ed tech 2009Ed tech 2009
Ed tech 2009
 
Ed techday 2011
Ed techday 2011Ed techday 2011
Ed techday 2011
 
NYSCATE 2010
NYSCATE 2010NYSCATE 2010
NYSCATE 2010
 
Launch
LaunchLaunch
Launch
 
Fosscon
FossconFosscon
Fosscon
 
FOSS and ISTE 21st Century Skills (Educational Technology)
FOSS and ISTE 21st Century Skills (Educational Technology)FOSS and ISTE 21st Century Skills (Educational Technology)
FOSS and ISTE 21st Century Skills (Educational Technology)
 

Último

Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
vu2urc
 

Último (20)

TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Developing An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of BrazilDeveloping An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of Brazil
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 

Open Source Tools for the Systems Administrator

  • 1. Open Source Tools for the Systems Administrator Charles Profitt
  • 5. ● Ca ● ● Cacti is a complete frontend to RRDTool, it stores all of the necessary information to create graphs and populate them with data in a MySQL database. The frontend is completely PHP driven. Along with being able to maintain Graphs, Data Sources, and Round Robin Archives in a database, cacti handles the data gathering. There is also SNMP support for those used to creating traffic graphs with MRTG. Ability to add templates and custom scripts Maintain historical data and display it visually to vendors and management Nm nmap Cacti Os Ossec Rt RackTables
  • 7. ● Os Ossec ● ● ● OSSEC is a scalable, multi-platform, open source Host-based Intrusion Detection System (HIDS). It has a powerful correlation and analysis engine, integrating log analysis, file integrity checking, Windows registry monitoring, centralized policy enforcement, rootkit detection, real-time alerting and active response. It runs on most operating systems, including Linux, OpenBSD, FreeBSD, MacOS, Solaris and Windows. Maintains logs beyond what is feasible for Windows to store Makes searching logs from multiple servers much easier Alerts can be setup for specific events and customized to go to individuals responsible
  • 10. ● Nm ● ● ● Nmap ("Network Mapper") is a free and open source (license) utility for network discovery and security auditing. Many systems and network administrators also find it useful for tasks such as network inventory, managing service upgrade schedules, and monitoring host or service uptime. It was designed to rapidly scan large networks, but works fine against single hosts. Establish baselines for servers and desktops. Find intrusions Ensure compliance nmap Nmap scan report for xxx.xxx.xxx.xxx Host is up (0.0011s latency). Not shown: 999 closed ports PORT STATE SERVICE 23/tcp open telnet Device type: router|WAP Running: Cisco IOS 12.X OS details: Cisco 836, 1751, 1841, or 2800 router (IOS 12.4 - 15.0), Cisco Aironet AIR-AP1141N WAP (IOS 12.4)
  • 11. Nm nmap Nmap scan report for esx01.pcsd.monroe.edu (10.120.254.61) Host is up (0.00044s latency). Not shown: 992 filtered ports PORT STATE SERVICE 80/tcp open http 427/tcp open svrloc 443/tcp open https 902/tcp open iss-realsecure 5988/tcp closed unknown 5989/tcp open unknown 8000/tcp open http-alt 8100/tcp open unknown Device type: general purpose|storage-misc|specialized Running (JUST GUESSING) : FreeBSD 7.X|8.X|6.X|5.X|5.x (92%), VMware ESX Server 3.X|4.X (90%), Crestron 2-Series (88%), Mirapoint embedded (87%) Aggressive OS guesses: FreeBSD 7.0-RELEASE-p1 - 8.0-CURRENT (92%), FreeNAS 0.686 (FreeBSD 6.2-RELEASE) or VMware ESXi Server 3.0 - 4.0 (90%), FreeBSD 5.2.1RELEASE (90%), FreeBSD 5.4 or 5.5 (x86) (90%), FreeNAS 0.69.2 (FreeBSD 6.3STABLE - 6.4-RELEASE) (90%), FreeBSD 7.1-RELEASE (90%), FreeBSD 8.0-BETA2 8.0-RC2 (89%), FreeBSD 7.0-CURRENT (pre-release) (89%), FreeBSD 7.0-RELEASE-p2 7.1-PRERELEASE (89%), FreeBSD 7.2-STABLE (89%) No exact OS matches for host (test conditions non-ideal).
  • 12. ● ● ● Rt RackTables ● ● ● Racktables is a nifty and robust solution for data center and server room asset management. It helps document hardware assets, network addresses, space in racks, networks configuration and much much more! Document your servers both physical and virtual Document networks Generate reports Maintain visual diagrams of rack placement Embed Cacti graphs
  • 13. ● ● ● ● Rt RackTables ● ● ● Drill down Filter Front, middle and back rack slots Automated rack slots (42 - default) Warranty dates Support contact information Asset management data