Posts Tagged ‘TripWire’

Tripwire ConfigCheck

Tuesday, June 17th, 2008

I was looking for an app that would investigate an ESX host that wasn’t configured by me to see how much work would be needed to secure it.

I found Tripwire’s ConfigCheck java app an absolute cracker.  As Michael Parkinson would say its simplicity is its genius.

Provide hostname, username and password and wait for a minute or so for ConfigCheck to analyse the security of the host.  A list of all the areas checked is displayed with either a pass or a fail.

This is all great, but what is even better is the fact that upon completion of the tests you are offered the opportunity to download a remediation document.  This 52 page document outlines why a particular test failed and how to fix the problem.

You can download ConfigCheck here, and the remediation guide here.