Actually I do run tripwire - and I started the day after I found that break-in (which happened about two years ago). It's a pain in the butt, but it makes me feel much better.
One other thing I do is to run top and other utilities that the simpler crackers can't reliably modify. The cracker that got me had a "root kit" that modified ps (which shows active processes), ls (file directories), and a few others. he left his root kit around for me to find and dissect. It was quite an education.
|