Code Newbie
News     Forums     Search     Members     Sign Up    

My Code Newbie
Username

Password

Articles/Snippets
ASP Classic
ASP.NET
C
C#
C++
HTML / CSS
Java
Javascript
Linux / BSD
Perl
PHP
Python
Ruby
SQL
VB 6
VB.NET

C.N. Friends
  Planet Rome

Link to Us!
Code Newbie
  Code Newbie
    forums
Old 05-10-2005, 04:33 AM   #1 (permalink)
Gillette
I r 1337 h4x0r?
 
Join Date: May 2005
Posts: 12
Gillette is on a distinguished road
Snort

Pretty soon I'll be setting up a SNORT box as (the main) part of an IDS system, I've read that FreeBSD is one of the best *nix flavours to do this with, but I am open to input.
Gillette is offline   Reply With Quote
Old 05-10-2005, 05:10 AM   #2 (permalink)
redhead
Newbie
 
redhead's Avatar
 
Join Date: Jun 2002
Location: Denmark
Posts: 1,712
redhead is on a distinguished road
What you want with snort, is basicaly a machine that will handle a vast amount of network trafic without seeming to slow the network activity down..
*BSD's network-stack was previusly a great deal faster than the linux stack, but since kernel 2.6.x theres virtualy not much difference between the two.
But since once uppon a time in the west.. the prefered system used to be *BSD, the implementation is widely performed on *BSD boxes.

(I hope KK want's to dip in on this)
__________________
Don't worry Ma'am, We're university students, We know what We're doing.
-----
If you pull the pin, Mr.Grenade would no longer be your friend.
-----
01000111 01101111 00100000 01000011 00100000 00100001
redhead is offline   Reply With Quote
Old 05-15-2005, 10:05 PM   #3 (permalink)
Kernel_Killer
Regular Contributor
 
Kernel_Killer's Avatar
 
Join Date: Feb 2003
Location: indisclosed
Posts: 210
Kernel_Killer is on a distinguished road
A Snort/Barnyard/MySQL/Sguil setup is a good one to do if you want to have a major IDS. Have the exact setup in FreeBSD. Considering the dependant packages having the FreeBSD ports, OpenBSD ports, or Gentoo ports can make for a good quick install. If you don't use Sguil, or use ACID, the dependant packages are less.
__________________
Network Synapse
Screaming Electron
Kernel_Killer is offline   Reply With Quote
Old 05-18-2005, 04:26 AM   #4 (permalink)
Gillette
I r 1337 h4x0r?
 
Join Date: May 2005
Posts: 12
Gillette is on a distinguished road
As far as I know we're only going to be putting SNORT on this box... We might end up using FC3, but I'll take a look at *BSD offerings.
Gillette is offline   Reply With Quote
Old 05-19-2005, 06:35 PM   #5 (permalink)
Kernel_Killer
Regular Contributor
 
Kernel_Killer's Avatar
 
Join Date: Feb 2003
Location: indisclosed
Posts: 210
Kernel_Killer is on a distinguished road
You could do the exact same setup on FC3 as well. One good thing about RH is that it has those deps in the CDs and not by crazy proprietary names like other distros.
__________________
Network Synapse
Screaming Electron
Kernel_Killer is offline   Reply With Quote
Old 05-20-2005, 04:50 AM   #6 (permalink)
Gillette
I r 1337 h4x0r?
 
Join Date: May 2005
Posts: 12
Gillette is on a distinguished road
Update: We're starting work on the box today, under FreeBSD 5.3. If things aren't smooth with that, chances are we'll be moving to FC3.
Gillette is offline   Reply With Quote
Old 05-20-2005, 08:02 PM   #7 (permalink)
Kernel_Killer
Regular Contributor
 
Kernel_Killer's Avatar
 
Join Date: Feb 2003
Location: indisclosed
Posts: 210
Kernel_Killer is on a distinguished road
If you have any questions/troubles you can always hit the Screaming Electron link my signature. There are quite a few of us that have set this particular setup in FreeBSD, and we hold a How-To as well. (sde, not trying to spam or anything. You go there too. )
__________________
Network Synapse
Screaming Electron
Kernel_Killer is offline   Reply With Quote
Old 05-25-2005, 08:34 AM   #8 (permalink)
Gillette
I r 1337 h4x0r?
 
Join Date: May 2005
Posts: 12
Gillette is on a distinguished road
After having way too much trouble getting a simple usb thumbdrive mounted in FreeBSD, I decided to scrap that and just dump Slack 10.0 on there... I know my way around it pretty well, so I don't forsee any problems there.
Gillette is offline   Reply With Quote
Old 05-25-2005, 10:21 PM   #9 (permalink)
Kernel_Killer
Regular Contributor
 
Kernel_Killer's Avatar
 
Join Date: Feb 2003
Location: indisclosed
Posts: 210
Kernel_Killer is on a distinguished road
Cool. Hope everything goes well there. BTW, to mount in FBSD, your device is a "da" drive.

mount -t msdos /dev/da0s1 /mnt/flash

I know you aren't using anymore, but never hurts to have a reference documented.
__________________
Network Synapse
Screaming Electron
Kernel_Killer is offline   Reply With Quote
Old 07-04-2005, 05:12 AM   #10 (permalink)
Gillette
I r 1337 h4x0r?
 
Join Date: May 2005
Posts: 12
Gillette is on a distinguished road
Wow... That's quite possibly the least sensical thing I've ever seen! Why on earth would it be called da!?

Anyway, thanks for the info.

Our SNORT box is rolling logs on a certain ruleset right now and is working very smoothly!
Gillette is offline   Reply With Quote
Old 07-04-2005, 08:54 AM   #11 (permalink)
idx
Senior Grasshopper
 
idx's Avatar
 
Join Date: Jun 2003
Location: FL
Posts: 317
idx is on a distinguished road
da - probably the driver name just as the network cards aren't all ethX. (I hate that in linux)

-r
idx is offline   Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -8. The time now is 04:11 AM.


Powered by vBulletin® Version 3.7.0
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0 RC8





Copyright © 2000-2008, Milano Interactive
Web Hosting provided by Portal 360 Web Hosting