Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 37 guests online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
Honeypot and IDS
EH-Net
May 23, 2013, 11:13:50 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
Honeypot and IDS
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Honeypot and IDS (Read 8995 times)
0 Members and 1 Guest are viewing this topic.
Determ
Newbie
Offline
Posts: 23
Honeypot and IDS
«
on:
July 15, 2010, 05:59:01 AM »
Hello.
I want to set up two devices. First will be honeypot. I think about setting up HoneyBot on WinXP box. First I thought to made Honeyd, but I don't find it useful to much. Does anybody heard for HOACD and has experience with it?
I also want to set up one Network IDS. I think that Snort is to hard to implement for me, so I think on Bro-IDS. Did anyone set it up already?
Logged
Ketchup
Hero Member
Offline
Posts: 1021
Re: Honeypot and IDS
«
Reply #1 on:
July 16, 2010, 05:51:00 PM »
I don't have experience with either of the honeypot packages.
I have used both Snort and Bro-IDS. If you are going to use Bro-IDS, use BSD as the OS. The documentation for Bro is quite bad for anything other than BSD. I had quite a few issues getting it up and running. I couldn't get any sort database logging going at all. It performed reasonably well, but I found it detected much less than Snort. It was also inconsistent. I put it through quite a few tests. In general, i wouldn't recommend this product from personal experience.
Snort, is much easier to configure. I had it running on Redhat and Ubuntu boxes without any issues. Most distributions even include it as package. Database integration was also easy to configure and well documented. The most difficult part is learning the exception, processor, and rules syntax. If you get stuck, pick up the "Snort IDS and IPS Toolkit" book. Also, make sure that you install a front-end for Snort, otherwise you will end up managing it through config files only. Snort, has much better documentation and much more support in the community. I would go with Snort.
Finally, you can look into the OSSIM package, which includes Snort, Arpwatch, Nessus, and a bunch of other tools. It's a good security management console.
http://www.alienvault.com/community.php?section=Home
Logged
~~~~~~~~~~~~~~
Ketchup
chrisj
Hero Member
Offline
Posts: 1163
Re: Honeypot and IDS
«
Reply #2 on:
July 16, 2010, 08:05:34 PM »
I've just spent the last few days building a box to monitor the network. Running syslog, bandwidthd, ntop, nagios, arpwatch, and wireshark. I used 1 book to help me get things set up. (Still have to finish setting up Nagios).
See if you're local library has Network Security Hacks. It talks about all the things you've wanted to do. The second edition chapter 11 goes through a lot for what you'll need to get Snort running, and honeyd.
If I get time in the near future, I'm going back to deal with snort, and get that running on the box too.
Logged
OSWP, Sec+
Determ
Newbie
Offline
Posts: 23
Re: Honeypot and IDS
«
Reply #3 on:
July 18, 2010, 12:32:46 PM »
Thanks for response. Yesterday I set up Ossec HIDS, but I'm not sure if it is useful. Modern internet security programs have some kind of "hids" already built in. And I think that HIDS is only useful for client host.
I also played with HoneyBOT, and it is cool, but to easy in some way. Do you know any european producer of modern honeypots and honeypot's like IDS software?
I checked OSSIM. It looks great. If I understood correctly, is all in one platform. But tell me, does make some program settings easier? Or will I have to spend few days configuring different programs which comes with OSSIM?
Logged
Ketchup
Hero Member
Offline
Posts: 1021
Re: Honeypot and IDS
«
Reply #4 on:
July 18, 2010, 03:11:12 PM »
OSSIM has a nice web-based management console. It will let you management everything from a single point. You will still need to tune Snort. I have yet to install any IDS and have it be useful out of the box. In most cases, you will just turn on and turn off rules packages that make sense for your environment. OSSIM should make this easier for you.
Logged
~~~~~~~~~~~~~~
Ketchup
mambru
Jr. Member
Offline
Posts: 98
Re: Honeypot and IDS
«
Reply #5 on:
July 19, 2010, 10:39:45 AM »
For an IDS, take a look at Suricata
http://www.openinfosecfoundation.org/
Logged
Determ
Newbie
Offline
Posts: 23
Re: Honeypot and IDS
«
Reply #6 on:
August 26, 2010, 03:02:31 AM »
I have heard lot about Suricata...Maybe they should set up web forum for users and those who want to give it a try. Also some tutorials would be great.
I plan to start with OSSIM in next two months. I will need to buy one used machine for that purpose. Otherwise I always read documentation first and look for some good tutorial or reviews.
One more question: Did anyone work on securing SCADA? What I mean is a small scada, which runs in small facilities. It is possible, that I will work on one project about protecting SCADA environtmen. For now I was thinking about implementing Host IDS and remote logs reading.
Logged
sil
Hero Member
Offline
Posts: 549
Re: Honeypot and IDS
«
Reply #7 on:
August 26, 2010, 07:43:02 AM »
Quote from: Determ on August 26, 2010, 03:02:31 AM
One more question: Did anyone work on securing SCADA? What I mean is a small scada, which runs in small facilities. It is possible, that I will work on one project about protecting SCADA environtmen. For now I was thinking about implementing Host IDS and remote logs reading.
Oh the SCADA PITA environment! I have a client who's one of the many contractors @ a gas plant which had a horrible explosion earlier this year. So I guess to an extent, the answer is yes, however, our testing did NOT include any HMI based controls, etc. For particular questions on that I'd post them to the SCADA mailing list (
http://news.infracritical.com/mailman/listinfo/scadasec
) With that said... Define SCADA.
Pentesting against say the corporate network in a SCADA based environment shouldn't interfere with mission critical controls (theoretically) as the controls infrastructure is usually segregated (theoretically).
Logged
http://www.infiltrated.net/mgz/puppylecter.jpg
mambru
Jr. Member
Offline
Posts: 98
Re: Honeypot and IDS
«
Reply #8 on:
August 26, 2010, 09:42:24 AM »
Quote
I have heard lot about Suricata...Maybe they should set up web forum for users and those who want to give it a try. Also some tutorials would be great.
We are going through the process of creating the documentation, though if you know how to set up Snort, you won't have problems setting up Suricata. If you need further assistance/have questions, there's a mailing list, developers will help you.
Logged
Determ
Newbie
Offline
Posts: 23
Re: Honeypot and IDS
«
Reply #9 on:
August 27, 2010, 05:57:22 AM »
I think about protecting on Operator Work station and HMI Web/DB server level. I believe (but i don't know yet) that Operator Work station isn't segregated from corporate network at small local plants in my area.
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(6) by
azmatt
Greetings
: Hi from the UK
(4) by
MrTuxracer
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(0) by
prats84
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(27) by
don
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.