<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-7970604688368987276</id><updated>2012-02-07T06:30:03.278+01:00</updated><category term='Howto´s and Guides'/><category term='Cryptology'/><category term='Switching + Routing'/><category term='Rant (useless crap)'/><title type='text'>Layer 8 Problem</title><subtitle type='html'>A blog that in a best case scenario will solve some layer 8 problems.           In other cases... hmm. Lets leave it at that. Use at your own risk.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://layer8problem.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7970604688368987276/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://layer8problem.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Fourknees</name><uri>http://www.blogger.com/profile/17221216896438461606</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_bZ7EhbBrv3Q/SP-WPaMDNYI/AAAAAAAAABE/ekK5saNOVps/S220/untitled2.GIF'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>8</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7970604688368987276.post-4795473551206827406</id><published>2009-04-08T10:45:00.006+02:00</published><updated>2009-04-08T10:58:34.378+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Switching + Routing'/><title type='text'>New switch stack</title><content type='html'>Today the new switch stack has arrived that will be used for our new datacenter:&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_bZ7EhbBrv3Q/Sdxka83YnJI/AAAAAAAAAG4/Di1gJJk4ORY/s1600-h/20090409094.jpg"&gt;&lt;img src="http://2.bp.blogspot.com/_bZ7EhbBrv3Q/Sdxka83YnJI/AAAAAAAAAG4/Di1gJJk4ORY/s200/20090409094.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5322239273822887058" style="cursor: pointer; width: 200px; height: 150px; " /&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_bZ7EhbBrv3Q/SdxkbNnhHDI/AAAAAAAAAHA/BfNluY73zWw/s1600-h/20090409095.jpg"&gt;&lt;img src="http://4.bp.blogspot.com/_bZ7EhbBrv3Q/SdxkbNnhHDI/AAAAAAAAAHA/BfNluY73zWw/s200/20090409095.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5322239278319737906" style="cursor: pointer; width: 200px; height: 150px; " /&gt;  &lt;/a&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_bZ7EhbBrv3Q/SdxkbNnhHDI/AAAAAAAAAHA/BfNluY73zWw/s1600-h/20090409095.jpg"&gt; &lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Its 4 * Cisco 3750-E with the IPS software. The first impression is that they are high quality switches, even compared to the stable 3560. The stacking cables comes along, one with each switch. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Its also nice that its super easy to get started, just hook up the stacking cables and start the switches and they will auto negotiate which switch will become the master. This can also be changed, for example i wanted the top switch to be the master and the second to be the next master in case of failure so ive set it up like this:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Switch 1 Priority 15&lt;/div&gt;&lt;div&gt;Switch 2 Priority 14&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Switch 3 Priority 1&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Switch 4 Priority 1&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;More about the configuring the Cisco 3750-E:&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.cisco.com/en/US/docs/switches/lan/catalyst3750e_3560e/software/release/12.2_50_se/configuration/guide/swstack.html#wp1153255"&gt;http://www.cisco.com/en/US/docs/switches/lan/catalyst3750e_3560e/software/release/12.2_50_se/configuration/guide/swstack.html#wp1153255&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Ive also gotten hold of the Juniper EX4200 and the Extreme Summit 200-24:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_bZ7EhbBrv3Q/Sdxmveo4Y1I/AAAAAAAAAHI/PFNnds_fn4Y/s1600-h/20090409096.jpg"&gt;&lt;img src="http://4.bp.blogspot.com/_bZ7EhbBrv3Q/Sdxmveo4Y1I/AAAAAAAAAHI/PFNnds_fn4Y/s200/20090409096.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5322241825509499730" style="cursor: pointer; width: 200px; height: 150px; " /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Ill se if i can write up something about the new Junos which is very nice. Also its very much like the Cisco IOS.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7970604688368987276-4795473551206827406?l=layer8problem.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://layer8problem.blogspot.com/feeds/4795473551206827406/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7970604688368987276&amp;postID=4795473551206827406' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7970604688368987276/posts/default/4795473551206827406'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7970604688368987276/posts/default/4795473551206827406'/><link rel='alternate' type='text/html' href='http://layer8problem.blogspot.com/2009/04/new-switch-stack.html' title='New switch stack'/><author><name>Fourknees</name><uri>http://www.blogger.com/profile/17221216896438461606</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_bZ7EhbBrv3Q/SP-WPaMDNYI/AAAAAAAAABE/ekK5saNOVps/S220/untitled2.GIF'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_bZ7EhbBrv3Q/Sdxka83YnJI/AAAAAAAAAG4/Di1gJJk4ORY/s72-c/20090409094.jpg' height='72' width='72'/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7970604688368987276.post-4835285891960641629</id><published>2009-03-31T10:26:00.020+02:00</published><updated>2009-03-31T16:12:12.409+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Howto´s and Guides'/><title type='text'>Howto: Collecting Snort logs with Splunk</title><content type='html'>Ok, now this time we will try to make snort logs into nice little colorful graphs. &lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;First off you need to think a little about your network design. Snort is very easily overloaded due to high CPU usage when using lots of signatures, thats why its always good to use several Snort installations(or Snort 3.0 which is multi-threaded) or use Vlans to delimit your network.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;For example this is how i set it up:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_bZ7EhbBrv3Q/SdHpWAY0zmI/AAAAAAAAAFo/0qiqPQI6R_g/s1600-h/snort.JPG"&gt;&lt;img src="http://4.bp.blogspot.com/_bZ7EhbBrv3Q/SdHpWAY0zmI/AAAAAAAAAFo/0qiqPQI6R_g/s400/snort.JPG" border="0" alt="" id="BLOGGER_PHOTO_ID_5319289199171784290" style="cursor: pointer; width: 315px; height: 400px; " /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;By setting it up this way i get two advantages:&lt;/div&gt;&lt;div&gt;1. This only scans firewalled traffic which takes off a big amount of load.&lt;/div&gt;&lt;div&gt;2. By using two Snorts i can use different signatures on each, for example on the DMZ snort its more likely that i will use WEB-ATTACKS rules etc.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Ok now lets start setting everything up:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:large;"&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="Apple-style-span" style="color: rgb(51, 204, 0);"&gt;1. Installing Snort&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="color: rgb(51, 204, 0);  font-weight: bold;font-size:18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.howtoforge.com/intrusion-detection-with-snort-mysql-apache2-on-ubuntu-7.10"&gt;Install and setup snort on as many machines as you want.&lt;/a&gt;&lt;/div&gt;&lt;div&gt;I am as always using Xubuntu 7.10 but Ubuntu should work aswell as many other dists.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="Apple-style-span"  style="font-size:large;"&gt;&lt;span class="Apple-style-span" style="color: rgb(51, 204, 0);"&gt;2. Traffic to Snort&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt; Make Trunk ports from your switches to your Snort machines. Remember that this is a great way to delimit the amount of traffic that will get to your Snort.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;On a Cisco machine with IOS you would use something like this:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;monitor session 1 source vlan 3 , 4 , 7 - 10&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;monitor session 1 destination interface Gi3/18&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;On an Extreme with Extremeware something like this: &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;enable mirroring to port 4:26 tagged&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;configure mirror add vlan "Default"&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;configure mirror add vlan "Dmz1"&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;configure mirror add vlan "Dmz2"&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;configure mirror add vlan "Dmz3"&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;configure mirror add vlan "Dmz4"&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;configure mirror add vlan "Dmz5"&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;configure mirror add vlan "Dmz6"&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;configure mirror add vlan "Dmz7"&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;For other switches &lt;a href="http://www.networkintrusion.co.uk/index.php/miscellaneous/switchport.html"&gt;please check this site out:&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="Apple-style-span"  style="font-size:large;"&gt;&lt;span class="Apple-style-span" style="color: rgb(51, 204, 0);"&gt;3. Install and setup Splunk&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt; Now you should have traffic flowing to your Snorts, so head over to &lt;a href="http://www.blogger.com/www.splunk.com"&gt;www.splunk.com&lt;/a&gt; and download the latest version, im using the windows 3.4.1 for this test.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;If possible you should use a server with dualcore since Splunk can draw lots of CPU and its nice to be able to administrate it while you are running some graphing.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Now that you have setup Splunk and confirmed that its working go to www.splunkbase.com and install &lt;a href="http://www.splunkbase.com/apps/All/Technologies/app:Splunk+for+Snort"&gt;this addon.&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Now go to your admin area of Splunk and go to application and enable splunk for snort.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;We also need to setup which port Splunk will listen to log files on so go to Data inputs -&gt; Network ports and add TCP and UDP 514. Configure them to listen to Snot application like this:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_bZ7EhbBrv3Q/SdH4P1pYeVI/AAAAAAAAAFw/tsMWUAmXUmY/s1600-h/data+input.bmp"&gt;&lt;img src="http://3.bp.blogspot.com/_bZ7EhbBrv3Q/SdH4P1pYeVI/AAAAAAAAAFw/tsMWUAmXUmY/s400/data+input.bmp" border="0" alt="" id="BLOGGER_PHOTO_ID_5319305585883642194" style="cursor: pointer; width: 327px; height: 400px; " /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Now i had lots of trouble to get Splunk to eat the snort logs correctly so i had a discussion on the Splunk forum and got some great help. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;You need to go to: %splunk system folder%\etc\system\local and edit props.conf&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;under the line [source::tcp:514] add:&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;SHOULD_LINEMERGE=true&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;BREAK_ONLY_BEFORE = ^.{3}\w{3}\s\d+\s\d+\:\d+\:\d+\s+\w+\s\[[^\]]+\]\s\[\d+\:\d+\:\d+&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;MAX_EVENTS = 500&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;TIME_PREFIX = (^|^\&lt;\d\&gt;)&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;TIME_FORMAT = %b %d %T&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;MAX_TIMESTAMP_LOOKAHEAD = 20&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;This enables all syslogs on TCP port 514 to be shown and proccesed in the right way.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Now restart Splunk.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:large;"&gt;&lt;span class="Apple-style-span" style="color: rgb(51, 204, 0);"&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;4. Configure Snort to send logs&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Ok now we actually need to have our Snorts to send the logs to Splunk. &lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;First off download &lt;a href="http://www.balabit.com/network-security/syslog-ng/"&gt;syslog-ng&lt;/a&gt; using your terminal in Xubuntu:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo apt-get install syslog-ng&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;Edit the config file with your favorite editor:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo gedit /etc/syslog-ng/syslog-ng.conf&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;Add this:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;source s_tail { file("&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;/var/log/snort/alert&lt;/span&gt;"&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;                    follow_freq(1) flags(no-parse) ) ; };&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;destination stail2 {  tcp("&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;10.10.10.10&lt;/span&gt;") ;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;};&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;log {&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;        source(s_tail);&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;        destination(stail2);&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;flags(flow-control);&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;};&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Everything in &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;bold&lt;/span&gt; you might need to edit. The first bold is where your alert logfile is located. By default it is at /var/log/snort/alert. The second is the adress of your Splunk server.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;So what this does is that it tails your alert logfile for updates, when its updated its sent to Splunk via TCP so it wont be discarded on the way. You can change it to UDP by switching out&lt;span class="Apple-style-span" style="font-style: italic; "&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic; "&gt;"{  tcp("&lt;span class="Apple-style-span" style="font-weight: bold; "&gt;10.10.10.10&lt;/span&gt;") ;"  to  "{  udp("&lt;span class="Apple-style-span" style="font-weight: bold; "&gt;10.10.10.10&lt;/span&gt;") ;"&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;Note that &lt;a href="http://sv.wikipedia.org/wiki/Transmission_control_protocol"&gt;TCP&lt;/a&gt; only makes sure it gets where its supposed to go, not that its encrypted and safe from interception. If you want that you should look in to &lt;a href="http://www.stunnel.org/"&gt;Stunnel.&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: rgb(51, 204, 0);"&gt;&lt;span class="Apple-style-span"  style="font-size:large;"&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;5. Create Graphs in Splunk&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Ok now you should have Snort logs arriving in your Splunk(if not activate the ICMP signature and ping a bit with your computer) so now we should make some nice graphs.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;First we need to extract the fields to make Splunk identify the Snort signatures, this is a very important lesson since you can use this to extract everything and have Splunk identify/graph it.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Click on the little arrow next to the logfile to open the extract menu:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_bZ7EhbBrv3Q/SdH-lpw70vI/AAAAAAAAAF4/eWwFVsYorm8/s1600-h/extract.JPG"&gt;&lt;img src="http://1.bp.blogspot.com/_bZ7EhbBrv3Q/SdH-lpw70vI/AAAAAAAAAF4/eWwFVsYorm8/s400/extract.JPG" border="0" alt="" id="BLOGGER_PHOTO_ID_5319312557720982258" style="cursor: pointer; width: 400px; height: 101px; " /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Now the extract menu will open, so select to name of the signature, in this example it is NETBIOS SMB-DS C$ unicode share access. Now paste it into the example box and select preview. Now Splunk is trying to identify the name of the signatures. This is how it should look like if its working:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_bZ7EhbBrv3Q/SdH_q0Pi1hI/AAAAAAAAAGA/OtbF6qTHhH8/s1600-h/extract2.JPG"&gt;&lt;img src="http://1.bp.blogspot.com/_bZ7EhbBrv3Q/SdH_q0Pi1hI/AAAAAAAAAGA/OtbF6qTHhH8/s400/extract2.JPG" border="0" alt="" id="BLOGGER_PHOTO_ID_5319313745944696338" style="cursor: pointer; width: 400px; height: 119px; " /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Now save it with a name, signature for ex.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Now we have names for the signatures and Splunk can identify them. So lets get to graphing.&lt;/div&gt;&lt;div&gt;So open up the logs again in Splunk and click "Report on results:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_bZ7EhbBrv3Q/SdIAcAfbhxI/AAAAAAAAAGI/DvEbJu9bJ7A/s1600-h/report.JPG"&gt;&lt;img src="http://4.bp.blogspot.com/_bZ7EhbBrv3Q/SdIAcAfbhxI/AAAAAAAAAGI/DvEbJu9bJ7A/s400/report.JPG" border="0" alt="" id="BLOGGER_PHOTO_ID_5319314591046141714" style="cursor: pointer; width: 400px; height: 161px; " /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Now to the left click on the extracted field you made. To the top left you can choose which timeline you want eg 15min 60min 3months etc. And then choose some graphing options, heres an example of how mine looks like:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_bZ7EhbBrv3Q/SdIBZItrecI/AAAAAAAAAGQ/5px3-YlT6L0/s1600-h/count.JPG"&gt;&lt;img src="http://4.bp.blogspot.com/_bZ7EhbBrv3Q/SdIBZItrecI/AAAAAAAAAGQ/5px3-YlT6L0/s400/count.JPG" border="0" alt="" id="BLOGGER_PHOTO_ID_5319315641225411010" style="cursor: pointer; width: 400px; height: 205px; " /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Ok now save your graph and put it on your dashboard and your done :) Happy Splunking!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="Apple-style-span" style="color: rgb(51, 204, 0);"&gt;&lt;span class="Apple-style-span"  style="font-size:large;"&gt;6. Enjoy the examples&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Here are some pictures of what you can Graph with Splunk:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Snort:&lt;/div&gt;&lt;div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_bZ7EhbBrv3Q/SdIHA8CbH7I/AAAAAAAAAGg/aK5n9pavGdY/s1600-h/snortsig.JPG"&gt;&lt;img src="http://3.bp.blogspot.com/_bZ7EhbBrv3Q/SdIHA8CbH7I/AAAAAAAAAGg/aK5n9pavGdY/s400/snortsig.JPG" border="0" alt="" id="BLOGGER_PHOTO_ID_5319321822575665074" style="cursor: pointer; width: 400px; height: 181px; " /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Juniper SA concurrent users and failed logins graphed with Splunk:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_bZ7EhbBrv3Q/SdIDUg3p-LI/AAAAAAAAAGY/pzcI4b0qFIU/s1600-h/Juniper.JPG"&gt;&lt;img src="http://4.bp.blogspot.com/_bZ7EhbBrv3Q/SdIDUg3p-LI/AAAAAAAAAGY/pzcI4b0qFIU/s400/Juniper.JPG" border="0" alt="" id="BLOGGER_PHOTO_ID_5319317760833616050" style="cursor: pointer; width: 400px; height: 204px; " /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;DHCP - Subnets without any ipadress left:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_bZ7EhbBrv3Q/SdIU-hCWdFI/AAAAAAAAAGo/Tz7U57rXVjw/s1600-h/dhcp.JPG"&gt;&lt;img src="http://1.bp.blogspot.com/_bZ7EhbBrv3Q/SdIU-hCWdFI/AAAAAAAAAGo/Tz7U57rXVjw/s400/dhcp.JPG" border="0" alt="" id="BLOGGER_PHOTO_ID_5319337174130652242" style="cursor: pointer; width: 400px; height: 95px; " /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Snort also has a default preprocessor namne snort-stats that lets you export loads of stuff, eg. cpu load, blocks/min etc:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_bZ7EhbBrv3Q/SdIZktYtOUI/AAAAAAAAAGw/qRlZt90tYIk/s1600-h/snortstats.JPG"&gt;&lt;img src="http://4.bp.blogspot.com/_bZ7EhbBrv3Q/SdIZktYtOUI/AAAAAAAAAGw/qRlZt90tYIk/s400/snortstats.JPG" border="0" alt="" id="BLOGGER_PHOTO_ID_5319342228327184706" style="cursor: pointer; width: 400px; height: 265px; " /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Ok, hopefully this will help you alot in securing your network. I will post some guides about nice rules and hints and tips later using Snort. Remember that Splunk can be used for lots of other stuff than graphing, just enter anything in the searchbar.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Enjoy!&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7970604688368987276-4835285891960641629?l=layer8problem.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://layer8problem.blogspot.com/feeds/4835285891960641629/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7970604688368987276&amp;postID=4835285891960641629' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7970604688368987276/posts/default/4835285891960641629'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7970604688368987276/posts/default/4835285891960641629'/><link rel='alternate' type='text/html' href='http://layer8problem.blogspot.com/2009/03/collecting-snort-logs-with-splunk.html' title='Howto: Collecting Snort logs with Splunk'/><author><name>Fourknees</name><uri>http://www.blogger.com/profile/17221216896438461606</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_bZ7EhbBrv3Q/SP-WPaMDNYI/AAAAAAAAABE/ekK5saNOVps/S220/untitled2.GIF'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_bZ7EhbBrv3Q/SdHpWAY0zmI/AAAAAAAAAFo/0qiqPQI6R_g/s72-c/snort.JPG' height='72' width='72'/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7970604688368987276.post-1610514484805289186</id><published>2009-01-26T10:29:00.020+01:00</published><updated>2009-04-09T11:07:06.989+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Rant (useless crap)'/><title type='text'>Juniper Cartoons</title><content type='html'>Dont get me wrong, i love Cisco but sometimes these are just spot on! A long time ago their home was at &lt;a href="http://www.juniper.net/cartoons/"&gt;http://www.juniper.net/cartoons/&lt;/a&gt;. I talked to a salesguy at Juniper that said they had to remove them because it made Juniper look unserious. Anyhow they are a good laugh!&lt;br /&gt;&lt;br /&gt;This week i had the "privilege" to try to upgrade an old Cisco 4003 with CatOs to IOS 12. These pictures pretty much says it all:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_bZ7EhbBrv3Q/SX2Da35TlKI/AAAAAAAAAEA/tMVxs88v3G8/s1600-h/juniper-03.gif"&gt;&lt;img style="cursor: pointer; width: 330px; height: 372px;" src="http://2.bp.blogspot.com/_bZ7EhbBrv3Q/SX2Da35TlKI/AAAAAAAAAEA/tMVxs88v3G8/s400/juniper-03.gif" alt="" id="BLOGGER_PHOTO_ID_5295533234561717410" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_bZ7EhbBrv3Q/SX2C595GT2I/AAAAAAAAADw/a4hM3LZU1fc/s1600-h/juniper-30.gif"&gt;&lt;img style="cursor: pointer; width: 290px; height: 351px;" src="http://1.bp.blogspot.com/_bZ7EhbBrv3Q/SX2C595GT2I/AAAAAAAAADw/a4hM3LZU1fc/s400/juniper-30.gif" alt="" id="BLOGGER_PHOTO_ID_5295532669235777378" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_bZ7EhbBrv3Q/SX2DUCGpQKI/AAAAAAAAAD4/FDje6BscPIc/s1600-h/juniper-24.gif"&gt;&lt;img style="cursor: pointer; width: 300px; height: 400px;" src="http://1.bp.blogspot.com/_bZ7EhbBrv3Q/SX2DUCGpQKI/AAAAAAAAAD4/FDje6BscPIc/s400/juniper-24.gif" alt="" id="BLOGGER_PHOTO_ID_5295533117042933922" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Good thing they have a upgrade tool over at tools.cisco.com!&lt;br /&gt;&lt;br /&gt;101 uses for a cisco router:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_bZ7EhbBrv3Q/SX2E6QpER9I/AAAAAAAAAEI/-MYMIPL7nl0/s1600-h/juniper-32.gif"&gt;&lt;img style="cursor: pointer; width: 297px; height: 339px;" src="http://1.bp.blogspot.com/_bZ7EhbBrv3Q/SX2E6QpER9I/AAAAAAAAAEI/-MYMIPL7nl0/s400/juniper-32.gif" alt="" id="BLOGGER_PHOTO_ID_5295534873292064722" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_bZ7EhbBrv3Q/SX2FB_THSDI/AAAAAAAAAEQ/ZxJXRqb5yZk/s1600-h/2002-12-13--Cisco_Litter_Box.jpg"&gt;&lt;img style="cursor: pointer; width: 384px; height: 288px;" src="http://2.bp.blogspot.com/_bZ7EhbBrv3Q/SX2FB_THSDI/AAAAAAAAAEQ/ZxJXRqb5yZk/s400/2002-12-13--Cisco_Litter_Box.jpg" alt="" id="BLOGGER_PHOTO_ID_5295535006075537458" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;If cisco invented:&lt;br /&gt;&lt;br /&gt;&lt;img src="file:///C:/Documents%20and%20Settings/FORMIC/Desktop/juniper%20bilder/cartoon.jpg" alt="" /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_bZ7EhbBrv3Q/SX2FdzsC8DI/AAAAAAAAAEY/gtu2zZjHxH0/s1600-h/juniper-01.gif"&gt;&lt;img style="cursor: pointer; width: 330px; height: 372px;" src="http://1.bp.blogspot.com/_bZ7EhbBrv3Q/SX2FdzsC8DI/AAAAAAAAAEY/gtu2zZjHxH0/s400/juniper-01.gif" alt="" id="BLOGGER_PHOTO_ID_5295535483995222066" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_bZ7EhbBrv3Q/SX2FjB8cUmI/AAAAAAAAAEg/POTDtR0ntGk/s1600-h/juniper-40.gif"&gt;&lt;img style="cursor: pointer; width: 297px; height: 344px;" src="http://4.bp.blogspot.com/_bZ7EhbBrv3Q/SX2FjB8cUmI/AAAAAAAAAEg/POTDtR0ntGk/s400/juniper-40.gif" alt="" id="BLOGGER_PHOTO_ID_5295535573721436770" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Others!:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_bZ7EhbBrv3Q/SX2F_FlU5QI/AAAAAAAAAFI/KTX6HNBPgc0/s1600-h/juniper-44.gif"&gt;&lt;img style="cursor: pointer; width: 300px; height: 397px;" src="http://4.bp.blogspot.com/_bZ7EhbBrv3Q/SX2F_FlU5QI/AAAAAAAAAFI/KTX6HNBPgc0/s400/juniper-44.gif" alt="" id="BLOGGER_PHOTO_ID_5295536055734560002" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_bZ7EhbBrv3Q/SX2F5UyTxaI/AAAAAAAAAFA/GLAsr5kiYbo/s1600-h/juniper-25.gif"&gt;&lt;img style="cursor: pointer; width: 298px; height: 400px;" src="http://4.bp.blogspot.com/_bZ7EhbBrv3Q/SX2F5UyTxaI/AAAAAAAAAFA/GLAsr5kiYbo/s400/juniper-25.gif" alt="" id="BLOGGER_PHOTO_ID_5295535956736329122" border="0" /&gt;&lt;/a&gt;&lt;span style="text-decoration: underline;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_bZ7EhbBrv3Q/SX2F0sEPJwI/AAAAAAAAAEw/kHq-fyKWoWc/s1600-h/Juniper1.jpg"&gt;&lt;img style="cursor: pointer; width: 308px; height: 400px;" src="http://1.bp.blogspot.com/_bZ7EhbBrv3Q/SX2F0sEPJwI/AAAAAAAAAEw/kHq-fyKWoWc/s400/Juniper1.jpg" alt="" id="BLOGGER_PHOTO_ID_5295535877086193410" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_bZ7EhbBrv3Q/SX2GYxeHQdI/AAAAAAAAAFY/Nnr2KgZKsIY/s1600-h/juniper-15.gif"&gt;&lt;img style="cursor: pointer; width: 327px; height: 400px;" src="http://2.bp.blogspot.com/_bZ7EhbBrv3Q/SX2GYxeHQdI/AAAAAAAAAFY/Nnr2KgZKsIY/s400/juniper-15.gif" alt="" id="BLOGGER_PHOTO_ID_5295536497012195794" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_bZ7EhbBrv3Q/SX2GS7fM6WI/AAAAAAAAAFQ/PKSJctF-CEs/s1600-h/router_cartoon.gif"&gt;&lt;img style="cursor: pointer; width: 244px; height: 320px;" src="http://3.bp.blogspot.com/_bZ7EhbBrv3Q/SX2GS7fM6WI/AAAAAAAAAFQ/PKSJctF-CEs/s400/router_cartoon.gif" alt="" id="BLOGGER_PHOTO_ID_5295536396621900130" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_bZ7EhbBrv3Q/SX2F2xdN9wI/AAAAAAAAAE4/uhEr8mKH1Rk/s1600-h/Chicken2News.gif"&gt;&lt;img style="cursor: pointer; width: 221px; height: 236px;" src="http://4.bp.blogspot.com/_bZ7EhbBrv3Q/SX2F2xdN9wI/AAAAAAAAAE4/uhEr8mKH1Rk/s400/Chicken2News.gif" alt="" id="BLOGGER_PHOTO_ID_5295535912892888834" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_bZ7EhbBrv3Q/SX2FyP4Lb7I/AAAAAAAAAEo/OPFyWpeLw0k/s1600-h/2003-12-13--Cisco_Stonehenge.jpg"&gt;&lt;img style="cursor: pointer; width: 400px; height: 300px;" src="http://3.bp.blogspot.com/_bZ7EhbBrv3Q/SX2FyP4Lb7I/AAAAAAAAAEo/OPFyWpeLw0k/s400/2003-12-13--Cisco_Stonehenge.jpg" alt="" id="BLOGGER_PHOTO_ID_5295535835159687090" border="0" /&gt;&lt;/a&gt;&lt;div&gt;Update 2009-04-09:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Found some intresting news(Translated to english by google):&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style=" -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px;font-family:-webkit-monospace;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style=" -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; font-family:-webkit-monospace;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;"Juniper continues cartoonist at the door &lt;br /&gt;&lt;br /&gt;4 March, 2009 - Luc Blyaert &lt;br /&gt;Kevin Pope was five years drawing cartoons for Juniper Networks, but his job is now for the ax. Long time the drawings of Pope a witty attack on Cisco. &lt;br /&gt;&lt;br /&gt;Kevin Pope began in late 2003 with his cartoons, then barely knew what networking and telecom, but has been thoroughly trained. "I could do what I wanted, was only able to show that the Juniper products were better or why the equipment of the competitors were undermined," says Kevin Pope to Light Reading. &lt;br /&gt;&lt;br /&gt;Not everyone loved the cartoons, some of them were unprofessional. But they were regularly forwarded by network engineers. Especially when the Pope got out of Cisco solutions, they were popular. Examples can be found here: http://layer8problem.blogspot.com/2009/01/juniper-cartoons.html &lt;br /&gt;&lt;br /&gt;There was an end to demand from Juniper CEO Scott Kriens. It was apparently a good friend of Cisco John Chambers. "John Scott told me that they are funny, but asked whether there is less of what can be published," says Pope. That is not bitter that he may not sign for Juniper. "Ultimately, five years is a very long period.""&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Original:&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.datanews.be/nl/news/90-104-22838/juniper-zet-cartoonist-aan-de-deur.html"&gt;http://www.datanews.be/nl/news/90-104-22838/juniper-zet-cartoonist-aan-de-deur.html&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;More info:&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.lightreading.com/document.asp?doc_id=172836&amp;amp;f_src=lightreading_gnews"&gt;http://www.lightreading.com/document.asp?doc_id=172836&amp;amp;f_src=lightreading_gnews&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The plot thickens!&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7970604688368987276-1610514484805289186?l=layer8problem.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://layer8problem.blogspot.com/feeds/1610514484805289186/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7970604688368987276&amp;postID=1610514484805289186' title='29 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7970604688368987276/posts/default/1610514484805289186'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7970604688368987276/posts/default/1610514484805289186'/><link rel='alternate' type='text/html' href='http://layer8problem.blogspot.com/2009/01/juniper-cartoons.html' title='Juniper Cartoons'/><author><name>Fourknees</name><uri>http://www.blogger.com/profile/17221216896438461606</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_bZ7EhbBrv3Q/SP-WPaMDNYI/AAAAAAAAABE/ekK5saNOVps/S220/untitled2.GIF'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_bZ7EhbBrv3Q/SX2Da35TlKI/AAAAAAAAAEA/tMVxs88v3G8/s72-c/juniper-03.gif' height='72' width='72'/><thr:total>29</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7970604688368987276.post-695293943425517398</id><published>2009-01-26T09:41:00.002+01:00</published><updated>2009-01-26T10:29:21.730+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cryptology'/><title type='text'>Cryptographic Analysis Program</title><content type='html'>&lt;span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Verdana; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;"&gt;If your new into cryptography then you should check out CAP, its a real nice tool that helps out alot when your learning(as im doing right now). Its really hard to find out there so im just going to post a link to it:&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Verdana; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;"&gt; http://www.cs.plu.edu/courses/privacy/cap.htm&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Verdana; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Verdana; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;"&gt;&lt;span style="font-style: italic;"&gt;CAP is a complete tool for cryptanalysis. It allows for encryption and decryption using several common algorithms. It provides tools for cryptanalysis of these and other ciphers. Among the tools are frequency analysis, Kasiski analysis, word patterns, anagramming, and a special autosolve tool. In addition, CAP provides a GAME option that will randomly generate ciphers and challenge you to break them. You can download a demo version of CAP from the download area of this page. Along with CAP you should download the CAP handbook which provides you with a complete CAP manual and a tutorial on ciphers and cryptanalysis.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Verdana; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7970604688368987276-695293943425517398?l=layer8problem.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.cs.plu.edu/courses/privacy/cap.htm' title='Cryptographic Analysis Program'/><link rel='replies' type='application/atom+xml' href='http://layer8problem.blogspot.com/feeds/695293943425517398/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7970604688368987276&amp;postID=695293943425517398' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7970604688368987276/posts/default/695293943425517398'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7970604688368987276/posts/default/695293943425517398'/><link rel='alternate' type='text/html' href='http://layer8problem.blogspot.com/2009/01/cryptographic-analysis-program.html' title='Cryptographic Analysis Program'/><author><name>Fourknees</name><uri>http://www.blogger.com/profile/17221216896438461606</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_bZ7EhbBrv3Q/SP-WPaMDNYI/AAAAAAAAABE/ekK5saNOVps/S220/untitled2.GIF'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7970604688368987276.post-1359045262081533847</id><published>2008-11-25T15:48:00.068+01:00</published><updated>2009-01-26T09:38:32.075+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Howto´s and Guides'/><title type='text'>Howto: The great and mighty tutorial about Snort 2.8 Inline + Base</title><content type='html'>Ok, so &lt;span style="font-family:georgia;"&gt;you have looked everywhere for a good tutorial about getting Snort working in bridge(inline, &lt;span class="Apple-style-span" style="white-space: pre;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;transparent&lt;/span&gt;&lt;/span&gt;) mode&lt;/span&gt;&lt;span style="font-family:georgia;"&gt;? Look&lt;/span&gt; no further stranger, the salvation is near. Sit back and enjoy the ride.&lt;br /&gt;&lt;br /&gt;Before you start to cheer please take a look at the requirements to get this stuff rolling:&lt;br /&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;* Processor x86&lt;/span&gt; preferably 1 ghz + (Depends on how many rules, preprocessors and mbit/s.)&lt;br /&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;* 2 or 3 Nic&lt;/span&gt; preferably 10/100/1000 (3 Nics if you want one separate for mgmt, you can manage it with 2 nics also but for security reasons you should invenst in a third.)&lt;br /&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;* 256+ ram&lt;/span&gt;, the more the better especially if your going to run alot of rules.&lt;br /&gt;&lt;br /&gt;(Ive ran this on my 1.6 ghz laptop with 512mb ram and 2 * 100 mbits nics for testing purposes and it pushed 10 mb(megabytes)/s with 100 rules and all preprocessors activated. with 19000 rules it could handle around 2-3 mb/s with alot of packet drops.&lt;br /&gt;&lt;br /&gt;For my setup this time i will be using a IBM x350 with Intel Xeon Quad Core 2.8ghz, 3 gb Ram and 1* 100mbit interface for mgmt and 2*1000mbit interface for the bridge. Note that it should be able to run on anything that can handle xubuntu.&lt;br /&gt;&lt;br /&gt;So as always start with a clean installation of Xubuntu 7.10 (it can be found here &lt;a href="http://cdimage.ubuntu.com/xubuntu/releases/gutsy/release/"&gt;http://cdimage.ubuntu.com/xubuntu/releases/gutsy/release/&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;This should be working with 8.10 also, havent tried it yet though.&lt;br /&gt;&lt;br /&gt;Always update an upgrade before using it. This is important since Xubuntu 7.10 comes preinstalled with a big flaw in the OpenSSL software.&lt;br /&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo apt-get update&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo apt-get upgrade&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_bZ7EhbBrv3Q/SSwX56fSH_I/AAAAAAAAAC4/9l6D07QSXOE/s1600-h/xubuntu.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5272615547464458226" style="width: 200px; cursor: pointer; height: 150px;" alt="" src="http://4.bp.blogspot.com/_bZ7EhbBrv3Q/SSwX56fSH_I/AAAAAAAAAC4/9l6D07QSXOE/s200/xubuntu.JPG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;So lets get started on the long and narrow road to getting a snort inline.&lt;br /&gt;&lt;br /&gt;Ive used alot of tutorials as a base for this one:&lt;br /&gt;&lt;a href="http://openmaniak.com/inline.php"&gt;http://openmaniak.com/inline.php&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.intarwebz.com/snort-ips/"&gt;http://www.intarwebz.com/snort-ips/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.snort.org/docs/snort_htmanuals/htmanual_2.4/node7.html"&gt;http://www.snort.org/docs/snort_htmanuals/htmanual_2.4/node7.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.howtoforge.com/intrusion-detection-with-snort-mysql-apache2-on-ubuntu-7.10"&gt;http://www.howtoforge.com/intrusion-detection-with-snort-mysql-apache2-on-ubuntu-7.10&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;So if something looks very similar then ive proberly copied it from the above. The reason for this tutorial is that none of them describes howto get the latest snort 2.8.3.1 running inline.&lt;br /&gt;&lt;br /&gt;So before heading to the first step you should get a cup of coffe/tea.&lt;br /&gt;&lt;span class="Apple-style-span" style="font-weight: bold; color: rgb(51, 204, 0);font-size:130%;" &gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-weight: bold; color: rgb(51, 204, 0);font-size:130%;" &gt;1. Installing the packages&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;So lets get started with installing all the crap that snort/base needs.&lt;br /&gt;&lt;br /&gt;i will list them with a short comment:&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:georgia;"&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse;"&gt;bridge-utils&lt;/span&gt; - &lt;em&gt;makes bridging of interfaces possible&lt;br /&gt;&lt;/em&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;libnet0-dev&lt;/span&gt; - &lt;em&gt;development files for libnet, its needed for snort inline&lt;br /&gt;&lt;/em&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;iptables-dev&lt;/span&gt; - &lt;em&gt;development files for iptables, used when compiling snort inline&lt;br /&gt;&lt;/em&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;build-essential&lt;/span&gt; - &lt;em&gt;important files for compiling, gcc etc&lt;br /&gt;&lt;/em&gt;&lt;span class="Apple-style-span" style="line-height: 18px; border-collapse: collapse;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;libpcap0.8-dev&lt;/span&gt;&lt;/span&gt;  - &lt;em&gt;snort inline does not use this but perfmonitor does&lt;/em&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="line-height: 18px; border-collapse: collapse;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;libmysqlclient15- dev&lt;/span&gt;&lt;/span&gt; - &lt;em&gt;needed by mysql&lt;/em&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="line-height: 18px; border-collapse: collapse;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;mysql-client-5.0&lt;/span&gt;&lt;/span&gt; - &lt;em&gt;client for accessing mysql&lt;br /&gt;&lt;/em&gt;&lt;span class="Apple-style-span" style="line-height: 18px; border-collapse: collapse;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;mysql-server-5.0&lt;/span&gt;&lt;/span&gt; - &lt;em&gt;mysql server for storing information for Base&lt;/em&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="line-height: 18px; border-collapse: collapse;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;apache2&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:georgia;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt; - &lt;em&gt;webserver&lt;/em&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="line-height: 18px; border-collapse: collapse;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;libapache2-mod-php5 -&lt;em&gt; library used by apache&lt;/em&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="line-height: 18px; border-collapse: collapse;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;php5-gd&lt;/span&gt;&lt;/span&gt; - &lt;em&gt;php-gd for drawing graphs&lt;/em&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="line-height: 18px; border-collapse: collapse;"&gt;php5-mysql&lt;/span&gt; - &lt;em&gt;php extension for mysql&lt;/em&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="line-height: 18px; border-collapse: collapse;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;libphp-adodb&lt;/span&gt;&lt;/span&gt; - &lt;em&gt;library for adodb&lt;/em&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="line-height: 18px; border-collapse: collapse;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;php-pear&lt;/span&gt;&lt;/span&gt; - &lt;em&gt;php extension for pear&lt;/em&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="line-height: 18px; border-collapse: collapse;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;bison&lt;/span&gt;&lt;/span&gt; - &lt;em&gt;language parser&lt;/em&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="line-height: 18px; border-collapse: collapse;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;flex&lt;/span&gt;&lt;/span&gt; - &lt;em&gt;recognises patterns for base&lt;/em&gt;&lt;br /&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;gedit&lt;/span&gt; - &lt;em&gt;text editor&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;Type:&lt;br /&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;blockquote&gt;sudo apt-get install build-essential libpcap0.8-dev libmysqlclient15-dev mysql-client-5.0 mysql-server-5.0 bison flex apache2 libapache2-mod-php5 php5-gd php5-mysql libphp-adodb php-pear iptables-dev libnet0-dev gedit bridge-utils&lt;/blockquote&gt;&lt;/span&gt;This will install everything you need.&lt;br /&gt;&lt;br /&gt;During the installation Mysql will prompt you for root password and give you a warning message about a moved library. This is normal.&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-weight: bold; color: rgb(51, 204, 0);font-size:130%;" &gt;2. Manual install of some packages&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;So now we need to manually install some crap. yes life sucks.&lt;br /&gt;&lt;br /&gt;Start by creating a temporary folder that we will be using.&lt;br /&gt;&lt;br /&gt;Ive put mine under the filesystem at&lt;span style="color: rgb(51, 204, 0);"&gt; &lt;strong&gt;/layer8/&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Do this by typing:&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;blockquote&gt;sudo mkdir /layer8/&lt;/blockquote&gt;&lt;/span&gt;Or you can do this by opening Thunar(the file manager) as root and rightclick and create a new folder. If you prefer this way type:&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo thunar&lt;/span&gt;&lt;/blockquote&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;Now head over to www.&lt;span style="color: rgb(0, 0, 0);"&gt;pcre&lt;/span&gt;.org and download the latest package of&lt;/span&gt;&lt;span class="Apple-style-span" style="line-height: 18px; border-collapse: collapse;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt; &lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;Perl Compatible Regular Expressions&lt;/span&gt; (ftp://ftp.csx.cam.ac.uk/pub/software/programming/pcre/) (7.8 at the time of writing)&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="line-height: 18px; border-collapse: collapse;"&gt;Download it and put it in the /layer8/ directory. &lt;/span&gt;&lt;br /&gt;Extract pcre-7.8.tar.gz to the directory.&lt;span class="Apple-style-span" style="line-height: 13px; font-style: italic;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="line-height: 13px; font-style: italic;"&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="line-height: normal;"&gt;cd /layer8&lt;br /&gt;&lt;span class="Apple-style-span" style="line-height: 13px;"&gt;sudo tar -xzvf /layer8/pcre-7.8.tar.gz &lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span class="Apple-style-span" style="line-height: 18px; border-collapse: collapse;"&gt;Now configure and install it:&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="line-height: 18px; border-collapse: collapse;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;cd pcre-7.8/&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="line-height: 18px; border-collapse: collapse;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo ./configure&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="line-height: 18px; border-collapse: collapse;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo make&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="line-height: 18px; border-collapse: collapse;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo make install&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span class="Apple-style-span" style="line-height: 18px; border-collapse: collapse;"&gt;Now you need to install &lt;span style="color: rgb(0, 153, 0);"&gt;Libnet&lt;/span&gt; (i use the latest 1.1.2.1). Head over to: &lt;a href="http://www.packetfactory.net/libnet/"&gt;http://www.packetfactory.net/libnet/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;And download it to the /layer8/ folder then install it.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="line-height: 18px; border-collapse: collapse;"&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;cd /layer8&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo tar -xzvf libnet.tar.gz&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;cd /layer8/libnet/&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo ./configure&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo make&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo make install&lt;/span&gt;&lt;/blockquote&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-weight: bold; color: rgb(51, 204, 0);font-size:130%;" &gt;3. Install and compile Snort Inline + rules&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Now lets download the latest version of &lt;span style="color: rgb(0, 0, 0);"&gt;snort&lt;/span&gt; and some nice rules. Put them in the /layer8/ folder. I will be writing about adding rules from bleedinsnort and emerging threats later so for now you can download the stable vrt registered user release. (snortrules-snapshot-2.8.tar.gz)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="line-height: 18px; border-collapse: collapse;"&gt;&lt;span class="Apple-style-span" style="line-height: 13px;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px; font-style: normal;"&gt;Extract Snort&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="line-height: 18px; border-collapse: collapse;"&gt;&lt;span class="Apple-style-span" style="line-height: 13px;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px; font-style: normal;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;cd /layer8&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;sudo tar -xzvf /layer8/snort-2.8.3.1.tar.gz&lt;span class="Apple-style-span" style="line-height: 18px; font-style: normal;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span class="Apple-style-span" style="line-height: 18px; border-collapse: collapse;"&gt;&lt;span class="Apple-style-span" style="line-height: 13px;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px; font-style: normal;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="line-height: 18px; border-collapse: collapse;"&gt;&lt;span class="Apple-style-span" style="line-height: 13px;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px; font-style: normal;"&gt;Extract Snort rules to the snort directory(you need to move the rules into the snort directory first)&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;span class="Apple-style-span" style="line-height: 18px; border-collapse: collapse;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;cd /layer8/snort-2.8.3.1/&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="line-height: 18px; border-collapse: collapse;"&gt;&lt;span class="Apple-style-span" style="line-height: 13px;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo tar -xzvf /layer8/snort-2.8.3.1/&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;snortrules-snapshot-2.8.tar.gz&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/blockquote&gt;Feel free to delete any old tar.gz files that you have already used.&lt;br /&gt;&lt;br /&gt;Now configure and install it:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;cd /layer8/snort-2.8.3.1/&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo ./configure -enable-dynamicplugin --with-mysql&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;--enable-inline --with-libipq-includes=/usr/include/libipq/ &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo make&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo make install&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;Done! If you get any errors while trying to configure it, here is a good helplist to see what you are missing: &lt;a href="http://openmaniak.com/inline_pre.php"&gt;http://openmaniak.com/inline_pre.php&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold; color: rgb(0, 153, 0);font-size:130%;" &gt;4. Pre Launch&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;Now before we testdrive our inline snort there is a little bit left to do. First create these 3 directorys:&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="line-height: 13px; border-collapse: collapse;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo &lt;span class="Apple-style-span" style="font-weight: bold; color: rgb(0, 0, 153);"&gt;/etc/snort&lt;/span&gt; &lt;span style="color: rgb(255, 0, 0);"&gt;/etc/snort/rules&lt;/span&gt; &lt;span class="Apple-style-span" style="font-weight: bold; color: rgb(51, 255, 255);"&gt;/var/log/snort&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;/span&gt;&lt;/span&gt;Now lets copy some files:&lt;/div&gt;&lt;div&gt;&lt;blockquote&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;cd /layer8/snort-2.8.3.1/rules&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo cp * /etc/snort/rules/&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;cd /layer8/snort-2.8.3.1/etc&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo cp * /etc/snort/&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo cp /usr/local/lib/libpcre.so.0 /usr/lib&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;So now our config file snort.conf resides in /etc/snort. Sweet. &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;So now Edit /etc/snort/snort.conf and change&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;var RULE_PATH ../rules to &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;var RULE_PATH /etc/snort/rule&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;Now testdrive snort inline!!!&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;blockquote&gt;sudo snort -Q -c /etc/snort/snort.conf -v &lt;/blockquote&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;The -Q is for snort inline to take packages from the ip_queue module. Currently you wont have any because we havent edited Iptables to forward to QUEUE yet, be patient. The -c is where is will find snort.conf and the -v is for Verbose output so you can see what is happening on the screen, if you want to you can launch it as a Daemon using the -D.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;If everything went succesful you will se a little pig and some text after its done loading:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:x-small;"&gt;--== Initialization Complete ==--&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;,,_ -*&gt; Snort! &lt;*-&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;o" )~ Version 2.8.3.1 (Build 17) inline &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;'''' By Martin Roesch &amp;amp; The Snort Team: http://www.snort.org/team.html&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;(C) Copyright 1998-2008 Sourcefire Inc., et al.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;Using PCRE version: 7.8 2008-09-05&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;Rules Engine: SF_SNORT_DETECTION_ENGINE Version 1.9 &lt;build 15=""&gt;&lt;/build&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;Preprocessor Object: SF_SSH Version 1.1 &lt;build 1=""&gt;&lt;/build&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;Preprocessor Object: SF_SMTP Version 1.1 &lt;build 7=""&gt;&lt;/build&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;Preprocessor Object: SF_FTPTELNET Version 1.1 &lt;build 10=""&gt;&lt;/build&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;Preprocessor Object: SF_DNS Version 1.1 &lt;build 2=""&gt;&lt;/build&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;Preprocessor Object: SF_DCERPC Version 1.1 &lt;build 4=""&gt;&lt;/build&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;Not Using PCAP_FRAMES&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;So now you have a working SNORT INLINE!!! But hey, were far from done yet :'(&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;You can stop snort by pressing CTRL + C anytime.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;So whats left to do?&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Base, Mysql setup,Apache2, Bridging the Nics and setting up Iptabels.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold; color: rgb(51, 204, 0);font-size:130%;" &gt;5. Download Base + Adodb Extension for PHP&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;Head over to &lt;a href="http://sourceforge.net/project/showfiles.php?group_id=42718&amp;amp;package_id=220409&amp;amp;release_id=636410"&gt;http://sourceforge.net/project/showfiles.php?group_id=42718&amp;amp;package_id=220409&amp;amp;release_id=636410&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;And download the &lt;span style="color: rgb(0, 153, 0);"&gt;adodb-php5-only&lt;/span&gt; to the /layer8/ folder.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Untar and move it.&lt;/div&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;cd /layer8/&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo tar -xzvf adodb506a.tgz&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo mv /layer8/adodb5 /var/www/&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;Done.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Head over to sourceforge and download latest version of &lt;span style="color: rgb(51, 204, 0);"&gt;Base&lt;/span&gt; ( &lt;a href="http://sourceforge.net/project/showfiles.php?group_id=103348&amp;amp;package_id=128846&amp;amp;release_id=617636"&gt;http://sourceforge.net/project/showfiles.php?group_id=103348&amp;amp;package_id=128846&amp;amp;release_id=617636&lt;/a&gt;)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Dowload it to /layer8/, untar it and move it:&lt;/div&gt;&lt;blockquote&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;cd /layer8/&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo tar -xzvf base-1.4.1.tar.gz&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo mv /layer8/base-php4 /var/www/base&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span style="color: rgb(51, 204, 0);font-size:130%;" &gt;6. Configure Mysql Server&lt;/span&gt; &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;Now lets setup the Mysql server:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Type:&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;blockquote&gt;sudo mysql -u root -p&lt;/blockquote&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;in the prompt that appears type:&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;SET PASSWORD FOR root@localhost=PASSWORD('Your password!!!!');&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;It will return something like: Query OK, 0 rows affected (0.00 sec)&lt;/div&gt;&lt;div&gt;Then type:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;create database snort;&lt;/div&gt;&lt;div&gt;exit&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;use the snort schema for the layout of the database.&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;blockquote&gt;sudo mysql -D snort -u root -p &lt; /layer8/snort-2.8.3.1/schemas/create_mysql &lt;/blockquote&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;Ok great lets move on.&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-weight: bold; color: rgb(51, 204, 0);font-size:130%;" &gt;7. Apache2 + Pear&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;Now edit &lt;/span&gt;&lt;span class="Apple-style-span" style="line-height: 13px; border-collapse: collapse;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;/etc/php5/apache2/php.ini&lt;/span&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo gedit /etc/php5/apache2/php.ini&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;Add under Dynamic Extensions:&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;extension=mysql.so&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;extension=gd.so&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;/span&gt;&lt;/div&gt;Restart apache by typing:&lt;br /&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;blockquote&gt;sudo /etc/init.d/apache2 restart&lt;/blockquote&gt;&lt;/span&gt;Now we need writing to be enabled at the /var/www folder:&lt;br /&gt;&lt;span class="Apple-style-span" style="line-height: 13px; border-collapse: collapse;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo chmod 757 /var/www/base&lt;/span&gt;&lt;/blockquote&gt;&lt;/span&gt;&lt;/span&gt;Now install som pear graphic tools:&lt;span class="Apple-style-span" style="line-height: 13px; font-style: italic;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="line-height: 13px; font-style: italic; border-collapse: collapse;"&gt;&lt;blockquote&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;sudo pear upgrade-all&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;sudo pear install Image_Color&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;sudo pear install Image_Canvas-alpha&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;sudo pear install Image_Graph-alpha&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;sudo pear install Mail&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;sudo pear install Mail_mime&lt;/span&gt;&lt;span class="Apple-style-span" style="font-style: normal;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: normal;"&gt;&lt;span class="Apple-style-span" style="color: rgb(51, 204, 0);font-size:130%;" &gt;8. Setup Base&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: normal;"&gt;&lt;span class="Apple-style-span" style="color: rgb(51, 204, 0);font-size:130%;" &gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: normal;"&gt;&lt;span class="Apple-style-span" style="color: rgb(51, 204, 0);font-size:130%;" &gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/span&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: normal;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: normal;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;Now base should be able to be installed using the websetup, use your browser and open:&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: normal;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;http://YOURIPADRESS/base/setup/&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: normal;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: normal;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;When they prompt you for path to ADODB enter:&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: normal;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: normal;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;/var/www/adodb5&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: normal;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: normal;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;Page 2:&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-family:georgia;"&gt;Database Name: snort&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:georgia;"&gt;Database Host: localhost&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:georgia;"&gt;Database Port: leave blank&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:georgia;"&gt;Database User Name: root&lt;br /&gt;Database Password: Your password!!!&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;page 3: Self-explanatory&lt;br /&gt;&lt;br /&gt;page 4: Press the create database button and you will get som text:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="color: rgb(255, 0, 0);"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;Successfully created 'acid_ag'&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="color: rgb(255, 0, 0);font-family:arial;" &gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;Successfully created 'acid_ag_alert'&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="color: rgb(255, 0, 0);font-family:arial;" &gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;Successfully created 'acid_ip_cache'&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="color: rgb(255, 0, 0);font-family:arial;" &gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;Successfully created 'acid_event'&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="color: rgb(255, 0, 0);font-family:arial;" &gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;Successfully created 'base_roles'&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="color: rgb(255, 0, 0);font-family:arial;" &gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;Successfully INSERTED Admin role&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="color: rgb(255, 0, 0);font-family:arial;" &gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;Successfully INSERTED Authenticated User role&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="color: rgb(255, 0, 0);font-family:arial;" &gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;Successfully INSERTED Anonymous User role&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="color: rgb(255, 0, 0);font-family:arial;" &gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;Successfully INSERTED Alert Group Editor role&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="color: rgb(255, 0, 0);font-family:arial;" &gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;Successfully created 'base_users'&lt;/span&gt;&lt;/span&gt; &lt;/li&gt;&lt;/ol&gt;Sweet now you should see the Base window!&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-weight: bold; color: rgb(51, 204, 0);font-size:130%;" &gt;9. Configure Output in snort.conf&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;/span&gt;&lt;br /&gt;edit /etc/snort/snort.conf and uncomment the line:&lt;br /&gt;&lt;br /&gt;#output database: log, mysql, user=root password=Your Password!! dbname=snort host=localhost&lt;br /&gt;&lt;br /&gt;Edit it so it looks like above.&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-weight: bold; color: rgb(51, 204, 0);font-size:130%;" &gt;10. Snort inline + Iptables&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;/span&gt;&lt;br /&gt;We want to test snort again but lets add som Iptables first.&lt;br /&gt;&lt;br /&gt;Check that ip_queue is loaded:&lt;br /&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;sudo modprobe ip_queue&lt;br /&gt;sudo lsmod |grep ip_queue&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;This should return something like:&lt;br /&gt;&lt;/blockquote&gt;ip_queue 11792 0&lt;br /&gt;&lt;br /&gt;Now add Iptables rule(you will loose any remote connection you have):&lt;br /&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;span class="Apple-style-span" style="font-style: normal; border-collapse: separate;"&gt;&lt;/span&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="border-collapse: separate;"&gt;sudo &lt;/span&gt;iptables -A INPUT -j QUEUE&lt;/blockquote&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse;"&gt;Check your iptables:&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;sudo iptables -L&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;You can flush/delete your Iptables at any time by issuing "sudo iptables -F"&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Now test snort again:&lt;br /&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;blockquote&gt;sudo snort -Q -v -c /etc/snort/snort.conf&lt;/blockquote&gt;&lt;/span&gt;You should now see any traffic going from your snort.&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span style="color: rgb(51, 204, 0);font-size:130%;" &gt;11. Bridging the interfaces&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;So lets bridge the interfaces you are going to have traffic passing through.&lt;br /&gt;&lt;br /&gt;To do this you need to load the bridge module:&lt;br /&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo modprobe bridge&lt;/span&gt;&lt;/blockquote&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse;"&gt;Now edit /etc/network/interfaces:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;blockquote&gt;sudo gedit /etc/network/interfaces&lt;/blockquote&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse;"&gt;Make it look like this:( if you have 3 Nics, 1 for Mgmt, if you dont check out &lt;span class="Apple-style-span" style="border-collapse: separate;"&gt;&lt;a href="http://openmaniak.com/inline_bridge.php"&gt;http://openmaniak.com/inline_bridge.php&lt;/a&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse;"&gt;):&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse;"&gt;###############################&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse;"&gt;# Loopback interface &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;auto lo&lt;br /&gt;iface lo inet loopback&lt;br /&gt;# the bridge&lt;br /&gt;auto br0&lt;br /&gt;iface br0 inet manual&lt;br /&gt;#&lt;span class="Apple-style-span" style="font-weight: bold;"&gt; &lt;span class="Apple-style-span" style="color: rgb(204, 0, 0);"&gt;Ethernet Interfaces you want to add to bridge !!!!&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;bridge_ports &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="Apple-style-span" style="color: rgb(255, 0, 0);"&gt;eth0 &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="Apple-style-span" style="color: rgb(255, 0, 0);"&gt;eth1 &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;# Time to wait before loading the bridge&lt;br /&gt;bridge_maxwait 0&lt;br /&gt;&lt;br /&gt;# Mgmt Interface:&lt;br /&gt;auto &lt;span class="Apple-style-span" style="color: rgb(255, 0, 0);"&gt;eth2 &lt;/span&gt;&lt;br /&gt;iface&lt;span class="Apple-style-span" style="color: rgb(255, 0, 0);"&gt; eth2&lt;/span&gt; inet static&lt;br /&gt;address 10.2.96.155&lt;br /&gt;netmask 255.255.255.0&lt;br /&gt;broadcast 10.2.96.255&lt;br /&gt;gateway 10.2.96.254&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;#################################&lt;br /&gt;&lt;br /&gt;After you have saved the file restart your NICS&lt;br /&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo /etc/init.d/networking restar&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;t&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span class="Apple-style-span" style="font-weight: bold; color: rgb(51, 204, 0);font-size:130%;" &gt;12. Snort Inline Bridge mode + Forward Ip_queue&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;So now eth1 and eth0 should be bridged, and we have a port for mgmt!&lt;br /&gt;&lt;br /&gt;Now send the packages that you want to the QUEUE and snort will alert, drop, log, alter etc. This is done by issuing Iptables to send all packets it would normally forward in the bridge to the QUEUE.&lt;span class="Apple-style-span" style="font-style: italic; border-collapse: collapse;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-style: italic; border-collapse: collapse;"&gt;&lt;blockquote&gt;sudo iptables -A FORWARD -j QUEUE&lt;/blockquote&gt;&lt;/span&gt;Now all you got to do is to start snort with the -Q argument.&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;blockquote&gt;&lt;em&gt;sudo snort -Q -v -c /etc/snort/snort.conf&lt;/em&gt;&lt;/blockquote&gt;&lt;/em&gt;&lt;span style="color: rgb(51, 204, 0);"&gt;Enjoy!!!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Now remember all rules are set to "Alert" by default so you will have to edit them and change them to drop manually or by using oinkmaster. I preffer IDSPM and i will write a howto on that soon. I will also write a Howto on getting splunk to eat snort alert logs and report some nice stuff about them. Check out these screens for a preview :)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: rgb(85, 26, 139); text-decoration: underline;"&gt;&lt;span class="Apple-style-span" style="color: rgb(0, 0, 0);"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_bZ7EhbBrv3Q/SSxG7FTouNI/AAAAAAAAADo/fZ5dREaO5Gc/s1600-h/splunk2.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5272667244594772178" style="width: 200px; cursor: pointer; height: 132px;" alt="" src="http://3.bp.blogspot.com/_bZ7EhbBrv3Q/SSxG7FTouNI/AAAAAAAAADo/fZ5dREaO5Gc/s200/splunk2.JPG" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_bZ7EhbBrv3Q/SSxG3dEAnwI/AAAAAAAAADg/iER_SQ7Ez6I/s1600-h/splunk1.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5272667182252203778" style="width: 200px; cursor: pointer; height: 128px;" alt="" src="http://4.bp.blogspot.com/_bZ7EhbBrv3Q/SSxG3dEAnwI/AAAAAAAAADg/iER_SQ7Ez6I/s200/splunk1.JPG" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_bZ7EhbBrv3Q/SSxCR_qcF0I/AAAAAAAAADI/iEAylEa6rfQ/s1600-h/idspm.JPG"&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_bZ7EhbBrv3Q/SSxCR_qcF0I/AAAAAAAAADI/iEAylEa6rfQ/s1600-h/idspm.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5272662140658652994" style="width: 200px; cursor: pointer; height: 138px;" alt="" src="http://2.bp.blogspot.com/_bZ7EhbBrv3Q/SSxCR_qcF0I/AAAAAAAAADI/iEAylEa6rfQ/s200/idspm.JPG" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_bZ7EhbBrv3Q/SSxCN0qzFvI/AAAAAAAAADA/3ETTSDYNxpY/s1600-h/base.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5272662068987893490" style="width: 200px; cursor: pointer; height: 125px;" alt="" src="http://1.bp.blogspot.com/_bZ7EhbBrv3Q/SSxCN0qzFvI/AAAAAAAAADA/3ETTSDYNxpY/s200/base.JPG" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7970604688368987276-1359045262081533847?l=layer8problem.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://layer8problem.blogspot.com/feeds/1359045262081533847/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7970604688368987276&amp;postID=1359045262081533847' title='13 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7970604688368987276/posts/default/1359045262081533847'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7970604688368987276/posts/default/1359045262081533847'/><link rel='alternate' type='text/html' href='http://layer8problem.blogspot.com/2008/11/howto-great-and-mighty-tutorial-about.html' title='Howto: The great and mighty tutorial about Snort 2.8 Inline + Base'/><author><name>Fourknees</name><uri>http://www.blogger.com/profile/17221216896438461606</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_bZ7EhbBrv3Q/SP-WPaMDNYI/AAAAAAAAABE/ekK5saNOVps/S220/untitled2.GIF'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_bZ7EhbBrv3Q/SSwX56fSH_I/AAAAAAAAAC4/9l6D07QSXOE/s72-c/xubuntu.JPG' height='72' width='72'/><thr:total>13</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7970604688368987276.post-8943984778318836049</id><published>2008-10-23T15:30:00.007+02:00</published><updated>2008-11-25T15:44:12.872+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Howto´s and Guides'/><title type='text'>Howto: Remote Desktop to Xubuntu 7.10 with FreeNX</title><content type='html'>I noticed that my other way of&lt;a href="http://layer8problem.blogspot.com/2008/10/howto-remote-desktop-to-xubuntu-710.html"&gt; remote desktop to Xubuntu via vine&lt;/a&gt; had a big flaw, and that was that everytime you had to restart your system you had to manually log in and start the vine session.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;So i installed the NX server and NX client instead. So heres a short tutorial on how to do it:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;1. Head over to &lt;a href="http://www.nomachine.com/download-package.php?Prod_Id=6"&gt;Nomachine&lt;/a&gt; and download all three Xubuntu .deb Packages to your server.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;And run them in this specific order: &lt;/div&gt;&lt;blockquote&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;sudo dpkg -i nxclient_3.2.0-14_i386.deb &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;sudo dpkg -i nxnode_3.2.0-13_i386.deb &lt;br /&gt;sudo dpkg -i nxserver_3.2.0-16_i386.deb&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div&gt;If you dont run them in this specific order you will get dependencies failure and you will have to issue  : "sudo apt-get install -f" to solve it.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;2. You also need to install the Opensshd server, thats the one that handles the authentication for NX. Do so by typing&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;blockquote&gt;sudo apt-get install ssh&lt;/blockquote&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;3. Now that the server is done, install your &lt;a href="http://www.nomachine.com/download.php"&gt;Freenx client&lt;/a&gt; Windows xp / Unix software.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Now you need to configure it. So point it to the ip your Xubuntu machine has, and in the desktop options choose "Unix" and "Custom":&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_bZ7EhbBrv3Q/SQB-weSzRTI/AAAAAAAAACo/p-RuHqsOei0/s1600-h/freenx.JPG"&gt;&lt;img src="http://3.bp.blogspot.com/_bZ7EhbBrv3Q/SQB-weSzRTI/AAAAAAAAACo/p-RuHqsOei0/s320/freenx.JPG" border="0" alt="" id="BLOGGER_PHOTO_ID_5260343735999481138" style="cursor: pointer; width: 262px; height: 320px; " /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Then click on the settings button and mark the "run the following command".&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;In the box type:&lt;/div&gt;&lt;div&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;startxfce4&lt;/span&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;div&gt;And also mark the "New Virtual Desktop" button.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_bZ7EhbBrv3Q/SQB_UFsvZxI/AAAAAAAAACw/NKiXpH8CfGE/s1600-h/freenx2.JPG"&gt;&lt;img src="http://2.bp.blogspot.com/_bZ7EhbBrv3Q/SQB_UFsvZxI/AAAAAAAAACw/NKiXpH8CfGE/s320/freenx2.JPG" border="0" alt="" id="BLOGGER_PHOTO_ID_5260344347872683794" style="cursor: pointer; width: 320px; height: 311px; " /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Voila! Remote connection that works when Xubuntu has rebooted!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7970604688368987276-8943984778318836049?l=layer8problem.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://layer8problem.blogspot.com/feeds/8943984778318836049/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7970604688368987276&amp;postID=8943984778318836049' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7970604688368987276/posts/default/8943984778318836049'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7970604688368987276/posts/default/8943984778318836049'/><link rel='alternate' type='text/html' href='http://layer8problem.blogspot.com/2008/10/howto-remote-desktop-to-xubuntu-710_23.html' title='Howto: Remote Desktop to Xubuntu 7.10 with FreeNX'/><author><name>Fourknees</name><uri>http://www.blogger.com/profile/17221216896438461606</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_bZ7EhbBrv3Q/SP-WPaMDNYI/AAAAAAAAABE/ekK5saNOVps/S220/untitled2.GIF'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_bZ7EhbBrv3Q/SQB-weSzRTI/AAAAAAAAACo/p-RuHqsOei0/s72-c/freenx.JPG' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7970604688368987276.post-5000776488018185873</id><published>2008-10-23T10:17:00.016+02:00</published><updated>2008-10-23T14:11:27.790+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Howto´s and Guides'/><title type='text'>Howto: Remote Desktop to Xubuntu 7.10 the simple way</title><content type='html'>&lt;blockquote&gt;&lt;/blockquote&gt;&lt;blockquote&gt;&lt;/blockquote&gt;&lt;blockquote&gt;&lt;/blockquote&gt;So, my first "tutorial". This idea spawned after i was trying to get remote access to my Xubuntu machine that i was trying to install &lt;a href="http://www.snort.org/"&gt;Snort&lt;/a&gt; on. I did not want to spend 2 hours in a cold serverroom so i thought that remote access would be really sweet. &lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;So the first thing that came to mind was installing a VNC server. That started out to be a lot more complicated than it should have to be. Then i rememberd that Ubuntu has this preinstalled, so i could use the same package as Ubuntu does. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This will also let you remote access your current session and its also resumable.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;So:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;(all text that is cursive should be typed into a terminal window!)&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;1. Make sure you have Xubuntu installed (prefferably 7.10)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;2. Make sure you have it updated to the latest version by typing:&lt;/div&gt;&lt;blockquote&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo apt-get update&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo apt-get upgrade&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div&gt;3. Now you should install &lt;a href="http://www.gnome.org/~markmc/remote-desktop-2.html"&gt;Vino&lt;/a&gt;, you do this by typing:&lt;span class="Apple-style-span" style="font-style: italic; "&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;blockquote&gt;sudo apt-get install vino&lt;/blockquote&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;4. This will install vino, after you are done you need to configure it, do this by typing:&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo vino-preferences&lt;/span&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;div&gt;this will launch the vino preferences window:&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_bZ7EhbBrv3Q/SQBDbgBFOAI/AAAAAAAAACg/MMJsFBRaafk/s1600-h/vino-preferences.JPG"&gt;&lt;img src="http://2.bp.blogspot.com/_bZ7EhbBrv3Q/SQBDbgBFOAI/AAAAAAAAACg/MMJsFBRaafk/s320/vino-preferences.JPG" border="0" alt="" id="BLOGGER_PHOTO_ID_5260278504498739202" style="cursor: pointer; width: 320px; height: 282px; " /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;5. Now check the following:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;"Allow other users to view your desktop"&lt;/div&gt;&lt;div&gt;"Allow other users to control your desktop"&lt;/div&gt;&lt;div&gt;"Require the user to enter this password"&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Enter a password, this is optional&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;And uncheck:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;"Ask for your confirmation"&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This will stop you from having to run all the way to the computer/server that runs Vino and allow yourself to remotely login each time you try to do it.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;6. Now start Vino by typing:&lt;/div&gt;&lt;div&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;sudo vino-session&lt;/span&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;div&gt;&lt;blockquote&gt;&lt;/blockquote&gt;A message stating that Vino has been started will follow.  Now you can close the terminal.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;7.Now download your favorite VNC viewer program:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Two free options:&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.blogger.com/www.realvnc.com/"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-family:arial;"&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;a href="http://www.realvnc.com/"&gt;Real VNC&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style=" ;font-family:arial;"&gt;&lt;span class="Apple-style-span" style=" "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;a href="http://www.tightvnc.com/"&gt;Thight VNC&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Congratulations, your done with setting up a Remote Desktop connection to your Xubuntu installation. The problem with this setup is that everytime you reboot you will have to login manually and start the vino server. If you want more challenging ways to get Remote Access to a Xubuntu machine you should check out the Vnc4 Server and the 51page thread over at &lt;a href="http://ubuntuforums.org/showthread.php?t=122402"&gt;Ubuntu Forums.&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7970604688368987276-5000776488018185873?l=layer8problem.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://layer8problem.blogspot.com/feeds/5000776488018185873/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7970604688368987276&amp;postID=5000776488018185873' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7970604688368987276/posts/default/5000776488018185873'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7970604688368987276/posts/default/5000776488018185873'/><link rel='alternate' type='text/html' href='http://layer8problem.blogspot.com/2008/10/howto-remote-desktop-to-xubuntu-710.html' title='Howto: Remote Desktop to Xubuntu 7.10 the simple way'/><author><name>Fourknees</name><uri>http://www.blogger.com/profile/17221216896438461606</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_bZ7EhbBrv3Q/SP-WPaMDNYI/AAAAAAAAABE/ekK5saNOVps/S220/untitled2.GIF'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_bZ7EhbBrv3Q/SQBDbgBFOAI/AAAAAAAAACg/MMJsFBRaafk/s72-c/vino-preferences.JPG' height='72' width='72'/><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7970604688368987276.post-7437534062777519439</id><published>2008-10-22T23:37:00.006+02:00</published><updated>2008-10-22T23:53:17.417+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Rant (useless crap)'/><title type='text'>In the beginning there was nothing.</title><content type='html'>And now here i am. So this is my first post, it feels great that i finally have gotten the thumb out and starting to contribute to the community at large.&lt;br /&gt;&lt;br /&gt;This Blog will serve 3 purposes:&lt;br /&gt;&lt;br /&gt;1. Improve my english, especially grammar. If you havent already noticed i am from sweden, so feel free to correct my english.&lt;br /&gt;&lt;br /&gt;2. Help others by publishing guides and stuff that i found useful when learning applications.&lt;br /&gt;&lt;br /&gt;3. Fun. Hopefully this blog will serve a good laugh or two.&lt;br /&gt;&lt;br /&gt;So thank you for reading. Hopefully you will find this blog useful.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7970604688368987276-7437534062777519439?l=layer8problem.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://layer8problem.blogspot.com/feeds/7437534062777519439/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7970604688368987276&amp;postID=7437534062777519439' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7970604688368987276/posts/default/7437534062777519439'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7970604688368987276/posts/default/7437534062777519439'/><link rel='alternate' type='text/html' href='http://layer8problem.blogspot.com/2008/10/in-beginning-there-was-nothing.html' title='In the beginning there was nothing.'/><author><name>Fourknees</name><uri>http://www.blogger.com/profile/17221216896438461606</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_bZ7EhbBrv3Q/SP-WPaMDNYI/AAAAAAAAABE/ekK5saNOVps/S220/untitled2.GIF'/></author><thr:total>2</thr:total></entry></feed>
