Modern Honey Network
Getting up and running using Vagrant
Thursday, 24 July 2014
Saturday, 31 August 2013
Using BackTrack5 R3 to provide Snort
I am using Oracle VM VirtualBox and the BT5R3-KDE-32.iso
At the menu screen, select Default Boot Text Mode, and wait for terminal screen to load.
startx [Enter] to get to the GUI.
Click the Install BackTrack icon
----
Thanks
http://www.backtrack-linux.org/wiki/index.php/VirtualBox_Install
http://www.backtrack-linux.org/wiki/index.php/Install_BackTrack_to_Disk
I am using Oracle VM VirtualBox and the BT5R3-KDE-32.iso
At the menu screen, select Default Boot Text Mode, and wait for terminal screen to load.
startx [Enter] to get to the GUI.
Click the Install BackTrack icon
----
Thanks
http://www.backtrack-linux.org/wiki/index.php/VirtualBox_Install
http://www.backtrack-linux.org/wiki/index.php/Install_BackTrack_to_Disk
Sunday, 21 April 2013
Snort little piggy
Install default Ubuntu 12.04 Server
sudo su
apt-get update
apt-get upgrade
Install SSH to enable remove admin
sudo apt-get install openssh-server
From a putty session
apt-get install mysql-server nmap nbtscan apache2 php5 php5-mysql php5-gd libpcap0.8-dev libpcre3-dev g++ bison flex libpcap-ruby make zlib1g-dev libmysqld-dev libdnet libdnet-dev libpcre3 libpcre3-dev gcc make flex byacc bison linux-headers-generic libxml2-dev libdumbnet-dev zlib1g zlib1g-dev
mkdir /usr/local/src/snort
cd /usr/local/src/snort
wget http://www.snort.org/dl/snort-current/daq-2.0.0.tar.gz
tar -xvzf daq-2.0.0.tar.gz
cd daq-2.0.0
./configure
wget http://www.snort.org/dl/snort-current/snort-2.9.4.5.tar.gz
cd snort-2.9.4.5
./configure --prefix /usr/local/snort && make && make install
--
Thanks
http://wiki.aanval.com/wiki/Community:Snort_2.9.2.3_Installation_Guide_for_Ubuntu_12.04,_with_Barnyard2,_Pulledpork,_and_Aanval#Setup_the_network_interface_you_will_be_using_for_sniffing_traffic_in_promiscuous_mode
https://github.com/da667/Autosnort
sudo su
apt-get update
apt-get upgrade
Install SSH to enable remove admin
sudo apt-get install openssh-server
From a putty session
apt-get install mysql-server nmap nbtscan apache2 php5 php5-mysql php5-gd libpcap0.8-dev libpcre3-dev g++ bison flex libpcap-ruby make zlib1g-dev libmysqld-dev libdnet libdnet-dev libpcre3 libpcre3-dev gcc make flex byacc bison linux-headers-generic libxml2-dev libdumbnet-dev zlib1g zlib1g-dev
Enter and confirm a MySQL password
mkdir /usr/local/src/snort
cd /usr/local/src/snort
wget http://www.snort.org/dl/snort-current/daq-2.0.0.tar.gz
tar -xvzf daq-2.0.0.tar.gz
cd daq-2.0.0
./configure
make
make install
cd /usr/local/src/snort
wget http://www.snort.org/dl/snort-current/snort-2.9.4.5.tar.gz
tar -zxvf snort-2.9.4.5.tar.gz
cd snort-2.9.4.5
./configure --prefix /usr/local/snort && make && make install
groupadd snort
useradd -g snort snort
ln -s /usr/local/snort/bin/snort /usr/sbin/
ln -s /usr/local/snort/etc /etc/snort
cd /usr/local/src/snort
wget -O snortrules-snapshot-2941.tar.gz http://www.snort.org/reg-rules/snortrules-snapshot-2941.tar.gz/9efdb56ce6e1409f2c3904c284bd1af8d506d6e4
--
Thanks
http://wiki.aanval.com/wiki/Community:Snort_2.9.2.3_Installation_Guide_for_Ubuntu_12.04,_with_Barnyard2,_Pulledpork,_and_Aanval#Setup_the_network_interface_you_will_be_using_for_sniffing_traffic_in_promiscuous_mode
https://github.com/da667/Autosnort
Friday, 8 February 2013
Adding DionaeaFR
following the 3 minute script.
apt-get install unzip
apt-get install make
apt-get install git
apt-get install python-netaddr
aptitude install g++
apt-get install npm
change /opt/dionaea/var/dionaea/logsql.sqlite to /var/dionaea/logsql.sqlite
---
Thanks
https://github.com/andrewmichaelsmith/honeypot-setup-script/
http://bruteforce.gr/visualizing-dionaeas-results-with-dionaeafr.html
apt-get install unzip
apt-get install make
apt-get install git
apt-get install python-netaddr
aptitude install g++
apt-get install npm
9) (optional) Edit DionaeaFR’s settings file located at /opt/DionaeaFR/DionaeaFR/settings.py. There you might want to change line 17 that points to Dionaea’s SQLite db. If you have followed the official installation guide for Dionaea this is already correct.
change /opt/dionaea/var/dionaea/logsql.sqlite to /var/dionaea/logsql.sqlite
---
Thanks
https://github.com/andrewmichaelsmith/honeypot-setup-script/
http://bruteforce.gr/visualizing-dionaeas-results-with-dionaeafr.html
Wednesday, 6 February 2013
Automatic Honeypot Setup Script
Now looking at a system to add honeypot to an Ubuntu server.
The write up says 3 mins to get it going, so well worth a look see
First get the Ubuntu -12.04.1-server-amd64.iso
Perform a default install.
After install and first logon, wget is not yet available.
---
Thanks
http://www.ubuntu.com/download/desktop/alternative-downloads
http://serverfault.com/questions/131816/how-to-install-wget-on-this
The write up says 3 mins to get it going, so well worth a look see
First get the Ubuntu -12.04.1-server-amd64.iso
Perform a default install.
After install and first logon, wget is not yet available.
sudo bash
apt-get update
apt-get -f install
apt-get install wget
wget -q https://raw.github.com/andrewmichaelsmith/honeypot-setup-script/master/setup.bash -O /tmp/setup.bash && bash /tmp/setup.bash
---
Thanks
http://www.ubuntu.com/download/desktop/alternative-downloads
http://andrewmichaelsmith.com/2013/01/automatic-honeypot-setup-script/
http://serverfault.com/questions/131816/how-to-install-wget-on-this
Thursday, 31 January 2013
Friday, 18 January 2013
Linux static address
edit /etc/network/interfaces
auto eth0
iface eth0 inet static
address 192.168.1.100
netmask 255.255.255.0
network 192.168.1.0
broadcast 192.168.1.255
gateway 192.168.1.1
Restart the neworking service using the following command
/etc/init.d/networking restart
---
Thanks
http://www.ubuntugeek.com/change-ubuntu-system-from-dhcp-to-a-static-ip-address.html
auto eth0
iface eth0 inet static
address 192.168.1.100
netmask 255.255.255.0
network 192.168.1.0
broadcast 192.168.1.255
gateway 192.168.1.1
Restart the neworking service using the following command
/etc/init.d/networking restart
---
Thanks
http://www.ubuntugeek.com/change-ubuntu-system-from-dhcp-to-a-static-ip-address.html
Subscribe to:
Posts (Atom)