Page 8 of 31 FirstFirst ... 67891018 ... LastLast
Results 71 to 80 of 309

Thread: Intrusion Detection

  1. #71
    Join Date
    Apr 2008
    Location
    Dulles, VA
    Beans
    392
    Distro
    Ubuntu 10.04 Lucid Lynx

    Re: Intrusion Detection

    I would report him, but it's an ISP in Mexico.

  2. #72
    Join Date
    Apr 2006
    Location
    Montana
    Beans
    Hidden!
    Distro
    Kubuntu Development Release

    Re: Intrusion Detection

    Quote Originally Posted by bmwman View Post
    I would report him, but it's an ISP in Mexico.


    Well, that is what black listing is for
    There are two mistakes one can make along the road to truth...not going all the way, and not starting.
    --Prince Gautama Siddharta

    #ubuntuforums web interface

  3. #73
    Join Date
    Jan 2009
    Beans
    1

    Re: Intrusion Detection

    Since I'm not a big fan of adding several resource hungry services (apache, mysql) when they are not essential, I decided to go for the sqlless snort + ossec. I used the "snort" ubuntu package from repository which installed and started flawlessly (it detected my own nmap scans, and even some random port scans from internet). However, when Ubuntu is booting, I can see that snort starting script has "failed" and snort doesn't start. But if I run "/etc/conf.d/snort start" from console it starts without any issues. I've tried running it with both original and bodhi.zazens scripts but the result is always the same - snort fails during boot, but starts and works perfectly when started from console... Executing from rc.local changes nothing. I've tried "snort -T -c /etc/snort/snort.conf" but it doesn't report any errors.

    Any ideas why is it happening? Or at least how to find out what is failing during boot?

  4. #74
    Join Date
    Jan 2009
    Beans
    11

    Re: Intrusion Detection

    I'm sorry for asking such a noob question ,
    Is there any way to translate honeypot captured data into a SNORT signature ?
    I'd like to deploy self-learning IDS with snort based on data caputred by honeypot softwares.
    THank you

  5. #75
    Join Date
    Feb 2008
    Beans
    821

    Re: Intrusion Detection

    wondering if this is for me. i think i get hacked almost on a daily bases. everytime i install any ubuntu 7.10 to 8.10 (i give up on 8.04 and 8.10 since i get systems 32 file along the installation process) . that same day my drive becomes "read only" and cannot save or anything. its either that or malicious software. going to reinstall sometime soon so wondering if i should install this before updates or after? i seem tobe getting hacked or getting malicious software during installation. i need to try something. please help

  6. #76
    Join Date
    Apr 2006
    Location
    Montana
    Beans
    Hidden!
    Distro
    Kubuntu Development Release

    Re: Intrusion Detection

    Quote Originally Posted by KEE View Post
    wondering if this is for me. i think i get hacked almost on a daily bases. everytime i install any ubuntu 7.10 to 8.10 (i give up on 8.04 and 8.10 since i get systems 32 file along the installation process) . that same day my drive becomes "read only" and cannot save or anything. its either that or malicious software. going to reinstall sometime soon so wondering if i should install this before updates or after? i seem tobe getting hacked or getting malicious software during installation. i need to try something. please help
    Sounds like a hard ware problem to me, my guess is your hard drive is old and/or failing. When there are disk errors they are remounted read only.
    There are two mistakes one can make along the road to truth...not going all the way, and not starting.
    --Prince Gautama Siddharta

    #ubuntuforums web interface

  7. #77
    Join Date
    Jul 2005
    Beans
    13

    Re: Intrusion Detection

    For some reason the ossec webui doesnt ask for a password when i access the site. Even though i set a username and password when i installed ossec.

    Is this a known issue? (when i installed apache i only did apt-get apache2 and php modules).

  8. #78
    Join Date
    Apr 2006
    Location
    Montana
    Beans
    Hidden!
    Distro
    Kubuntu Development Release

    Re: Intrusion Detection

    Quote Originally Posted by catolh View Post
    For some reason the ossec webui doesnt ask for a password when i access the site. Even though i set a username and password when i installed ossec.

    Is this a known issue? (when i installed apache i only did apt-get apache2 and php modules).
    I use https / .htaccess for the webui
    There are two mistakes one can make along the road to truth...not going all the way, and not starting.
    --Prince Gautama Siddharta

    #ubuntuforums web interface

  9. #79
    Join Date
    Jul 2005
    Beans
    13

    Re: Intrusion Detection

    Quote Originally Posted by bodhi.zazen View Post
    I use https / .htaccess for the webui
    Ah, i figured there was something about .htaccess. But how do i go about and make it require https ?

  10. #80
    Join Date
    Apr 2006
    Location
    Montana
    Beans
    Hidden!
    Distro
    Kubuntu Development Release

    Re: Intrusion Detection

    Quote Originally Posted by catolh View Post
    Ah, i figured there was something about .htaccess. But how do i go about and make it require https ?
    You have to install / configure ssl and apache :

    http://www.tc.umn.edu/~brams006/selfsign_ubuntu.html
    There are two mistakes one can make along the road to truth...not going all the way, and not starting.
    --Prince Gautama Siddharta

    #ubuntuforums web interface

Page 8 of 31 FirstFirst ... 67891018 ... LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •