LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-29-2006, 02:40 AM   #1
true_atlantis
Member
 
Registered: Oct 2003
Distribution: fedora cor 5 x86_64
Posts: 639

Rep: Reputation: 30
honeynet question


so im trying to set up a honeynet spererate from my home LAN, im using roo from www.honeynet.org and am trying to figure something out. i have it set up so i have my modem connected to a hub, then from the hub going to my honeypot and the other port on the hub going to my home wireless router. in reading on honeynet.org i see this

* eth0 is the "Internet" or outside Interface
* eth1 is the LAN interface (Honeypot side)
* eth2 is the Management interface
* br0 is the virtual bridge interface (eth0 + eth1)

what exactly does this mean? are all in and outgoing connections going through eth0, and do i need to add another computer to eth1 with services on it? im not sure i completely understand how they are expecting this to be set up. do i need to set up a gateway? whats the deal? thanks
 
Old 03-30-2006, 05:51 AM   #2
ledow
Member
 
Registered: Apr 2005
Location: UK
Distribution: Slackware 13.0
Posts: 241

Rep: Reputation: 34
So you're trying to set up a network that is DESIGNED to be used so that ANYONE can detect and attack it, alongside your own home network? And you're not even sure of the naming of the interfaces and their functions or how to set it up?

<quote>what exactly does this mean? are all in and outgoing connections going through eth0, and do i need to add another computer to eth1 with services on it? im not sure i completely understand how they are expecting this to be set up. do i need to set up a gateway? whats the deal? thanks</quote>

Okay... is it not time to rethink this then?

I set up Linux and Windows networks, build my own firewall/gateway machines and wireless networks FOR A LIVING and despite my confidence in my ability to secure such networks, there is no way I would ever INVITE people to try to attack any part of my network or to create networks for them to attack, whether that was for monitoring purposes or not.

I'm paranoid enough that I don't use wireless at home (unless the only access across the wireless link is via authenticated public key SSH2). I absolutely cannot fathom why you would want to do this at all, especially if there's any possibility that you are uncertain as to how it should be set up. If you get it even slightly wrong, they could easily get inside your home computer and do whatever they wanted.

Go away and think about it for just five minutes before you try to install anything even resembling this.
 
Old 03-30-2006, 03:20 PM   #3
true_atlantis
Member
 
Registered: Oct 2003
Distribution: fedora cor 5 x86_64
Posts: 639

Original Poster
Rep: Reputation: 30
i do not think i need to rethink this. my question was specific to how the honeynet.org cd was set up to be used. i dont know how much you have read about it, but it has snort-inline pre installed, so i could make it so it would drop packets immediatly, so nothing could get to my home network. the reason i want it alongside my home network is because it is a lot cheaper to split one internet connection into 2 IPS via a hub than pay for a whole new high speed connection. the honeypot is set up so that any access to it would be considered an intrusion, with direct email to my phone, i will be able to see these things immediatley. im not very paranoid about security issues because i know that if any of my machines got compromised i am positive that i would be able to recognize it and be able to recover in a timley manner.

now, i appreciate your concern with my decision to set up a honeynet, but do you have an answer to my question?

thanks
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
honeynet tutorial true_atlantis Linux - Security 10 03-01-2006 11:39 AM
Question, Apples Contribution to Open Source + MacOs file structure question Higgy3k Other *NIX 5 07-25-2005 04:23 AM
hoacd honeynet installation troubles zuessh Linux - Security 2 06-22-2004 06:12 PM
login prompt question & kde scheme question JustinCoyan Slackware 2 06-09-2004 02:02 PM
Honeynet for intrusion detection? Pcghost Linux - Security 1 05-23-2003 02:43 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:18 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration