LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-25-2006, 09:31 AM   #1
144419855310001
Member
 
Registered: Apr 2006
Distribution: ubuntu 7.04
Posts: 219

Rep: Reputation: 30
Intrusion detection for a newbie


Hello

Whilst googling how to make my network connections more secure, I came across "snort", which looks like an interesting tool. Particularly, I would like to be able to detect whether other people are trying / have broken into my wireless networking.

However, I am very much a beginner whennnit comes to security (e.g. I use the firstarter GUI to set up my firewall - the iptables man pages are a little advanced for me), and am on the whole a newbie anyway. I was wondering whether it would be worth my time to (research how to) use snort, or whether as software it was designed as something more for the mission-critical server environment.

I don't have a clue how to set it up, so before I even try, I thought it would be worth asking this (and so possibly save myself some frustration).


[Also, I was wondering about Wireshark (formerly ethereal). What do people gnereally use this for? Is there an actual administrative use, or is it mostly used for snooping on the transmissions of e.g. unsecured wireless networks?]
 
Old 08-25-2006, 09:40 AM   #2
Matir
LQ Guru
 
Registered: Nov 2004
Location: San Jose, CA
Distribution: Debian, Arch
Posts: 8,507

Rep: Reputation: 128Reputation: 128
Ethereal is commonly used by application developers and network admins to see traffic on the network. I use it at work to see problems with the dhcp servers and clients. It lets you see what is actually hitting the wire rather than just what programs claim to be sending.

Snort is a very complex IDS. It's configuration would take quite a bit of work, but it is very powerful.

What sort of attack are you looking to guard against/detect?
 
Old 08-26-2006, 07:08 AM   #3
144419855310001
Member
 
Registered: Apr 2006
Distribution: ubuntu 7.04
Posts: 219

Original Poster
Rep: Reputation: 30
Quote:
It's configuration would take quite a bit of work, but it is very powerful.
That's what I wanted to know. I was just looking for something fairly basic and easy to configure (newbie-orientated) as a piece of general extra security ofr my system. Snort sounds a bit too advanced.

(Particularly, to see if anyone is [or is trying to] hack into my WAN. I read of people using kismet (?) etc. to detect if anyone is trying to, but how you do this, I don't know).
 
Old 08-26-2006, 06:33 PM   #4
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Quote:
Originally Posted by 144419855310001
That's what I wanted to know. I was just looking for something fairly basic and easy to configure (newbie-orientated) as a piece of general extra security ofr my system. Snort sounds a bit too advanced.
but there's super friendly web-based GUI interfaces for snort which will let you configure it and get all kinds of nice reports and stuff... check-out some of those firewall distros and you'll see...
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
intrusion detection fakie_flip Linux - Security 4 08-19-2005 05:24 PM
Intrusion Detection Systems subaruwrx Linux - Security 5 08-31-2004 07:31 PM
Intrusion Detection L1nuxbug Linux - Security 4 07-21-2004 05:20 AM
Intrusion Detection!!! egyptian Linux - Security 2 04-02-2004 11:37 AM
Intrusion Detection? matador Linux - Security 5 09-03-2003 04:44 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:45 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration