LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 02-01-2006, 10:44 AM   #1
Atrocity
Member
 
Registered: Nov 2002
Location: Hell
Distribution: FreeBSD, Slackware
Posts: 308

Rep: Reputation: 30
Snort-Wireless


Anyone have any experience with snort-wireless they want to share...

I have this thing set up and running with mysql and syslog and it does log normal alerts fine when it is running on my ethernet card!!! But when I set it to work on my wireless card I dont get any alerts and I turn on rogue acceess points and such and I get nothing!!!

I have all of the preprocessors uncommented in the snort.conf
I also uncommented all the rules in the wiFi rules file.
I have made no changes to these rules so they should be set so that everything triggers and alert.


The wireles card I set to (iwconfig wifi0 mode Master) I didnt do anything else to the card and that may be the problem I am not sure if I need to do more... I have tried a cisco aironet card and an intell pro wirless so far. I have access to atheros and onronco cards as well. But the cisco should definatly work

current OS: Slackware 10.2
snortwireless: newest version http://snort-wireless.org/
 
Old 02-02-2006, 09:39 AM   #2
acidzebra
Member
 
Registered: Mar 2005
Location: Netherlands
Distribution: FC4, debian, SuSE
Posts: 64

Rep: Reputation: 15
I *think* your card needs to be in monitoring mode, try
iwpriv $DEVICE
(where device is your wireless card; ie eth1 or eth0 etc)

If you don't see a line like
monitor (8BE8) : set 2 int & get 0
(it has to feature the monitor, the specifics can vary)
your wireless NIC drivers is incapable of monitor mode.

If you do see a monitor mode these two commands:
/sbin/iwpriv $DEVICE monitor 1 $CHANNEL
/sbin/ifconfig $DEVICE promisc up
should enable monitoring.
 
Old 02-02-2006, 03:07 PM   #3
Atrocity
Member
 
Registered: Nov 2002
Location: Hell
Distribution: FreeBSD, Slackware
Posts: 308

Original Poster
Rep: Reputation: 30
Thanks the iwconfig eth1 m monitor and the ifconfig promisc did the trick!!!!!!!!!! Now just need to find a patch for mysql support for wirless alerts on the newest release, I havnt seen one yet
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Error when starting up snort: bash:!/bin/sh/usr/local/bin/snort :Eent not found cynthia_thomas Linux - Software 1 11-11-2005 02:59 PM
snort failed: snort: symbol lookup error: undefined symbol: usmAES192PrivProtocol Emmanuel_uk Linux - Security 1 07-10-2005 10:29 AM
wireless ids with snort and kismet evilchild Linux - Security 1 01-26-2005 04:03 PM
Snort: Block False Positive from Dlink Wireless Router omICron Linux - Security 1 01-01-2005 01:41 AM
snort snort.conf help crealkiller175 Linux - Software 1 03-08-2003 05:58 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 11:44 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration