Slashdot Mirror


Using Snort Stealthily

jukal writes "Linux Journal has an article on using Snort as stealth sniffer, a stealth NDIS probe and stealth loger -- on a network interface with no IP address. 'Snort is a versatile and powerful tool for sniffing, intrusion detection and packet logging. Configuring it to run stealthily in sniffing mode or NIDS mode is easy; incorporating it into a stealth-logging solution is only slightly less so'"

5 of 148 comments (clear)

  1. Re:Snort UI by HappyPhunBall · · Score: 3, Informative

    The "133t hax0r" type you mentioned is much more likely to be trying to avoid snort than deploying it.

    You can find some snort enhancements at this site. Have fun.

  2. www.prelude-ids.org by Anonymous Coward · · Score: 1, Informative

    Also worth investigate Prelude
    "Prelude is a new innovative hybrid Intrusion Detection system designed to be very modular, distributed, rock solid and fast. "

  3. A better article, and other links .... by ericman31 · · Score: 5, Informative
    --
    In my universe I'm perfectly normal, it's not my fault you don't live in my universe.
  4. Re:Interesting challenge by stinky+wizzleteats · · Score: 4, Informative

    Simple, you connect your firewall to a hub on each interface.

    Which would be a great idea, except that hubs are half-duplex.

  5. Re:Warning by GeorgeH · · Score: 4, Informative

    A 10baseT patch cable with the TX wires clipped will get you a whole lotta nothing because the TX wires are used for heartbeat signals. You need to corrupt the outgoing frames instead, which is a PITA.

    The easier method is to use a 10 Mbit AUI adapter with the TX pins cut. You can probably even find a 10baseT -> AUI adapter at a computer junk shop for a buck or three.

    For more about creating a receive-only ethernet adapter check out http://www.robertgraham.com/pubs/sniffing-faq.html #receive-only or read up on Antisniff (weird, I can't find anything about it on @stake's site).

    --
    Why can't I moderate something "Wrong" or at least "Grossly Misinformed"?