Koozali.org: home of the SME Server

dshield client howto

Cyrus Bharda

dshield client howto
« on: July 01, 2003, 04:38:36 AM »
Hello all,

Just finished my howto on installing the dshield client.

DShield provides a platform for users of firewalls to share intrusion
information. DShield is a free and open service.

DShield.org is now helping users to fight back against attackers. We will
analyse submitted log reports and pick a number of strong cases to forward
them to the ISP from which the attack originated. A copy of the abuse report
will be forwarded to the user.


Questions/Comments greatly appreciated!

http://mirror.contribs.org/smeserver/contribs/cbharda/howto/dshield-howto.htm

Thanks!

Cyrus Bharda

Willy Roesen

Re: dshield client howto
« Reply #1 on: July 01, 2003, 11:25:28 AM »
Thats fine, Cyrus.
A couple of days ago I went and registered, and began to install, without realising, that your howto covers only SME.5.5 or less.
Now I'm running 5.6U4, and of course the install attempt died in step 4.
Any plans for an updated howto, as well as updated packages of course ?
I get a bit annoyed with myself everytime i see a mail from dshield, telling me that I haven't submitted a report.

greetings
wyron

Cyrus Bharda

Re: dshield client howto
« Reply #2 on: July 02, 2003, 02:33:32 AM »
Willy,

I am sorry that you got half way through the howto and realised that it was for 5.5 or less, I thought the heading at the top of the howto:

Release supported: SME 5.5 or less ONLY

would give you some clue, but I might make that point in a larger font so that it stands out.

I am sorry to say that no I will not be looking at updating it in the near future as I only use 5.5 and have no plans to upgrade at this point in time.

There is a iptables client, it should be similar to install?

Again I am sorry that I did not clearly point out that this howto was for 5.5 or less, I will change this asap so that other users do not fall into the same trap.

I think you can remove your membership from dshield? I really do not know as I have never tried to de-register.

Again I am sorry this has caused you greif and I will be changing the howto so that this does not happen to other users.

Cyrus Bharda

Jesper Knudsen

Re: dshield client howto
« Reply #3 on: July 04, 2003, 10:11:27 PM »
All,

I have based on the excellent howto from Cyrus make a version that will work on 5.6. I have already seen MANY attacks (app. 200 a day) and dshield reports shows the details.

See:

sme.swerts-knudsen.dk

for the howto. Thanks Cyrus for the inspiration, as you can see its somewhat close to the 5.5 installation guide from you.

Rgds,
Jesper

George

Re: dshield client howto
« Reply #4 on: July 05, 2003, 07:14:24 PM »
Thanks, it works great. I'm running 5.6U4 and it was very simple and straight foward. Good job