Koozali.org: home of the SME Server

Legacy Forums => General Discussion (Legacy) => Topic started by: Jehu on March 13, 2002, 10:32:23 PM

Title: Intrusion Detection
Post by: Jehu on March 13, 2002, 10:32:23 PM
Is there an Intrusion Detection monitor that works with e-smith 5.1.2.  That can let me know if anyone is trying to hack my system. One that has a graphicial interface.

Thanks,
Jehu.
Title: Re: Intrusion Detection
Post by: kenshin on March 14, 2002, 12:11:46 AM
I'm currently working on an RPM of psionic's portsentry for SME 5.1.2
Title: Re: Intrusion Detection
Post by: Kevin McClain on March 14, 2002, 04:03:07 AM
Great! let us know when you are finished.
I would be happy to help test it for you.
Title: Re: Intrusion Detection
Post by: Wietse on March 14, 2002, 01:44:28 PM
I am interested too! Please post a reply here as soon as you have more info!!! Thanks in advance!
Title: Re: Intrusion Detection
Post by: Bruce on March 14, 2002, 05:00:10 PM
I am interested too! Please post a reply here as soon as you have more info!!! Thanks in advance!
Title: Re: Intrusion Detection
Post by: Sassou Efoe Boris on March 14, 2002, 11:50:17 PM
I'm working a version of Demarc Pure Secure for SME/E-SMITH (http://www.demarc.org)

There is an alpha version available at ftp://ftp.speedfactor.ath.cx/demarc

If you could send me some feed back i would be please.
(Sorry for my english , i'm french)
Title: Re: Intrusion Detection
Post by: Dean Mumby on March 15, 2002, 12:15:32 AM
This really looks cool (demarc) I will download and install tonight on a test server , will report back asap. I think this is really worth a look , a whole centralized monitoring system.

Dean
Title: Re: Intrusion Detection
Post by: kenshin on March 15, 2002, 12:29:30 AM
Well I got the RPM I made to install... and it works.. I'll put it on a site and give you guys the link tonight...
I'll have the ServerManager mod done by tomorrow...

As for Demarc... it looks cool, but you need to install libpcap, SNORT and add more perl modules...

Too much of a headache for nothing.
Title: Re: Intrusion Detection
Post by: Dean Mumby on March 15, 2002, 12:42:04 AM
Hi Kenshin

I will also gives yours a shot .. no point putting all our eggs in one basket..

I look forward to your contrib

Regards
Dean
Title: Re: Intrusion Detection
Post by: Confucius on March 15, 2002, 01:18:27 AM
Kenshin,

Can you mail me your link for the RPM you made... love to see your work at my work :-)

TIA,

Harro
Title: Re: Intrusion Detection
Post by: Jehu on March 15, 2002, 03:02:13 AM
Hey kenshin can you help me with the install. I installed it but don't know how to login. I get to the last login and I get access denied. I don't know how to create the account to access this.  The documentations at the website does not go into details.  It is hard for a newbie like me to understand.
Please help.
Thanks,
Jehu.
Title: Re: Intrusion Detection
Post by: kenshin on March 15, 2002, 05:18:42 AM
Hey guys, I got the How To at http://www.netfrost.com/kenshin
A friend of mine is hosting it for now...
This is just the first release, so be gentle...

I'll have an other release with more configurability and with more ServerManager functions out in a few days.

Kenshin Out.
Title: Re: Intrusion Detection
Post by: Craig on March 15, 2002, 06:21:19 AM
Just adding my name to the list of people interested in this project. Please post any updated information as available.

Will download and try what you have so far.

Regards
Craig
Title: Re: Intrusion Detection
Post by: Jehu on March 15, 2002, 04:42:42 PM
I think I have done everything and I cannot log into https://myserver/demarc, no matter what username and password I use.
Also when I try to run demarcd -I and it ask for the name of this sensor. What name should I use, I get an error at the end when this is finish. Tried to use different names but it does not work.
Issuing: /usr/sbin//snort -q -c /usr/local/demarc/conf/snortppp0.conf -i ppp0
database: mysql_error: Access denied for user: 'admin@localhost' (Using password: YES)
Fatal Error, Quitting..
snort: no process killed.
Please can someone help.
Thanks,
Jehu.
Title: Re: Intrusion Detection
Post by: Sassou Efoe Boris on March 17, 2002, 09:20:09 PM
Hi !
Have you read all the how-to (sorry for my poor english) ?
You seems to have a database problem , and snort problem
I've not enough information but i suggest you to read the documentation on the Demarc site : http://demarc.com/documentation/demarc-install.html

I hope it will help you

Greetings
Boris
Title: Re: Intrusion Detection
Post by: John Gause on March 24, 2002, 04:03:52 PM
Yes I would love to get the link to. I am a big fan of portsentry I have it running on my other linux boxes but I would like to deploy it to my SME 5.1.2 boxes
Title: PortSentry
Post by: John Gause on March 31, 2002, 10:09:37 AM
Just wanted to see if anyone got portsentry to work with SME 5.1.2
Title: Re: PortSentry
Post by: matjaz on April 30, 2002, 06:35:52 AM
Add me too! :-)
Title: Re: Intrusion Detection
Post by: John on May 03, 2002, 10:05:59 AM
I just wanted to see if you got the RPM finished I would really love to use Portsentry I am a fan of the program. I currently use it on a couple of Redhat Linux boxes but would love to use it with SME
Title: Re: Intrusion Detection
Post by: SniperG on May 07, 2002, 08:02:41 PM
ftp://ftp.rpmfind.net/linux/freshrpms/enigma/portsentry/portsentry-1.1-fr6.i386.rpm

For PSentry RPMs .. I have installed this and it works fine .
Title: Re: Intrusion Detection
Post by: Cyrus Bharda on December 18, 2002, 04:13:21 AM
Kenshin,

tryed to find your Howto at http://www.netfrost.com/kenshin but got 404, is there any other place your Howto is available?

Thanks

Cyrus Bharda
Title: Re: Intrusion Detection
Post by: Sassou Efoe Boris on December 18, 2002, 06:44:03 PM
Yes,

You can find it on this address : ftp://ftp.speedfactor.ath.cx/demarc/

Greetings
Sassou Efoe Boris
Title: Re: Intrusion Detection
Post by: Tony on December 19, 2002, 12:05:47 AM
Thanks for this howto...

One question tho...at the end of the installation proces I get an error about the table snort.sensor that does not exist. If I check the tables that were created I can't see that table. Should I create that table myself?

or did I do something wrong?
Title: Re: Intrusion Detection
Post by: Tony on March 11, 2003, 09:57:40 PM
I think it's time to kick this topic :)

Anyone yet?