About Me
- Doug Burks
- Christian, Husband and Father, Security Guy, SANS Mentor, Security Onion LiveCD developer, Snort/Sguil/OSSEC/ModSecurity enthusiast
Security Onion Links
Links
Tuesday, June 30, 2009
Suggestions for the Security Onion LiveCD
I'm currently working on the next version of the Security Onion LiveCD. What specific packages/features would you like to see added to the Security Onion LiveCD? Post a comment here or contact me on Twitter. Thanks!
Subscribe to:
Post Comments (Atom)
Intrusion Detection
Blog Archive
-
▼
2009
(30)
-
►
April
(8)
- Announcing Detroit Dave's Raves
- How a Single Piece of Paper Can Saturate a WAN Lin...
- SANS GCIA Gold Paper on Snort 3.0 Beta 3
- Wireshark 1.0.7 is out!
- Snort 2.8.4 is out!
- Snort 3.0 (SnortSP) Beta 3 -- Inline Bridging Mode...
- Integrating Snort 3.0 Beta 3 and Sguil in 3 Steps
- Installing Snort 3.0 (SnortSP) Beta 3 on Ubuntu 8....
-
►
January
(9)
- Integrating Snort 3.0 (SnortSP) and Sguil in 3 Ste...
- Installing Snort 3.0 (SnortSP) on Ubuntu in 3 Step...
- NSMnow 1.3
- SANS 503 Mentor class is full
- Links for Binary and Hex Refreshers
- Creating md5 and sha1 hashes using dcfldd
- 2009 SANS Log Management Survey
- Reminder about SANS 503 training here in Augusta
- Upgrading from Fedora 9 to Fedora 10 using Preupgr...
-
►
April
(8)
8 comments:
NAT, full router flexibility, and a direct access to the internet from a computer on the local network.This should be possible?
al wills
Hi Al,
You can certainly accomplish this with the iptables command. I will look at including fwbuilder in the future for a GUI frontend for iptables.
Please let me know if you have any further suggestions!
Thanks,
Doug Burks
NAT, full router flexibility, and a direct access to the internet from a computer on the local network.Access from the local network only This should be possible?
al wills
"Access from the local network only"
This could mean a few different things and could be implemented either with a local iptables firewall or with the existing routing infrastructure already in place outside of the box.
Please let me know if you have any further questions or suggestions!
Thanks,
Doug Burks
is it possible to combine Security Onion with BackTrack or use both of them at the same time?
Hi Metasploit,
Backtrack 4 is based on Ubuntu (just like Security Onion) and so is therefore a good candidate for using the NSMnow installer to install and configure Snort, Sguil, Barnyard2, Sancp, etc. Reference this post for more information.
Likewise, Snort 3.0 (SnortSP) Beta 3 can be installed and configured on Backtrack 4 using my tutorials here:
Installing Snort 3.0 (SnortSP) Beta 3 on Ubuntu 8.04 in 3 Steps
Integrating Snort 3.0 Beta 3 and Sguil in 3 Steps
Please let me know if you have any further questions.
Thanks,
Doug Burks
ok thanks.. and i have another question. can i install it on a usb stick?
Absolutely! You can use Unetbootin to install Security Onion on a bootable USB drive. For more information, please see:
http://pentestit.com/2009/06/28/boot-snort-sguil-usb/
Please let me know if you have any further questions or suggestions.
Thanks,
Doug Burks
Post a Comment