I'm practicing my security skills at home. I have two servers from college in my home and their is only my AT&T 3600HGV Router. I do not want to buy a Tap yet.
Is there a way to build this without purchasing any hardware. I do not mind putting this in front of my firewall/router/dmz, as I would like to see all traffic for educational research.
I understand the simple solution in the $40 Tap, but I really don't want to spend my food money :-)
--
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To post to this group, send email to securit...@googlegroups.com.
Visit this group at http://groups.google.com/group/security-onion.
For more options, visit https://groups.google.com/groups/opt_out.
Jason
1) Run SecurityOnion in standalone mode in a VM. Run another nested VM product in that (NOTE: vmware can do nested VMs. Nothing else I know of can. So you use one product for SO, and another on the inside). The inner one uses NAT so it's forced to go through SO. Let the "that's really hacky" flames begin, but it has worked for me.
2) I know you said no hardware, but for about usd$20 you can build a hardware tap. This is what I'm using right now and it works great. You may already have a lot of the parts, or be able to find them: http://www.instructables.com/id/Make-a-Passive-Network-Tap/
Does anyone know if its possible to Tap DSL RJ-11? Do I need a way to convert RJ-11 to RJ-45?
Once the DSL RJ-11 connects to the router the signal cannot be sniffed? Or just not the wireless traffic?
I want to Tap the DSL directly from the RJ-11 cable so that I get both wireless and ethernet.
Thanks responders for your ideas.
If have a switch that has a span port, you could use that instead of a tap. And depending on the software on the router/wap, it might give you the ability to span/monitor traffic and that might give you something.
I have two generic twin boxes, with P4, 2GB, 500GB
Onion-1 = 1 on-board NIC
Onion-2 = 1 on-board NIC, 1 Intel NIC
AT&T U-Verse comes with DSL Router: 3600HGV
RJ-11 from wall to router, then RJ-45 out on 4 ports
I can authenticate to my Wireless DSL Router, in which we have an old laptop that my wife uses.
I could monitor her wireless laptop for intrusions or data leaks, or spamming.
This would concern me in a couple ways:
1.) Signal degraded: AT&T breaks permanently, until rewired back to original spec.
2.) Is DSL routable directly from the wall through a device Doug recommended? I could re-pin the DSL RJ-11 into a RJ-45 tip, then plug into the switch, and have the data spanned or mirrored into my server's RJ-45, and re-pin the RJ-45 coming out of the switch back into an RJ-11 for my AT&T DSL Router.
P.S. I attached a drawing for simplicity.
~ Jason
Jon
Sorry, I know my drawing has already been answered.
I'm thinking about the switch. In which, if I ever swap out DSL for Comcast, all my network components become normal. DSL is the issue, but it was cheapest. I don't see upgrading, breaking my deal/contract just for that.
I know I can work with a tcpdump and replay, but I would like to work with live data in real time.
Which leads to my final question...
Can I setup Security Onion, standalone with a NIC and a Wireless Card to sniff wireless.
Will all the tools work? Snort, Snorby, Bro, etc?
--
You received this message because you are subscribed to a topic in the Google Groups "security-onion" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/security-onion/nJYacIiKDjY/unsubscribe.
To unsubscribe from this group and all its topics, send an email to security-onio...@googlegroups.com.
But keep in mind that if your SO box breaks, then so does your (and your wife's) Internet traffic.
--
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
I'm going to try and see if the college has some old wifi routers that are not needed ...
I talked to the Director of Networking, and he explained a lot to me, so he is my new best friend on this science project :D
Thanks, again.