One thing I'll add is that, by default, mon0 would not be exposed in
Setup. Edit /usr/local/bin/setup and change this:
INTERFACES=`cat "/proc/net/dev" | egrep "(eth|bond|wlan|br|ath|bge|fe)[0-9]+"
to this:
INTERFACES=`cat "/proc/net/dev" | egrep
"(eth|bond|wlan|br|ath|bge|mon|fe)[0-9]+"
Then try running Setup and see if that helps.
I've created Issue 220 to produce an official update for this:
http://code.google.com/p/security-onion/issues/detail?id=220
If anybody knows of any other interface designations that need to be
added to the list, please add them to Issue 220.
Thanks,
Doug
--
Doug Burks
SANS GSE and Community Instructor
Security Onion | http://securityonion.blogspot.com
President, Greater Augusta ISSA | http://augusta.issa.org
Replies inline.
On Wed, Feb 8, 2012 at 11:30 PM, Rhoda Dendron <rhoda....@gmail.com> wrote:
> Well, hmmm.
>
> I was able to put wlan0 in monitor mode and assign it to channel 6.
> Mon0 wouldn't let me switch frequencies for some reason, but I
> confirmed through tcpdump that it was getting a whole mess of
> packets. :)
>
> Applied the suggest changes to the conf file, did nsm_all_del, then
> did setup. Mon0 was available so I selected. However, Sguil won't
> trigger on any packets (tried going to testmyids.com and putting a
> whole bunch of Cs into a Google search) and snorby, after refusing to
> load on localhost:3000 a few times,
Snorby can take a few seconds to start, depending on hardware. What
are your RAM/CPU specs? If the box is overloaded, this could cause
you to drop packets as well and not get any alerts. You said you
selected Mon0 so I assume you chose Advanced Setup? Did you only
select Mon0 or did you select another interface as well? Please send
the output of the following commands:
sudo service nsm status
ps aux |grep snort
> won't accept the password I set.
The only time I've seen this happen is when you don't meet the minimum
password length for Snorby (6 characters). How many characters is
your password?
> I need sleep so I'll stop for now, but I'll keep trying. All of my
> notes will go into a doc as requested.
Thanks for any and all documentation!
Well, hmmm.
I was able to put wlan0 in monitor mode and assign it to channel 6.
Mon0 wouldn't let me switch frequencies for some reason, but I
confirmed through tcpdump that it was getting a whole mess of
packets. :)
Applied the suggest changes to the conf file, did nsm_all_del, then
did setup. Mon0 was available so I selected. However, Sguil won't
trigger on any packets (tried going to testmyids.com and putting a
whole bunch of Cs into a Google search) and snorby, after refusing to
load on localhost:3000 a few times, won't accept the password I set.
I need sleep so I'll stop for now, but I'll keep trying. All of my
notes will go into a doc as requested.