Re: securing nic's for snort

From: Stephen Samuel (samuel@bcgreen.com)
Date: 05/29/02


Date: Wed, 29 May 2002 02:30:25 -0700
From: Stephen Samuel <samuel@bcgreen.com>
To: "Renaud, Andre" <Andre.Renaud@hp.com>, focus-linux@securityfocus.com

If you wish to have the card be semi-stealth, but still be reachable
over the net (it'd be better, for 'real' hardening, if you left it
non-IP), then you can give it a 'private' non-used address
in another subnet (say, 192.168.251.225/30 ). The corresponding
address (192.168.251.226/30 ) would belong to your 'controlling'
machine (probably on eth0:1).

Only two address can fit into a /30 subnet, so if your box
doesn't route to it, it should be pretty hard for someone else
to talk to it. Someone else snooping on the net could still
see the packets between the machines and, thus, know about
the existence of your snort box, but they should have a
hard time talking to it without your permission.

BTW: On Linux, you can apparently remove a card's IP address
by giving it an address of '0'.

Renaud, Andre wrote:
> One of the easiest ways is to simply not give the card an IP address,
> it can still go into promiscuous mode, and works fine under snort
....

-- 
Stephen Samuel +1(604)876-0426                samuel@bcgreen.com
		   http://www.bcgreen.com/~samuel/
Powerful committed communication, reaching through fear, uncertainty and
doubt to touch the jewel within each person and bring it to life.



Relevant Pages

  • TV Card Problems
    ... hard time getting my TV Card to work. ... Wonder VE (an older card). ... and TV-on-Demand Performance will be degraded on this ... when I check in the Control Panel I ...
    (microsoft.public.win2000.hardware)
  • Re: Microcontroller ... which one ??
    ... > I have a VERY hard time trying to figure the best microcontroller to ... I am in australia and they charged me $87USfor a Digi Key card ... other country. ...
    (sci.electronics.design)
  • Re: Microcontroller ... which one ??
    ... >> I have a VERY hard time trying to figure the best microcontroller to ... > I am in australia and they charged me $87USfor a Digi Key card ... > other country. ...
    (sci.electronics.design)
  • Re: HP Laserjet 2550 Configuration
    ... Most likely you are not on the same subnet. ... For example if ipconfig returns the ip adress of your computer as 169.254.1.10 then assign the printer the address 169.254.10.25 providing that 25 is not being used by anything else in the network. ... The light is on the printer card. ... I've followed the manual and running software and drivers to set it up will be futile unless this card can be located. ...
    (comp.periphs.printers)
  • Re: HP LaserJet 4000 w/ ethernet
    ... fine when in a different subnet, and one wants to change the IP address. ... current ip address of the jetdirect card and then direct your internet ... the jet direct card for the latest version. ...
    (comp.sys.hp.hardware)