From owner-freebsd-security Mon Jan 14 6:47: 9 2002 Delivered-To: freebsd-security@freebsd.org Received: from smtp011.mail.yahoo.com (smtp011.mail.yahoo.com [216.136.173.31]) by hub.freebsd.org (Postfix) with SMTP id CE09037B405 for ; Mon, 14 Jan 2002 06:47:01 -0800 (PST) Received: from unknown (HELO warhawk) (202.1.200.109) by smtp.mail.vip.sc5.yahoo.com with SMTP; 14 Jan 2002 14:46:55 -0000 From: "Haikal Saadh" To: "'Krzysztof Zaraska'" , Subject: RE: Which intrusion detection to use? Date: Mon, 14 Jan 2002 19:46:38 +0500 Message-ID: <004c01c19d0a$4e0cf3b0$6dc801ca@warhawk> X-Priority: 3 (Normal) X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook, Build 10.0.2616 In-reply-to: <20020113210809.6be9f991.kzaraska@student.uci.agh.edu.pl> X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000 Importance: Normal Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org *snip* > I don't know how tight your particular setup is, but if you > deny access to all unused ports to the world there will be no > use in PortSentry since the offending packets will never his > the port PortSentry is listening on. Snort does not care > about firewalls, so just tell it to listen on outside > interface and you're set. > I have been thinking about this a bit lately. I am (was until I broke it this morning upgrading to 1.8.3, blast it!) running snort and ipfw, and while I would get ipfw dropping packets in my logs, I have nothing in my snort alerts from my outside network. (Quite a few from the inside though, mostly malformed NetBIOS packets and other mostly harmless (as far as I'm concerned) traffic). My firewall policy is default deny, but with dynamic rules so that I can actually use stuff. My snort's HOMENET is set to any, and I'm on dialup. What I'd like to someone to clarify for me is: Is snort actually seeing incoming packets on my outside interface, and I've been really lucky so far OR Is snort not hearing anything on my outside interface? (tun0) What you've said above suggests the former, but I would appreciate it if someone confirms my suspicions. *snip* > > > Does anyone have some recommendations for me. > If this is a NAT gateway that has all ports firewalled from > the outside I'd be satisified with the steps described above. > Just re-check your firewall rules, since it's your most > important line of defense. > > You may however (it's your system, anyhow ;-)) consider > raising your securelevel and making some files immutable > (binaries, configuration) and some other append-only (logs). > man securelevel for details. > > > Other recommendations to increase my security are also welcome? If you want a good book I'd recommend "Building Internet Firewalls" by Zwicky et al, published by O'reilly and associates, Also for inspiration, look at: A) /etc/login.access B) /etc/hosts.allow C) /etc/login.conf D) running daemons (like bind,sendmail, and even snort, among others) as their own user/group, and _NOT_ root.wheel. > Well, there are some papers on the subject available on the > net, so just do a Google search :) but they mostly focus on > multi-user systems and servers. Actually simple setup == less > possible points of entry. > > I'm afraid that if you exagerrate you may end up with a > system generating tons of logs although nothing serious is happening. _________________________________________________________ Do You Yahoo!? Get your free @yahoo.com address at http://mail.yahoo.com To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message