<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>Jabablog &#187; linux</title>
	<atom:link href="http://blog.jabawoki.com/tag/linux/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.jabawoki.com</link>
	<description>Nothing to see here, move along...</description>
	<lastBuildDate>Mon, 30 Aug 2010 23:20:19 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<!-- podcast_generator="podPress/8.8" - maintenance_release="8.8.6.3" -->
	<copyright>2006-2010 </copyright>
	<managingEditor>jay@jabawoki.com (Jabawoki)</managingEditor>
	<webMaster>jay@jabawoki.com (Jabawoki)</webMaster>
	<category>music</category>
	<ttl>1440</ttl>
	<image>
		<url>http://blog.jabawoki.com/wp-content/plugins/podpress/images/SubSide-small.jpg</url>
		<title>Jabablog &#187; linux</title>
		<link>http://blog.jabawoki.com</link>
		<width>144</width>
		<height>144</height>
	</image>
	<itunes:subtitle>Jabawoki Presents: </itunes:subtitle>
	<itunes:summary>House Music Mixes, everything from electro, progressive, vocal to hard, from 2000 onwards, courtesy of Jabawoki.</itunes:summary>
	<itunes:keywords>House,electro,hard,mix,dj,hardcore,hardstyle,trance, progressive, house, music, hardcore, handbag, happy, tech, deep, security, infosec, itsec, jay, abbott, jay abbott, jabawoki</itunes:keywords>
	<itunes:category text="Music" />
	<itunes:category text="Games &#38; Hobbies">
		<itunes:category text="Hobbies" />
	</itunes:category>
	<itunes:category text="Technology" />
	<itunes:author>Jabawoki</itunes:author>
	<itunes:owner>
		<itunes:name>Jabawoki</itunes:name>
		<itunes:email>jay@jabawoki.com</itunes:email>
	</itunes:owner>
	<itunes:block>no</itunes:block>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://blog.jabawoki.com/wp-content/plugins/podpress/images/SubSide-Large.jpg" />
		<item>
		<title>Architecures RISC or x86?</title>
		<link>http://blog.jabawoki.com/2008/07/13/architecures-risc-or-x86/</link>
		<comments>http://blog.jabawoki.com/2008/07/13/architecures-risc-or-x86/#comments</comments>
		<pubDate>Sun, 13 Jul 2008 19:59:46 +0000</pubDate>
		<dc:creator>Jabs</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[linux]]></category>

		<guid isPermaLink="false">http://blog.jabawoki.com/?p=53</guid>
		<description><![CDATA[I have been working with a large retailer of late who is a heavy user of Sun &#38; Solaris. As you can imagine, this is perfectly normal, and in fact, considered best practice for what they are doing. That said though, in an area such as retail, with low margins and profits based on sheer [...]]]></description>
			<content:encoded><![CDATA[<p>I have been working with a large retailer of late who is a heavy user of Sun &amp; Solaris. As you can imagine, this is perfectly normal, and in fact, considered best practice for what they are doing. That said though, in an area such as retail, with low margins and profits based on sheer quantity, surely a leap of faith into the &#8220;dark side&#8221; or as we prefer to call it, <a href="http://blog.jabawoki.com/tag/linux/" class="st_tag internal_tag" rel="tag" title="Posts tagged with linux">Linux</a>, would be a better option?<span id="more-53"></span></p>
<p>Once upon a time the argument was simple, RISC architecture was simply ahead of the game, by a long way, but guess what, x86 grew up, caught up, and overtook. These days, the performance you get out of multi-core x86 is significantly more than it&#8217;s RISC based equivalent. I realise that point could be considered contentious by the purists out there, but for mainstream computing in a world that is ever more cost concious, I struggle see how any argument for RISC can win over x86.</p>
<p>Once you have your x86 base, you can go with an x86 version of Solaris (not that you would) or thanks to Sun not playing silly games, you can actually use something useful, such as Redhat, Suse, Ubuntu or if you so desire, Novell.This additional flexibility is core to getting the base of your platform right. Large scale architectures need solid foundations to remain stable, perform and scale as desired.</p>
<p>Lets consider it for a moment. Sparc vs x86 &amp; Solaris vs <a href="http://blog.jabawoki.com/tag/linux/" class="st_tag internal_tag" rel="tag" title="Posts tagged with linux">Linux</a>, well to be honest, there is barley anything in the comparison except cost. Sun make x86 hardware based on multi-core AMD processors which are blisteringly fast and being manufactured by Sun, they are rock solid.</p>
<p>Now. If I were that retailer, I know where I would be looking to spend my money, but thats not what I am there to talk to them about, so I&#8217;ll keep it for my blog and not overstep my scope.</p>
<div class="lightsocial_container"><a class="lightsocial_a" href="http://digg.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F13%2Farchitecures-risc-or-x86%2F&amp;title=Architecures+RISC+or+x86%3F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/digg.png" alt="Digg This" title="Digg This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.reddit.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F13%2Farchitecures-risc-or-x86%2F&amp;title=Architecures+RISC+or+x86%3F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/reddit.png" alt="Reddit This" title="Reddit This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F13%2Farchitecures-risc-or-x86%2F&amp;title=Architecures+RISC+or+x86%3F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/stumbleupon.png" alt="Stumble Now!" title="Stumble Now!" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://buzz.yahoo.com/buzz?targetUrl=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F13%2Farchitecures-risc-or-x86%2F&amp;headline=Architecures+RISC+or+x86%3F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/yahoo_buzz.png" alt="Buzz This" title="Buzz This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dzone.com/links/add.html?title=Architecures+RISC+or+x86%3F&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F13%2Farchitecures-risc-or-x86%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dzone.png" alt="Vote on DZone" title="Vote on DZone" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.facebook.com/sharer.php?t=Architecures+RISC+or+x86%3F&amp;u=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F13%2Farchitecures-risc-or-x86%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/facebook.png" alt="Share on Facebook" title="Share on Facebook" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://delicious.com/save?title=Architecures+RISC+or+x86%3F&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F13%2Farchitecures-risc-or-x86%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/delicious.png" alt="Bookmark this on Delicious" title="Bookmark this on Delicious" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dotnetkicks.com/kick/?title=Architecures+RISC+or+x86%3F&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F13%2Farchitecures-risc-or-x86%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetkicks.png" alt="Kick It on DotNetKicks.com" title="Kick It on DotNetKicks.com" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://dotnetshoutout.com/Submit?title=Architecures+RISC+or+x86%3F&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F13%2Farchitecures-risc-or-x86%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetshoutout.png" alt="Shout it" title="Shout it" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F13%2Farchitecures-risc-or-x86%2F&amp;title=Architecures+RISC+or+x86%3F&amp;summary=&amp;source=" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/linkedin.png" alt="Share on LinkedIn" title="Share on LinkedIn" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.technorati.com/faves?add=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F13%2Farchitecures-risc-or-x86%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/technorati.png" alt="Bookmark this on Technorati" title="Bookmark this on Technorati" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://twitter.com/home?status=Reading+http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F13%2Farchitecures-risc-or-x86%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/twitter.png" alt="Post on Twitter" title="Post on Twitter" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.google.com/buzz/post?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F13%2Farchitecures-risc-or-x86%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/google_buzz.png" alt="Google Buzz (aka. Google Reader)" title="Google Buzz (aka. Google Reader)" /></a>&nbsp;&nbsp;</div>
	Tags: <a href="http://blog.jabawoki.com/tag/linux/" title="linux" rel="tag">linux</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.jabawoki.com/2008/07/02/snort-rocks/" title="Snort Rocks! (July 2, 2008)">Snort Rocks!</a> (2)</li>
	<li><a href="http://blog.jabawoki.com/2008/07/06/linux-defence-tweaks/" title="Linux Defence Tweaks (July 6, 2008)">Linux Defence Tweaks</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/07/05/free-security-for-all/" title="Free Security for All! (July 5, 2008)">Free Security for All!</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://blog.jabawoki.com/2008/07/13/architecures-risc-or-x86/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Linux Defence Tweaks</title>
		<link>http://blog.jabawoki.com/2008/07/06/linux-defence-tweaks/</link>
		<comments>http://blog.jabawoki.com/2008/07/06/linux-defence-tweaks/#comments</comments>
		<pubDate>Sun, 06 Jul 2008 20:13:11 +0000</pubDate>
		<dc:creator>Jabs</dc:creator>
				<category><![CDATA[InfoSec]]></category>
		<category><![CDATA[linux]]></category>

		<guid isPermaLink="false">http://blog.jabawoki.com/?p=52</guid>
		<description><![CDATA[If your planning on using Linux in a hostile environment, i.e. the Internet! then its worth thinking about some simple little tweaks to the TCP/IP stack in conjunction with some funky firewall madness to keep your box your own, and not end up &#8220;owned&#8221; too quickly! Lets start with the TCP/IP stack. There are a [...]]]></description>
			<content:encoded><![CDATA[<p>If your planning on using <a href="http://blog.jabawoki.com/tag/linux/" class="st_tag internal_tag" rel="tag" title="Posts tagged with linux">Linux</a> in a hostile environment, i.e. the Internet! then its worth thinking about some simple little tweaks to the TCP/IP stack in conjunction with some funky firewall madness to keep your box your own, and not end up &#8220;owned&#8221; too quickly!</p>
<p>Lets start with the TCP/IP stack. There are a number of quick easy wins here that can help defend against attacks through making the default behaviours of the stack more in-line with what we would like:<span id="more-52"></span></p>

<div class="wp_syntax"><div class="code"><pre class="bash" style="font-family:monospace;"><span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;1&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>conf<span style="color: #000000; font-weight: bold;">/</span>eth0<span style="color: #000000; font-weight: bold;">/</span>rp_filter
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;0&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>conf<span style="color: #000000; font-weight: bold;">/</span>lo<span style="color: #000000; font-weight: bold;">/</span>rp_filter
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;1&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>conf<span style="color: #000000; font-weight: bold;">/</span>all<span style="color: #000000; font-weight: bold;">/</span>log_martians
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;0&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>conf<span style="color: #000000; font-weight: bold;">/</span>lo<span style="color: #000000; font-weight: bold;">/</span>log_martians
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;1&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>icmp_ignore_bogus_error_responses
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;1&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>icmp_echo_ignore_broadcasts
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;0&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>icmp_echo_ignore_all
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;0&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>conf<span style="color: #000000; font-weight: bold;">/</span>all<span style="color: #000000; font-weight: bold;">/</span>accept_source_route
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;0&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>conf<span style="color: #000000; font-weight: bold;">/</span>all<span style="color: #000000; font-weight: bold;">/</span>send_redirects
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;0&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>conf<span style="color: #000000; font-weight: bold;">/</span>all<span style="color: #000000; font-weight: bold;">/</span>accept_redirects
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;0&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>conf<span style="color: #000000; font-weight: bold;">/</span>all<span style="color: #000000; font-weight: bold;">/</span>secure_redirects
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;1&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>ip_dynaddr
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;10&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>tcp_fin_timeout
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;1800&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>tcp_keepalive_time
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;15&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>ipfrag_time
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;2048&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>tcp_max_syn_backlog
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;32768 61000&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>ip_local_port_range
<span style="color: #7a0874; font-weight: bold;">echo</span> <span style="color: #ff0000;">&quot;2&quot;</span> <span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>proc<span style="color: #000000; font-weight: bold;">/</span>sys<span style="color: #000000; font-weight: bold;">/</span>net<span style="color: #000000; font-weight: bold;">/</span>ipv4<span style="color: #000000; font-weight: bold;">/</span>tcp_synack_retries</pre></div></div>

<p>Now, that little lot above needs some caveats. Firstly, use at your own risk! Secondly, As per usual, you often get a small performance hit when you start getting more secure, so test each tweak fully before you go into production. Once your happy with the ones you like, add then to your /etc/rc.local or other start up file of your choice.</p>
<p>The next step is to use iptables to help deal with dodgy looking traffic.</p>
<p><strong>Step 1</strong>, set-up a bunch of new chains:</p>

<div class="wp_syntax"><div class="code"><pre class="bash" style="font-family:monospace;"><span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-N</span> CHECK_FLAGS
<span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-N</span> ALLOW_ICMP
<span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-N</span> SRC_EGRESS
<span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-N</span> DST_EGRESS</pre></div></div>

<p><strong>Step 2</strong>, now lets get those chains to do something useful:</p>

<div class="wp_syntax"><div class="code"><pre class="bash" style="font-family:monospace;"><span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> CHECK_FLAGS <span style="color: #660033;">-p</span> tcp <span style="color: #660033;">--tcp-flags</span> ALL FIN,URG,PSH <span style="color: #660033;">-m</span> limit
        <span style="color: #660033;">--limit</span> <span style="color: #000000;">5</span><span style="color: #000000; font-weight: bold;">/</span>minute <span style="color: #660033;">-j</span> LOG <span style="color: #660033;">--log-level</span> <span style="color: #007800;">$LOG_LEVEL</span> <span style="color: #660033;">--log-prefix</span> <span style="color: #ff0000;">&quot;NMAP-XMAS:&quot;</span>
<span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> CHECK_FLAGS <span style="color: #660033;">-p</span> tcp <span style="color: #660033;">--tcp-flags</span> ALL FIN,URG,PSH <span style="color: #660033;">-j</span> DROP
<span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> CHECK_FLAGS <span style="color: #660033;">-p</span> tcp <span style="color: #660033;">--tcp-flags</span> SYN,RST SYN,RST <span style="color: #660033;">-m</span> limit
        <span style="color: #660033;">--limit</span> <span style="color: #000000;">5</span><span style="color: #000000; font-weight: bold;">/</span>minute <span style="color: #660033;">-j</span> LOG <span style="color: #660033;">--log-level</span> <span style="color: #007800;">$LOG_LEVEL</span> <span style="color: #660033;">--log-prefix</span> <span style="color: #ff0000;">&quot;SYN/RST:&quot;</span>
<span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> CHECK_FLAGS <span style="color: #660033;">-p</span> tcp <span style="color: #660033;">--tcp-flags</span> SYN,RST SYN,RST <span style="color: #660033;">-j</span> DROP
<span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> CHECK_FLAGS <span style="color: #660033;">-p</span> tcp <span style="color: #660033;">--tcp-flags</span> SYN,FIN SYN,FIN <span style="color: #660033;">-m</span> limit
        <span style="color: #660033;">--limit</span> <span style="color: #000000;">5</span><span style="color: #000000; font-weight: bold;">/</span>minute <span style="color: #660033;">-j</span> LOG <span style="color: #660033;">--log-level</span> <span style="color: #007800;">$LOG_LEVEL</span> <span style="color: #660033;">--log-prefix</span> <span style="color: #ff0000;">&quot;SYN/FIN:&quot;</span>
<span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> CHECK_FLAGS <span style="color: #660033;">-p</span> tcp <span style="color: #660033;">--tcp-flags</span> SYN,FIN SYN,FIN <span style="color: #660033;">-j</span> DROP
<span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> ALLOW_ICMP <span style="color: #660033;">-p</span> icmp <span style="color: #660033;">--icmp-type</span> echo-reply <span style="color: #660033;">-j</span> ACCEPT
<span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> ALLOW_ICMP <span style="color: #660033;">-p</span> icmp <span style="color: #660033;">--icmp-type</span> destination-unreachable
        <span style="color: #660033;">-j</span> ACCEPT
<span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> ALLOW_ICMP <span style="color: #660033;">-p</span> icmp <span style="color: #660033;">--icmp-type</span> echo-request <span style="color: #660033;">-j</span> ACCEPT
<span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> ALLOW_ICMP <span style="color: #660033;">-p</span> icmp <span style="color: #660033;">--icmp-type</span> time-exceeded <span style="color: #660033;">-j</span> ACCEPT
&nbsp;
        <span style="color: #000000; font-weight: bold;">for</span> SRCNET <span style="color: #000000; font-weight: bold;">in</span> <span style="color: #007800;">$EGRESS_NETS</span>; <span style="color: #000000; font-weight: bold;">do</span>
                <span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> SRC_EGRESS <span style="color: #660033;">-s</span> <span style="color: #007800;">$SRCNET</span> <span style="color: #660033;">-j</span> DROP
        <span style="color: #000000; font-weight: bold;">done</span>
&nbsp;
        <span style="color: #000000; font-weight: bold;">for</span> DSTNET <span style="color: #000000; font-weight: bold;">in</span> <span style="color: #007800;">$EGRESS_NETS</span>; <span style="color: #000000; font-weight: bold;">do</span>
                <span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> DST_EGRESS <span style="color: #660033;">-d</span> <span style="color: #007800;">$DSTNET</span> <span style="color: #660033;">-j</span> DROP
        <span style="color: #000000; font-weight: bold;">done</span></pre></div></div>

<p><strong>Step 3</strong>, Apply the prior two steps to your input, forward and output chains as needed:</p>

<div class="wp_syntax"><div class="code"><pre class="bash" style="font-family:monospace;"><span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> <span style="color: #007800;">$CHAIN</span> <span style="color: #660033;">-i</span> <span style="color: #007800;">$EXT_INT</span> <span style="color: #660033;">-j</span> SRC_EGRESS
<span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> <span style="color: #007800;">$CHAIN</span> <span style="color: #660033;">-i</span> <span style="color: #007800;">$EXT_INT</span> <span style="color: #660033;">-j</span> DST_EGRESS
<span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> <span style="color: #007800;">$CHAIN</span> <span style="color: #660033;">-i</span> <span style="color: #007800;">$EXT_INT</span> <span style="color: #660033;">-p</span> icmp <span style="color: #660033;">-j</span> ALLOW_ICMP
<span style="color: #007800;">$IPTABLES</span> <span style="color: #660033;">-A</span> <span style="color: #007800;">$CHAIN</span> <span style="color: #660033;">-i</span> <span style="color: #007800;">$EXT_INT</span> <span style="color: #660033;">-p</span> tcp <span style="color: #660033;">-j</span> CHECK_FLAGS</pre></div></div>

<p>Variables. In all of the above, variables are used to save typing!, here are some of the important variables, the rest are fairly self explanatory:</p>

<div class="wp_syntax"><div class="code"><pre class="bash" style="font-family:monospace;"><span style="color: #007800;">EGRESS_NETS</span>=<span style="color: #ff0000;">&quot;
        172.16.0.0/12
        224.0.0.0/4
        240.0.0.0/5
        14.0.0.0/8
        169.254.0.0/16
        172.16.0.0/12
        192.0.2.0/24
        192.88.99.0/24
        192.18.0.0/15
        0.0.0.0/8
        &quot;</span></pre></div></div>

<p>What we have just done is setup some new chains, apply some filters that can identify dodgy looking traffic and do something useful with it (limit it rather than drop it, as we don&#8217;t want to arouse suspicion with our attackers). Then apply all that nice Packet Mangling to each of our primary chains.</p>
<p>I provide all of this advice for free, with no guarantees, any use of the above code should be with full testing prior to its use in a production environment. Enjoy!</p>
<div class="lightsocial_container"><a class="lightsocial_a" href="http://digg.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F06%2Flinux-defence-tweaks%2F&amp;title=Linux+Defence+Tweaks" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/digg.png" alt="Digg This" title="Digg This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.reddit.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F06%2Flinux-defence-tweaks%2F&amp;title=Linux+Defence+Tweaks" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/reddit.png" alt="Reddit This" title="Reddit This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F06%2Flinux-defence-tweaks%2F&amp;title=Linux+Defence+Tweaks" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/stumbleupon.png" alt="Stumble Now!" title="Stumble Now!" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://buzz.yahoo.com/buzz?targetUrl=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F06%2Flinux-defence-tweaks%2F&amp;headline=Linux+Defence+Tweaks" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/yahoo_buzz.png" alt="Buzz This" title="Buzz This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dzone.com/links/add.html?title=Linux+Defence+Tweaks&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F06%2Flinux-defence-tweaks%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dzone.png" alt="Vote on DZone" title="Vote on DZone" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.facebook.com/sharer.php?t=Linux+Defence+Tweaks&amp;u=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F06%2Flinux-defence-tweaks%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/facebook.png" alt="Share on Facebook" title="Share on Facebook" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://delicious.com/save?title=Linux+Defence+Tweaks&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F06%2Flinux-defence-tweaks%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/delicious.png" alt="Bookmark this on Delicious" title="Bookmark this on Delicious" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dotnetkicks.com/kick/?title=Linux+Defence+Tweaks&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F06%2Flinux-defence-tweaks%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetkicks.png" alt="Kick It on DotNetKicks.com" title="Kick It on DotNetKicks.com" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://dotnetshoutout.com/Submit?title=Linux+Defence+Tweaks&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F06%2Flinux-defence-tweaks%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetshoutout.png" alt="Shout it" title="Shout it" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F06%2Flinux-defence-tweaks%2F&amp;title=Linux+Defence+Tweaks&amp;summary=&amp;source=" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/linkedin.png" alt="Share on LinkedIn" title="Share on LinkedIn" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.technorati.com/faves?add=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F06%2Flinux-defence-tweaks%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/technorati.png" alt="Bookmark this on Technorati" title="Bookmark this on Technorati" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://twitter.com/home?status=Reading+http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F06%2Flinux-defence-tweaks%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/twitter.png" alt="Post on Twitter" title="Post on Twitter" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.google.com/buzz/post?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F06%2Flinux-defence-tweaks%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/google_buzz.png" alt="Google Buzz (aka. Google Reader)" title="Google Buzz (aka. Google Reader)" /></a>&nbsp;&nbsp;</div>
	Tags: <a href="http://blog.jabawoki.com/tag/infosec/" title="InfoSec" rel="tag">InfoSec</a>, <a href="http://blog.jabawoki.com/tag/linux/" title="linux" rel="tag">linux</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.jabawoki.com/2008/07/02/snort-rocks/" title="Snort Rocks! (July 2, 2008)">Snort Rocks!</a> (2)</li>
	<li><a href="http://blog.jabawoki.com/2008/07/05/free-security-for-all/" title="Free Security for All! (July 5, 2008)">Free Security for All!</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/26/the-asymmetry-of-security/" title="The Asymmetry of Security (November 26, 2008)">The Asymmetry of Security</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/19/security-as-a-career/" title="Security as a Career (November 19, 2008)">Security as a Career</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2010/01/17/press-coverage-january-2010/" title="Press Coverage &#8211; January 2010 (January 17, 2010)">Press Coverage &#8211; January 2010</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://blog.jabawoki.com/2008/07/06/linux-defence-tweaks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Free Security for All!</title>
		<link>http://blog.jabawoki.com/2008/07/05/free-security-for-all/</link>
		<comments>http://blog.jabawoki.com/2008/07/05/free-security-for-all/#comments</comments>
		<pubDate>Sat, 05 Jul 2008 22:42:49 +0000</pubDate>
		<dc:creator>Jabs</dc:creator>
				<category><![CDATA[InfoSec]]></category>
		<category><![CDATA[linux]]></category>

		<guid isPermaLink="false">http://blog.jabawoki.com/?p=51</guid>
		<description><![CDATA[Its time for a small reality check. Security does not have to cost the earth. Just because your a large corporate with over a 1000 employees doesn&#8217;t mean you &#8220;have&#8221; to buy brand name security. In fact, I would argue quite the opposite, invest that money in some quality people, treat them well, and get [...]]]></description>
			<content:encoded><![CDATA[<p>Its time for a small reality check. <strong>Security does not have to cost the earth.</strong> Just because your a large corporate with over a 1000 employees doesn&#8217;t mean you &#8220;have&#8221; to buy brand name security. In fact, I would argue quite the opposite, invest that money in some quality people, treat them well, and get 10 times the return on investment you planned.<span id="more-51"></span></p>
<p>lets put it into perspective. First of all, you have to accept that open source software is your friend, then accept that just because it doesn&#8217;t have a &#8220;GUI&#8221; doesn&#8217;t mean its any more complex. Ok, now that you have accepted an alternate reality, it is time to look at some comparisons. Lets look at some good, typically expensive security controls, typically, usually reserved for Banks, because &#8220;they have the budget for it&#8221;.</p>
<p>We will start with IDS &#8220;Intrusion Detection System&#8221;, specifically, the network variety (NIDS), deployed across the infrastructure, and designed to spot malicious traffic flowing across your network and highlight suspicious activity that may be happening under the radar. If you were to buy one of the very excellent and very expensive commercial solutions, on a medium size network, you could be spending 6 figures before breakfast. That&#8217;s a serious hole in a security budget, so what other options exist? Well, for a start, &#8220;snort&#8221; an open source, well maintained and mature project that&#8217;s been around for years. Its 100% free, and will only cost you the physical hardware and some administrative overhead getting it up and running. Its very scalable, equally configurable and its signatures are maintained by a community of experts in the field. What more could you ask for? Ok, so the reality is, in our scenario of 6 figures for the commercial solution, the free one would likely cost you 10-20K in hardware and specialist labour, but whats 20K compared to £200,000K, I know which one I would prefer to sign off.</p>
<p>Next, lets look at another hot topic, SIMS &#8220;Security Information Management Solution&#8221;. This is another typically large investment to essentially, analyse logs generated by the infrastructure. Again, the concept has been available in open source for years. Syslog servers shipping logs to each other with some sort of Perl analysis scripting has been around forever, and again, its just the labour and hardware costs to consider.</p>
<p>What about Firewalls? The staple diet of all organisations of any size. Now, these can be quite cheap or ridiculously expensive. I have built, deployed and managed most of the top end ones, and can after a career of using them, I can happily say, I would deploy a well configured &#8220;iptables&#8221; firewall in <a href="http://blog.jabawoki.com/tag/linux/" class="st_tag internal_tag" rel="tag" title="Posts tagged with linux">Linux</a> over a Cisco or Checkpoint any day of the week. Ok, so you don&#8217;t get the nice gui with all your 200 firewalls in, but, there are options&#8230;. Gui&#8217;s exist, and again, a specialist can easily make this whole concept easily manageable for any organisation. Now, if a key control for limiting the impact of a hack is through network segregation, then the ability to deploy low cost firewalls can only improve the overall security of the network</p>
<p>So, if I had a 1000 user network to protect, a budget of 500K and full autonomy. I would spend 100K on every open source solution available, home grow some of my own, contract a team of top class <a href="http://blog.jabawoki.com/tag/linux/" class="st_tag internal_tag" rel="tag" title="Posts tagged with linux">Linux</a> / security gurus to get it all up and running, then sit back in my SOC &#8220;Security Operations Centre&#8221; and wait for the siren to go off! Of course, I would take the other 400K as my bonus <img src='http://blog.jabawoki.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<div class="lightsocial_container"><a class="lightsocial_a" href="http://digg.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Ffree-security-for-all%2F&amp;title=Free+Security+for+All%21" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/digg.png" alt="Digg This" title="Digg This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.reddit.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Ffree-security-for-all%2F&amp;title=Free+Security+for+All%21" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/reddit.png" alt="Reddit This" title="Reddit This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Ffree-security-for-all%2F&amp;title=Free+Security+for+All%21" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/stumbleupon.png" alt="Stumble Now!" title="Stumble Now!" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://buzz.yahoo.com/buzz?targetUrl=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Ffree-security-for-all%2F&amp;headline=Free+Security+for+All%21" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/yahoo_buzz.png" alt="Buzz This" title="Buzz This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dzone.com/links/add.html?title=Free+Security+for+All%21&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Ffree-security-for-all%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dzone.png" alt="Vote on DZone" title="Vote on DZone" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.facebook.com/sharer.php?t=Free+Security+for+All%21&amp;u=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Ffree-security-for-all%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/facebook.png" alt="Share on Facebook" title="Share on Facebook" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://delicious.com/save?title=Free+Security+for+All%21&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Ffree-security-for-all%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/delicious.png" alt="Bookmark this on Delicious" title="Bookmark this on Delicious" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dotnetkicks.com/kick/?title=Free+Security+for+All%21&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Ffree-security-for-all%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetkicks.png" alt="Kick It on DotNetKicks.com" title="Kick It on DotNetKicks.com" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://dotnetshoutout.com/Submit?title=Free+Security+for+All%21&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Ffree-security-for-all%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetshoutout.png" alt="Shout it" title="Shout it" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Ffree-security-for-all%2F&amp;title=Free+Security+for+All%21&amp;summary=&amp;source=" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/linkedin.png" alt="Share on LinkedIn" title="Share on LinkedIn" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.technorati.com/faves?add=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Ffree-security-for-all%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/technorati.png" alt="Bookmark this on Technorati" title="Bookmark this on Technorati" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://twitter.com/home?status=Reading+http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Ffree-security-for-all%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/twitter.png" alt="Post on Twitter" title="Post on Twitter" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.google.com/buzz/post?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F05%2Ffree-security-for-all%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/google_buzz.png" alt="Google Buzz (aka. Google Reader)" title="Google Buzz (aka. Google Reader)" /></a>&nbsp;&nbsp;</div>
	Tags: <a href="http://blog.jabawoki.com/tag/infosec/" title="InfoSec" rel="tag">InfoSec</a>, <a href="http://blog.jabawoki.com/tag/linux/" title="linux" rel="tag">linux</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.jabawoki.com/2008/07/02/snort-rocks/" title="Snort Rocks! (July 2, 2008)">Snort Rocks!</a> (2)</li>
	<li><a href="http://blog.jabawoki.com/2008/07/06/linux-defence-tweaks/" title="Linux Defence Tweaks (July 6, 2008)">Linux Defence Tweaks</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/26/the-asymmetry-of-security/" title="The Asymmetry of Security (November 26, 2008)">The Asymmetry of Security</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/19/security-as-a-career/" title="Security as a Career (November 19, 2008)">Security as a Career</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2010/01/17/press-coverage-january-2010/" title="Press Coverage &#8211; January 2010 (January 17, 2010)">Press Coverage &#8211; January 2010</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://blog.jabawoki.com/2008/07/05/free-security-for-all/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Snort Rocks!</title>
		<link>http://blog.jabawoki.com/2008/07/02/snort-rocks/</link>
		<comments>http://blog.jabawoki.com/2008/07/02/snort-rocks/#comments</comments>
		<pubDate>Wed, 02 Jul 2008 16:21:36 +0000</pubDate>
		<dc:creator>Jabs</dc:creator>
				<category><![CDATA[InfoSec]]></category>
		<category><![CDATA[linux]]></category>

		<guid isPermaLink="false">http://blog.jabawoki.com/?p=28</guid>
		<description><![CDATA[Ok, its been ages since I actually had snort up and running, so long in fact that the last time I used it, ACID was still the best way to deal with the alerts! Well after a couple of days (well a couple of hours here and there at least) I have a fully functional [...]]]></description>
			<content:encoded><![CDATA[<p>Ok, its been ages since I actually had snort up and running, so long in fact that the last time I used it, ACID was still the best way to deal with the alerts! Well after a couple of days (well a couple of hours here and there at least) I have a fully functional set of snort sensors in place on public and private segments of my networks, all feeding to a centralised database with &#8220;BASE&#8221; handling the analysis! woohoo. small victories are the best!<span id="more-28"></span></p>
<p>I can definatley say its come a long way. It was much easier to install, and only took a small amount of syntax debugging to figure out the configs. During my research / re-learning curve though it would seem that version 2.8 with the stream5 processor is not as good as version 2.4 with the flow processor at detecting portscans. This was certainley the concensus of the community, and after a bit of playing I can agree. However, I now have sfPortscan running with stream5 and its seems pretty accurate to me, so I am certainly happy with the results.</p>
<p>BASE is also a welcome move onwards from what used to be a very clunky interface. It seems light and intuitive, with decent features. I think it could do with the addition of some basic graphs, rather than having to use the graph engine to define your graphs each time, but on the whole i think it is certainly a good alternative to spending a large amount of money on a commercial product. Certainly the ability to abstract the managemnet interface, data storage and sensors from each other gives you a highly scaleable model to use a basis for a large scale deployment.</p>
<p>Of course, if you don&#8217;t fancy the pain of compiling code from scratch, or your just dam lazy, check out <a title="EasyIDS" href="http://www.skynet-solutions.net/easyids/" target="_blank">EasyIDS</a> for a complete &#8220;IDS in a box&#8221; that gives you everything I just said with none of the hastle!</p>
<p>&#8230;.You just can&#8217;t ingore the momentum that opensource has gained <img src='http://blog.jabawoki.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<div class="lightsocial_container"><a class="lightsocial_a" href="http://digg.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F02%2Fsnort-rocks%2F&amp;title=Snort+Rocks%21" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/digg.png" alt="Digg This" title="Digg This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.reddit.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F02%2Fsnort-rocks%2F&amp;title=Snort+Rocks%21" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/reddit.png" alt="Reddit This" title="Reddit This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F02%2Fsnort-rocks%2F&amp;title=Snort+Rocks%21" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/stumbleupon.png" alt="Stumble Now!" title="Stumble Now!" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://buzz.yahoo.com/buzz?targetUrl=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F02%2Fsnort-rocks%2F&amp;headline=Snort+Rocks%21" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/yahoo_buzz.png" alt="Buzz This" title="Buzz This" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dzone.com/links/add.html?title=Snort+Rocks%21&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F02%2Fsnort-rocks%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dzone.png" alt="Vote on DZone" title="Vote on DZone" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.facebook.com/sharer.php?t=Snort+Rocks%21&amp;u=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F02%2Fsnort-rocks%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/facebook.png" alt="Share on Facebook" title="Share on Facebook" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://delicious.com/save?title=Snort+Rocks%21&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F02%2Fsnort-rocks%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/delicious.png" alt="Bookmark this on Delicious" title="Bookmark this on Delicious" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.dotnetkicks.com/kick/?title=Snort+Rocks%21&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F02%2Fsnort-rocks%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetkicks.png" alt="Kick It on DotNetKicks.com" title="Kick It on DotNetKicks.com" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://dotnetshoutout.com/Submit?title=Snort+Rocks%21&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F02%2Fsnort-rocks%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/dotnetshoutout.png" alt="Shout it" title="Shout it" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F02%2Fsnort-rocks%2F&amp;title=Snort+Rocks%21&amp;summary=&amp;source=" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/linkedin.png" alt="Share on LinkedIn" title="Share on LinkedIn" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.technorati.com/faves?add=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F02%2Fsnort-rocks%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/technorati.png" alt="Bookmark this on Technorati" title="Bookmark this on Technorati" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://twitter.com/home?status=Reading+http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F02%2Fsnort-rocks%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/twitter.png" alt="Post on Twitter" title="Post on Twitter" /></a>&nbsp;&nbsp;<a class="lightsocial_a" href="http://www.google.com/buzz/post?url=http%3A%2F%2Fblog.jabawoki.com%2F2008%2F07%2F02%2Fsnort-rocks%2F" ><img class="lightsocial_img" src="http://blog.jabawoki.com/wp-content/plugins/light-social/google_buzz.png" alt="Google Buzz (aka. Google Reader)" title="Google Buzz (aka. Google Reader)" /></a>&nbsp;&nbsp;</div>
	Tags: <a href="http://blog.jabawoki.com/tag/infosec/" title="InfoSec" rel="tag">InfoSec</a>, <a href="http://blog.jabawoki.com/tag/linux/" title="linux" rel="tag">linux</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.jabawoki.com/2008/07/06/linux-defence-tweaks/" title="Linux Defence Tweaks (July 6, 2008)">Linux Defence Tweaks</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/07/05/free-security-for-all/" title="Free Security for All! (July 5, 2008)">Free Security for All!</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/26/the-asymmetry-of-security/" title="The Asymmetry of Security (November 26, 2008)">The Asymmetry of Security</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2008/11/19/security-as-a-career/" title="Security as a Career (November 19, 2008)">Security as a Career</a> (0)</li>
	<li><a href="http://blog.jabawoki.com/2010/01/17/press-coverage-january-2010/" title="Press Coverage &#8211; January 2010 (January 17, 2010)">Press Coverage &#8211; January 2010</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://blog.jabawoki.com/2008/07/02/snort-rocks/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
