• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

Need monitoring app/OS option for snooping

client has had numerous data thefts and break ins and would like to catch the hackers/thieves in the act or at least logs to show the cops (?)

I have setup an Astaro security Linux box as their firewall (all paid for and such) but the logging capabilities don't seem to include source/destination tables. I have infinite amounts of graphs, but they all analyze the data, and not the data path.

I have setup an HTTP proxy so everything is logged and such, but alas, the logging I require is not here.


I was interested to see what other options are at my disposal.


I was thinking about using etheral but that isn't practical. I simply need a proxy that can capture as much good stuff as I can possibly get.

Either way the firewall will remain Astaro, which is excellent. I am jsut looking for a good snooping tool.

Possible things to log:

1) trojan infiltration
2) keyloggers dialing home
3) DNS redirection

blah blah blah

Would smoothwall provide more adaquate logging for me?

Hell, even my POS sonicwall offers a simple source/destination/port/protocol logging.
 
might try NTOP, I have a CVS from last month that seems pretty stable. Might be more then you are looking for though. I usually set up a hub at the wan side of my network and monitor on an ip-less address, with a normal net connection for accessing the box.
 
Originally posted by: nweaver
might try NTOP, I have a CVS from last month that seems pretty stable. Might be more then you are looking for though. I usually set up a hub at the wan side of my network and monitor on an ip-less address, with a normal net connection for accessing the box.

That's how I setup <insert IDS here>. 😛
 
I say use CVS, as it's a bit better. I know that the bsd ports are old, as is the debian repositories and gentoo portage. 3.1 is fine, but there is some very nice stuff added recently in the source, and it's stable for me. I know some folks get scared to compile from source/use CVS versions and will just pull a precompiled package from their favorite repository.
 
Back
Top