Lost Password? No account yet? Sign up! Why bother?
  • Narrow screen resolution
  • Wide screen resolution
  • Auto width resolution
  • Increase font size
  • Decrease font size
  • Default font size

SmallNetBuilder - Small Network Help

  
Home arrow Wireless arrow Wireless How To arrow How To: Sniffing the Air
How To: Sniffing the Air Print E-mail
Derek Boiko-Weyrauch   
September 28, 2005

Setting up

Before you begin, you need a system that is capable of not only running Snort, but also acting as a wireless access point. The cheapest way to do this is with the venerable Linksys WRT54G wireless router [reviewed here]. The WRT54G runs open source firmware that can be replaced with many alternative distros that offer enhanced capabilities - including running Snort. Alternatively, if you have a spare machine, a wireless card, a normal Ethernet adaptor, and a lot of spare time, you can set it up as an access point.

Linksys WRT54G

Figure 3: Linksys WRT54G

This article will use examples using a WRT54G router running OpenWRT RC 2 (codenamed 'White Russian'). There are many Linux distributions for wireless routers available (something I hope to cover in a future article), but I chose OpenWRT because it is simple, lightweight, and comes with a package system similar to Debian Linux.

OpenWRT in action

Figure 4: OpenWRT in action
(Click image to enlarge)
NOTE!Disclaimer: Loading OpenWRT, Snort Wireless or other alternative firmware onto your WRT54G will void your warranty.

SmallNetBuilder, Pudai LLC and I are not responsible for any damage that the information in this article may cause to your WRT54G.

So download a copy of the current firmware before you start, and don't go trying to get help from Linksys if you break it.

I won't go into the details of installing OpenWRT, since there is very good installation documentation on the OpenWRT website. Once the install is complete, you can Telnet into the router [instructions here] and poke around.

Once OpenWRT has been set up on the router, the Snort Wireless program may be downloaded and installed. This can be done through OpenWRT's aforementioned package manager system, ipkg, with the following command:

ipkg install http://nthill.free.fr/openwrt/ipkg/testing/20041204/snort-wireless_2.1.1-1_mipsel.ipk

Note that this package is nearly a year out of date. This is all right, as all of the basic functionality that we want in an IDS is still there, and all of the latest Snort rulesets may be downloaded with ipkg (see the OpenWRT tracker page for details on the latest packages). For those of you running a dedicated machine as an access point, you can get a copy of the Snort Wireless source and compile that on the machine. Take special care to add the --enable-wireless flag when you configure, otherwise the Wi-Fi-specific preprocessors will not function.

Snort Wireless works in a similar way to Snort itself, but is intended to be deployed on a wireless access point to defend against wireless attacks. In particular, it contains a new rule protocol (entitled wifi) to allow the IDS to properly identify traffic associated with common wireless attacks such as Netstumbler traffic or WEP cracking attempts. Using the wifi protocol for rules in Snort Wireless follows the same pattern as writing normal Snort rules, with one notable exception: instead of specifying the IP addresses and ports of the first and second hosts, their MAC addresses are used.



Tags: How To, security, sniff, Snort, WiFi,

Related Articles:

Snort vulnerability found
Yoggie releases MacOS mini security appliances
Nmap getting SNORTed
How To Crack WEP - Part 3: Securing your WLAN
The Feds can own your WLAN too
 

Most Read

 
 

Over At The Forums

NAS box build
So I'm building a Media Storage NAS box. Eventually I will be building a MythTV back end & front end, and running media -...

Making NAS accessible remotely?
I would like to be able to login and mount my NAS network drive from anywhere with an internet connection. What do I need to...

A DIY SSL VPN with SSL-Explorer - Part 1
Complete waste of time and needs to be removed. I went through and instaled the JRE, compiled ant, got the latest SSLExplorer and started...

Question about changing ISPs and the Equipment
I am changing from AT&T to Comcast so I need a new modem. Based on my reading of various fora, the Moto SB5100 seems...

Will I have to reformat to create a RAID-1 mirror?
I am using Ubuntu 8.10 + webmin for Samba file sharing server. I currently have 1x1.5tb HDD, NTFS formatted. I would like to add a...

Slideshows

Linksys Media Hub LaCie 5big Network Jazinga IP PBX NETGEAR ReadyNAS Pro Western Digital ShareSpace QNAP TS-509 Pro More
Go Shopping with PriceGrabber

Get Email Updates

Enter your email address:

Delivered by FeedBurner once a day

 
 

Ldr:0.00166702270508, Rct:0.00639986991882, Sky:0.00810384750366, Tlink:0.326967000961, TopPG:0.327066898346, GQV:0.327243804932 seconds to load.