Latest Post
Showing posts with label Network Security. Show all posts
Showing posts with label Network Security. Show all posts

UPDATE SNORT V-2.9.4.1 - network intrusion detection and prevention system

Written By Unknown on Thursday, 7 March 2013 | 07:06

Release Notes v-2.9.4.1: This release updates file processing for partial HTTP content and MIME attachments, adds the new configuration option max_attribute_services_per_host and improves memory usage within attribute tables, handles excessive overlaps in frag3, adds Stream API updates to return a session key for a session, reduces false positives for TCP window slam events, updates to provide better encoding for TCP packets generated for “respond and react”, and disables non-ethernet decoders by default (for performance reasons)
Snort is a network intrusion detection and prevention system. It is the most widely deployed technology of its kind in the world. It performs detection using a variety of methods including rules-based detection, anomaly detection, and heuristic analysis of network traffic. Its rules language is open source and available to the public as well.

Features

  • Protocol analysis and content searching/matching
  • Uses a flexible rules language to describe traffic that it should collect or pass
  • Detection engine that utilizes a modular plug-in architecture
  • Real-time alerting capability
  • Detects buffer overflows, stealth port scans, CGI attacks, SMB probes, OS fingerprinting attempts, and more
Download version :
windows : Snort_2_9_4_1_Installer.exe (2.7 MB)
Unix/Linux : snort-2.9.4.1.tar.gz (5.3 MB)
Find Other version |
Sources : http://www.snort.org

Web Application Firewall (WAF) Testing Framework - Find Out If Your Application Security Controls Work

Written By Unknown on Saturday, 23 February 2013 | 02:39

Imperva has developed a free evaluation toolkit that enables you to test your application security solution—your Web application firewall or network firewall or intrusion prevention system—and find out if it can stop advanced application attacks. The Web Application Firewall (WAF) Testing Framework conducts over 150 tests, including SQL injection, cross site scripting, and remote file inclusion. It leverages the same evasion techniques used by hackers to bypass simple signature-based solutions and it generates a report that reveals
overall security efficacy.

Measure False Positives
While you need to safeguard your applications, your ironclad defenses should not block legitimate users. You should evaluate whether your security solution can stop attacks without blocking valid traffic. The WAF Testing Framework determines the rate of false positives by inserting legitimate, but potentially suspicious, input into form fields and parameters. It produces clear, informative reports that summarize false positives and false negatives, allowing you to gauge the accuracy of your security solution.

The WAF Testing Framework allows you to:

  • Quickly evaluate the effectiveness of your application security solution
  • Recognize if your security controls might block legitimate users
  • Examine stateful attacks like cookie tampering and Cross Site Request Forgery (CSRF)
  • Produce clear, concise reports that illustrate overall security status
  • Extend the baseline set of security assessments to include custom tests
Application Security Test Environment
The WAF Testing Framework provides everything you need to test your application security controls. It includes a Java-based executable for Windows and WebGoat, an intentionally insecure Web application developed by OWASP. Download the WAF Testing Framework today to evaluate your Web application firewall today.

Download now 91.1 MB
Software RequirementsOperating Systems:
Windows XP/Vista/7/
Server 2003/Server 2008,
Redhat Linux
Sun Java JRE 1.6+File Size:

Source-












Vulture - Open Source Reverse Proxy / Web Application Firewall

Written By Unknown on Friday, 22 February 2013 | 00:56


Vulture is a reverse proxy that features Web-SSO and application firewall. Vulture is based on Apache2, mod_perl and mod_security. Vuture interfaces between Web applications and Internet to provide unified security and authentication.

The main features of Vulture are: 
  • SSO users with many methods supported 
  • LDAP, SQL, text file, RADIUS server, digital certificates ... 
  • Modular design allows you to add new authentication methods
  • The spread of authentication protected applications 
  • Encryption flow 
  • Filtering and rewriting content 
  • An application firewall based on ModSecurity 
  • Load balancing




    IPFire 2.13 - Core 66 released - An Open Source Firewall Distribution

    Written By Unknown on Thursday, 21 February 2013 | 23:23


    IPFire 2.13 is a new major version of IPFire, the Open Source Firewall distribution. The list of changes, enhancements, and fixes is endless.Following features which we’re the most excited about:

    Base System

    The most important components of the base system have been updated to include a brand new kernel based on the Linux 3.2 release. With that, IPFire now supports more hardware than ever before and many of the hardware problems from the past should be gone.
    The most basic system libraries have been replaced as well, giving us great performance and fixing some general security issues. If you’d like to know more about this specifically, please read this post on our planet.

    Quality of Service with CoDeL

    In case you are struggling with a slow internet connection, CoDeL is your solution. This new algorithm shares the bandwidth fairly between all connections. It doesn’t need any configuration at all, but when tied together with our Quality of Service features, CoDeL gives you the most out of your connection.

    ARM

    We have finally declared the ARM versions of IPFire as stable. Since the very first testing release back in October 2011, a multitude of things have improved. As of today, IPFire runs on many different platforms, such as Marvell Kirkwood and Texas Instruments OMAP4-based systems, and of course, the Raspberry Pi computer.
    The vast amount of people who have already been using IPFire ARM since we began to port it to the ARM architecture know that there was never really any big trouble to begin with. You can find more about this over here.

    IPsec VPNs with strongswan 5

    The IPsec implementation strongswan recently released a new version which cleaned up a significant amount of old code, some of which has been in use for over a decade. If you want to know the details, check out the IPFire planet post.

    Wireless LAN

    From our wishlist, we’ve implemented proper support for 5 GHz WLANs. Read this planet post to learn about the benefits.
    Latest release: IPFire 2.13 - Core 66
    Please click the button to download the IPFire ISO image for i586-compatible computers. This is the default image, you will most likely need to install IPFire. You may also pick your desired architecture from the tabs above and see a list of all image formats.
    Download IPFire 2.13 - Core 66 (ISO-Image - i586 - 93.4M)
    IPFire is a server distribution with intended to use as a firewall. It focuses on flexibility, and scales from small to middle sized business networks and home networks.

    Along with this hardened, minimalist come lots of addons that can be installed with a simple click. That's what makes IPFire different from other firewall distributions: it is easy to configure for any task, and easy to administer once it's set up.

    Features
    • stateful inspection firewall based on linux netfilter architecture
    • intrusion detection system with Guardian addon as extension (IPS system)
    • filter for invalid/non-standard packages
    • separate network segments for server (DMZ) and wireless with custom policies
    • DoS attack protection
    • application proxies for HTTP and FTP (with access control and content filtering) and DNS
    • incoming and outgoing packet filtering
    • Quality of Service and traffic shaping
    Source-

    Nessus 5.0.3 released

    Written By Unknown on Tuesday, 19 February 2013 | 19:55



    Nessus team announce the immediate availability of Nessus 5.0.3. This release is a bugfix only release and addresses the following issues:

    - Added the ability to limit of the number of sessions per user
    - Use less memory by default on desktop systems (incl. Mac OS X) by setting qdb_mem_usage = low
    - Reduced memory fragmentation on recent glibc (Linux) systems (ie: Red Hat 6)
    - New mecanism to load the reports for the users sessions, using less memory
    - Prevent a crash when generating a too large XMLRPC buffer
    - Fixed a crash occurring sometimes on Windows related to DNS lookups
    - Fixed thread race conditions
    -  nessusd.dump would sometimes contain the following errors, especially when used with SC:
    [Wed Jan 23 20:00:04 2013][9987.15599433] SQL error - no such table: main.RESULTS
    - Windows files permissions are more secure by default
    - Worked around a bug in older Linux kernels where pathconf() would fail when the scanner data is hosted in a very large NFS server
    - Fixed an issue where plugin updates would fail if cipher_file_on_disk is set to 'no' in the config
    - New function server_log() allowing the web server to write to nessusd.messages
    - Bigger SSL CA key size by default (2048 bits)
    - The SSL CA generates keys with a pathlen constraint of 1
    - Now ships with OpenSSL 1.0.0k

    You can download Nessus 5.0.3 at 


    Nessus Vulnerability Scanner
    Regarding plug-ins

    Netcat - simple utility reads and writes data across TCP or UDP network connections

    Written By Unknown on Monday, 18 February 2013 | 04:32

    Netcat is a featured networking utility which reads and writes data across network connections, using the TCP/IP protocol.
    It is designed to be a reliable "back-end" tool that can be used directly or easily driven by other programs and scripts. At the same time, it is a feature-rich network debugging and exploration tool, since it can create almost any kind of connection you would need and has several interesting built-in capabilities.

    It provides access to the following main features:

    • Outbound and inbound connections, TCP or UDP, to or from any ports.
    • Featured tunneling mode which allows also special tunneling such as UDP to TCP, with the possibility of specifying all network parameters (source port/interface, listening port/interface, and the remote host allowed to connect to the tunnel.
    • Built-in port-scanning capabilities, with randomizer.
    • Advanced usage options, such as buffered send-mode (one line every N seconds), and hexdump (to stderr or to a specified file) of trasmitted and received data.
    • Optional RFC854 telnet codes parser and responder.


    Source-

    For more information-
    Netcat - The Swiss Army Knife



    Java LOIC - Network stress testing application.

    Written By Unknown on Sunday, 17 February 2013 | 05:19

    JavaLOIC is a clone of LOIC written entirely in java.

    Download latest version updated on 16/2/2013

    Source-

    UPDATE GNS3 0.8.4 RC2 Released

    Written By Unknown on Monday, 11 February 2013 | 19:56

    GNS3 0.8.4 RC2 released ON 11-02-2013. Because there are quite a lot of changes since RC1, we have decided to release one more release candidate version before a final 0.8.4.

    GNS3 is a graphical network simulator that allows you to design complex network topologies. You may run simulations or configure devices ranging from simple workstations to powerful Cisco routers. It is based on Dynamips, Pemu/Qemu and Dynagen.

    Download can be found here: GNS3 0.8.4 RC2 Download

    Here is a quick list of the changes since RC1, without including bug fixes:
    New hub device (yes for real!).
    VPCS is included in DMG package on Mac OS X.
    New Idlemax and Idlesleep settings (advanced manipulation of idlepc).
    IOS image and settings test button.
    New tips dialog to promote GNS3 products/videos/tutorials (totally optional and can be deactivated).
    New Tool menu to start external scripts/tools. Should help users on Windows 8.
    Qemu 1.3 has been removed from the all-in-one (not fully functional).
    Please post your suggestions/comments on the forum and let us know if you find any issue.

    Download can be found here: GNS3 0.8.4 RC2 Download

    Download GNS3-0.8.3.1-all-in-one.exe (48.9 MB)
    Download other versions from here

    Source-
    http://www.gns3.net/gns3-0-8-4-rc2/


    Screenshot -



















    GNS3 0.8.4 RC1 released

    Written By Unknown on Tuesday, 29 January 2013 | 00:17

    GNS3 0.8.4 RC1 is now released. This is the last step before a final release and last chance to catch bugs.
    Here is a quick list of the changes:
    • GUI improvements.
    • Drag & drop of multiple devices when pressing SHIFT.
    • Temporary projects are created by default.
    • Winpcap compatibility mode set in all-in-one, allowing it to be installed on Windows 8
    • Dynamips 0.2.8-RC5-community is now default on Windows.
    • Qemu 1.3 can be installed from the all-in-one (experimental). Qemu 0.11.0 is still the default.
    • Qemu 0.11.0 integrated to the DMG for Mac OS X (used by default).
    • Qemu 0.14.1 integrated to the DMG for Mac OS X.
    • Qemu monitor (to pause/resume) and user backend options (experimental).
    • Support for multiple flavors of Qemu: sparc, arm, i386, x86_64
    • SuperPutty command line support.
    • SuperPutty in all-in-one on Windows (optional).
    • VirtualBox interface numbering starts at 0 (e.g. e0 = VirtualBox interface 1 = eth0 on Linux).
    • Dash is now accepted for hostnames.
    • Fixed issues with ports reported as already in use.
    • Gray out VLAN box when selecting dot1q port type in Ethernet Switch.
    • Default delay for console adjusted from 0.5 to 1 second.
    • Default base console is now 2101 instead of 2001
    • Changed Dynamips default base UDP from 10000 to 10001
    • Mouse wheel scrolls the scene by default + options to deactivate the wheel or use it for zooming
    • Support for 36 network cards in VirtualBox (using ICH9 chipset)
    • Patching for Dynagen (see topic5659.html for details)
    • Wrappers improvements all over the place.
    • New baseconfig.txt
    • New option to save traffic capture in project directories.
    • Experimental auto IDLE PC calculation feature (requires Dynamips 0.2.8-RC5, included in Windows all-in-one and OSX DMG).
    • ASA pre-configuration.
    Download it here: GNS3 0.8.4 RC1
    Or by visiting http://www.gns3.net/gns3-0-8-4-rc1/
    What is GNS3 ? 
    GNS3 is a graphical network simulator that allows simulation of complex networks.
    To provide complete and accurate simulations, GNS3 is strongly linked with:
    • Dynamips, a Cisco IOS emulator.
    • Dynagen, a text-based front end for Dynamips.
    • Qemu, a generic and open source machine emulator and virtualizer.
    • VirtualBox, a free and powerful virtualization software.
    GNS3 is an excellent complementary tool to real labs for network engineers, administrators and people wanting to study for certifications such as Cisco CCNA, CCNP, CCIP and CCIE as well as Juniper JNCIA, JNCIS and JNCIE.
    It can also be used to experiment features of Cisco IOS, Juniper JunOS or to check configurations that need to be deployed later on real routers.
    Thanks to VirtualBox integration, now even system engineers and administrators can take advantage of GNS3 to make labs and study for Redhat (RHCE, RHCT), Microsoft (MSCE, MSCA), Novell (CLP) and many other vendor certifications.
    This project is an open source, free program that may be used on multiple operating systems, including Windows, Linux, and MacOS X.
    Features overview
    Important notice: users have to provide their own IOS/IPS/PIX/ASA/JunOS to use in their labs with GNS3.

    Screenshot-


    ESSPEE - (ESSPEE-R3 x86) Penetration Testing & Forensics

    Written By Unknown on Monday, 28 January 2013 | 01:23

    ESSPEE is a derivetive of Back | Track 5, based on Ubuntu 12.04. Designed for users who wish to use only free software. It is packed with featured security tools with stable configurations. This version consolidates the Unity desktop interface; a brand new way to find and manage your applications.

    Features

    • A Perfect Forensics Mode - Read-Only Mount
    • A Perfect Stealth Mode - Networking Disabled
    • Latest kernel with aufs support (Kernel 3.7.4)
    • Metasploit Framework v4.6.0-dev [core:4.6 api:1.0]
    • OSSEC - Open Source Host-based Intrusion Detection System
    • Gnome-fallback Desktop Environment.
    • Gnome-Pie - All your favourite applications at single click
    • Suricata - Open Source Next Generation IDS/ IPS.
    • Snorby - Suricata IDS/IPS Monitoring Web Interface.
    • Meld - A visual diff and merge tool for compare files and directories.
    • MySQL Workbench - A visual MySQL database designing tool.
    • ESSPEE Personal Firewall - Realtime Pop-up Notification. (Thanks to Leopard Flower)
    • Net Activity Viewer - A graphical network connections viewer.
    • LOIQ - Open source network stress testing application.
    • Guymager - Forensics imaging tool (GUI)
    • Ostinato - Open-source network packet crafter/traffic generator.
    • FSlint - Find and clean various unwanted extraneous files.
    • Ruby 1.9.3p327 (2012-11-10 revision 37606)
    • Fern Wi-Fi Cracker
    • Virtualbox - Create your own virtual lab
    • Nemiver - A standalone graphical C and C++ debugger
    • Open Audit - Network inventory, audit and management tool
    • Mobile Phone Forensics tools
    • Anonymity - Tor network and many more .......
    ESSPEE_R3_Live_DVD released on 26/01/2013

    Download - https://docs.google.com/uc?export=download&confirm=no_antivirus&id=0B9Qo6IGWg3_qVzUzTmk1eG95QzQ MD5 - 61aa7c877568d8c109fb407b0540f0f4 Size - 3.35 GB Type - ISO (DVD) OS - Linux (Based on Ubuntu 12.04 - Precise Pangolin) Category - Network Security, Penetration testing, Forensics, Data Recovery.


    Source-
    http://sourceforge.net/projects/esspee/

    Nova - Network Anti-Reconnaissance Tool

    Written By Unknown on Saturday, 12 January 2013 | 09:55

    Nova is a software application for preventing and detecting hostile network reconnaissance (such as nmap scans). It does this by first creating the Haystack: a large collection of low interaction honeypots using an updated version of Honeyd. 

    Finding real machines on the network becomes like finding a needle in a haystack of fake machines. Second, Nova uses machine learning algorithms to automatically detect and classify attempts at hostile reconnaissance, so there's no need to go searching manually through your honeypot's log files. It provides an easy to use Web-based interface powered by Node.js to configure itself and Honeyd instances.



    Nova is a software application for preventing and detecting hostile Network
      Reconnaissance.  It does this by first creating the Haystack: a large array of
      thin virtual machines on the target network. These VMs are created using an
      updated Honeyd to be extremely lightweight. They're not your typical VMs that
      you might see from VirtualBox or VMWare. They just appear to be real from the
      perspective of the network, and run network "services", which are just shell
      scripts.

    - Second, Nova uses machine learning algorithms to automatically detect and

      classify attempts at hostile reconnaissance, so there's no need to go
      searching manually through your honeypot's log files.

    =============================== 

    The Installation Guide
    ===============================

    - The first thing to note is that Nova is currently only compatible with Linux.

      All of our development is done on Ubuntu 12.04, so we suggest using that to
      make installation easiest. We provide a helper script which should get all
      dependencies and download, build, and install Nova and Honeyd. 

            wget https://raw.github.com/DataSoft/Nova/master/debian/novaInstallHelper.sh

            sudo bash novaInstallHelper.sh

    - This script has only been tested on the most recent stable version of Ubuntu.

      Any other distributions or versions should manually compile using the
      instructions below.

    =============================== 

    Getting the newest code
    ===============================

    - Nova and Honeyd are stored as seperate Git repositories on github. Go to the

      directory you wish to download the code to and run the following commands,

        git clone git://github.com/DataSoft/Honeyd.git    

        git clone git://github.com/DataSoft/Nova.git Nova
        
        # You also need to get the git submodules where training data is stored
        # in it's own repo
       
        cd Nova 
        git submodule init
        git submodule update

    - This will create a "honeyd" and "Nova" folder with the source located inside.

      From this point on they will be referred to as $HONEYD_SOURCE and
      $NOVA_SOURCE. 

    - This will default to the "master" branch, which is the latest stable release.

      If you want to use the latest unstable version, cd to the $NOVA_SOURCE and
      $HONEYD_SOURCE and run the following,

            git checkout integration


    - Beware that the integration branch changes on a daily basis and may be

      unstable.

    =============================== 

    Getting Dependencies on Ubuntu
    ===============================

    - Install required dependencies with the following command:


        sudo apt-get install git build-essential libcap2-bin libann-dev libpcap0.8-dev libboost-program-options-dev libboost-serialization-dev libnotify-dev sqlite3 libsqlite3-dev libcurl3 libcurl4-gnutls-dev iptables libxml2-dev libboost-system-dev libboost-filesystem-dev


    - Now, we'll have to take a quick detour to get another integral component of

      Nova: Honeyd. We will have to download some extra libraries for Honeyd as
      well; you can get them using this command:

        sudo apt-get install libevent-dev libdumbnet-dev libpcap-dev libpcre3-dev libedit-dev bison flex libtool automake 


    - For the Honeyd Autoconfiguration tool, we require Nmap 6.00 or higher. The

      current version in the apt repository is 5.21, so you'll have to go to the
      Nmap website and get 6.00.  It can be found here: 

        http://nmap.org/download.html


            OR


        wget http://nmap.org/dist/nmap-6.01.tar.bz2




    - To get the dependencies for the Quasar web UI (nodejs 0.8.5, npm's forever,

      and cvv8) you can either install them manually or get them by running the
      following script,

        sudo bash Quasar/getDependencies.sh


    - There are instructions for manual install on the same page (but are just the

      standard ./configure, make, and sudo make install commands).


    - NOTE: Honeyd requires libevent version 2.x. If you are running Ubuntu 10.10 or

      lower, the version of libevent available in the repos is only 1.x. So you will
      need to either find a backport or build libevent 2.x from source.

    - If you wish to optionally generate Debian packages for Nova, you will also

      require dpkg-dev:

        sudo apt-get install dpkg-dev


    =============================== 

    Building Honeyd
    ===============================

    - Change directories to the $HONEYD_SOURCE folder where all of the Honeyd source

      code should be on your machine. When inside the source directory, follow the
      next steps to build and install.

        Step 1: ./autogen.sh

        Step 2: automake
        Step 3: ./configure
        Step 4: make
        Step 5: sudo make install

    ===============================

    Building Nova
    ===============================

    - Change into the $NOVAD_SOURCE folder where the novad source code resides.


    To build and install Nova run the commands,


        Step 1: autoconf

        Step 2: ./configure
        Step 3: make
        Step 4: sudo make install

    - Note: If building fails for some reason, make sure you run 'make clean' before

      trying again.

    - Finally, while logged in as the user you plan to run Novad with, run the

      following command to add your user to the 'nova' permission group and to set
      up database tables for the web interface.

        Step 5: sudo nova_init


    - Your user will have to be in the "nova" group in order for nova and Honeyd to

      run properly. The nova_init script will do this, but you must log in and back
      out for the change to take effect.

        Step 6: Log out and log back in


    Refer to the Nova wiki on github for more information.


    =============================== 

    Daemonizing with Upstart
    ===============================

    - If you want to start Quasar, novad, and the haystack when the machine boots

    and have them restart if they crash, you can use the upstart service by copying
    the files in $NOVAD_SOURCE/Installer/miscFiles/upstart/* to /etc/init. This is
    assuming that upstart is already installed and configured on your system (it
    comes by default on newer versions of Ubuntu).

    =============================== 

    High Level Nova Components
    ===============================

    Haystack: Active honeypots

            - The Haystack is the collection of honeypots which emulate machines on
              the network.  The haystack is created using the Honeyd daemon and runs
              in it's own executable. Configuration for Honeyd is auto generated at
              ~/.config/nova/Config/haystack_honeyd.config.

    Novad: Classification tool

            - The Novad executable is the daemon that monitors and classifies
              network traffic to identify hostile looking traffic. Novad will listen
              promiscuously on the configured network interfaces and keep track of
              various statistics such as IPs contacted, ports contacted, honeypots
              contacted, and other details. Novad is can be configured manually via
              the configuration file ~/.config/nova/config/NOVAConfig.txt, but it is
              recommended that you use the GUI (Quasar) unless you know what you're
              doing.

    NovaCLI: Nova Command line Interface

            - NovaCLI provides a simple interface for accessing some of the Novad
              functionality.  Usage for the tool can be gotten by running "novacli
              --help".

    Quasar: Nova Web Interface

            - Nova's main GUI, Quasar, is a web interface run with a nodejs web
              server.
            
            - To start the web interface, run the command "quasar" and go to
              https://localhost:8080 in a web browser.

            Default username: nova

            Default password: toor
            
            - "quasar --debug" may provide more information if there are problems.
              Quasar launches the nodejs server with the "forever" daemon so it will
              be restarted if it crashes.  The command "forever list" can be useful
              for seeing the current status, and it can be stopped with "forever
              stop index (usually 0)". See the forever documentation for more
              information.
            
    Haystack Auto Configuration Tool: Generates honeyd configurations based off of
    nmap scans

            - This tool can scan your network with nmap and then generate honeypot

              configurations that are based on the operating systems and ethernet
              vendors that it finds.

    NovaTest: Unit Tests


    - If you're a developer interested in using the unit tests in NovaTest, you can

      find instructions at,

    https://github.com/DataSoft/Nova/wiki/Unit-Testing


    ===============================

    TLS Keys
    =============================== 
    A set of example TLS keys are provided, but because of their public nature 
    provide no real security.  Paths to the TLS keys are in the Nova configuration 
    file at ~/.config/nova/config/NOVAConfig.txt

    To generate a self signed certificate and key for the Quasar or Pulsar https

    interfaces,

    # Generate a private key

    openssl genrsa -des3 -out ui.key 1024

    # Create a request for a certificate

    openssl req -new -key ui.key -out ui.csr

    # Generate a self signed certificate

    openssl x509 -req -days 365 -in ui.csr -signkey ui.key -out ui.crt

    # Creating keys for the Pulsar/Quasar connection is a bit more complicated.

    # Pulsar authenticates clients by using TLS client certificates signed by a
    # certificate authority. 

    # Create a new certificate athority 

    openssl genrsa -des3 -out ca.key 1024
    openssl req -new -key ca.key -out ca.csr
    openssl x509 -req -days 365 -in ca.csr -out ca.crt -signkey ca.key

    # Create and sign the Pulsar key

    openssl genrsa -des3 -out pulsarTether.key 1024
    openssl req -new -key server.key -out pulsarTether.csr
    openssl x509 -req -in pulsarTether.csr -out pulsarTether.crt -CA ca.crt -CAkey ca.key -CAcreateserial -days 365

    # Create and sign the Quasar keys. For each quasar instance,

    openssl genrsa -des3 -out quasarTether.key 1024
    openssl req -new -key server.key -out quasarTether.csr
    openssl x509 -req -in quasarTether.csr -out quasarTether.crt -CA ca.crt -CAkey ca.key -CAcreateserial -days 365 

    # Transfer this key to the Quasar instance


    Remember to make sure that all paths and passphrases are updated correctly in

    ~/.config/nova/config/NOVAConfig.txt to use the new keys you created.

    ===============================

    Debian Packages
    ===============================

    - To generate a Debian package, simply checkout what version of the software you

      like (or make what changes to it that you want) and run the generateDebs
      script (as a normal user). 

            ./generateDebs <version number>


    ===============================

    Common Problems and solutions
    ===============================
            
            ==================
            Haystack Autoconfig nmap fails on large networks
            ==================
              
              Nmap will often fail when scanning networks of size greater than 1024
              IPs with the error "nexthost: failed to determine route" or "Strange
              connect error(105): No buffer space available".  This is usually
              caused by the kernel ARP table running out of space and not being
              garbaged collected fast enough to handle all of the ARP requests nmap
              is doing. The solution is to increase the size by adding the following
              lines to /etc/sysctl.conf,

                    net.ipv4.neigh.default.gc_thresh1 = 1024

                    net.ipv4.neigh.default.gc_thresh2 = 4096
                    net.ipv4.neigh.default.gc_thresh3 = 65536

              Then run the command,


                    sysctl -p

            
              And try running the Haystack autoconfig tool again.


    =============================== 

    Tips for debugging problems
    ===============================

            ================== 

            General problems 
            ==================
       
              To enable verbose debug log messages, run the command,

                    novacli writesetting SERVICE_PREFERENCES 0:0+\;1:5+\;2:6+\;


              If the above fails for some reason, you can also change the logging

              settings manually in the ~/.config/nova/config/NOVAConfig.txt file
              under the SERVICE_PREFERENCES setting.

            =================== 

            Permission Problems 
            ===================

              You should be able to run quasar/novad/honeyd without needing explicit

              root permissions. One requirement for this is that the user you're
              running with is in the "nova" group and has run the nova_init script
              located in Installer/. This script adds the user to the group and also
              configures sudo (via adding a file to /etc/sudoers.d). Logging out and
              back in is required for the group addition to work.

              If you're seeing permission related errors, you can try the following

              commands,

                    sudo chmod -R g+rw /usr/share/nova

                    sudo chgrp -R nova /usr/share/nova

            =================== 

            Web interface problems 
            ===================
              
              If you can't access the web interface, try stopping it if it's running
              in 'forever' and manually running it as a foreground process with the
              commands,

                    forever stopall

                    quasar --debug

              This should provide more verbose output and show if it is crashing

              rather than running it as a background daemon process.

              =================== 

              Novad Problems 
              ===================

              If Novad appears to be having problems, try to start it manually

              instead of as a background process with the command
                    
                    novacli start nova debug

              =================== 

              Haystack Problems 
              ===================

                If the Haystack appears to be having problems, try to start it

                manually instead of as a background process with the command,

                    novacli start haystack debug

            
              =================== 
              Reinstalling 
              ===================

                If something gets messed up to the point you want to start over, you

                can do so with the commands,

                    cd $NOVA_SOURCE sudo make reinstall


                Note that this will remove any configuration changes that you made.


              =================== 

              Building with debugging symbols
              ===================

                If you're seeing novad crash, it might be helpful to compile with

                debugging symbols and get a stack trace. 

                    cd $NOVA_SOURCE make clean make debug make reinstall


                    gdb novad run backtrace


    =============================== 

    RSyslog Support 
    ===============================

    There is an option for designating a target Rsyslog instance electing to receive

    messages exposed within the Advanced Options page of the Quasar Web UI. Some
    suggestions:

     -Make sure that whatever IP is pointed is given in the format IP_ADDRESS:PORT. 


     -Make sure the designated port is both open and listening on the receiving

     machine. The easiest way to do this is to uncomment the InputTCPServer lines in
     /etc/rsyslog.conf and change the port number away from 514 (because rsyslog now
     drops permissions, using port 514 is no longer an option, as it's < 1024). To
     test that rsyslog is listening, run
      
            netstat -tlnup | grep PORT

      as root and check that the PID/Name combination for rsyslogd is listed under
      the results.  The port may also need to be registered into the /etc/services
      file, if changed from the normal port 514.

     -Within /etc/rsyslog.d/ lie the configuration files; in one of these files, a

     rule MUST be created similar to the following:

            :programname,isequal,"Nova" YOUR_ACTION_CHOICE  


      where YOUR_ACTION_CHOICE represents the action (most likely a write to a

      destination) to take upon receipt of messages from a client server that have
      those program names. This is to help organize the logs, as Nova can
      potentially send many log messages that would otherwise pollute the normal
      syslog file.  Note that there will be three rules like this total, one each
      for the strings "Nova", "novad" and "honeyd"

    Testing that these changes worked is a good idea as well. Simply start and stop

    novad on the client with the novacli command line interface and check that the
    log messages sent at startup arrived at the right place

    ===============================

    Pulsar
    ===============================
        Pulsar does not install with the standard Nova ./configure, make, make
    install process. Instead, the user must change directory into the Nova
    directory (most commonly located in the /home/$USER/Code/ directory) and
    run make install- pulsar with superuser permissions. This will place the
    Pulsar files within the proper directories and allow for the user to
    use the alias 'pulsar' on the command line to start the forever process
    for Pulsar. To access the Pulsar interface, the user must first
    have configured Nova such that it has the MASTER_UI_ENABLED
    configuration variable set to 1, as well as properly configuring the
    MASTER_UI_IP and MASTER_UI_CLIENT_ID variables to match the location and
    naming requirements for the user's network. 


    Website -
    https://github.com/DataSoft/Nova
     
    Support : Creating Website | Johny Template | Mas Template
    Copyright © 2011. Turorial Grapich Design and Blog Design - All Rights Reserved
    Template Created by Creating Website Published by Mas Template
    Proudly powered by Blogger