<?xml version="1.0" encoding="utf-8"?>
<!-- generator="FeedCreator 1.7.2-ppt DokuWiki" -->
<?xml-stylesheet href="http://ids.surfnet.nl/wiki/lib/exe/css.php?s=feed" type="text/css"?>
<rdf:RDF
    xmlns="http://purl.org/rss/1.0/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
    xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel rdf:about="http://ids.surfnet.nl/wiki/feed.php">
        <title>SURFcert IDS Development Homepage</title>
        <description></description>
        <link>http://ids.surfnet.nl/wiki/</link>
        <image rdf:resource="http://ids.surfnet.nl/wiki/lib/tpl/sidebar-rc2006-09-28/images/favicon.ico" />
       <dc:date>2013-05-20T00:23:33+02:00</dc:date>
        <items>
            <rdf:Seq>
                <rdf:li rdf:resource="http://ids.surfnet.nl/wiki/doku.php?id=latest_docs:3_sensor:1b._bootable_usb&amp;rev=1348747407&amp;do=diff"/>
                <rdf:li rdf:resource="http://ids.surfnet.nl/wiki/doku.php?id=kb:honeypot_ports&amp;rev=1343315973&amp;do=diff"/>
                <rdf:li rdf:resource="http://ids.surfnet.nl/wiki/doku.php?id=kb:installing_kippo&amp;rev=1343308064&amp;do=diff"/>
                <rdf:li rdf:resource="http://ids.surfnet.nl/wiki/doku.php?id=other:contact&amp;rev=1343207693&amp;do=diff"/>
                <rdf:li rdf:resource="http://ids.surfnet.nl/wiki/doku.php?id=latest_docs:2_tunnel_server:1._installation&amp;rev=1341580267&amp;do=diff"/>
                <rdf:li rdf:resource="http://ids.surfnet.nl/wiki/doku.php?id=latest_docs:2_tunnel_server:1b._arp_detection&amp;rev=1326205127&amp;do=diff"/>
                <rdf:li rdf:resource="http://ids.surfnet.nl/wiki/doku.php?id=latest_docs:faq&amp;rev=1324572265&amp;do=diff"/>
                <rdf:li rdf:resource="http://ids.surfnet.nl/wiki/doku.php?id=sidebar&amp;rev=1323866892&amp;do=diff"/>
                <rdf:li rdf:resource="http://ids.surfnet.nl/wiki/doku.php?id=home&amp;rev=1323169198&amp;do=diff"/>
                <rdf:li rdf:resource="http://ids.surfnet.nl/wiki/doku.php?image=kb%3Avmware_network_0a.jpg&amp;ns=kb&amp;rev=1269271478&amp;tab_details=history&amp;mediado=diff&amp;do=media"/>
                <rdf:li rdf:resource="http://ids.surfnet.nl/wiki/doku.php?image=kb%3Avmware_network_0.jpg&amp;ns=kb&amp;rev=1269267537&amp;tab_details=history&amp;mediado=diff&amp;do=media"/>
                <rdf:li rdf:resource="http://ids.surfnet.nl/wiki/doku.php?image=kb%3Avmware_network_2.jpg&amp;ns=kb&amp;rev=1269259804&amp;tab_details=history&amp;mediado=diff&amp;do=media"/>
                <rdf:li rdf:resource="http://ids.surfnet.nl/wiki/doku.php?image=kb%3Avmware_network_3.jpg&amp;ns=kb&amp;rev=1269258858&amp;tab_details=history&amp;mediado=diff&amp;do=media"/>
                <rdf:li rdf:resource="http://ids.surfnet.nl/wiki/doku.php?image=kb%3Avmware_network_1.jpg&amp;ns=kb&amp;rev=1269258841&amp;tab_details=history&amp;mediado=diff&amp;do=media"/>
            </rdf:Seq>
        </items>
    </channel>
    <image rdf:about="http://ids.surfnet.nl/wiki/lib/tpl/sidebar-rc2006-09-28/images/favicon.ico">
        <title>SURFcert IDS Development Homepage</title>
        <link>http://ids.surfnet.nl/wiki/</link>
        <url>http://ids.surfnet.nl/wiki/lib/tpl/sidebar-rc2006-09-28/images/favicon.ico</url>
    </image>
    <item rdf:about="http://ids.surfnet.nl/wiki/doku.php?id=latest_docs:3_sensor:1b._bootable_usb&amp;rev=1348747407&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2012-09-27T14:03:27+02:00</dc:date>
        <dc:creator>ktrippelvitz</dc:creator>
        <title>1a: Bootable USB - [Building] </title>
        <link>http://ids.surfnet.nl/wiki/doku.php?id=latest_docs:3_sensor:1b._bootable_usb&amp;rev=1348747407&amp;do=diff</link>
        <description>1a: Bootable USB

The other option of creating a SURFids sensor is by making a bootable USB stick function as a SURFids sensor. These USB sticks can be deployed throughout your network on any machine that will boot from USB.



This page will describe how you can create the USB image that will be used for creating a USB sensor. This image can be used to create any number of USB sticks (ie, the image is only created once).



First we need to get the necessary files from the SURFids repository:</description>
    </item>
    <item rdf:about="http://ids.surfnet.nl/wiki/doku.php?id=kb:honeypot_ports&amp;rev=1343315973&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2012-07-26T17:19:33+02:00</dc:date>
        <dc:creator>ktrippelvitz</dc:creator>
        <title>Honeypot ports - [Honeypot ports] </title>
        <link>http://ids.surfnet.nl/wiki/doku.php?id=kb:honeypot_ports&amp;rev=1343315973&amp;do=diff</link>
        <description>Honeypot ports
 Port        Amun                                       Nepenthes                        Dionaea     21          ftpd                                                                             ftp         25          imail                                                                                        42          wins                                            wins                                         69                                                                   …</description>
    </item>
    <item rdf:about="http://ids.surfnet.nl/wiki/doku.php?id=kb:installing_kippo&amp;rev=1343308064&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2012-07-26T15:07:44+02:00</dc:date>
        <dc:creator>ktrippelvitz</dc:creator>
        <title>Installing Kippo - [Other configuration] </title>
        <link>http://ids.surfnet.nl/wiki/doku.php?id=kb:installing_kippo&amp;rev=1343308064&amp;do=diff</link>
        <description>BETA

BETA

BETA

BETA



NOTE : Kippo support in SURFids is still in beta phase. This document is mainly intended for people that want to help testing Kippo along with SURFids.

Installation


cd /opt/
svn checkout http://kippo.googlecode.com/svn/trunk/ kippo</description>
    </item>
    <item rdf:about="http://ids.surfnet.nl/wiki/doku.php?id=other:contact&amp;rev=1343207693&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2012-07-25T11:14:53+02:00</dc:date>
        <dc:creator>ktrippelvitz</dc:creator>
        <title>Contact - [Developers] </title>
        <link>http://ids.surfnet.nl/wiki/doku.php?id=other:contact&amp;rev=1343207693&amp;do=diff</link>
        <description>Project leader

Rogier.Spoor[at]surfnet[dot]nl

Developers

Kees Trippelvitz - Kees.Trippelvitz[at]surfnet[dot]nl

IRC

SURFnet IDS:
#surfnetids irc.freenode.net

Nepenthes: 
#nepenthes irc.freenode.net</description>
    </item>
    <item rdf:about="http://ids.surfnet.nl/wiki/doku.php?id=latest_docs:2_tunnel_server:1._installation&amp;rev=1341580267&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2012-07-06T15:11:07+02:00</dc:date>
        <dc:creator>ktrippelvitz</dc:creator>
        <title>1: Installation - [Debian Squeeze] </title>
        <link>http://ids.surfnet.nl/wiki/doku.php?id=latest_docs:2_tunnel_server:1._installation&amp;rev=1341580267&amp;do=diff</link>
        <description>1: Installation

First you need to add the SURFids key to your local key chain:


wget -q http://repo.ids.surfnet.nl/key.pub -O- | sudo apt-key add -


Then create a file /etc/apt/sources.list.d/surfids.list with the content:


deb http://repo.ids.surfnet.nl/surfnetids/ lenny main</description>
    </item>
    <item rdf:about="http://ids.surfnet.nl/wiki/doku.php?id=latest_docs:2_tunnel_server:1b._arp_detection&amp;rev=1326205127&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2012-01-10T15:18:47+02:00</dc:date>
        <dc:creator>ktrippelvitz</dc:creator>
        <title>1a: Installing Ethernet module</title>
        <link>http://ids.surfnet.nl/wiki/doku.php?id=latest_docs:2_tunnel_server:1b._arp_detection&amp;rev=1326205127&amp;do=diff</link>
        <description>1a: Installing Ethernet module

The detectarp.pl script uses various perl libraries. These libraries are not always available as standard Debian packages. To enable ARP detection we will somehow need to install these libraries. Here is how it works:

What is needed?

The list of needed libraries is:</description>
    </item>
    <item rdf:about="http://ids.surfnet.nl/wiki/doku.php?id=latest_docs:faq&amp;rev=1324572265&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2011-12-22T17:44:25+02:00</dc:date>
        <dc:creator>ktrippelvitz</dc:creator>
        <title>FAQ - [Dionaea FAQ] </title>
        <link>http://ids.surfnet.nl/wiki/doku.php?id=latest_docs:faq&amp;rev=1324572265&amp;do=diff</link>
        <description>FAQ

Tunnel server FAQ

T01: I have a sensor that keeps starting and reseting it's connection. Certificate is not yet valid.

 
SERVER: /var/log/daemon.log



Mar 28 15:38:02 localhost openvpn[31788]: Connection reset, inetd/xinetd exit [-1]




SENSOR: /var/log/daemon.log</description>
    </item>
    <item rdf:about="http://ids.surfnet.nl/wiki/doku.php?id=sidebar&amp;rev=1323866892&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2011-12-14T13:48:12+02:00</dc:date>
        <dc:creator>ktrippelvitz</dc:creator>
        <title>Global</title>
        <link>http://ids.surfnet.nl/wiki/doku.php?id=sidebar&amp;rev=1323866892&amp;do=diff</link>
        <description>[http://ids.surfnet.nl/]

Global

	*  SURFcert IDS
	*  Global
	*  Tunnel server
	*  Sensor
	*  Logging server
	*  SURFids Demo
	*  Downloadable Demo

Files

	*  Screenshots
	*  SURFids packages
	*  Subversion
	*  SURFids Trac
	*  Miscellaneous
	*  Manual
latest_docs index

kb index</description>
    </item>
    <item rdf:about="http://ids.surfnet.nl/wiki/doku.php?id=home&amp;rev=1323169198&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2011-12-06T11:59:58+02:00</dc:date>
        <dc:creator>ktrippelvitz</dc:creator>
        <title>SURFcert IDS</title>
        <link>http://ids.surfnet.nl/wiki/doku.php?id=home&amp;rev=1323169198&amp;do=diff</link>
        <description>Welcome to the SURFcert IDS Development homepage. SURFcert IDS (previously SURFids) is an open source Distributed Intrusion Detection System based on passive sensors. The goal is to provide an early warning system which lets system administrators correlate known and unknown exploits to attacks directed towards their networks.</description>
    </item>
    <item rdf:about="http://ids.surfnet.nl/wiki/doku.php?image=kb%3Avmware_network_0a.jpg&amp;ns=kb&amp;rev=1269271478&amp;tab_details=history&amp;mediado=diff&amp;do=media">
        <dc:format>text/html</dc:format>
        <dc:date>2010-03-22T16:24:38+02:00</dc:date>
        <dc:creator>ktrippelvitz</dc:creator>
        <title>SURFcert IDS</title>
        <link>http://ids.surfnet.nl/wiki/doku.php?image=kb%3Avmware_network_0a.jpg&amp;ns=kb&amp;rev=1269271478&amp;tab_details=history&amp;mediado=diff&amp;do=media</link>
        <description>&lt;img src=&quot;/wiki/lib/exe/fetch.php?w=500&amp;h=291t=1342085232&amp;amp;media=kb:vmware_network_0a.jpg&quot; alt=&quot;kb:vmware_network_0a.jpg&quot; /&gt;</description>
    </item>
    <item rdf:about="http://ids.surfnet.nl/wiki/doku.php?image=kb%3Avmware_network_0.jpg&amp;ns=kb&amp;rev=1269267537&amp;tab_details=history&amp;mediado=diff&amp;do=media">
        <dc:format>text/html</dc:format>
        <dc:date>2010-03-22T15:18:57+02:00</dc:date>
        <dc:creator>ktrippelvitz</dc:creator>
        <title>SURFcert IDS</title>
        <link>http://ids.surfnet.nl/wiki/doku.php?image=kb%3Avmware_network_0.jpg&amp;ns=kb&amp;rev=1269267537&amp;tab_details=history&amp;mediado=diff&amp;do=media</link>
        <description>&lt;img src=&quot;/wiki/lib/exe/fetch.php?w=500&amp;h=292t=1342085232&amp;amp;media=kb:vmware_network_0.jpg&quot; alt=&quot;kb:vmware_network_0.jpg&quot; /&gt;</description>
    </item>
    <item rdf:about="http://ids.surfnet.nl/wiki/doku.php?image=kb%3Avmware_network_2.jpg&amp;ns=kb&amp;rev=1269259804&amp;tab_details=history&amp;mediado=diff&amp;do=media">
        <dc:format>text/html</dc:format>
        <dc:date>2010-03-22T13:10:04+02:00</dc:date>
        <dc:creator>ktrippelvitz</dc:creator>
        <title>SURFcert IDS</title>
        <link>http://ids.surfnet.nl/wiki/doku.php?image=kb%3Avmware_network_2.jpg&amp;ns=kb&amp;rev=1269259804&amp;tab_details=history&amp;mediado=diff&amp;do=media</link>
        <description>&lt;img src=&quot;/wiki/lib/exe/fetch.php?w=499&amp;h=366t=1342085232&amp;amp;media=kb:vmware_network_2.jpg&quot; alt=&quot;kb:vmware_network_2.jpg&quot; /&gt;</description>
    </item>
    <item rdf:about="http://ids.surfnet.nl/wiki/doku.php?image=kb%3Avmware_network_3.jpg&amp;ns=kb&amp;rev=1269258858&amp;tab_details=history&amp;mediado=diff&amp;do=media">
        <dc:format>text/html</dc:format>
        <dc:date>2010-03-22T12:54:18+02:00</dc:date>
        <dc:creator>ktrippelvitz</dc:creator>
        <title>SURFcert IDS</title>
        <link>http://ids.surfnet.nl/wiki/doku.php?image=kb%3Avmware_network_3.jpg&amp;ns=kb&amp;rev=1269258858&amp;tab_details=history&amp;mediado=diff&amp;do=media</link>
        <description>&lt;img src=&quot;/wiki/lib/exe/fetch.php?w=455&amp;h=500t=1342085232&amp;amp;media=kb:vmware_network_3.jpg&quot; alt=&quot;kb:vmware_network_3.jpg&quot; /&gt;</description>
    </item>
    <item rdf:about="http://ids.surfnet.nl/wiki/doku.php?image=kb%3Avmware_network_1.jpg&amp;ns=kb&amp;rev=1269258841&amp;tab_details=history&amp;mediado=diff&amp;do=media">
        <dc:format>text/html</dc:format>
        <dc:date>2010-03-22T12:54:01+02:00</dc:date>
        <dc:creator>ktrippelvitz</dc:creator>
        <title>SURFcert IDS</title>
        <link>http://ids.surfnet.nl/wiki/doku.php?image=kb%3Avmware_network_1.jpg&amp;ns=kb&amp;rev=1269258841&amp;tab_details=history&amp;mediado=diff&amp;do=media</link>
        <description>&lt;img src=&quot;/wiki/lib/exe/fetch.php?w=500&amp;h=366t=1342085232&amp;amp;media=kb:vmware_network_1.jpg&quot; alt=&quot;kb:vmware_network_1.jpg&quot; /&gt;</description>
    </item>
</rdf:RDF>
