Anyone ever tried this?

Discussion in 'Networks' started by zebulebu, Jan 2, 2007.

  zebulebu

    zebulebu Terabyte Poster

    Just for giggles yesterday I ran my WAN traffic from my modem through a hub before it reached my firewall so that i could connect a box outside and sniff some traffic (I plan to include it in the much-delayed final part of my Ethereal/Wireshark tutorial) from the 'unsanitised' Internet.

    It worked fine - I got loads of juicy messenger spam & 1433/143 probes amongst the rest of the usual background noise - and I'm thinking of hardening the box and leaving it on there, just to see what flies I can attract.

    Its not exactly a honeynet i know, but it might be interesting to see the actual packets that get blocked by my firewall...

    Anyone ever tried this and have any suggestions for what OS to put on the box? I'm 90% certain it'll be some stripped down flavour of Linux, but it might be a perfect time for me to learn FreeBSD - as I understand you can configure that down to the real barebones - all it needs to run is the absolute basic OS and Wireshark, so it should be (relatively - especially for someone with no experience of it) easy to set up.

    Anyone have any thoughts?
  Spice_Weasel

    Spice_Weasel Kilobyte Poster

    The Darknet Project is the place to start - an excellent introduction to creating a passive, invisible packet vacuum. At work we have a good sized block of unused ip's which make an excellent darknet.


    A home darknet is not ideal, since the ip is used for legitimate traffic, but it is very interesting to see what is blocked.

  hbroomhall

    hbroomhall Petabyte Poster Gold Member

    As far as I can see there isn't much to choose from FreeBSD and a non-X11 Linux distro like Debian. Both can be pared down to the bone on resources.

