|
|
发表于 2007-7-29 17:39:50
|
显示全部楼层
嘿嘿~~,我来说两句吧,哈哈~~~
看楼主的要求,你想把gentoo处理成双宿主机吧?意思是带两个网卡,一个对外连接(Internet),一个对内局域网.
此时的gentoo不要带X-window,网卡要设置为混杂模式,可以监控网络进出的包,内核要允许包过滤功能,安装iptable包过滤,ssh随机启动,远程监控.这个主机不要搞太多项目了,除非他很空闲,哈哈~~~
/usr/portage/net-analyzer目录下有许多网络监控工具,把他玩一遍,看谁好用,给个列表你:
aimsniff httping nessus-core scanssh
amap hunt nessus-libraries scapy
angst hydra nessus-plugins scli
argus hyperic-hq-agent netcat sec
argus-clients ibmonitor netcat6 sflowtool
arping ifmetric netdiscover sguil-client
arpoison ifstat netdude sguil-sensor
arp-sk ifstatus nethogs sguil-server
arptools iftop neti siphon
arpwatch ike-scan netio slurm
authforce ipac-ng netperf smokeping
barnyard ipaudit netselect sniffit
base ipband net-snmp snmpmon
bigeye ipcad netspeed_applet snmptt
bing iplog nettop snort
bmon ippl netwag snortalog
braa iptraf netwox snortsam
bsnmp iptstate nfdump sonar
bwbar isic ngrep squid-graph
bwm-ng jffnms nikto squidsites
bwmon jnettop nipper ssldump
cacti knetscan nload ssmping
cacti-cactid knocker nmap sussen
calamaris labrea nmbscan sysmon
carl lft ns tcpdump
chaosreader libnasl nsat tcpflow
cnet linkchecker nstats tcpreen
cryptcat macchanger ntop tcpreplay
cutter mbrowse nttcp tcpslice
darkstat metadata.xml oinkmaster tcpstat
dnstracer metasploit p0f tcptrace
dosdetector midas-nms packit tcptraceroute
driftnet mirmon paketto tcptrack
dsniff mping pathload thcrut
echoping mrtg pathrate thrulay
egressor mrtg-ping-probe pbnj tleds
etherape mtr pchar tptest
ethloop munin pinger traceproto
ethstatus mwcollect pktstat traceroute
ettercap nagios pmacct traceroute-nanog
fail2ban nagios-core poink trafd
fe3d nagios-imagepack portmon traffic-vis
ffp nagios-nrpe portsentry trafshow
firewalk nagios-nsca postal ttcp
FlowScan nagios-plugins prelude-nessus ttt
flow-tools nagios-plugins-snmp prewikka upnpscan
fping nagios-sap-ccms-plugin quidscor vnstat
fprobe nam raddump webfuzzer
fragroute nast rain wireshark
ftester nb rrdcollect xnetload
fwlogwatch nbaudit rrdtool xprobe
gensink nbtscan rtg yersinia
gnome-netstatus ndoutils rtpbreak zabbix
gnome-nettool ndsad sancp zabbix-agent
gnu-netcat nepenthes sara zabbix-frontend
gspoof nessus sarg zabbix-server
honeyd nessus-bin sbd zniper
hping nessus-client scanlogd
再把这个主机环境处理成Live CD ,就完美了.需时不少啊~~~~
ntop是用web登陆的. |
|