TurnKey Linux Virtual Appliance Library

Security appliance (Snorby).

phillip bailey's picture

Dear all,

I'm pleased to announce the release of Snorby Appliance based on Turnkey.

This virtual appliance have been developed to provide an out of the box
runing  web front end for snort, the popular ids . The snorby web interface
is  developed by Dustin Webber. This appliance is indicated for security
professionals with a depth knowledge of intrusion detection and security
monitoring.  Nevertheless beginners can use the appliance to to understand
and learn about intrusion detection and network security.

Snorby website: http://snorby.org

Snorby appliance web site: http://bailey.st/blog/snorby-spsa/

best regards ,
Phillip Bailey

ISO

The iso link is broken.

Jeremy's picture

It's moved

If you follow the second link above (Snorby appliance web site) it states that the project has moved to http://www.bailey.st/blog/snorby-spsa/

If you follow that link you will see the new iso download.

phillip bailey's picture

Url correcterd

Url correcterd

snorby tklpatch

hi phillip. snorby looks really interesting. i cant seem to find a link to the tklpatch, can you post it?

Liraz Siri's picture

A TKLPatch would allow us to include snorby in the next release

Excellent work Phillip. It's great to see upstream pick up the glove and leverage TurnKey. We'd love to pull this work into the next release and a TKLPatch will help do that.

Late but wants to comment

Hi everybody! I guess I'm so late here but still wants to comment. I used Snorby before and got satisfied with it. That virtual appliance is really secured and has a good monitoring system. Thanks for developing it guys!

Fara

Issues related to Snorby 0.7.0 - Help

Hello,

I'm a beginner user of Snorby. I have been downloaded the ISO file, create a boot CD and everything goes right. But when I start Snorby, my sensors are only the loopback interface, even with an eth1 interface configured. Actually the appliance is connected in a Cisco Router 877 without any port mirroring.

If I start snort in a verbose mode I can see captured packets, but snorby doesn't capture nothing.

How can  I change the interfaces that I wish to capture packets?

Any tip?

Best Regards,

 

Vitor

Post new comment

The content of this field is kept private and will not be shown publicly. If you have a Gravatar account, used to display your avatar.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <p> <span> <div> <h1> <h2> <h3> <h4> <h5> <h6> <img> <map> <area> <hr> <br> <br /> <ul> <ol> <li> <dl> <dt> <dd> <table> <tr> <td> <em> <b> <u> <i> <strong> <font> <del> <ins> <sub> <sup> <quote> <blockquote> <pre> <address> <code> <cite> <strike> <caption>

More information about formatting options

Leave this field empty. It's part of a security mechanism.
(Dear spammers: moderators are notified of all new posts. Spam is deleted immediately)