ready
Intellectual preparation
Learning teacher to upload files to set up the environment.
Running on a VMware virtual machine software operating system network connection in three ways:
Bridge mode (Bridge): In bridge mode, VMware simulate a virtual network card to the customer system, the main
system for client systems is the equivalent of a bridge. The system seems to have their own customer card as
their own directly connected to the network, which means that the client system directly visible to the outside;Network address translation (NAT): In this mode, the client system can not connect to the network their own, but must
address translation for the client transceiver system network of all incoming and outgoing data packets via the host system. In this way,
the client system is not visible to the outside.Host mode (Host-Only): In this manner, the main system simulates a virtual switch, all of the guest
user by the system out of the network switches. In this way, if the primary system is connected with a public network IP
Internet, the system that the customer can only use private IP.
Download ready
VMware workstation download, has been subjected to a pre-;
VM_Win2kServer_SP0_target.rar;
VM_WinXPattacker.rar;
SEEDUbuntu9_August_2010.tar;
roo-1.4.hw-20090425114542.iso;
2 to 5 above Baidu sharing cloud from the teacher.
Set up
Network Topology FIG.
Virtual machine configuration
- Virtual network configuration editor
- Import other virtual machines
Other similar conduct.
- problem
Due to their own understanding of the problem, no good during the editing process, after the completion of all installation problems later, unable to ping each virtual machine, honey can not access the page because described later. Therefore, re-examine and configure
- Weight distribution
The emphasis changed the IP address itself
Installation configuration Honeywall
Installation Process
In VMware File -> New Virtual Machine
Select Custom Installation
Hardware Compatibility election 6.5-7.x
Install the operating system later
The client operating system is Linux, and earlier version Centos5
Virtual machine name and location of the custom
The default number of processors can be
512MB memory instead
Network connections using NAT
LSI LOGIC
Create a new virtual hard disk
The maximum disk size 8G, stored as a single file
Add two network cards, the adapter 2 is set to host only mode, the adapter 3 is set to NAT, specify the CD / DVD path is the path roo-1.4.hw-20090425114542.iso file
Configuration process
Start Honeynet virtual machine, enter the following installation interface. Type the Enter key to start the installation, Honeywall software is installed, enter the login screen
Login Honeywall, account name roo password honey, and acquire root privileges after entering the user's password will enter the configuration interface
Select 4 Honeywall Configuration configure
Select Defaults configuration
Reselection 4 HoneyWall Configuration, follow the steps below
6. Select 5 LAN Broadcast Address
7. Select 6 LAN CIDR Prefix
8. return to the main selection screen 4 HoneyWall Configuration, and select 2 Remote Management
9. Select 1 Management IP Address
10. Select 2 Management Netmask
11. Select 3 Management Gateway
12. Select 7 Manager, is provided to manage Honeywall remote control terminal IP range, fill in CIDR format, there may be multiple IP network segments, separated by spaces
13.Sebek server configuration, return to the main selection interface selection 4 HoneyWall Configuration 11 Sebek
14. The target port selection is 1101, Sebek packet processing option to select the Drop
practice
Remote Access Access https://192.168.200.8 192.168.200.2 on this virtual machine, and change passwords
Attack on a virtual machine honeypot host ping IP
Listen for ICMP ping packets through the external network interface and the network port on Honeywall
problem solved
Linux in access to the machine's IP address ifconfig statement;
Address different bands of the virtual machine can not be cross-ping, the others Solution Reference blog, link to https://blog.csdn.net/ChengTong007/article/details/81777656;
Upon entering the honeypot, for the first time directly into the menu, then problems arise when a check is entered by the statement;
cd /usr/sbin
./menu
to sum up
This very practical hands-on work, to own some of the basics meter network has been used, at the time of the self can not go, see the Sun Qilong students learning process and explain this very grateful. Through this practice we have a more flexible application of basic knowledge networks to enhance their practical ability.