Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Detect-tor.bro not detecting traffic in live network #4

Open
binups opened this issue Feb 17, 2016 · 5 comments
Open

Detect-tor.bro not detecting traffic in live network #4

binups opened this issue Feb 17, 2016 · 5 comments

Comments

@binups
Copy link

binups commented Feb 17, 2016

Hi,
I tried the detect-tor.bro script security onion system for capturing tor packets, but its not capturing any tor packets

followed steps
1) added the script in /nsm/bro/share/bro/policy/frameworks/files/ path
2) loaded the script into local.bro script
3 ) in broctl i ,executed check, install , restart commands
4) created the tor traffic using tor browser

@sethhall
Copy link
Owner

You need to give more information. A packet capture would be ideal.

@binups
Copy link
Author

binups commented Feb 17, 2016

followed steps in security onion

  1. added the script in /nsm/bro/share/bro/policy/frameworks/files/ path
  2. loaded the script into local.bro script
    3 ) in broctl i ,executed check, install , restart commands
  3. created the tor traffic using tor browser

@sethhall
Copy link
Owner

�I suspect you just aren't tripping the thresholds defined in that script. Please read through the variables in the export section, you will probably need a bit more activity than you are doing. Again, a packet capture would be ideal.

@binups
Copy link
Author

binups commented Feb 17, 2016

Hmm i think my tor packets generating area have problem , you have any idea about how to create tor traffic

@binups
Copy link
Author

binups commented Feb 24, 2016

Hi,
Thank you my new local setup its working fine with out changing any tor_cert_threshold value , now we are testing with live network setup , the packets will come from outside the network and , we know tor packets are coming to my network , but its not detecting Tor using this script do we need extra cases to add ? or any other bro script are there ? and you know any tor related extra logic's ? Thank you

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants