文章详情

短信预约-IT技能 免费直播动态提醒

请输入下面的图形验证码

提交验证

短信预约提醒成功

Snort安装与使用 as3+apach

2023-01-31 03:30

关注
系统环境:rh as3+apache+php+snort+base
所需snort相关软件包:
adodb462.tgz
base-1.2.6.tar.gz
Image_Canvas-0.3.0.tar.gz
//Image_Color-1.0.2.tar.gz
Image_Graph-0.7.2.tar.gz
libpcap-0.9.5.tar.gz
pcre-6.7.tar.gz
snort-2.6.0.tar.gz
snortrules-pr-2.4.tar.gz
下载软件:
wget
http://download.sso.cn/security/ids/snort_base/adodb462.tgz
wget http://download.sso.cn/security/ids/snort_base/base-1.2.6.tar.gz
wget http://download.sso.cn/security/ids/snort_base/Image_Canvas-0.3.0.tar.gz
wget http://download.sso.cn/security/ids/snort_base/Image_Color-1.0.2.tar.gz
wget http://download.sso.cn/security/ids/snort_base/Image_Graph-0.7.2.tar.gz
wget http://download.sso.cn/security/ids/snort_base/install.txt
wget http://download.sso.cn/security/ids/snort_base/libpcap-0.9.5.tar.gz
wget http://download.sso.cn/security/ids/snort_base/pcre-6.7.tar.gz
wget http://download.sso.cn/security/ids/snort_base/snort-2.6.0.tar.gz
wget http://download.sso.cn/security/ids/snort_base/snortrules-pr-2.4.tar.gz
软件安装路径:
snort:
/usr/local/snort
rules:
/usr/local/snort/rules
snort.conf
/usr/local/snort/conf/snort.conf
adodb:
/usr/local/snort/adodb
base:
/usr/local/snort/base
libpcap:
/usr/local/snort/libpcap
pcre
/usr/local/snort/pcre
1 配置apache+php+mysql环境
2 安装snort前提组件libpcap-0.9.5.tar.gz和pcre-6.7.tar.gz
tar zxvf libpcap-0.9.5.tar.gz
cd libpcap-0.9.5
./configure --prefix=/usr/local/snort/libpcap
make
make install
tar zxvf pcre-6.7.tar.gz
cd pcre-6.7
./configure --prefix=/usr/local/snort/pcre
make
make install
3 安装snort-2.6.0.tar.gz并加载plugin
groupadd snort
useradd -g snort -s /sbin/nologin
建立日志文件目录和配置文件目录:
mkdir /var/log/snort
mkdir /usr/local/snort/conf
tar zxvf snort-2.6.0.tar.gz
cd snort-2.6.0
./configure --prefix=/usr/local/snort --with-mysql \
--with-libpcap-includes=/usr/local/snort/libpcap/include \
--with-libpcap-libraries=/usr/local/snort/libpcap/lib   \
--with-libpcre-includes=/usr/local/snort/pcre/include \
--with-libpcre-libraries=/usr/local/snort/pcre/lib \
--enable-dynamicplugin
make
make install
4 配置snort并加载rules
cp etc/classification.config /usr/local/snort/conf
cp etc/reference.config /usr/local/snort/conf
cp etc/snort.conf /usr/local/snort/conf
cp etc/unicode.map /usr/local/snort/conf
我查看过snort.conf文件,好象只用如上几个配置文件就可以了,如果有错误,可以使用:
cp etc/* /usr/local/snort/conf
创建snort数据库,并导入数据
mysql -uroot -prootpassword -e "create database snrot"
mysql -uroot -prootpassword -e "grant all on snort.* to
snort@localhost identified by 'snort'"
mysql -usnort -psnort
tar zxvf snortrules-pr-2.4.tar.gz
mv rules /usr/local/snort/
启动snort
/usr/local/snort/bin/snort -c /usr/local/snort/conf/snort.conf -i eth0 -g snort -D
如果实现开机自动启动,把上面的语句添加到/etc/rc.local
5 安装adodb和base
tar zxvf base-1.2.6.tar.gz
mv base-1.2.6 /usr/local/snort/base
tar zxvf adodb462.tgz
mv adodb /usr/local/snort/
6 配置base_conf.php
cd /usr/local/base
cp base_conf.php.dist base_conf.php
修改 “base_conf.php”
$BASE_urlpath = "/base";
$DBlib_path = "../adodb ";
$DBtype = "mysql";
$alert_dbname    = 'snort';
$alert_host      = 'localhost';
$alert_port      = '';
$alert_user      = 'snort';
$alert_password = 'snort';
7 配置apache
在httpd.conf文件中加入如下:
     Alias /base /usr/local/snort/base
这样您就可以在
http://ip/base
参考文档
http://download.sso.cn/security/ids/snort_base/snort_base_SSL.pdf
http://download.sso.cn/security/ids/snort_base/snort-barnyard.pdf
http://download.sso.cn/security/ids/snort_base/Snortman.htm
http://www.snort.org/docs/faq.html
http://www.snort.org/docs/
 
阅读原文内容投诉

免责声明:

① 本站未注明“稿件来源”的信息均来自网络整理。其文字、图片和音视频稿件的所属权归原作者所有。本站收集整理出于非商业性的教育和科研之目的,并不意味着本站赞同其观点或证实其内容的真实性。仅作为临时的测试数据,供内部测试之用。本站并未授权任何人以任何方式主动获取本站任何信息。

② 本站未注明“稿件来源”的临时测试数据将在测试完成后最终做删除处理。有问题或投稿请发送至: 邮箱/279061341@qq.com QQ/279061341

软考中级精品资料免费领

  • 历年真题答案解析
  • 备考技巧名师总结
  • 高频考点精准押题
  • 2024年上半年信息系统项目管理师第二批次真题及答案解析(完整版)

    难度     813人已做
    查看
  • 【考后总结】2024年5月26日信息系统项目管理师第2批次考情分析

    难度     354人已做
    查看
  • 【考后总结】2024年5月25日信息系统项目管理师第1批次考情分析

    难度     318人已做
    查看
  • 2024年上半年软考高项第一、二批次真题考点汇总(完整版)

    难度     435人已做
    查看
  • 2024年上半年系统架构设计师考试综合知识真题

    难度     224人已做
    查看

相关文章

发现更多好内容

猜你喜欢

AI推送时光机
位置:首页-资讯-后端开发
咦!没有更多了?去看看其它编程学习网 内容吧
首页课程
资料下载
问答资讯