Beruflich Dokumente
Kultur Dokumente
1 of 16 4/26/2018, 9:15 PM
How to Install Snort NIDS on Ubuntu Linux https://blog.rapid7.com/2017/01/11/how-to-install-snort-nids-on-ubuntu-...
apt-get update -y
apt-get upgrade -y
2 of 16 4/26/2018, 9:15 PM
How to Install Snort NIDS on Ubuntu Linux https://blog.rapid7.com/2017/01/11/how-to-install-snort-nids-on-ubuntu-...
wget https://www.snort.org/downloads/snort/daq-2.0.6.tar.gz
daq-2.0.6
cd daq-2.0.6
eth0
wget https://www.snort.org/downloads/snort/snort-2.9.8.3.tar.gz
3 of 16 4/26/2018, 9:15 PM
How to Install Snort NIDS on Ubuntu Linux https://blog.rapid7.com/2017/01/11/how-to-install-snort-nids-on-ubuntu-...
cd snort-2.9.8.3
ldconfig
ln -s /usr/local/bin/snort /usr/sbin/snort
snort -V
4 of 16 4/26/2018, 9:15 PM
How to Install Snort NIDS on Ubuntu Linux https://blog.rapid7.com/2017/01/11/how-to-install-snort-nids-on-ubuntu-...
mkdir /etc/snort
mkdir /etc/snort/preproc_rules
mkdir /etc/snort/rules
mkdir /var/log/snort
mkdir /usr/local/lib/snort_dynamicrules
touch /etc/snort/rules/white_list.rules
touch /etc/snort/rules/black_list.rules
touch /etc/snort/rules/local.rules
5 of 16 4/26/2018, 9:15 PM
How to Install Snort NIDS on Ubuntu Linux https://blog.rapid7.com/2017/01/11/how-to-install-snort-nids-on-ubuntu-...
snort-2.9.8.3
cd snort-2.9.8.3
/etc/snort/snort.conf
6 of 16 4/26/2018, 9:15 PM
How to Install Snort NIDS on Ubuntu Linux https://blog.rapid7.com/2017/01/11/how-to-install-snort-nids-on-ubuntu-...
nano /etc/snort/snort.conf
7 of 16 4/26/2018, 9:15 PM
How to Install Snort NIDS on Ubuntu Linux https://blog.rapid7.com/2017/01/11/how-to-install-snort-nids-on-ubuntu-...
local.rules
nano /etc/snort/rules/local.rules
alert tcp any any -> $HOME_NET 21 (msg:"FTP connection attempt"; sid:1000001; rev:1
alert icmp any any -> $HOME_NET any (msg:"ICMP connection attempt"; sid:1000002; rev
alert tcp any any -> $HOME_NET 80 (msg:"TELNET connection attempt"; sid:1000003; rev
-A
-q
-c
-i
8 of 16 4/26/2018, 9:15 PM
How to Install Snort NIDS on Ubuntu Linux https://blog.rapid7.com/2017/01/11/how-to-install-snort-nids-on-ubuntu-...
eth0
ping 192.168.15.189
ftp 192.168.15.189
telnet 192.168.15.189 80
192.168.15.189
Ctrl+c
snort.service
nano /lib/systemd/system/snort.service
9 of 16 4/26/2018, 9:15 PM
How to Install Snort NIDS on Ubuntu Linux https://blog.rapid7.com/2017/01/11/how-to-install-snort-nids-on-ubuntu-...
[Unit]
Description=Snort NIDS Daemon
After=syslog.target network.target
[Service]
Type=simple
ExecStart=/usr/local/bin/snort -q -c /etc/snort/snort.conf -i eth0
[Install]
WantedBy=multi-user.target
10 of 16 4/26/2018, 9:15 PM
How to Install Snort NIDS on Ubuntu Linux https://blog.rapid7.com/2017/01/11/how-to-install-snort-nids-on-ubuntu-...
11 of 16 4/26/2018, 9:15 PM
How to Install Snort NIDS on Ubuntu Linux https://blog.rapid7.com/2017/01/11/how-to-install-snort-nids-on-ubuntu-...
LOG IN WITH
OR SIGN UP WITH DISQUS ?
12 of 16 4/26/2018, 9:15 PM
How to Install Snort NIDS on Ubuntu Linux https://blog.rapid7.com/2017/01/11/how-to-install-snort-nids-on-ubuntu-...
13 of 16 4/26/2018, 9:15 PM
How to Install Snort NIDS on Ubuntu Linux https://blog.rapid7.com/2017/01/11/how-to-install-snort-nids-on-ubuntu-...
14 of 16 4/26/2018, 9:15 PM
How to Install Snort NIDS on Ubuntu Linux https://blog.rapid7.com/2017/01/11/how-to-install-snort-nids-on-ubuntu-...
15 of 16 4/26/2018, 9:15 PM
How to Install Snort NIDS on Ubuntu Linux https://blog.rapid7.com/2017/01/11/how-to-install-snort-nids-on-ubuntu-...
16 of 16 4/26/2018, 9:15 PM