扫一扫
分享文章到微信
扫一扫
关注官方公众号
至顶头条
作者:51cto 2007年10月16日
关键字:
在本页阅读全文(共2页)
[root@kykin-L-linux snort-1.9.0]# cp etc /usr/local/snort19 –r (复制当前文件夹下的ETC目录到SNORT19下面) [root@kykin-L-linux snort-1.9.0]# cp rules /usr/local/snort19 –r (复制全部规则文件) [root@kykin-L-linux snort-1.9.0]# cp etc/classification.config /root/ [root@kykin-L-linux snort-1.9.0]# cp etc/snort.conf /root/.snortrc (将调用的文件属性修改) |
[root@kykin-L-linux snort-1.9.0]#vi /root/.snortrc # This file contains a sample snort configuration. # You can take the following steps to create your # own custom configuration: # # 1) Set the network variables for your network # 2) Configure preprocessors # 3) Configure output plugins # 4) Customize your rule set # |
# Step #1: Set the network variables: # # You must change the following variables to reflect # your local network. The variable is currently # setup for an RFC 1918 address space. # # You can specify it explicitly as: # # var HOME_NET 10.1.1.0/24 |
var RULE_PATH ../rules |
var RULE_PATH /usr/local/snort19/rules |
include $RULE_PATH/bad-traffic.rules |
include $RULE_PATH/bad-traffic.rules include $RULE_PATH/exploit.rules include $RULE_PATH/scan.rules include $RULE_PATH/finger.rules include $RULE_PATH/ftp.rules include $RULE_PATH/telnet.rules include $RULE_PATH/rpc.rules include $RULE_PATH/rservices.rules include $RULE_PATH/dos.rules |
[root@kykin-L-linuxsnort-1.9.0]#ln –s /usr/local/snort19/bin/snort /usr/sbin/snort |
[root@kykin-L-linux snort-1.9.0]#cd /var/log [root@kykin-L-linux snort-1.9.0]#mkdir snort |
[root@kykin-L-linux snort-1.9.0]#snort Initializing Output Plugins! Log directory = /var/log/snort Initializing Network Interface eth0 using config file /root/.snortrc Initializing Preprocessors! Initializing Plug-ins! Parsing Rules file /root/.snortrc |
Initializing rule chains... No arguments to frag2 directive, setting defaults to: Fragment timeout: 60 seconds Fragment memory cap: 4194304 bytes< |
如果您非常迫切的想了解IT领域最新产品与技术信息,那么订阅至顶网技术邮件将是您的最佳途径之一。
现场直击|2021世界人工智能大会
直击5G创新地带,就在2021MWC上海
5G已至 转型当时——服务提供商如何把握转型的绝佳时机
寻找自己的Flag
华为开发者大会2020(Cloud)- 科技行者