[Discussion] Snort on CentOS 5.5 64bit |
17/11/2010 10:12:15 (+0700) | #1 | 225033 |
Mai Vu
Member
|
0 |
|
|
Joined: 15/11/2010 03:29:45
Messages: 3
Offline
|
|
Hi các Bro
Mình install snort xong service snortd đã OK. Nhưng khi chạy snort -c /etc/snort/snort.conf -l /var/log/snort/ -A console -i eth0 thi có warning như sau :
Warning: flowbits key 'email.pdf' is checked but not ever set.
Warning: flowbits key 'aiff_file.request' is set but not ever checked.
Warning: flowbits key 'http.jpeg' is set but not ever checked.
Warning: flowbits key 'http.ppt' is set but not ever checked.
Warning: flowbits key 'http.oless.v3' is set but not ever checked.
Warning: flowbits key 'access.download' is set but not ever checked.
Warning: flowbits key 'wav_file.request' is set but not ever checked.
Warning: flowbits key 'http.mp3' is set but not ever checked.
Warning: flowbits key 'starttls.attempt' is set but not ever checked.
Warning: flowbits key 'http.rtf' is set but not ever checked.
Warning: flowbits key 'caff_request' is set but not ever checked.
Warning: flowbits key 'tlsv1.client_hello.request' is checked but not ever set.
Warning: flowbits key 'chm_content_type' is set but not ever checked.
Warning: flowbits key 'xls.download' is set but not ever checked.
Warning: flowbits key 'smb.tree.create.sql.query' is set but not ever checked.
Warning: flowbits key 'http.bmp' is checked but not ever set.
Warning: flowbits key 'http.oless.v4' is set but not ever checked.
Warning: flowbits key 'pop3.stat' is set but not ever checked
......................
Xin hỏi có bị gì không ?
Với lại Snort không giám được toàn mạng chỉ alert khi ping đến Snort với rule test như sau :
alert icmp $EXTERNAL_NET any -> $HOME_NET any (msg: "ICMP Packet found";sid:1000111
Cho hỏi mình có config gì sai trong snort.conf hay không
Chân thành cảm ơn các Bro
|
|
|
|
|
[Discussion] Snort on CentOS 5.5 64bit |
17/11/2010 10:21:11 (+0700) | #2 | 225036 |
lanmc
Member
|
0 |
|
|
Joined: 06/10/2010 11:04:40
Messages: 30
Offline
|
|
Bạn nên thảy nội dung snort.conf lên |
|
|
[Discussion] Snort on CentOS 5.5 64bit |
17/11/2010 10:38:36 (+0700) | #3 | 225038 |
Mai Vu
Member
|
0 |
|
|
Joined: 15/11/2010 03:29:45
Messages: 3
Offline
|
|
Chỉ chỉnh những dòng sau :
var HOME_NET 192.168.1.0/24
var EXTERNAL_NET !$HOME_NET
var RULE_PATH /etc/snort/rules
var SO_RULE_PATH /etc/snort/so_rules
output alert_unified: filename snort.alert, limit 128
output log_unified: filename snort.log, limit 12
Ngoài ra để default cả
Thanks Bro |
|
|
|