12 Aug 2012 21:56
Installing & Configuring snort
Damien Hull <dhull <at> section9.us>
2012-08-12 19:56:18 GMT
2012-08-12 19:56:18 GMT
I've played around with snort off and on for the past couple of years. Every time I use it I run into the same problem. It doesn't seem to work after following the instructions. I must be missing something. OS: Ubuntu 10.04 server SNORT: 2.9.3.1 Instructions: The Ubuntu-10.04-LTS instructions on the snort.org website. Barnyard2: Installed and configured MySQL: Using this and it seems to work Snort Rules: 2923 Problem #1 The dynamic rules don't work for some reason. I commented out the "dynamicdetection" line to turn that off. Problem #2 I'm not getting any alerts. I added sfportscan to snort.conf but I'm getting no action in the log file. Can someone point me in the right direction? ------------------------------------------------------------------------------ Live Security Virtual Conference Exclusive live event will cover all the ways today's security and threat landscape has changed and how IT managers can respond. Discussions will include endpoint security, mobile security and the latest in malware threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ _______________________________________________ Snort-users mailing list Snort-users <at> lists.sourceforge.net(Continue reading)
RSS Feed