LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-03-2004, 08:27 PM   #1
arkamir
Member
 
Registered: Nov 2003
Location: Califroni
Distribution: Fedora
Posts: 51

Rep: Reputation: 15
Help with Snort


I just set up snort and have a few questions. First of all I'm using it on a Fedora 1 box, source install into /usr/local/lib/snort*. I'm using the default rules.

I ran it like this as a NIDS:
snort -d -h 192.168.0.0/24 -l /var/log/snort/ -c /usr/local/lib/snort-2.1.0/etc/snort.conf

Then I did a Syn/Stealth port scan like this:

nmap -sS 192.168.0.12

on the machine, from the machine. The problem is when I checked the alert file in /var/log/snort there was nothing in there. In the nmap documentation in says that this scan will be detected and logged by snort and even shows an example.

Also was is the -dev option, I cant find it in the man page, and its on several examples.





Thanks a lot
 
Old 02-04-2004, 12:10 AM   #2
di11rod
Member
 
Registered: Jan 2004
Location: Austin, TEXAS
Distribution: CentOS 6.5
Posts: 211

Rep: Reputation: 32
I am using snort and logging to a mysql db. That is determined by my settings in the config file... Here is the syntax I used to start snort

/usr/sbin/snort -U -d -D -c /etc/snort/snort.conf

When you start yours, do you see any info reported back saying it's started? Is it in the process table if you do a ps -ef |grep snort ?

di11rod
 
Old 02-04-2004, 12:54 AM   #3
Skunk_Face
Member
 
Registered: Jan 2004
Posts: 54

Rep: Reputation: 15
like dil1rod said..try checking if snort is up and runnig first. I'm not sure on this but u could also check the snort config file to see which ethernet card u placed ur snort sensors on and the local address. If u have 2 nic's (one for LAN and another for internet) sensor might be on internet nic ...in which case if u used anoter comp on LAN to scan...snort prolly wont detect it.
Again im not sure on this.
 
Old 02-04-2004, 05:27 PM   #4
arkamir
Member
 
Registered: Nov 2003
Location: Califroni
Distribution: Fedora
Posts: 51

Original Poster
Rep: Reputation: 15
I'm using it on my ath0 card (wireless). I know it is running since my screen gets a huge message. I can attach my config file or at least the first part if that would help.
 
Old 02-04-2004, 11:58 PM   #5
di11rod
Member
 
Registered: Jan 2004
Location: Austin, TEXAS
Distribution: CentOS 6.5
Posts: 211

Rep: Reputation: 32
Post the message that appears when it starts.

Do you really get any wireless traffic to your box? Try using a browser on another computer and request a web page that doesn't exist. Snort should flag a 403 alert. Request a nonexistent page that ends with admin.php.

di11rod
 
Old 02-05-2004, 06:26 PM   #6
arkamir
Member
 
Registered: Nov 2003
Location: Califroni
Distribution: Fedora
Posts: 51

Original Poster
Rep: Reputation: 15
ahh thanks a lot it works now!
I think the problem is that I tried doing it from the localhost. Is there anyway I can so it so that it also alerts me when suspicous activity is taken from localhost?
 
Old 02-06-2004, 05:00 AM   #7
di11rod
Member
 
Registered: Jan 2004
Location: Austin, TEXAS
Distribution: CentOS 6.5
Posts: 211

Rep: Reputation: 32
It should flag stuff sourced from local host pointing at other hosts. Like if your box is comprimised and it's doing network scans or something, Snort will pick it up. The rules are probably lenient on requesting admin.php from localhost.

Good luck,

di11rod
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Error when starting up snort: bash:!/bin/sh/usr/local/bin/snort :Eent not found cynthia_thomas Linux - Software 1 11-11-2005 02:59 PM
snort failed: snort: symbol lookup error: undefined symbol: usmAES192PrivProtocol Emmanuel_uk Linux - Security 1 07-10-2005 10:29 AM
Snort help Atrocity Slackware 9 05-24-2005 11:17 AM
Snort juanb Linux - Software 0 03-19-2003 06:22 AM
snort snort.conf help crealkiller175 Linux - Software 1 03-08-2003 05:58 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:56 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration