LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-14-2004, 02:06 PM   #1
shoombool_tala
Member
 
Registered: Apr 2004
Posts: 35

Rep: Reputation: 15
How to use SNORT?


Hi,
I installed Snort, but i have no clue how it works. As a normal user i ran "snort -D" and also i configured /etc/snort/snort.conf . So now what? It just sits in the background and logs all the traffic? and also where does it keep track of all the info and logs and attacks? /var/log/snort/ ??? and also does it pop up saying there is a attack or something.. or do i have to check the files myself on regular bases?

thanks a lot
 
Old 04-14-2004, 02:08 PM   #2
ugge
Senior Member
 
Registered: Dec 2000
Location: Gothenburg, SWEDEN
Distribution: OpenSUSE 10.3
Posts: 1,028

Rep: Reputation: 45
Have you taken a look in the documentation. There it speek about the three dufferent modes that snort can be run in. In addition there are documentation on how to configure and monitor the result.
www.snort.org
 
Old 04-21-2004, 09:12 AM   #3
71Monte
LQ Newbie
 
Registered: Jul 2003
Location: Tampa, FL
Distribution: Debian
Posts: 5

Rep: Reputation: 0
Check out this book on Snort. It is great and comes with source and lots of tips.

http://www.amazon.com/exec/obidos/tg...books&n=507846

Ian
 
Old 05-13-2004, 10:34 PM   #4
NoSS
LQ Newbie
 
Registered: May 2004
Posts: 3

Rep: Reputation: 0
Can I have the pdf file of that book ??
 
Old 05-14-2004, 01:49 AM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Can I have the pdf file of that book ??
You're asking for a free copy of something commercial. That's close enough to asking for warez. Please don't do that on LQ. There's enough Snort/IDS docs on the 'net you could start with.
 
Old 05-16-2004, 11:22 PM   #6
NoSS
LQ Newbie
 
Registered: May 2004
Posts: 3

Rep: Reputation: 0
Sorry.
Well, If there is free ebook about snort with easy tutorial. Can I have the URL ???
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Error when starting up snort: bash:!/bin/sh/usr/local/bin/snort :Eent not found cynthia_thomas Linux - Software 1 11-11-2005 02:59 PM
snort failed: snort: symbol lookup error: undefined symbol: usmAES192PrivProtocol Emmanuel_uk Linux - Security 1 07-10-2005 10:29 AM
Snort help Atrocity Slackware 9 05-24-2005 11:17 AM
Snort juanb Linux - Software 0 03-19-2003 06:22 AM
snort snort.conf help crealkiller175 Linux - Software 1 03-08-2003 05:58 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:21 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration