LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-18-2003, 04:27 AM   #1
TheIrish
Member
 
Registered: Oct 2003
Location: ITALY
Distribution: Debian, Ubuntu, Fedora
Posts: 137

Rep: Reputation: 15
Snort... my seach continue...


Hi all!
First of all, I looked for answers in other posts but I couldn't find the exact answer for my questions, so, being a well known ignorant, I'll post a new thread.

Finally, I've been able to set-up snort properly.
Here comes the first question:
I set up a snortalert.log files where all the alerts go, and this works but my /var/log/snort/ fills up with snort-nnnn@nnnn.log What are these? I tried to see them but they looks binary.

Here comes the second question:
In my network setup, eth0 is linked to an ethernet switch for LAN purpose and eth1 is linked to a ADSL modem. I connect using ppp.
Should I monitor eth1 or ppp0?

Thank you all... and sorry for me to be so banal
 
Old 11-18-2003, 11:42 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
my /var/log/snort/ fills up with snort-nnnn@nnnn.log What are these? I tried to see them but they looks binary.
Try "file snort-nnnn@nnnn.log". If it says "tcpdump", then you can read them with "tcpdump -r <file>". If it says "8086 relocatable", then it's Snort's Unified binary logging format files, and you can read them with Barnyard (see snort.org / download / contrib / barnyard).
Using Snort unified logging is faster than logging ASCII, cuz it doesn't need to do stuff like interprete alerts and write them, resolve addresses etc etc. If you have troubles automating Barnyard usage, let me know, it's simple to script and hook up with cron or logrotate or whatever else.


Should I monitor eth1 or ppp0?
Depends on what you want to log. Go wild. Log 'em all.
Check out the LQ FAQ: Security references, post #3, under "Snort on two interfaces" for solutions and caveats.
 
Old 11-18-2003, 01:15 PM   #3
TheIrish
Member
 
Registered: Oct 2003
Location: ITALY
Distribution: Debian, Ubuntu, Fedora
Posts: 137

Original Poster
Rep: Reputation: 15
Before I start worrying... (I'm at work now and I can't check), do the snort binary log files contain sensitive data? I mean, if I need to understand if something went wrong, should I trust the human-readable alert file?
Thank you
 
Old 11-18-2003, 03:37 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Before I start worrying... (I'm at work now and I can't check), do the snort binary log files contain sensitive data?
It contains the logged packets' contents, yes.


I mean, if I need to understand if something went wrong, should I trust the human-readable alert file?
What do you mean by "trust"? I mean, what you get depends on how much info you log in your human-readable alert file. Still, it's parsed data, meaning you can't refilter or work on the data itself.
Binary format can produce both tcpdumps and human-readable alerts.
 
Old 11-18-2003, 04:03 PM   #5
TheIrish
Member
 
Registered: Oct 2003
Location: ITALY
Distribution: Debian, Ubuntu, Fedora
Posts: 137

Original Poster
Rep: Reputation: 15
Ok, now I see clearly. I was misundestanding a few things.
Thank you very much
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Error when starting up snort: bash:!/bin/sh/usr/local/bin/snort :Eent not found cynthia_thomas Linux - Software 1 11-11-2005 02:59 PM
binary seach; vector instead of an array niteshadw Programming 1 08-25-2005 09:03 AM
snort failed: snort: symbol lookup error: undefined symbol: usmAES192PrivProtocol Emmanuel_uk Linux - Security 1 07-10-2005 10:29 AM
why dont seach results show search string? Fascistchicken LQ Suggestions & Feedback 6 04-25-2004 02:29 PM
php mysql databate seach program set up spoody_goon Programming 2 11-21-2003 06:02 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:14 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration