LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 06-19-2009, 10:01 PM   #1
liang3391
LQ Newbie
 
Registered: May 2009
Posts: 20

Rep: Reputation: 0
snort + mysql+ acid


snort installed to normal operation after the procedure, but I used nmap scanning when there is no log record, mysql to work, but no data is written into the snort. acid can not produce images visit.


snort installed on the server Cpanel/WHM
 
Old 06-24-2009, 01:59 PM   #2
unixfool
Member
 
Registered: May 2005
Location: Northern VA
Distribution: Slackware, Ubuntu, FreeBSD, OpenBSD, OS X
Posts: 782
Blog Entries: 8

Rep: Reputation: 158Reputation: 158
Quote:
Originally Posted by liang3391 View Post
snort installed to normal operation after the procedure, but I used nmap scanning when there is no log record, mysql to work, but no data is written into the snort. acid can not produce images visit.


snort installed on the server Cpanel/WHM
Quote:
Originally Posted by liang3391 View Post
snort installed to normal operation after the procedure, but I used nmap scanning when there is no log record, mysql to work, but no data is written into the snort. acid can not produce images visit.

snort installed on the server Cpanel/WHM
IMO, you need to know what the exact issue is. Is it with Snort? MySQL?

1. MySQL issues tend to be due to user permissions issues (if its even running), so check to see if you're using the correct password (or if you're supplying a password when the service is set up to not use one...if this is the case, don't supply a password, [fix the service later]).

2. Check to see if Snort is running in daemon mode.

3. Run snort in the foreground, then do your scan. Your scan should output to screen.

4. Use netstat to check MySQL connections.

5. Run tcpdump to look for MySQL traffic (or leverage Snort in sniff mode).

6. Even if Snort is running properly, it may not be configured to detect port scans (I had to play with my snort.conf file to get this working). You can attempt to trigger a web-based alert by putting the following in your browser: http://a-web-server/cmd.exe or http://a-web-server/root.exe. I used to use this method all the time at my workplace to ensure that an IDS was functioning properly. This should work if you've Nimda and Codered sigs enabled on the Snort sensor and if you're actually sniffing for web-based traffic.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Snort doesn't log to MySQL Ephracis Linux - Security 3 04-22-2009 07:15 PM
snort & mysql zali Linux - Security 1 05-10-2006 12:13 PM
compile snort for mysql xeebeeeeeee Mandriva 2 12-19-2005 04:55 PM
snort and mysql lord-fu *BSD 1 11-20-2005 09:11 PM
snort and mysql ilnli Linux - General 1 03-28-2005 02:20 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 04:20 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration