PDA

View Full Version : [ubuntu] Something I've never understood about Snort


MaindotC
November 12th, 2008, 01:39 AM
Snort is really nice and I set up the configuration per the tutorial on howtoforge and I used BASE to view snort's results in a web browser. That's really cool, but something I've never understood is why isn't there some type of alarm or notification in the event something is detected in the rules? For example, say snort detects a port scan. Ya, I know there are billions of port scans each day, but isn't there some way I could get an email or a text message if snort detected something that I wanted to know about? The windows version has an auditory alarm that plays through the speakers.

randy78
November 13th, 2008, 01:41 AM
Swatch is what you're looking for:

sudo apt-get install swatch

Then, check here: http://www.snort.org/docs/faq/1Q05/node94.html

MaindotC
November 13th, 2008, 02:21 AM
randy you're the man! I was reading the snort docs but I hadn't gotten to this point yet. That's what forums are for :) THanks!

randy78
November 13th, 2008, 02:34 AM
Sweet! Mark this as solved using the Thread Tools tab so others can use it :)

Take Care:guitar:

MaindotC
November 13th, 2008, 02:54 AM
Well first I'll have to see if it works. Some of those links on the snort site are outdated - personal web pages of .edu domains. I'll keep you updated.

randy78
November 13th, 2008, 03:35 AM
Jeez, no joke... sorry for the bad links man :(

Here's another you might try: http://www.linuxsecurity.com/content/view/117377/171/

MaindotC
November 13th, 2008, 04:45 AM
I'll google more of it but for now you've given me a good direction to research :D