There are two mistakes one can make along the road to truth...not going all the way, and not starting.
--Prince Gautama Siddharta
#ubuntuforums web interface
I am registered with snort and logged in.
Well then download the rules
Notice, they limit how often you can download, I think there is a 10 or 15 minute time out.
http://www.snort.org/pub-bin/downloads.cgi
There are two mistakes one can make along the road to truth...not going all the way, and not starting.
--Prince Gautama Siddharta
#ubuntuforums web interface
i will try again. is your guide pretty up to date? i am using ubuntu 8.04 right now and trying to learn more!!
I had a lot of trouble using wget. So I just downloaded the file to my desktop using Firefox, then copied the file to the directory that I wanted like /usr/src/snort or /etc/snort/ .
Good luck
Hi Bodhi,
My problem is not mysql. I see alerts there:
I just do not see them in BASE. I also do not see a sensor. BTW, I did not see anything about us having to install ACID. Did I miss a step? Other procedures I have seen about this, involves installing ACID.Code:mysql> show tables; +------------------+ | Tables_in_snort | +------------------+ | acid_ag | | acid_ag_alert | | acid_event | | acid_ip_cache | | base_roles | | base_users | | data | | detail | | encoding | | event | | icmphdr | | iphdr | | opt | | reference | | reference_system | | schema | | sensor | | sig_class | | sig_reference | | signature | | tcphdr | | udphdr | +------------------+ 22 rows in set (0.00 sec) mysql> select * from event; +-----+-----+-----------+---------------------+ | sid | cid | signature | timestamp | +-----+-----+-----------+---------------------+ | 1 | 2 | 1 | 2009-04-12 15:24:20 | | 1 | 3 | 1 | 2009-04-12 15:24:20 |
this part is confusing:
I mostly copy and pasting but the URL i copy are not correct.
wget http://www.snort.org/the_rules_you_wish_to_use
If you downloaded snort 2.8.x ( x = whatever revision ), then you want this url:
Bodhi just wrote it that way, meaning you need to select which version or rules matches your snort file.Code:http://www.snort.org/pub-bin/downloads.cgi/Download/vrt_os/snortrules-snapshot-2.8.tar.gz
I think I have an issue with the way I set up the permissions. I see a couple of other posts regarding missing sensor id in mysql, which causes BASE not to show anything. How can I get more information about this and troubleshoot it please?
thanks for the URL that worked now i went to the next command
cd snort2.8.3 what does this mean there is no directory for that
I downloaded that latest snort 2.8.4
Bookmarks