免费注册 查看新帖 |

Chinaunix

  平台 论坛 博客 文库
12下一页
最近访问板块 发新帖
查看: 2629 | 回复: 19
打印 上一主题 下一主题

snort的输出是空白,到底哪里出错了? [复制链接]

论坛徽章:
0
跳转到指定楼层
1 [收藏(0)] [报告]
发表于 2004-09-27 16:54 |只看该作者 |倒序浏览
我有正常运行snort的(系统为debian):
  1. /usr/sbin/snort -D -c /etc/snort/snort.conf
复制代码

但是什么警告也没有,这是什么原因?如图:

混杂模式也开的,messages日志如下:

  1. :
  2. :
  3. :
  4. Sep 28 00:58:43 test kernel: eth0: Promiscuous mode enabled.
  5. Sep 28 00:58:43 test  kernel: device eth0 entered promiscuous mode
  6. Sep 28 00:58:43 test  kernel: device eth0 left promiscuous mode
  7. Sep 28 01:05:36 test  kernel: eth0: Promiscuous mode enabled.
  8. Sep 28 01:05:36 test  kernel: device eth0 entered promiscuous mode
  9. Sep 28 01:05:46 test  kernel: device eth0 left promiscuous mode
  10. :
  11. :
  12. :
复制代码

acid.gif (53.37 KB, 下载次数: 7)

acid.gif

论坛徽章:
0
2 [报告]
发表于 2004-09-27 16:57 |只看该作者

snort的输出是空白,到底哪里出错了?

snort log

  1. test:/var/log/snort# ls -al
  2. total 24
  3. drwxr-s---    2 snort    snort        4096 Sep 28 01:21 .
  4. drwxr-xr-x    8 root     root         4096 Sep 27 21:32 ..
  5. -rw-r-----    1 snort    snort           0 Sep 27 21:03 alert
  6. -rw-r-----    1 root     snort          24 Sep 27 21:50 tcpdump.log.1096293003
  7. -rw-------    1 root     snort          24 Sep 28 01:05 tcpdump.log.1096304736
  8. -rw-------    1 root     snort          24 Sep 28 01:08 tcpdump.log.1096304899
  9. -rw-------    1 root     snort           0 Sep 28 01:14 tcpdump.log.1096305268
  10. -rw-------    1 root     snort          24 Sep 28 01:21 tcpdump.log.1096305704
复制代码

论坛徽章:
0
3 [报告]
发表于 2004-09-27 17:23 |只看该作者

snort的输出是空白,到底哪里出错了?

真搞不明了,我把日志输出到syslog出又能看到日志,但我不输出到syslog的话,alert里面什么也没有。

  1. /usr/sbin/snort -s -D -c /etc/snort/snort.conf
复制代码

syslog日志输出如下:

  1. Sep 28 01:57:48 test snort: Initializing daemon mode
  2. Sep 28 01:57:48 test snort: PID path stat checked out ok, PID path set to /var/run/
  3. Sep 28 01:57:48 test snort: Writing PID "7228" to file "/var/run//snort_eth0.pid"
  4. Sep 28 01:57:48 test snort: ,-----------[Flow Config]----------------------
  5. Sep 28 01:57:48 test snort: | Stats Interval:  0
  6. Sep 28 01:57:48 test snort: | Hash Method:     2
  7. Sep 28 01:57:48 test snort: | Memcap:          10485760
  8. Sep 28 01:57:48 test snort: | Rows  :          4099
  9. Sep 28 01:57:48 test snort: | Overhead Bytes:  16400(%0.16)
  10. Sep 28 01:57:48 test snort: `----------------------------------------------
  11. Sep 28 01:57:48 test snort: HttpInspect Config:
  12. Sep 28 01:57:48 test snort:     GLOBAL CONFIG
  13. Sep 28 01:57:48 test snort:       Max Pipeline Requests:    0
  14. Sep 28 01:57:48 test snort:       Inspection Type:          STATELESS
  15. Sep 28 01:57:48 test snort:       Detect Proxy Usage:       NO
  16. Sep 28 01:57:48 test snort:       IIS Unicode Map Filename: /etc/snort/unicode.map
  17. Sep 28 01:57:48 test snort:       IIS Unicode Map Codepage: 1252
  18. Sep 28 01:57:48 test snort:     DEFAULT SERVER CONFIG:
  19. Sep 28 01:57:48 test snort:       Ports:
  20. Sep 28 01:57:48 test snort: 80
  21. Sep 28 01:57:48 test snort: 8080
  22. Sep 28 01:57:48 test snort: 8180
  23. Sep 28 01:57:48 test snort:  
  24. Sep 28 01:57:48 test snort:       Flow Depth: 300
  25. Sep 28 01:57:48 test snort:       Max Chunk Length: 500000
  26. Sep 28 01:57:48 test snort:       Inspect Pipeline Requests: YES
  27. Sep 28 01:57:48 test snort:       URI Discovery Strict Mode: NO
  28. Sep 28 01:57:48 test snort:       Allow Proxy Usage: NO
  29. Sep 28 01:57:48 test snort:       Disable Alerting: NO
  30. Sep 28 01:57:48 test snort:       Oversize Dir Length: 500
  31. Sep 28 01:57:48 test snort:       Only inspect URI: NO
  32. Sep 28 01:57:48 test snort:       Ascii: YES alert: NO
  33. Sep 28 01:57:48 test snort:       Double Decoding: YES alert: YES
  34. Sep 28 01:57:48 test snort:       %U Encoding: YES alert: YES
  35. Sep 28 01:57:48 test snort:       Bare Byte: YES alert: YES
  36. Sep 28 01:57:48 test snort:       Base36: OFF
  37. Sep 28 01:57:48 test snort:       UTF 8: OFF
  38. Sep 28 01:57:48 test snort:       IIS Unicode: YES alert: YES
  39. Sep 28 01:57:48 test snort:       Multiple Slash: YES alert: NO
  40. Sep 28 01:57:48 test snort:       IIS Backslash: YES alert: NO
  41. Sep 28 01:57:48 test snort:       Directory Traversal: YES alert: NO
  42. Sep 28 01:57:48 test snort:       Web Root Traversal: YES alert: YES
  43. Sep 28 01:57:48 test snort:       Apache WhiteSpace: YES alert: YES
  44. Sep 28 01:57:48 test snort:       IIS Delimiter: YES alert: YES
  45. Sep 28 01:57:48 test snort:       IIS Unicode Map: GLOBAL IIS UNICODE MAP CONFIG
  46. Sep 28 01:57:48 test snort:       Non-RFC Compliant Characters:
  47. Sep 28 01:57:48 test snort: NONE
  48. Sep 28 01:57:48 test snort:  
  49. Sep 28 01:57:48 test snort: rpc_decode arguments:
  50. Sep 28 01:57:48 test snort:     Ports to decode RPC on: 111 32771  
  51. Sep 28 01:57:48 test snort:     alert_fragments: INACTIVE
  52. Sep 28 01:57:48 test snort:     alert_large_fragments: ACTIVE
  53. Sep 28 01:57:48 test snort:     alert_incomplete: ACTIVE
  54. Sep 28 01:57:48 test snort:     alert_multiple_requests: ACTIVE
  55. Sep 28 01:57:48 test snort: telnet_decode arguments:
复制代码

论坛徽章:
1
荣誉会员
日期:2011-11-23 16:44:17
4 [报告]
发表于 2004-09-27 20:29 |只看该作者

snort的输出是空白,到底哪里出错了?

complier 時有 enable mysql 嗎 !?
snort.conf 有 mysql 的相關設定嗎 !?
acid 有設對 mysql 嗎 !?

snort -c /etc/snort/snort.conf  全部顯示訊息為何 !?

论坛徽章:
0
5 [报告]
发表于 2004-09-28 10:30 |只看该作者

snort的输出是空白,到底哪里出错了?

谢谢,输出是正常的,如图:

  1. Running in IDS mode
  2. Log directory = /var/log/snort

  3. Initializing Network Interface eth0

  4.         --== Initializing Snort ==--
  5. Initializing Output Plugins!
  6. Decoding Ethernet on interface eth0
  7. Initializing Preprocessors!
  8. Initializing Plug-ins!
  9. Parsing Rules file /etc/snort/snort.conf

  10. +++++++++++++++++++++++++++++++++++++++++++++++++++
  11. Initializing rule chains...
  12. ,-----------[Flow Config]----------------------
  13. | Stats Interval:  0
  14. | Hash Method:     2
  15. | Memcap:          10485760
  16. | Rows  :          4099
  17. | Overhead Bytes:  16400(%0.16)
  18. `----------------------------------------------
  19. No arguments to frag2 directive, setting defaults to:
  20.     Fragment timeout: 60 seconds
  21.     Fragment memory cap: 4194304 bytes
  22.     Fragment min_ttl:   0
  23.     Fragment ttl_limit: 5
  24.     Fragment Problems: 0
  25.     Self preservation threshold: 500
  26.     Self preservation period: 90
  27.     Suspend threshold: 1000
  28.     Suspend period: 30
  29. Stream4 config:
  30.     Stateful inspection: ACTIVE
  31.     Session statistics: INACTIVE
  32.     Session timeout: 30 seconds
  33.     Session memory cap: 8388608 bytes
  34.     State alerts: INACTIVE
  35.     Evasion alerts: INACTIVE
  36.     Scan alerts: INACTIVE
  37.     Log Flushed Streams: INACTIVE
  38.     MinTTL: 1
  39.     TTL Limit: 5
  40.     Async Link: 0
  41.     State Protection: 0
  42.     Self preservation threshold: 50
  43.     Self preservation period: 90
  44.     Suspend threshold: 200
  45.     Suspend period: 30
  46. Stream4_reassemble config:
  47.     Server reassembly: INACTIVE
  48.     Client reassembly: ACTIVE
  49.     Reassembler alerts: ACTIVE
  50.     Zero out flushed packets: INACTIVE
  51.     flush_data_diff_size: 500
  52.     Ports: 21 23 25 53 80 110 111 143 513 1433
  53.     Emergency Ports: 21 23 25 53 80 110 111 143 513 1433
  54. HttpInspect Config:
  55.     GLOBAL CONFIG
  56.       Max Pipeline Requests:    0
  57.       Inspection Type:          STATELESS
  58.       Detect Proxy Usage:       NO
  59.       IIS Unicode Map Filename: /etc/snort/unicode.map
  60.       IIS Unicode Map Codepage: 1252
  61.     DEFAULT SERVER CONFIG:
  62.       Ports: 80 8080 8180
  63.       Flow Depth: 300
  64.       Max Chunk Length: 500000
  65.       Inspect Pipeline Requests: YES
  66.       URI Discovery Strict Mode: NO
  67.       Allow Proxy Usage: NO
  68.       Disable Alerting: NO
  69.       Oversize Dir Length: 500
  70.       Only inspect URI: NO
  71.       Ascii: YES alert: NO
  72.       Double Decoding: YES alert: YES
  73.       %U Encoding: YES alert: YES
  74.       Bare Byte: YES alert: YES
  75.       Base36: OFF
  76.       UTF 8: OFF
  77.       IIS Unicode: YES alert: YES
  78.       Multiple Slash: YES alert: NO
  79.       IIS Backslash: YES alert: NO
  80.       Directory Traversal: YES alert: NO
  81.       Web Root Traversal: YES alert: YES
  82.       Apache WhiteSpace: YES alert: YES
  83.       IIS Delimiter: YES alert: YES
  84.       IIS Unicode Map: GLOBAL IIS UNICODE MAP CONFIG
  85.       Non-RFC Compliant Characters: NONE
  86. rpc_decode arguments:
  87.     Ports to decode RPC on: 111 32771
  88.     alert_fragments: INACTIVE
  89.     alert_large_fragments: ACTIVE
  90.     alert_incomplete: ACTIVE
  91.     alert_multiple_requests: ACTIVE
  92. telnet_decode arguments:
  93.     Ports to decode telnet on: 21 23 25 119
  94. database: compiled support for ( mysql )
  95. database: configured to use mysql
  96. database:          user = snort
  97. database: password is set
  98. database: database name = snortdb
  99. database:          host = localhost
  100. database:   sensor name = 192.168.2.2
  101. database:     sensor id = 1
  102. database: schema version = 106
  103. database: using the "log" facility
  104. 1863 Snort rules read...
  105. 1863 Option Chains linked into 186 Chain Headers
  106. 0 Dynamic rules
  107. +++++++++++++++++++++++++++++++++++++++++++++++++++

  108. Warning: flowbits key 'realplayer.playlist' is checked but not ever set.

  109. +-----------------------[thresholding-config]----------------------------------
  110. | memory-cap : 1048576 bytes
  111. +-----------------------[thresholding-global]----------------------------------
  112. | none
  113. +-----------------------[thresholding-local]-----------------------------------
  114. | gen-id=1      sig-id=2523      type=Both       tracking=dst count=10  seconds=10
  115. | gen-id=1      sig-id=2496      type=Both       tracking=dst count=20  seconds=60
  116. | gen-id=1      sig-id=2495      type=Both       tracking=dst count=20  seconds=60
  117. | gen-id=1      sig-id=2494      type=Both       tracking=dst count=20  seconds=60
  118. | gen-id=1      sig-id=2275       type=Threshold tracking=dst count=5   seconds=60
  119. +-----------------------[suppression]------------------------------------------
  120. -------------------------------------------------------------------------------
  121. Rule application order: ->;activation->;dynamic->;alert->;pass->;log

  122.         --== Initialization Complete ==--

  123. -*>; Snort! <*-
  124. Version 2.2.0 (Build 30)
  125. By Martin Roesch (roesch@sourcefire.com, www.snort.org)
  126. 然后光标在这里停住
复制代码

我都将snort数据库用户设为GRANT了

论坛徽章:
0
6 [报告]
发表于 2004-09-28 10:50 |只看该作者

snort的输出是空白,到底哪里出错了?

和我的一样
如果你是-l path,则在path里有数据
如果你编译的时候是--with-mysql=/xxx,建立好数据库,应该写到数据库里

我也是没有数据,只有UDP-161(SNMP),其他没有
执行snort后,过一段时间按下ctrl + c,能看到各个协议的百分比,但是数据没有,我怀疑是snort.conf配置不对造成的

论坛徽章:
0
7 [报告]
发表于 2004-09-28 11:15 |只看该作者

snort的输出是空白,到底哪里出错了?

我用的是debian,安装时是直接将apache php4 msyql libpcap snort-mysql等一股脑装上的,后来,昨天晚上的测试的时候将snort用户加了GRANT后得到一点数据,也就是说alert里面有一小点内容,但现在不管怎么扫描,怎么弄都没了,都没了。如果我不将数据写进数据库,那可以syslog里面看得到。

论坛徽章:
0
8 [报告]
发表于 2004-09-28 11:18 |只看该作者

snort的输出是空白,到底哪里出错了?

我是在REDHAT里面,所有插件都是编译安装的
其中包括
acid-0.9.6b23.tar.gz
adodb452.tgz
jpgraph-1.17-beta.tar.gz
pcre-4.3.tar.bz2
snort-2.2.0.tar.gz

论坛徽章:
0
9 [报告]
发表于 2004-09-28 14:17 |只看该作者

snort的输出是空白,到底哪里出错了?

我按这里面http://www.snort.org/docs/faq.html#6.15的FAQ配置过后,能够有一些数据进mysql了,但有时又没有(snort是正常的,可是ACID就是不出日志) 使用-l path是有一个以IP命名的数据,但一写进数据库却什么也没有,日志又看不出有什么错误
虽然知道是与mysql相关,但又不知道真正问题在哪,真郁闷

log.gif (14.13 KB, 下载次数: 8)

log.gif

论坛徽章:
0
10 [报告]
发表于 2004-09-28 14:27 |只看该作者

snort的输出是空白,到底哪里出错了?

output database: alert, mysql
这个你设置的是alert还是log
如果用log,可能数据会更多一些
您需要登录后才可以回帖 登录 | 注册

本版积分规则 发表回复

  

北京盛拓优讯信息技术有限公司. 版权所有 京ICP备16024965号-6 北京市公安局海淀分局网监中心备案编号:11010802020122 niuxiaotong@pcpop.com 17352615567
未成年举报专区
中国互联网协会会员  联系我们:huangweiwei@itpub.net
感谢所有关心和支持过ChinaUnix的朋友们 转载本站内容请注明原作者名及出处

清除 Cookies - ChinaUnix - Archiver - WAP - TOP