Ãâ·Ñ×¢²á ²é¿´ÐÂÌû |

Chinaunix

  ƽ̨ ÂÛ̳ ²©¿Í ÎÄ¿â
×î½ü·ÃÎÊ°å¿é ·¢ÐÂÌû
Â¥Ö÷: phiazat
´òÓ¡ ÉÏÒ»Ö÷Ìâ ÏÂÒ»Ö÷Ìâ

»ùÓÚSnortµÄÈëÇÖ¼ì²âϵͳ [¸´ÖÆÁ´½Ó]

ÂÛ̳»ÕÕÂ:
1
³óÅ£
ÈÕÆÚ:2015-01-07 15:25:00
81Â¥ [±¨¸æ]
·¢±íÓÚ 2006-10-27 23:40 |Ö»¿´¸Ã×÷Õß
ACIDÊÇÒ»ÖÖͨ¹ýweb½çÃæÀ´·ÖÎö²ì¿´SnortÊý¾ÝµÄ¹¤¾ß¡£ËüÊÇÓÃPHP±àдµÄ£¬ÓëSnortºÍMySQL»òÆäËûÊý¾Ý¿âһͬ¹¤×÷£¬Í¨¹ýweb·þÎñÆ÷£¬Ê¹Óû§Äܹ»·½±ãµÄ·ÃÎÊÊý¾Ý¡£³ýÁ˺ÍSnortһͬ¹¤×÷Í⣬ACIDÒ²¿ÉÒÔ±»Óû§ÆäËûһЩ°²È«Ïà¹ØµÄ²úÆ·£¬Èç·À»ðǽºÍÍøÂç¼à¿ØµÈ¡£\r\n±¾Õ½«ÌÖÂÛACIDÓëSnort¼°MySQLµÄÕûºÏ£¬ACIDµÄͼÐλ¯ÌصãÄܹ»¸øÄãºÜºÃµÄ°ïÖú¡£\r\n³ýÁËACIDÍ⣬±¾ÕÂÒ²»á½éÉÜһЩ¹ØÓÚSnortSnarfµÄ»ù±¾ÐÅÏ¢£¬SnortSnarfÊÇÁíÍâÒ»ÖÖͨ¹ýweb½çÃæÀ´·ÖÎöSnortÊý¾ÝµÄ¹¤¾ß¡£±¾Êé¼Ù¶¨ÄãÓÃApache×÷Ϊweb·þÎñÆ÷¡£\r\n6£®1ʲôÊÇACID£¿\r\nACID°üÀ¨Ò»Ð©PHP½Å±¾ºÍÅäÖÃÎļþ£¬ËüÃÇ¿ÉÒÔÊÕ¼¯ºÍ·ÖÎöÊý¾Ý¿âÖеÄÐÅÏ¢²¢Í¨¹ýwebÒ³Ãæ±íʾ¡£Óû§Í¨¹ýwebä¯ÀÀÆ÷ÓëACID½»»¥¡£ÎªÊ¹ACIDÄܹ»Ê¹Óã¬ÄãµÄϵͳÖÐÐèÒªweb·þÎñÆ÷£¬MySQLÒÔ¼°PHP£¬ÕâЩ¶¼ËæRedHatÒ»Æð·Ö·¢¡£ACIDµÄ×î½ü°æ±¾¿ÉÒÔÔÚhttp://www.cer.org/kb/acidÏÂÔØ¡£\r\nACID¾ßÓкܶàÌØÐÔ£º\r\n1¡¢        ¿ÉÒÔ½øÐлùÓÚ¶àÖÖÌõ¼þµÄ²éѯ£¬ÈçÔ´ºÍÄ¿µÄµØÖ·¡¢¶Ë¿Ú£¬Ê±¼äµÈµÈ£¬Èçͼ6-7Ëùʾ¡£\r\n2¡¢        °üÍ·²¿¼°ÔغÉÄÚÈݵIJ쿴£¬Èçͼ6-6ËùʾµÄICMP°ü¡£\r\n3¡¢        ¸æ¾¯¿ÉÒÔ°´²úÉúÀà±ð¹ÜÀí£¬Êä³ö£¬É¾³ý£¬»ò·¢Ë͵½Ä³¸öe-mailµØÖ·¡£\r\n4¡¢        ¿ÉÒÔ»ùÓÚʱ¼ä¡¢Ð­Òé¡¢IPµØÖ·¡¢¶Î¿ÚºÅµÈ²úÉú¿ÉÊÓ»¯Í¼±í¡£\r\n5¡¢        ¿ÉÒÔ²úÉúÊý¾Ý¿âµÄ¿ìÕÕ£¬ÀýÈç²ì¿´×îºó24СʱµÄ¸æ¾¯£¬µ¥¶ÀµÄ¸æ¾¯ÒÔ¼°Ä³ÖÖƵÂʵĸ澯µÈµÈ£¬Èçͼ6-7Ëùʾ¡£\r\n6¡¢        ¿ÉÒÔͨ¹ýInternetµÄwhoisÊý¾Ý¿â²ì¿´IPµØÖ·µÄËùÓÐÕߣ¬Èç¹ûij¸öIPÕýÔÚ¹¥»÷Ä㣬Äã¿ÉÒÔÁªÏµ¸ºÔðÈËÒÔ²ÉÈ¡´ëÊ©¡£\r\nÄã¿ÉÒÔͨ¹ýURLÀ´·ÃÎÊACID£¬ÀýÈçhttp://www.conformix.com/acid/£¬ ... Ý¿âµÄÓû§ÃûºÍÃÜÂë¡£\r\n        ΪÁ˸üºÃµÄ±íÊö£¬ÎÒÃÇÏÖÔÚÀ´¿´¿´µ±Ä³¸öÈËÊÔͼÈëÇÖʱ£¬ÏµÍ³»á·¢ÉúһЩʲô£º\r\nÈëÇÖÕßÊÔͼ½øÈëÄãµÄÍøÂç\r\nSnort̽²âÆ÷¸ù¾Ý¹æÔò¼ì²âµ½ÈëÇÖÐÐΪ£¬¸ù¾Ýsnort.confµÄÉèÖ㬽«ÐÅÏ¢¼Ç¼µ½MySQLÊý¾Ý¿â¡£\r\nÓû§Æô¶¯ä¯ÀÀÆ÷£¬Á¬½Óµ½MySQLËùÔÚµÄweb·þÎñÆ÷£¬²¢ÇëÇóPHPÒ³Ãæ¡£\r\nPHPÒýÇæÁ¬½Óµ½Êý¾Ý¿â£¬²¢´ÓÊý¾Ý¿â·þÎñÆ÷»ñÈ¡ÐÅÏ¢¡£\r\nWeb·þÎñÆ÷´¦ÀíÐÅÏ¢£¬²¢Ïòä¯ÀÀÆ÷·¢ËÍÒ³Ã棬ÕâÑùÓû§¾Í¿ÉÒÔ¿´µ½ÈëÇÖÐÅÏ¢¡£\r\nÕâʱÓû§¿ÉÒÔͨ¹ýwebÒ³Ãæ¶ÔÊý¾Ý½øÐи÷ÖÖ²Ù×÷¡£\r\n\r\n±¾ÕµĺóÃæÐðÊöÕâЩ¹¤¾ßµÄ°²×°ºÍÅäÖá£

ÂÛ̳»ÕÕÂ:
1
³óÅ£
ÈÕÆÚ:2015-01-07 15:25:00
82Â¥ [±¨¸æ]
·¢±íÓÚ 2006-10-27 23:41 |Ö»¿´¸Ã×÷Õß
6£®2°²×°ºÍÅäÖÃ\r\nACIDÐèÒªPHPLOT£¬GD¿â²ÅÄÜÕý³£¹¤×÷¡£ÐҺã¬ÕâЩ×é¼þÊÇÏ໥¶ÀÁ¢µÄ£¬Äã¿ÉÒÔÔÚ°²×°µÄʱºò²»ÐèÒª¿¼ÂÇ°²×°Ë³Ðò¡£ÏÂÃæÊÇ°²×°²½Ö裺\r\n1¡¢        °²×°²¢²âÊÔSnort¡£\r\n2¡¢        °²×°²¢²âÊÔMySQL£¬½¨Á¢Ïà¹ØµÄÊý¾Ý¿âºÍ±í¡£\r\n3¡¢        °²×°Apache¡£\r\n4¡¢        ÔÚhttp://www.cert.org/kb/acidÏÂÔØA ... â¸öĿ¼ҲÐí»á²»Í¬¡£\r\n5¡¢        °²×°PHP£¬Äã¿ÉÒÔÔÚhttp://www.php.netÏÂÔØ»òÕßÓÃRedH ... ­×÷Ϊģ¿é°²×°ºÃÁË¡£\r\n6¡¢        ´Óhttp://www.boutell.com/gd/ÏÂÔز¢ ... /lib.libgd.soÎļþ¡£\r\n7¡¢        ´Óhttp://www.phplot.comÏÂÔØPHPLOT² ... webÒ³ÃæÖвúÉúͼÐΡ£\r\n8¡¢        ´Óhttp://php.weblogs.com/adodbÏÂÔØ ... faqÀ´»ñµÃ¸ü¶àÐÅÏ¢¡£

ÂÛ̳»ÕÕÂ:
1
³óÅ£
ÈÕÆÚ:2015-01-07 15:25:00
83Â¥ [±¨¸æ]
·¢±íÓÚ 2006-10-27 23:41 |Ö»¿´¸Ã×÷Õß
ÏÖÔÚÎÒÃÇÏêϸÐðÊö°²×°¹ý³Ì£¬ÎÒ¼Ù¶¨ÄãÒѾ­×÷ÁËÒÔϵÄÊÂÇ飺\r\nMySQLÊý¾Ý¿â·þÎñÆ÷Òѱ»°²×°¡£\r\nSnortÒѾ­°²×°Íê³É²¢ÅäÖúÃÓëÊý¾Ý¿âµÄ½Ó¿Ú¡£\r\nÒѾ­°²×°Íê³ÉApache£¬GD¿âºÍPHP¡£\r\n\r\nÏÖÔÚÎÒÃǾͿÉÒÔÏÂÔز¢°²×°ÏÂÃæµÄÈí¼þ\r\nÏÂÔØACIDÎļþ²¢·ÅÔÚ/optĿ¼Ï¡£\r\nÏÂÔØADODBÎļþ²¢·ÅÔÚ/optĿ¼Ï¡£\r\nÏÂÔØPHPLOTÎļþ²¢·ÅÔÚ/optĿ¼Ï¡£\r\nÇл»µ±Ç°Ä¿Â¼µ½/var/www/htmlĿ¼¡£\r\nÔËÐÐÃüÁî¡°tar zxvf /opt/acid-0.9.6b21.tar.gz.¡±£¬ÕâÑù»á´´½¨/var/www/html/acidĿ¼£¬²¢½«ACIDÎļþ´æ·ÅÖÁ´Ë¡£\r\nÇл»µ±Ç°Ä¿Â¼µ½/var/www/html/acid¡£\r\nÔËÐÐÃüÁî¡°tar zxvf /opt/adodb221.tgz¡±½«ADODBÎļþÊͷŵ½/var/www/html/acid/adodbĿ¼ÖС£\r\nÓÃÃüÁî¡°tar zxvf /opt/phplot-4.4.6.tar.gz¡±ÊÍ·ÅPHPLOTÎļþµ½Ä¿Â¼/var/www/html/acid/phplot-4.4.6ÖС£\r\nÔÚmysql¿Í»§¶ËÖÐÓÃÃüÁî¡°create database snort_archive;¡±´´½¨Ò»¸öеÄÊý¾Ý¿â£¬Õâ¸öÊý¾Ý¿â±»ACIDÓÃÀ´´æ·Å¾ÍµÃÊý¾Ý¡£Snort±¾Éí²¢²»ÐèÒªËüÀ´´æ·ÅÊý¾Ý¡£Èç¹ûÄã²»ÐèÒª±¸·Ý¾ÉµÄÊý¾Ý£¬¿ÉÒÔÌø¹ýÕâÒ»²½¡£\r\n°Ñ¸Õ²Å´´½¨µÄÊý¾Ý¿âµÄ¹ÜÀíȨÏÞ¸³ÓèÓû§£¬ÀýÈçrr£¬ÔÚ¿Í»§¶ËÓÃÃüÁ ¡°grant CREATE,INSERT,DELETE,UPDATE,SELECT on snort_archive.* to rr@localhost;¡±¡£\r\nÓÃÃüÁî¡°mysql -u rr ¨Cp snort_archive <contrib/create_mysql¡±ÎªÊý¾Ý¿â´´½¨ËùÓõ½µÄ±í¡£\r\n½«/etc/php.iniÖеÄdisplay_errors±äÁ¿µÄÖµÉèΪoff¡£

ÂÛ̳»ÕÕÂ:
1
³óÅ£
ÈÕÆÚ:2015-01-07 15:25:00
84Â¥ [±¨¸æ]
·¢±íÓÚ 2006-10-27 23:41 |Ö»¿´¸Ã×÷Õß
ÏÖÔÚÒªÅäÖÃACIDʹ֮Äܹ»ÓëMySQLÊý¾Ý¿â½»»¥£¬²¢Ê¹SnortÄܹ»Ê¹ÓÃPHPLOTÈí¼þ°ü¡£ÎÒÃÇÐèÒªÐÞ¸ÄÅäÖÃÎļþacid_conf.phpÖеÄһЩ²ÎÊý£¬Õâ¸öÎļþÔÚÄãÊÍ·ÅACIDÎļþµÄĿ¼£¬ÄãÐèÒª×öÒÔÏÂÉèÖãº\r\nADODBÎļþµÄλÖÃÔÚÕâÀïÊÇ./adodb£¬Äã¿ÉÒÔ¸ù¾Ý×Ô¼ºµÄÇé¿öÐ޸ġ£\r\nÊý¾Ý¿â·þÎñÆ÷µÄÀàÐÍ£¬ÔÚÕâÀïÊÇmysql¡£\r\nMySQL¼Ç¼SnortÊý¾ÝµÄÊý¾Ý¿âÃû¡£\r\nMySQLÊý¾Ý¿â·þÎñÆ÷Ãû³Æ»òÕßIPµØÖ·¡£\r\nMySQLÊý¾Ý¿âÓû§ÃûºÍ¿ÚÁî¡£\r\n±¸·ÝÊý¾Ý¿âµÄÃû³Æ£¬Èç¹ûÄ㱸·ÝÊý¾ÝµÄ»°¡£\r\n±¸·ÝÊý¾Ý¿âµÄ·þÎñÆ÷Ö÷»úÃû»òÕßIPµØÖ·£¬ÔÚÕâÀÊÇÓësnortÊý¾Ý¿âÏàͬµÄ£¬¶¼ÊÇlocalhost¡£\r\nPHPLOTÎļþµÄλÖã¬ÔÚÕâÀïÊÇ./phplot-4.4.6¡£\r\nÕâЩÐÅÏ¢ÔÚacid_conf.phpÎļþµÄ¿ªÊ¼²¿·Ö£¬ÏÂÃæÊÇÒ»¸öʵÀý£º\r\n<?php\r\n$ACID_VERSION = \"0.9.6b21\";\r\n/* Path to the DB abstraction library\r\n* (Note: DO NOT include a trailing backslash after the\r\n* directory)\r\n* e.g. $foo = \"/tmp\" [OK]\r\n* $foo = \"/tmp/\" [OK]\r\n* $foo = \"c:\\tmp\" [OK]\r\n* $foo = \"c:\\tmp\\\" [WRONG]\r\n*/\r\n$DBlib_path = \"./adodb\";\r\n/* The type of underlying alert database\r\n*\r\n* MySQL : \"mysql\"\r\n* PostgresSQL : \"postgres\"\r\n* MS SQL Server : \"mssql\"\r\n*/\r\n$DBtype = \"mysql\";\r\n/* Alert DB connection parameters\r\n* - $alert_dbname : MySQL database name of Snort\r\n: alert DB\r\n* - $alert_host : host on which the DB is stored\r\n* - $alert_port : port on which to access the DB\r\n* - $alert_user : login to the database with\r\n: this user\r\n* - $alert_password : password of the DB user

ÂÛ̳»ÕÕÂ:
1
³óÅ£
ÈÕÆÚ:2015-01-07 15:25:00
85Â¥ [±¨¸æ]
·¢±íÓÚ 2006-10-27 23:41 |Ö»¿´¸Ã×÷Õß
* This information can be gleaned from the Snort database\r\n* output plugin configuration.\r\n*/\r\n$alert_dbname = \"snort\";\r\n$alert_host = \"localhost\";\r\n$alert_port = \"\";\r\n$alert_user = \"rr\";\r\n$alert_password = \"rr78x\";\r\n/* Archive DB connection parameters */\r\n$archive_dbname = \"snort_archive\";\r\n$archive_host = \"localhost\";\r\n$archive_port = \"\";\r\n$archive_user = \"rr\";\r\n$archive_password = \"rr78x\";\r\n/* Type of DB connection to use\r\n* 1 : use a persistant connection (pconnect)\r\n* 2 : use a normal connection (connect)\r\n*/\r\n$db_connect_method = 1;\r\n/* Path to the graphing library\r\n* (Note: DO NOT include a trailing backslash after the\r\ndirectory)\r\n*/\r\n$ChartLib_path = \"./phplot-4.4.6\";\r\nÔÚÕâÀÎÒÃÇÉèÖõÄÓû§Ãû¡¢¿ÚÁîºÍÊý¾Ý¿âÃûºÍÔÚsnort.confÖÐÊÇÏàͬµÄ£¬ÏÂÃæÊǶÔÅäÖÃÎļþµÄ½âÊÍ£º\r\nÏÂÃæµÄÒ»ÐÐÓÃÀ´ÉèÖÃADODBÎļþµÄ·¾¶£º\r\n$DBlib_path = \"./adodb\";\r\nÏÂÃæµÄÒ»ÐÐÓÃÀ´ÉèÖÃÊý¾Ý¿âµÄÀàÐÍ£º\r\n$DBtype = \"mysql\";\r\nÏÂÃæµÄ¼¸ÐÐÓÃÀ´ÉèÖÃSnortµÄÖ÷Êý¾Ý¿âÐÅÏ¢£º\r\n$alert_dbname = \"snort\";\r\n$alert_host = \"localhost\";\r\n$alert_port = \"\";\r\n$alert_user = \"rr\";\r\n$alert_password = \"rr78x\";\r\nÏÂÃæµÄ¼¸ÐÐÓÃÀ´ÉèÖÃSnort±¸·ÝÊý¾Ý¿âÐÅÏ¢£º\r\n$alert_dbname = \"snort_archive\";\r\n$alert_host = \"localhost\";\r\n$alert_port = \"\";\r\n$alert_user = \"rr\";\r\n$alert_password = \"rr78x\";\r\nÏÂÃæµÄÒ»ÐÐÓÃÀ´ÕâÊÇPHPLOTÎļþµÄ·¾¶£º\r\n$ChartLib_path = \"./phplot-4.4.6\";\r\nÅäÖÃÍê³Éºó£¬Äã¾Í¿ÉÒÔÓÃweb½çÃæ·ÃÎÊACIDÁË¡£

ÂÛ̳»ÕÕÂ:
1
³óÅ£
ÈÕÆÚ:2015-01-07 15:25:00
86Â¥ [±¨¸æ]
·¢±íÓÚ 2006-10-27 23:42 |Ö»¿´¸Ã×÷Õß
6£®3ʹÓÃACID\r\nÍê³ÉÇ°ÃæµÄ¹¤×÷ºó£¬Äã¿ÉÒÔÓÃURLÀ´·ÃÎÊACIDÁË£º http://<ÄãµÄweb·þÎñÆ÷>/acid/¡£ÀýÈ磬ÎÒµÄweb·þÎñÆ÷µÄµØÖ·ÊÇ192.168.1.2,Òò´Ë£¬ÎÒ¾ÍÓÃhttp://192.168.1.2/acid/¡£\r\nµÚÒ»´Î·ÃÎʵÄʱºò£¬Ä㻹ÐèҪͨ¹ýweb½çÃæ×öһЩÉèÖã¬Èçͼ6-1Ëùʾ¡£\r\nÔÚÕâ¸ö´°¿Ú£¬µã»÷SetupÒ³ÃæÁ¬½Ó£¬Ò³Ãæ¾Í»áתµ½DBÉèÖÃÒ³Ã棬Èçͼ6-2Ëùʾ¡£\r\nÔÚÕâ¸öÒ³Ã棬µã»÷¡°Create ACID AG¡±Á¬½Ó£¬ACID¾Í»áÔÚsnortÊý¾Ý¿âÖд´½¨Ò»Ð©×Ô¼ºËùÐèÒªµÄ±í£¬ÒÔÖ§³ÖSnort¡£Í¼6-3ÏÔʾÁË´´½¨Ð±íµÄ½á¹û¡£\r\n        ÔÚͼ6-3ËùʾµÄÒ³Ã棬Äã¿ÉÒÔµã»÷¡°Main Page¡±µ½Ö÷Ò³Ãæ¡£\r\n6-1£¬6-2£¬6-3Ò³ÃæÔÚÄãÏÂÒ»´ÎʹÓÃACIDµÄʱºò¾Í²»»á³öÏÖÁË¡£

ÂÛ̳»ÕÕÂ:
1
³óÅ£
ÈÕÆÚ:2015-01-07 15:25:00
87Â¥ [±¨¸æ]
·¢±íÓÚ 2006-10-27 23:42 |Ö»¿´¸Ã×÷Õß
6.3.1ACIDÖ÷Ò³Ãæ\r\nACIDÖ÷Ò³ÃæÏÔʾµ±Ç°Êý¾ÝµÄ¸ÅÒª¡£ËüÓò»Í¬µÄ²¿·Ö·Ö×éÏÔʾÐÅÏ¢¡£Äã¿ÉÒÔ¿´µ½¸÷¸öЭÒéµÄÁ÷Á¿¸Å¿ö£¬È¡µÃij¸öSnort¸ÐÓ¦Æ÷µÄ¿ìÕÕÐÅÏ¢£¬ËÑË÷Êý¾ÝµÈµÈ£¬Èçͼ6-4Ëùʾ¡£\r\n\r\nµã»÷ͼ6-4ÉÏÃæµÄÁ¬½Ó£¬Äã¿ÉÒÔ¿´µ½´óÁ¿µÄÐÅÏ¢¡£\r\n\r\nÏòÊý¾Ý¿â¼Ç¼Êý¾ÝµÄ̽²âÆ÷ÁÐ±í¡£\r\n¸æ¾¯µÄÊýÁ¿¼°ÏêϸÐÅÏ¢¡£\r\nËù²¶»ñµÄ°üµÄÔ´µØÖ·£¬Äã¿ÉÒÔ´ÓÖв쿴˭ÔÚÊÔͼ¹¥»÷ÄãµÄÍøÂç¡£ÄãÒ²¿ÉÒÔͨ¹ýÏà¹ØÁ¬½ÓÀ´²ì¿´whoisÊý¾Ý¿â¡£\r\nËù²¶»ñµÄ°üµÄÄ¿µÄµØÖ·¡£\r\nÔ´ºÍÄ¿µÄ¶Ë¿Ú¡£\r\nÓëÌض¨Ð­ÒéÏà¹ØµÄ¸æ¾¯£¬ÈçTCP¡¢UDP¡¢ICMP¸æ¾¯¡£\r\n²éÕÒÌض¨ÀàÐ͵ĸ澯ºÍÈÕÖ¾ÌõÄ¿¡£\r\nƵÂÊ×î¸ßµÄ¸æ¾¯¡£\r\n¸æ¾¯Êý¾ÝµÄͼ±í£¬Ä¿Ç°Õâ¸ö¹¦ÄÜ»¹ÔÚʵÑéÖС£\r\n\r\nÔÚÏÂÃæµÄÆÁÄ»½ØͼÖÐÄã¿ÉÒÔÁ˽âһЩÖØÒªµÄÐÅÏ¢£¬µ«Í¨¹ýʵ¼ùÄã¿ÉÒÔÁ˽⣬ACIDÄܹ»Ìṩ¸øÄã¸ü¶àµÄÓÐÓÃÐÅÏ¢¡£\r\n6.3.1ЭÒéÏà¹ØÊý¾ÝÁбí\r\nÔÚÖ÷Ò³Ã棬Äã¿ÉÒÔµã»÷Ò»¸öЭÒéÀ´È¡µÃËù¼Ç¼µÄ¹ØÓÚÕâ¸öЭÒéµÄ°üµÄÐÅÏ¢¡£Í¼6-5ÏÔʾµÄÊǹØÓÚICMPЭÒéÐÅÏ¢µÄÆÁÄ»½Øͼ¡£ÔÚÆÁÄ»µÄÏÂÃ棬Äã¿ÉÒÔ¿´µ½15¸ö°üµÄÐÅÏ¢±»¼Ç¼µ½Êý¾Ý¿â¡£Äã¿ÉÒÔµã»÷ÆäÖÐÈÎÒâÒ»¸öÀ´»ñµÃ¹ØÓÚÕâ¸ö°üµÄÏêϸÐÅÏ¢¡£\r\n6.3.3¸æ¾¯ÐÅϢϸ½Ú\r\nͼ6-6ÏÔʾÁËij¸öÄãÔÚͼ6-5¿´µ½µÄICMP°üµÄϸ½Ú£¬ÆäÖаüº¬ºÜ¶à²¿·Ö£¬Ã¿²¿·ÖÏÔʾÁËÊý¾Ý°üµÄÒ»¸ö²ãÃ棬×îÉÏÃæµÄ²¿·ÖÊǹØÓÚÕâ¸ö¸æ¾¯µÄ×ÜÌåÐÅÏ¢¡£IP²¿·ÖÏÔʾÁËIPÍ·²¿µÄËùÓв¿·Ö£¬ICMPÍ·²¿ÏÔʾÁËICMPÊý¾Ý£¬½Ó×ÅÊÇÔغɡ£ÔغÉͬʱÒÔ16½øÖƺÍASCIIÂëÐÎʽ±íʾ¡£\r\n6.3.4 ²éѯ\r\nACIDµÄÒ»¸öÖØÒªÌØÐÔÊÇ¿ÉÒÔÓÃһЩ²ÎÊýÀ´²éѯÈÕÖ¾ºÍ¸æ¾¯£¬ÀýÈ磺\r\nij¸ö̽²âÆ÷\r\n¿ªÊ¼ºÍ½áÊøµÄʱ¼ä\r\nÔ´ºÍÄ¿µÄµØÖ·\r\nIPÍ·²¿µÄ²»Í¬×Ö¶Î\r\n´«Êä²ãЭÒé\r\nIP°üÔغÉÖеÄ×Ö·û\r\n\r\nÈçͼ6-7,Ö´ÐвéѯÊǷdz£¼òµ¥µÄ£¬ÄãÖ»Òªµã»÷¡°Query DB¡±¾Í¿ÉÒÔÏÔʾËù²éѯµÄÊý¾Ý¡£\r\nÀýÈ磬Èç¹ûÄãÏëÔÚËùÓеĸ澯ÐÅÏ¢Öвéѯ°üº¬×Ö·û¡°ATTACK RESPONSE¡±µÄ°ü£¬Äã¿ÉÒÔÏñͼ6-8ÄÇÑùÌî³äÐÅÏ¢¡£\r\n²éѯ½á¹ûÈç6-9Ëùʾ¡£

ÂÛ̳»ÕÕÂ:
1
³óÅ£
ÈÕÆÚ:2015-01-07 15:25:00
88Â¥ [±¨¸æ]
·¢±íÓÚ 2006-10-27 23:42 |Ö»¿´¸Ã×÷Õß
6.3.²éѯwhoisÊý¾Ý¿â\r\nÄã¿ÉÒÔµã»÷ÈκÎÒ»¸öIPµØÖ·²¢Ñ¡Ôñij¸öwhoisÊý¾Ý¿âÀ´²éѯwhoisÐÅÏ¢£¬ÀýÈçÄã¿ÉÒÔͨ¹ýλÓÚhttp://www.arin.netµÄARIN£¬ÀýÈçÍ ... 6.16.52µÄ²éѯ½á¹û¡£\r\nÔÚ´¦ÀíÍøÂ簲ȫÎÊÌâµÄʱºò£¬ÕâÖÖÐÅÏ¢ÊǷdz£ÓÐÓõģ¬ÍùÍùÔÚ·¢ÉúÏà¹ØÎÊÌâµÄµÚÒ»²½£¬ÄãÒª²éѯÈëÇÖÕßÊÇË­£¬ÕâÖÖÐÅÏ¢»á¸øÄãһЩÓÐÓõİïÖú¡£\r\n6.3.6²úÉúͼ±í\r\nACIDµÄ»æͼ¹¦ÄÜÈÔÈ»ÔÚʵÑéÖУ¬ACIDÌṩһ¸öÁ¬½ÓÓÃÀ´²úÉúͼ±í£¬ÄãÐèҪѡÔñÊý¾ÝºÍͼ±íÀàÐÍ¡£ÀýÈ磬Äã¿ÉÒÔ²úÉú×î½ü5ÌìµÄ¸æ¾¯µÄÏßͼ»òÕßÖ±·½Í¼£¬Í¼6-12ÊÇÒ»¸öʵÀý¡£\r\nPHPLOT±»ÓÃÀ´ÔÚºǫ́²úÉúͼ±í£¬ÄãÒ²¿ÉÒÔÓÃÆäËûÈçJPRAPHÀ´´úÌæËü¡£\r\n6.3.7SnortÊý¾Ý¿â´æµµ\r\nÊý¾Ý¿âsnort_archiveÓÃÀ´´ÓÖ÷Êý¾Ý¿â´æµµÊý¾Ý£¬ÀûÓÃACID£¬Äã¿ÉÒÔ½«¸æ¾¯´ÓÖ÷Êý¾Ý¿â¸´ÖÆ»òÕßÒƶ¯µ½´æµµÊý¾Ý¿â¡£\r\nÄã¿ÉÒÔÑ¡Ôñ½«Õû¸ö¹ØÓÚÊý¾Ý¿âµÄ²éѯ´æµµ»òÕߴ浵ijЩ²éѯ¡£\r\n6.3.8ACIDµÄ±í\r\nµ±ÄãµÚÒ»´ÎÔËÐÐACIDµÄʱºò£¬ËüÔÚSnortÊý¾Ý¿âÖд´½¨ÁËһЩ×Ô¼ºµÄ±í£¬ÕâЩ±íÓÃ×÷ACIDµÄ¹ÜÀí¹¦ÄÜ¡£\r\nÏÂÃæÊÇÔËÐÐACIDÇ°ºóMySQLµÄsnortÊý¾Ý¿âÖбíµÄ¶Ô±È£º\r\n֮ǰ£º\r\nmysql> show tables;\r\n+------------------+\r\n| Tables_in_snort |\r\n+------------------+\r\n| data |\r\n| detail |\r\n| encoding |\r\n| event |\r\n| flags |\r\n| icmphdr |\r\n| iphdr |\r\n| opt |\r\n| protocols |\r\n| reference |\r\n| reference_system |\r\n| schema |\r\n| sensor |\r\n| services |\r\n| sig_class |\r\n| sig_reference |\r\n| signature |\r\n| tcphdr |\r\n| udphdr |\r\n+------------------+

ÂÛ̳»ÕÕÂ:
1
³óÅ£
ÈÕÆÚ:2015-01-07 15:25:00
89Â¥ [±¨¸æ]
·¢±íÓÚ 2006-10-27 23:42 |Ö»¿´¸Ã×÷Õß
19 rows in set (0.01 sec)\r\nmysql>\r\n\r\nÖ®ºó£º\r\nmysql> show tables;\r\n+------------------+\r\n| Tables_in_snort |\r\n+------------------+\r\n| acid_ag |\r\n| acid_ag_alert |\r\n| acid_event |\r\n| acid_ip_cache |\r\n| data |\r\n| detail |\r\n| encoding |\r\n| event |\r\n| flags |\r\n| icmphdr |\r\n| iphdr |\r\n| opt |\r\n| protocols |\r\n| reference |\r\n| reference_system |\r\n| schema |\r\n| sensor |\r\n| services |\r\n| sig_class |\r\n| sig_reference |\r\n| signature |\r\n| tcphdr |\r\n| udphdr |\r\n+------------------+\r\n23 rows in set (0.00 sec)\r\nmysql>\r\nÇ°Ãæ4¸ö±íÊÇACIDн¨Á¢µÄ¡£

ÂÛ̳»ÕÕÂ:
1
³óÅ£
ÈÕÆÚ:2015-01-07 15:25:00
90Â¥ [±¨¸æ]
·¢±íÓÚ 2006-10-27 23:42 |Ö»¿´¸Ã×÷Õß
6.4SnortSnarf\r\nSnortSnarfÊÇÁíÍâÒ»¸öÓÃweb½çÃæÀ´ÏÔʾSnortÊý¾ÝµÄ¹¤¾ß¡£Äã¿ÉÒÔÔÚhttp://www.silicondefense.com/so ... ¹ýwebä¯ÀÀÆ÷À´²ì¿´¡£\r\nsnortsnarf.pl /var/log/snort/alert -d /var/www/html/snortsnarf\r\nÏÂÃæµÄÃüÁî´ÓlocalhostÉϵÄMySQLÊý¾Ý¿âÌáÈ¡Êý¾Ý£¬ËüÓõ½ÁËÇ°ÃæÎÒÃÇÉèÖõÄÓû§ÃûºÍ¿ÚÁî¡£\r\nsnortsnarf.pl rr:rr78x@snort@localhost -d /var/www/html/snortsnarf\r\nÄã¿ÉÒÔÓÃcronÀ´Ê¹SnortSnarf¶¨ÆÚÔËÐУ¬Í¼6-15ÏÔʾÁËSnortSnarf²úÉúµÄÖ÷Ò³Ã棬ËüÌṩÁ˸澯ÐÅÏ¢µÄ»ù±¾Çé¿ö¡£\r\nͼ6-16ÊǹØÓÚij¸ö¸æ¾¯µÄÐÅÏ¢£¬Äã¿ÉÒÔµã»÷6-15ËùʾµÄ¸æ¾¯ÌõÄ¿À´µÃµ½ÕâÑùµÄÐÅÏ¢¡£\r\nͼ6-17ÊÇwhois²éѯµÄÆÁÄ»½Øͼ¡£
ÄúÐèÒªµÇ¼ºó²Å¿ÉÒÔ»ØÌû µÇ¼ | ×¢²á

±¾°æ»ý·Ö¹æÔò ·¢±í»Ø¸´

  

±±¾©Ê¢ÍØÓÅѶÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾. °æȨËùÓÐ ¾©ICP±¸16024965ºÅ-6 ±±¾©Êй«°²¾Öº£µí·Ö¾ÖÍø¼àÖÐÐı¸°¸±àºÅ£º11010802020122 niuxiaotong@pcpop.com 17352615567
δ³ÉÄê¾Ù±¨×¨Çø
Öйú»¥ÁªÍøЭ»á»áÔ±  ÁªÏµÎÒÃÇ£ºhuangweiwei@itpub.net
¸ÐлËùÓйØÐĺÍÖ§³Ö¹ýChinaUnixµÄÅóÓÑÃÇ ×ªÔر¾Õ¾ÄÚÈÝÇë×¢Ã÷Ô­×÷ÕßÃû¼°³ö´¦

Çå³ý Cookies - ChinaUnix - Archiver - WAP - TOP