ÔÚwindows server 2003´î½¨snortÈëÇÖ¼ì²âϵͳ²½Öè
2008-03-11 11:37:01
°æÈ¨ÉùÃ÷£ºÔ´´×÷Æ·£¬ÔÊÐí×ªÔØ£¬×ªÔØÊ±ÇëÎñ±ØÒÔ³¬Á´½ÓÐÎʽ±êÃ÷ÎÄÕ Ôʼ³ö´¦ ¡¢×÷ÕßÐÅÏ¢ºÍ±¾ÉùÃ÷¡£·ñÔò½«×·¾¿·¨ÂÉÔðÈΡ£http://chuan.blog.51cto.com/130796/65178 |
Ò»¡¢²¿ÊðIDSÈëÇÖ¼ì²âϵͳËùÐèÈí¼þ: 1¡¢apache
2¡¢acid
3¡¢adodb
4¡¢jpgraph
5¡¢mysql
6¡¢php
7¡¢snort
8¡¢winpcap
9¡¢snortrules
¶þ¡¢°²×°²½Ö裺
¼Æ»®°ÑËùÓеÄÈí¼þ°ü°²×°µ½ c:\ids Îļþ¼Ð
1¡¢ °²×° apache
Ö¸¶¨°²×°Ä¿Â¼ c:\ids\apache
2¡¢°²×° php
½âѹËõ php µ½ c:\ids\php5 Îļþ¼Ð
¸´ÖÆ php5ts.dll Îļþµ½ c:\windows\system32 Îļþ¼Ð
¸´ÖÆ php.ini-dist µ½ c:\windows ϲ¢ÖØÃüÃûΪ php.ini
ÐÞ¸Ä c:\ids\apache\conf\httpd.conf Îļþ , ¼ÓÈë apache ¶Ô php µÄÖ§³Ö ÈçÏÂͼ£º
ͼ1
![]() ÉÏͼΪ¾É°æ±¾µÄд·¨
¼ÓÈ룺loadmodule php5_module c:\ids\php\php5apache2.dll£¬
а汾µÄд·¨£ºloadmodule php5_module c:/ids/php5/php5apache2_2.dll¡£
ͼ2
![]() ¼ÓÈ룺addtype application/x-httpd-php .php
3¡¢ ÐÞ¸Ä c:\widows\php.ini Îļþ , µô extension=php_gd2.dll ǰµÄ·ÖºÅ
¸´ÖÆ c:\ids\php5\ext Îļþ¼ÐÏ php_gd2.dll Îļþµ½ c:\windows Îļþ¼ÐÏÂ
4¡¢ ÖØÐÂÆô¶¯ apache
5¡¢ ÔÚ c:\ids\apache\htdocs Îļþ¼Ðϱàд test.php ÎļþÄÚÈÝΪ <?php phpinfo(); ?>
6¡¢ ´ò¿ªä¯ÀÀÆ÷ÊäÈë http://lcoalhsot/test.php. Èç¹ûä¯ÀÀµ½ÁË php µÄÐÅÏ¢Ôò˵Ã÷Ò»ÇÐÕý³££¬ £¨ ×¢Ò⣺Èç¹û test.php Îļþ³öÏÖÏÂÔØÌáʾ£¬ÔÒòÊÇ addtype µÄÄǾ仰ÓдíÎ󣬼ì²éÐ޸ľͿÉÒÔÁË £©ÈçÏÂͼ£º
![]() ÉÏͼΪ֮ǰ½ÚµÄ¾É°æ±¾Í¼£¬ÍµÀÁһϣ¬×îа汾µÄÓ¦¸ÃÊÇ PHP Version 5.2.5¡£
7¡¢ °²×° winpcap
²ÉȡĬÈÏÖµ¼´¿É
8¡¢ °²×° snort ²¢Ö¸¶¨Â·¾¶Îª c:\ids\snort Îļþ¼Ð
9¡¢ ²âÊÔ snort °²×°ÊÇ·ñÕýÈ·
C:\ids\snort\snort\bin\snort.exe ¨CW£¬Èç¹û°²×° snort³É¹¦»á³öÏÖÒ»¸ö¿É°®µÄСÖí£¬ ÈçÏÂͼ£º
![]() 10¡¢°²×° mysql
Ö¸¶¨Â·¾¶Îª c:\ids\mysql
11¡¢´´½¨ snort Êý¾Ý¿âµÄ±í
¸´ÖÆ c:\ids\snort\schames Îļþ¼ÐÏ嵀 create_mysql Îļþµ½ c:\ids\mysql\bin Îļþ¼ÐÏÂ
´ò¿ª mysql µÄµÄ¿Í»§¶ËÖ´ÐÐÈçÏÂÃüÁî
Create database snort;
Create database snort_archive;
Use snort;
Source create_mysql;
Use snort_archive;
Source create_mysql;
Grant all on *.* to ¡°root¡±@¡±localhost¡±
12¡¢ ¼ÓÈë php ¶Ô mysql µÄÖ§³Ö£º
ÐÞ¸Ä c:\windows\php.ini ÎļþÈ¥µô extension=php_mysql.dll ǰµÄ·ÖºÅ¡£
¸´ÖÆc:\ids\php5\ext Îļþ¼ÐÏ嵀 php_mysql.dll Îļþµ½ c:\windows Îļþ¼Ð¡£
¸´ÖÆc:\ids\php5\libmysql.dllÎļþµ½c:\windows\system32Ï¡£
13¡¢°²×° adodb
½âѹËõ adodb µ½ c:\ids\php5\adodb Îļþ¼ÐÏ¡£
14¡¢ °²×° jgraph
½âѹËõ jpgraph µ½ c:\ids\php5\jpgraph Îļþ¼ÐÏ¡£
15¡¢°²×° acid
½âѹËõ acid µ½ c\ids\apache\htdocs\acid Îļþ¼ÐÏÂ
ÐÞ¸Ä acid_conf.php Îļþ
ΪÒÔÏÂÄÚÈÝ
$DBlib_path = "c:\ids\php5\adodb";
$DBtype = "mysql";
$alert_dbname = "snort";
$alert_host = "localhost";
$alert_port = "3306";
$alert_user = "root";
$alert_password = "810930";
$archive_dbname = "snort_archive";
$archive_host = "localhost";
$archive_port = "3306";
$archive_user = "root";
$archive_password = "810930";
$ChartLib_path = "c:\ids\php5\jpgraph\src";
16¡¢ÖØÆôapache¡¢mysql·þÎñ¡£
17¡¢ ÔÚä¯ÀÀÆ÷Öгõʼ»¯ acid Êý¾Ý¿â£º
Èç¹ûÅäÖÃÒÔÉÏ11~18²½ÕýÈ·£¬»á³öÏÖÈçÏÂͼ£º
![]() 18¡¢ ½âѹËõ snort ¹æÔò°ü
°ÑѹËõ°üÄÚµÄËùÓÐÎļþ½âѹËõµ½ c:\ids\snort\ ÏÂ
19¡¢ Æô¶¯ snort ÈëÇÖ¼ì²â
C:\ids\snort\bin\snort.exe ¨Cc ¡°c:\ids\snort\etc\snort.conf¡± ¨Cl ¡°c:\ids\snort\log¡± ¨Cd -e ¨CX
Èç¹ûÄãÏ£Íû¿´µ½ snort ץȡµÄÊý¾Ý°üÔò¿ÉÒÔÔÚ -X Ö®ºó¼ÓÈë²ÎÊý -v
20¡¢Èç¹û³öÏÖÒÔÏ´íÎó £º
ERROR: Unable to open rules file: ../rules/local.rules or c:\ids\snort\etc\../rules/local.rules
Fatal Error, Quitting..
´¦Àí·½·¨ £º ¹æÔò°ü»¹Ã»Óа²×°
21¡¢ÔÙ´ÎÔËÐÐ20ÏîÃüÁ³öÏÖÈçÏ´íÎó£º
Loading dynamic engine /usr/local/lib/snort_dynamicengine/libsf_engine.so... ERROR: Failed to load /usr/local/lib/snort_dynamicengine/libsf_engine.so: 126
Fatal Error, Quitting..
´¦Àí·½·¨ : ÔÚ snort µÄÅäÖÃÎļþÖÐÖ¸¶¨ libsf_engine. µÄ·¾¶ºÍÎļþÃû
Loading dynamic preprocessor library /usr/local/lib/snort_dynamicpreprocessor/libsf_dcerpc_preproc.so... ERROR: Failed to load /usr/local/lib/snort_dynamicpreprocessor/libsf_dcerpc_preproc.so: 126
´¦Àí·½·¨ : ÔÚ snort µÄÅäÖÃÎļþÖÐÖ¸¶¨ libsf_dcerpc_prepro µÄ·¾¶ºÍÎļþÃû
ÐÞ¸ÄÄÚÈÝÈçÏÂ:
dynamicpreprocessor file C:\ids\Snort\lib\snort_dynamicpreprocessor\sf_dcerpc.dll
dynamicpreprocessor file C:\ids\Snort\lib\snort_dynamicpreprocessor\sf_dns.dll
dynamicpreprocessor file C:\ids\Snort\lib\snort_dynamicpreprocessor\sf_ftptelnet.dll
dynamicpreprocessor file C:\ids\Snort\lib\snort_dynamicpreprocessor\sf_smtp.dll
dynamicpreprocessor file C:\ids\Snort\lib\snort_dynamicpreprocessor\sf_ssh.dll
dynamicengine C:/ids/Snort/lib/snort_dynamicengine/sf_engine.dll
output database: alert, mysql, user=root password=810930 dbname=snort host=localhost encoding=hex detail=full
include c:\ids\snort\etc\classification.config
include c:\ids\snort\etc\reference.config
ͼ1
![]() ͼ2
![]() ͼ3
![]() ÐÞ¸ÄÒÔÉÏ´íÎóºóÔÙ´ÎÔËÐÐC:\ids\snort\bin\snort.exe ¨Cc ¡°c:\ids\snort\etc\snort.conf¡± ¨Cl ¡°c:\ids\snort\log¡± ¨Cd -e ¨CX -v -i 2
2ÎªÍø¿¨µÄ±àºÅ¡£
´Ëʱ»á³öÏÖ£ºNot Using PCAP_FRAMES
¹Ø±ÕsnortÔËÐгÌÐò£¬ÊäÈ룺Set PCAP_FRAMES=MAX £¬snort -W±£´æÅäÖá£
ÔÙ´ÎÔËÐУºC:\ids\snort\bin\snort.exe ¨Cc ¡°c:\ids\snort\etc\snort.conf¡± ¨Cl ¡°c:\ids\snort\log¡± ¨Cd -e ¨CX -v i 2
´Ëʱ»á³öÏÖ£ºusing PCAP_FRAMES 23¡¢²é¿´Í³¼ÆÊý¾Ý
±¾Îijö×Ô ¡°Ð¡ÕÅ¡± ²©¿Í£¬ÇëÎñ±Ø±£Áô´Ë³ö´¦http://chuan.blog.51cto.com/130796/65178 ±¾Îijö×Ô 51CTO.COM¼¼Êõ²©¿Í |











zhangmingchuan
²©¿Íͳ¼ÆÐÅÏ¢
ÈÈÃÅÎÄÕÂ
×îÐÂÆÀÂÛ
ÓÑÇéÁ´½Ó