亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频

? 歡迎來到蟲蟲下載站! | ?? 資源下載 ?? 資源專輯 ?? 關于我們
? 蟲蟲下載站

?? faq

?? 入侵檢測系統.linux下與MySql連用的例子
??
?? 第 1 頁 / 共 5 頁
字號:
SNORT FAQ Version 1.8.1 - 13 August 2001Suggestions for enhancements of this document arealways welcome please email them to Dragos Ruiu at dr@kyx.netThe following people have contributed to this faq:Marty RoeschFyodor YarochkinDragos RuiuJed PickelMax VisionMichael DavisJoe McAlerneyJoe StewartErek AdamsRoman DanyliwChristopher CramerFrank KnobbePhil Wood   Toby KohlenbergRamin AlidoustiJim HankinsDennis HollingworthPaul Howell Erek AdamsStef Mit    Ofir ArkinJason HaarBlake FrantzLars Norman S鴑dergaardBrent Erickson-----------------------------------------------------------------------------Frequently Asked Questions about "snort"Section 1: Snort Background--------------------------1.1 Q: How do you pronounce the names of some of these guys who work on snort?1.2 Q: Is Fyodor Yarochkin the same Fyodor who wrote nmap?1.3 Q: Where do I get more help on snort?1.4 Q: Where can I get more reading and courses about IDS?1.5 Q: Does Snort handle IP defragmentation?1.6 Q: Does Snort perform TCP stream reassembly? 1.7 Q: Does Snort do stateful protocol analysis?1.8 Q: I'm on a switched network, can I still use Snort?1.9 Q: I've heard IDSes are vulnerable to noise generators like "Stick" and        "Snot", is snort vulnerable ?1.10 Q: I've heard it is possible to use polymorphic mutators on shellcode?1.11 Q: Does Snort log the full packets that it generates alerts on? Section 2: Getting Started--------------------------2.1 Q: How do I run snort?2.2 Q: Where are my log files located?  What are they named?2.3 Q: Where's a good place to physically put a Snort sensor?2.4 Q: Libpcap complains about permissions problems, what's going on?2.5 Q: Why does snort complain about /var/log/snort?2.6 Q: I've got RedHat and ....2.7 Q: Where do I get the latest version of libpcap?2.8 Q: Why does building snort complain about missing references?2.9 Q: Why does building snort fail with errors about yylex and lex_init?2.10 Q: I Want to build a snort box.  Will this <Insert List> handle         <this much> traffic?2.11 Q: What are CIDR netmasks?2.12 Q: What is the use of the "-r" switch to read tcpdump files? Section 3: Configuring Snort----------------------------3.1 Q: How do I setup snort on a 'stealth' interface?3.2 Q: How do I run snort on an interface with no IP address?3.3 Q: My network spans multiple subnets.  How do I define HOME_NET?3.4 Q: How can I run snort on multiple interfaces simultaneously?3.5 Q: IP address is assigned dynamically to my interface, can I use snort        with it?3.6 Q: I have one network card and two aliases, how can I force snort to        "listen" on both addresses ? 3.7 Q: How do I ignore traffic coming from a particular host or hosts?3.8 Q: How do I get Snort to log the packet payload as well as the header? 3.9 Q: Why are there no subdirectories under /var/log/snort for IP addresses?3.10 Q: How do you get snort to ignore some traffic?3.11 Q: Why does the portscan plugin log "stealth" packets even though the         host is in the portscan-ignorehosts list?3.12 Q: Which takes precedence, commandline or rule file ?3.13 Q: How does rule ordering work?3.14 Q: How do I configure stream4?3.15 Q: Where does one obtain new/modifed rules? How do you merge them in?3.16 Q: How do you get the latest snort via cvs?Section 4: Snort Rules and Alerts---------------------------------4.1 Q: When I start snort I get errors from my rules files4.2 Q: Snort says "Rule IP addr ("1.1.1.1") didn't x-late, WTF?"4.3 Q: Snort is behind a firewall (ipf/pf/ipchains/ipfilter) and awfully        quiet...4.4 Q: I'm getting large amounts of some alerts type. What should I do?  Where       can I go to find out more about it?4.5 Q: What about all these false alarms?4.6 Q: What are all these ICMP files in subdirectories under /var/log/snort?4.7 Q: Why does the program generate alerts on packets that have pass rules? 4.8 Q: What are all these "ICMP destination unreachable" alerts?4.9 Q: Why do many snort rules have the flags P (TCP PuSH) and A (TCP ACK) set?4.10 Q: What are these IDS codes in the alert names?4.11 Q: Snort says BACKDOOR SIGNATURE... does my machine have a Trojan?4.12 Q: What about "CGI Null Byte attacks"?4.13 Q: Why do certain alerts seem to have 'unknown' IPs in ACID?4.14 Q: Can priorities be assigned to Alerts using ACID? 4.15 Q: What about 'SMB Name Wildcard' alerts?4.16 Q: What the heck is a SYNFIN scan?4.17 Q: I am getting too many "IIS Unicode attack detected" and/or "CGI Null         Byte attack detected" false positives.  How can I turn this detection         off?4.18 Q: How do I test snort alerts and logging?Section 5: Getting Fancy------------------------5.1 Q: How do I process those snort logs into HTML reports?5.2 Q: How do I log to multiple databases?5.3 Q: How can I test snort without having an ethnernet card or a connection        to other computers? 5.4 Q: How to start snort as a win32 service?5.5 Q: Is it possible with snort to add a ipfilter/ipfw rule to a firewall?5.6 Q: Snort complains about the "react" keyword...5.7 Q: How do I get snort to e-mail me alerts?5.8 Q: How do I log a specific type of traffic and send alerts to syslog?5.9 Q: Is it possible to have snort call an external program when an alert        is raised?   Section 6: Problems-------------------6.1 Q: I think I found a bug in snort. Now what?6.2 Q: SMB alerts aren't working, what's wrong? 6.3 Q: Snort says "Garbage Packet with Null Pointer discarded!". Huh?6.4 Q: Snort says "Ran Out Of Space". Huh?6.5 Q: I'm having problems getting snort to log to a database...6.6 Q: My ACID db connection times-out when performing long operations (e.g.   deleting a large number of alerts) 6.7 Q: Why does snort report "Packet loss statistics are unavailable under        Linux"?6.8 Q: My /var/log/snort directory get very large.....6.9 Q: Why does the 'error deleting alert' message occur when attempting to        delete an alert with ACIO? 6.10 Q: ACID appears to be broken in Lynx 6.11 Q: I am getting 'snort [pid] uses obsolete (PF_INET, SOCK_PACKET)'         warnings, what's wrong.6.12 Q: on HPUX I get device lan0 open: recv_ack: promisc_phys: Invalid         argument6.13 Q: I am getting snort dying with 'can not create file' error and I have         plenty of diskspace, what's wrong?6.14 Q: I am using Snort on Windows and receive an OpenPcap() error upon         startup:6.15 Q: Snort is not logging to my database6.16 Q: Portscans are not being logged to my database6.17 Q: Snort is not logging to syslog6.18 Q: I am still getting bombarded with spp_portscan messages even though         the IP that I am getting the portscan from is in my $DNS_SERVERs var6.19 Q: Why chrooted snort die when I send it a SIGHUP? 6.20 Q: My snort crashes, how do I restart it? 6.21 Q: Why can't snort see one of either the 10Mbps or 100Mbps traffic on my         autoswitch hub--faq-- --snort-- --faq-- --snort-- --faq-- --snort-- --faq--***************************************Section 1: SNORT BACKGROUND***************************************1.1 --faq-- --snort-- --faq-- --snort-- --faq-- --snort-- --faq--Q: How do you pronounce the names of some of these guys who work on snort?A: For the record, 'Roesch' is pronounced like 'fresh' without the 'f'.   Additionally, 'Ruiu' is pronounced like 'screw you' without the 'sc'.  And   Jed's last name is like "pick-el", not "pickle". :)1.2 --faq-- --snort-- --faq-- --snort-- --faq-- --snort-- --faq--Q: Is Fyodor Yarochkin the same Fyodor who wrote nmap?A: Nope. fyodor@insecure.org is the author of nmap, and he uses the   same pseudonym as other snort Fyodor's real surname. Yeah, messes up   my mailbox too, but I think it's too late to change either of them :-).1.3 --faq-- --snort-- --faq-- --snort-- --faq-- --snort-- --faq--Q: Where do I get more help on snort?A: http://lists.sourceforge.net/mailman/listinfo/snort-users   Also look in the USAGE file in the distribution.1.4 --faq-- --snort-- --faq-- --snort-- --faq-- --snort-- --faq--Q:  Where can I get more reading and courses about IDS?A:  Sans has some courses:     http://www.sans.org        So does Usenix:     http://www.usenix.org/event/sec01/tutorials/tut.html#t1        And Networld/Interop:     http://www.key3media.com/interop/atlanta2001/conf/info/WorkshopW955_285.html    There are also some books you might want to look into getting.	Network Intrusion Detection An Analyst's Handbook	By Stephen Northcutt	ISBN 0735708681	TCP/IP Illustrated, Volume 1 The Protocols	By W. Richard Stevens	ISBN 0201633469    Intrusion Detection    By Rebecca G. Bace    ISBN 1578701856  1.5 --faq-- --snort-- --faq-- --snort-- --faq-- --snort-- --faq--Q: Does Snort handle IP defragmentation?A: Yes, use "preprocessor frag2"  or "preprocessor defrag" or "preprocessor    defrag2"   Each has slightly different capabilities.1.6 --faq-- --snort-- --faq-- --snort-- --faq-- --snort-- --faq--Q: Does Snort perform TCP stream reassembly? A: Yes, check out the stream4 preprocessor that does stateful analysis   session loggin, tcp reassembly and much much more... Check the FAQ question   on configuring stream4.1.7 --faq-- --snort-- --faq-- --snort-- --faq-- --snort-- --faq--Q: Does Snort perform stateful protocol analysis? A: Yes, see above answer regarding stream4 preprocessor1.8 --faq-- --snort-- --faq-- --snort-- --faq-- --snort-- --faq--Q: I'm on a switched network, can I still use Snort?A: This depends on the type of switch you have.  If it can mirror traffic, you   can direct it to the port that your Snort box is on.1.9 --faq-- --snort-- --faq-- --snort-- --faq-- --snort-- --faq--Q: I've heard IDSes are vulnerable to noise generators like "Stick" and    "Snot", is snort vulnerable ?A: It is now pssible to defeat these kids of noise generators with   the stream4 preprocessor.  Even without this enabled snort will    weather the alert storm without falling over or losing a lot of    alerts due to its highly optimized nature... and using these   kinds of gimmicks hardly qualifies as executing a stealthy attack...1.11 --faq-- --snort-- --faq-- --snort-- --faq-- --snort-- --faq--Q: I've heard it is possible to use polymorphic mutators on shellcode?A: Yes, and this could defeat some of the NOP sled detection signatures   but the ordinary exploit rules should not be affected by this kind   of obfuscation. As well the SPADE statistical anomaly detector may   detect some of these attacks, and another defense is being prepared   for the next version of snort...1.12 --faq-- --snort-- --faq-- --snort-- --faq-- --snort-- --faq--Q: Does Snort log the full packets that it generates alerts on? A: Yes, they should be in the directory that has the same IP address as the   source host of the packet which generated the alert.     --faq-- --snort-- --faq-- --snort-- --faq-- --snort-- --faq--***************************************Section 2: GETTING STARTED***************************************2.1 --faq-- --snort-- --faq-- --snort-- --faq-- --snort-- --faq--Q: How do I run snort?A: Run Snort in sniffer mode (snort -dvi eth0) and make sure it can see the   packets.  Then run it with the HOME_NET set appropriately for the network   you're defending in your rules file.  A default rules file comes with the   snort distribution and is called "snort.conf" You can run this basic ruleset   with the following command line:     snort -Afull -c snort.conf   If it's all set right, once it's running do an "ifconfig -a" and make sure   the interface is in promiscuous mode (it'll say so in the options section of   the printout).  If it's not, there should be a way to set it manually.   2.2 --faq-- --snort-- --faq-- --snort-- --faq-- --snort-- --faq--Q: Where are my log files located?  What are they named?A: If you specified a logging directory with the -l parameter then that is   where your files are located.  If you did not specify a logging directory   then Snort will log to /var/log/snort/.   In the past, running Snort in daemon mode (-D) produced a file named   "snort.alert".  For consistency sake, this has been changed. Running   Snort in both standard or daemon modes (-D) will produce a file named   "alert".2.3 --faq-- --snort-- --faq-- --snort-- --faq-- --snort-- --faq--Q: Where's a good place to physically put a Snort sensor?A:  This is going to be heavily influenced by your organizations policy, and    what you want to detect.  One way of looking at it is determining if you    want to place it inside or outside your firewall.  Placing an IDS outside    of your firewall will allow you monitor all attacks directed at your    network, regardless of whether or not they are stopped at the firewall.    This almost certainly means that the IDS will pick up on more events    than an IDS inside the firewall, and hence more logs will be generated.    Place an IDS inside your firewall if you are only interested in monitoring    traffic that your firewall let pass.  If resources permit, it may be best    to place one IDS outside and one IDS inside of your firewall.  This way    you can watch for everything directed at your network, and anything that    made it's way in. 

?? 快捷鍵說明

復制代碼 Ctrl + C
搜索代碼 Ctrl + F
全屏模式 F11
切換主題 Ctrl + Shift + D
顯示快捷鍵 ?
增大字號 Ctrl + =
減小字號 Ctrl + -
亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频
欧美性videosxxxxx| 一区二区三区欧美日韩| 国产精品黄色在线观看| 午夜国产不卡在线观看视频| 国产成人在线免费观看| 欧美美女一区二区| 亚洲视频免费在线观看| 国产一区999| 日韩一区二区免费视频| 一区二区三区在线视频观看58| 看电影不卡的网站| 精品视频在线免费观看| 亚洲欧美乱综合| 国产.欧美.日韩| 日韩欧美激情在线| 五月天久久比比资源色| 99国产欧美久久久精品| 国产精品无遮挡| 国产大陆亚洲精品国产| 精品美女被调教视频大全网站| 天天综合色天天综合| 91国偷自产一区二区使用方法| 国产精品丝袜黑色高跟| 国产精品888| 久久久久久久久久电影| 国产在线不卡视频| www日韩大片| 久久国产精品99久久人人澡| 日韩美女在线视频| 久久精品国内一区二区三区| 91精品国产全国免费观看| 亚洲成人资源在线| 欧美二区在线观看| 视频一区视频二区中文字幕| 9191国产精品| 免费黄网站欧美| 久久综合久久综合久久综合| 国产主播一区二区| 久久伊99综合婷婷久久伊| 国产乱子轮精品视频| 久久精品人人做人人爽97| 国产aⅴ精品一区二区三区色成熟| 久久久久久久久一| 国产馆精品极品| 国产精品久久久久久久久免费相片 | 成人动漫一区二区在线| 国产精品毛片a∨一区二区三区 | 国产午夜精品久久| 成人午夜电影小说| 亚洲免费在线观看| 欧美日韩一二区| 极品美女销魂一区二区三区| 国产三级欧美三级日产三级99 | 欧美mv日韩mv| 国产suv精品一区二区883| 亚洲天堂成人在线观看| 欧美日韩和欧美的一区二区| 男女男精品视频网| 久久蜜桃香蕉精品一区二区三区| 不卡的电影网站| 午夜精品一区二区三区免费视频| 精品福利在线导航| 99久久精品国产一区| 首页亚洲欧美制服丝腿| 国产日韩三级在线| 欧美影院精品一区| 国产在线播精品第三| 亚洲一区二三区| 久久久亚洲精品石原莉奈| 在线观看国产日韩| 久久成人免费网| 亚洲天堂a在线| 日韩午夜激情视频| 91电影在线观看| 国产一区二区三区观看| 亚洲国产欧美一区二区三区丁香婷| 日韩视频一区二区在线观看| 99久久久免费精品国产一区二区| 亚洲va欧美va人人爽| 国产精品欧美久久久久一区二区 | 久久久久久**毛片大全| 欧美吞精做爰啪啪高潮| 国产suv一区二区三区88区| 天堂一区二区在线| 亚洲天堂成人在线观看| 久久嫩草精品久久久久| 91精品国产综合久久婷婷香蕉| 成人免费毛片嘿嘿连载视频| 奇米一区二区三区| 亚洲自拍偷拍欧美| 国产精品久久二区二区| 亚洲精品一区二区三区蜜桃下载 | 精品日韩99亚洲| 欧美日韩1区2区| 91久久精品午夜一区二区| 国产成人aaa| 久久国内精品视频| 日本午夜一本久久久综合| 亚洲综合色区另类av| 国产精品不卡在线| 国产日韩一级二级三级| 久久久亚洲精品石原莉奈| 欧美一区二区人人喊爽| 欧美另类一区二区三区| 色哟哟亚洲精品| 不卡的电影网站| 成人av网站免费| 成人免费的视频| 大胆亚洲人体视频| 成人网在线播放| 成人av电影免费观看| 国产91高潮流白浆在线麻豆| 粉嫩欧美一区二区三区高清影视 | 三级精品在线观看| 亚洲va欧美va国产va天堂影院| 亚洲精品成人a在线观看| 亚洲男人的天堂网| 亚洲免费av高清| 亚洲三级在线看| 亚洲免费视频中文字幕| 亚洲另类在线视频| 一区二区三区成人| 亚洲国产精品久久久久秋霞影院| 一区二区激情小说| 亚洲国产精品一区二区www| 天堂午夜影视日韩欧美一区二区| 性感美女久久精品| 视频一区二区中文字幕| 日本大胆欧美人术艺术动态| 久久99精品国产麻豆不卡| 国产麻豆9l精品三级站| gogogo免费视频观看亚洲一| 色网综合在线观看| 欧美妇女性影城| 久久美女高清视频| 亚洲美女偷拍久久| 日韩av在线发布| 国产成人免费视频网站| 99re热视频精品| 欧美夫妻性生活| 欧美高清在线一区二区| 伊人夜夜躁av伊人久久| 三级欧美在线一区| 国产高清成人在线| 欧美中文字幕久久| 精品国产乱码久久久久久夜甘婷婷 | 这里只有精品免费| 国产日韩欧美高清在线| 亚洲免费观看高清完整版在线 | 国产91丝袜在线播放0| 色婷婷综合久久久久中文一区二区 | 国产在线精品一区二区夜色| 不卡的av中国片| 91精品国产色综合久久ai换脸 | 精品国产1区2区3区| 亚洲色欲色欲www在线观看| 青青草原综合久久大伊人精品| 国产一区二区精品久久| 欧美三片在线视频观看| 欧美国产日韩一二三区| 欧美aaaaaa午夜精品| www.亚洲激情.com| 日韩精品一区二区三区视频 | 久久欧美一区二区| 午夜久久久影院| 波多野洁衣一区| 日韩精品一区二区三区四区 | 一本大道久久a久久综合| 久久久综合精品| 日韩极品在线观看| 91九色最新地址| 国产精品蜜臀av| 黑人巨大精品欧美黑白配亚洲| 91麻豆视频网站| 国产精品女同互慰在线看| 久久精品国产一区二区三| 欧美综合亚洲图片综合区| 中文字幕乱码一区二区免费| 久久精品72免费观看| 欧美精品免费视频| 一区二区三区在线免费播放| 成人在线视频首页| 精品国产亚洲在线| 久久福利视频一区二区| 3d成人h动漫网站入口| 亚洲综合激情小说| 91免费观看视频| 日韩毛片精品高清免费| 成人在线综合网| 国产精品美女久久久久高潮| 国产精品 欧美精品| 2023国产一二三区日本精品2022| 无码av免费一区二区三区试看 | 欧美精品一区二区三区高清aⅴ| 亚洲电影一级片| 欧美另类一区二区三区| 亚洲成av人片一区二区三区| 欧美日韩国产乱码电影| 天天影视色香欲综合网老头| 欧美日韩高清影院|