亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频

? 歡迎來到蟲蟲下載站! | ?? 資源下載 ?? 資源專輯 ?? 關于我們
? 蟲蟲下載站

?? snort_manual.tex

?? This is the snapshot of Snot Latest Rules
?? TEX
?? 第 1 頁 / 共 5 頁
字號:
% $Id: snort_manual.tex,v 1.89 2007/06/01 13:58:12 ssturges Exp $% % BUILDING HTML VERSION:% latex2html -info 0 -local_icons -show_section_numbers -link +2 -split +2 -noaddress snort_manual.tex%% BUILDING PDF VERSION:% pdflatex snort_manual.tex\documentclass[english]{report}%\usepackage[T1]{fontenc}\usepackage[latin1]{inputenc}\usepackage{geometry}\usepackage{longtable}\geometry{verbose,letterpaper,tmargin=1in,bmargin=.5in,lmargin=1in,rmargin=1in}\IfFileExists{url.sty}{\usepackage{url}}                      {\newcommand{\url}{\texttt}}\usepackage{html}% \makeatletter\newcounter{slistnum}\newcounter{subslistnum}\newcounter{subsublistnum}\newenvironment{slist}{ \begin{list}{ {\bf \arabic{slistnum}.} }{\usecounter{slistnum} } }{ \end{list} }\newenvironment{subslist}{ \begin{list} { {\bf \arabic{slistnum}-\Alph{subslistnum}. } }        {\usecounter{subslistnum} }   }{ \end{list} }\newenvironment{subsubslist} {    \begin{list}{        {\bf \arabic{slistnum}-\arabic{subslistnum}-\arabic{subsublistnum}. }    }{        \usecounter{subsubslistnum}    }}{    \end{list}}%\begin{latexonly}\newsavebox{\savepar}\newenvironment{note}{\samepage    \vspace{10pt}{\textsf{        {\hspace{7pt}\Huge{$\triangle$\hspace{-12.5pt}{\Large{$^!$}}}}\hspace{5pt}        {\Large{NOTE}}    }    }   \begin{center}    \par\vspace{-17pt}    \begin{lrbox}{\savepar}    \begin{minipage}[r]{6in}}{    \end{minipage}    \end{lrbox}    \fbox{        \usebox{            \savepar	}    }    \par\vskip10pt    \end{center}}%\end{latexonly}\begin{htmlonly}\newenvironment{note}{        \begin{rawhtml}        <p><table border="1"><tr><td><b>        Note:&nbsp;&nbsp;</b>        \end{rawhtml}}{        \begin{rawhtml}        </b></td></tr></table></p>        \end{rawhtml}}\end{htmlonly}\usepackage{babel}% \makeatother\addtolength{\parindent}{-5mm}\addtolength{\parskip}{2mm}%\renewcommand\floatpagefraction{.9}%\renewcommand\topfraction{.9}%\renewcommand\bottomfraction{.9}%\renewcommand\textfraction{.1}   %\setcounter{totalnumber}{50}%\setcounter{topnumber}{50}%\setcounter{bottomnumber}{50}\begin{document}\title{Snort\texttrademark  Users Manual\\  2.7.0 }\author{The Snort Project}\maketitle\newpageCopyright \copyright 1998-2003 Martin RoeschCopyright \copyright 2001-2003 Chris GreenCopyright \copyright 2003-2006 Sourcefire, Inc.\tableofcontents{}\chapter{Snort Overview}This manual is based on \emph{Writing Snort Rules} by Martin Roesch and furtherwork from Chris Green $<$cmg@snort.org$>$.  It is now maintained by BrianCaswell $<$bmc@snort.org$>$.  If you have a better way to say something or findthat something in the documentation is outdated, drop us a line and we willupdate it.  If you would like to submit patches for this document, you can findthe latest version of the documentation in \LaTeX\ format in the Snort CVSrepository at \verb!/doc/snort_manual.tex!.  Small documentation updates arethe easiest way to help out the Snort Project.\section{Getting Started}Snort really isn't very hard to use, but there are a lot of command lineoptions to play with, and it's not always obvious which ones go together well.This file aims to make using Snort easier for new users.Before we proceed, there are a few basic concepts you should understand aboutSnort. Snort can be configured to run in three modes:\begin{itemize}\item {\em Sniffer mode,} which simply reads the packets off of the network and displays them for you in a continuous stream on the console (screen). \item {\em Packet Logger mode,} which logs the packets to disk. \item {\em Network Intrusion Detection System (NIDS) mode,} the most complex and configurable configuration,which allows Snort to analyze network traffic for matches against a user-definedrule set and performs several actions based upon what it sees.\item {\em Inline mode,} which obtains packets from iptables instead of from libpcap and thencauses iptables to drop or pass packets based on Snort rules that use inline-specific rule types.\end{itemize}\section{Sniffer Mode}First, let's start with the basics. If you just want to print outthe TCP/IP packet headers to the screen (i.e. sniffer mode), try this:\begin{verbatim}./snort -v\end{verbatim}This command will run Snort and just show the IP and TCP/UDP/ICMPheaders, nothing else. If you want to see the application data intransit, try the following:\begin{verbatim}./snort -vd\end{verbatim}This instructs Snort to display the packet data as well as the headers.If you want an even more descriptive display, showing the data linklayer headers, do this:\begin{verbatim}./snort -vde\end{verbatim}(As an aside, these switches may be divided up or smashed togetherin any combination. The last command could also be typed out as:\begin{verbatim}./snort -d -v -e\end{verbatim}and it would do the same thing.)\section{Packet Logger Mode}OK, all of these commands are pretty cool, but if you want to recordthe packets to the disk, you need to specify a logging directory andSnort will automatically know to go into packet logger mode:\begin{verbatim}./snort -dev -l ./log\end{verbatim}Of course, this assumes you have a directory named \verb!log!in the current directory. If you don't, Snort will exit with an errormessage. When Snort runs in this mode, it collects every packet itsees and places it in a directory hierarchy based upon the IP addressof one of the hosts in the datagram.If you just specify a plain -l switch, you maynotice that Snort sometimes uses the address of the remote computeras the directory in which it places packets and sometimes it usesthe local host address. In order to log relative to the home network,you need to tell Snort which network is the home network:\begin{verbatim}./snort -dev -l ./log -h 192.168.1.0/24\end{verbatim}This rule tells Snort that you want to print out the data link andTCP/IP headers as well as application data into the directory \verb!./log!,and you want to log the packets relative to the 192.168.1.0 classC network. All incoming packets will be recorded into subdirectoriesof the log directory, with the directory names being based on theaddress of the remote (non-192.168.1) host. \begin{note}Note that if both the source and destination hosts are on the home network, they are logged to a directory with a name based on the higher of the two port numbers or, in the case of a tie, the source address.\end{note}If you're on a high speed network or you want to log the packets intoa more compact form for later analysis, you should consider loggingin binary mode. Binary mode logs the packets intcpdump format to a single binary file in thelogging directory:\begin{verbatim}./snort -l ./log -b\end{verbatim}Note the command line changes here. We don't need to specify a homenetwork any longer because binary mode logs everything into a singlefile, which eliminates the need to tell it how to format the outputdirectory structure. Additionally, you don't need to run in verbosemode or specify the -d or -e switches because in binary mode the entirepacket is logged, not just sections of it. All you really need to doto place Snort into logger mode is to specify a loggingdirectory at the command line using the -l switch---the -b binary loggingswitch merely provides a modifier that tells Snort to log the packets insomething other than the default output format of plain ASCII text.Once the packets have been logged to the binary file, you can readthe packets back out of the file with any sniffer that supports thetcpdump binary format (such as tcpdump or Ethereal). Snort can alsoread the packets back by using the -r switch, which puts it into playbackmode. Packets from any tcpdump formatted file can be processed throughSnort in any of its run modes. For example, if you wanted to run abinary log file through Snort in sniffer mode to dump the packetsto the screen, you can try something like this:\begin{verbatim}./snort -dv -r packet.log\end{verbatim}You can manipulate the data in the file in a number of ways throughSnort's packet logging and intrusion detection modes, as well as withthe BPF interface that's available from the command line. For example,if you only wanted to see the ICMP packets from the log file, simplyspecify a BPF filter at the command line and Snort will only seethe ICMP packets in the file:\begin{verbatim}./snort -dvr packet.log icmp \end{verbatim}For more info on how to use the BPF interface, read the Snort andtcpdump man pages.\section{Network Intrusion Detection System Mode}To enable Network Intrusion Detection System (NIDS) mode so that you don'trecord every single packet sent down the wire, try this:\begin{verbatim}./snort -dev -l ./log -h 192.168.1.0/24 -c snort.conf\end{verbatim}where \texttt{snort.conf} is the name of your rules file. This will apply therules configured in the \verb!snort.conf! file to each packet to decide if an actionbased upon the rule type in the file should be taken. If you don'tspecify an output directory for the program, it will default to \verb!/var/log/snort!.One thing to note about the last command line is that if Snort isgoing to be used in a long term way as an IDS, the -vswitch should be left off the command line for the sake of speed.The screen is a slow place to write data to, and packets can be droppedwhile writing to the display.It's also not necessary to record the data link headers for most applications,so you can usually omit the -e switch, too.\begin{verbatim}./snort -d -h 192.168.1.0/24 -l ./log -c snort.conf\end{verbatim}This will configure Snort to run in its most basic NIDS form, loggingpackets that trigger rules specified in the \texttt{snort.conf} in plain ASCII to disk using a hierarchical directory structure (just like packet logger mode). 

?? 快捷鍵說明

復制代碼 Ctrl + C
搜索代碼 Ctrl + F
全屏模式 F11
切換主題 Ctrl + Shift + D
顯示快捷鍵 ?
增大字號 Ctrl + =
減小字號 Ctrl + -
亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频
91免费视频网址| 久久久久久一级片| 丁香天五香天堂综合| 日韩福利视频网| 亚洲精品第1页| 国产精品麻豆一区二区| 精品国产第一区二区三区观看体验| 欧美在线不卡一区| 日韩三级在线观看| 欧美情侣在线播放| 色妹子一区二区| 91在线无精精品入口| 成熟亚洲日本毛茸茸凸凹| 国产一区二区三区精品视频| 蜜臂av日日欢夜夜爽一区| 日本欧美加勒比视频| 天堂成人国产精品一区| 五月婷婷欧美视频| 日韩黄色免费电影| 日韩电影在线观看电影| 免费不卡在线观看| 麻豆国产精品一区二区三区| 久久国产人妖系列| 韩国成人精品a∨在线观看| 舔着乳尖日韩一区| 男人的天堂久久精品| 午夜日韩在线观看| 蜜臀av一级做a爰片久久| 麻豆精品国产传媒mv男同| 黄网站免费久久| 国产在线观看免费一区| 国产成人综合自拍| 99久久免费视频.com| 色妹子一区二区| 欧美猛男男办公室激情| 日韩午夜精品视频| 久久精品欧美一区二区三区麻豆| 亚洲精品在线电影| 亚洲日韩欧美一区二区在线| 一区二区三区加勒比av| 秋霞国产午夜精品免费视频| 亚洲国产cao| 亚洲高清免费观看 | 亚洲妇熟xx妇色黄| 亚洲成av人片一区二区| 精品亚洲porn| 色菇凉天天综合网| 日韩视频一区二区在线观看| 中文一区一区三区高中清不卡| 亚洲美女偷拍久久| 视频精品一区二区| 成人va在线观看| 欧美电影在线免费观看| 国产日韩高清在线| 香蕉久久夜色精品国产使用方法| 国产寡妇亲子伦一区二区| 色久优优欧美色久优优| www久久久久| 亚洲图片欧美综合| 国产成人午夜视频| 91精品在线一区二区| 国产精品久线在线观看| 青青草精品视频| 欧美在线不卡一区| 国产精品美女久久久久久久网站| 日韩电影在线免费| 色婷婷一区二区| 国产午夜精品久久久久久久| 肉色丝袜一区二区| 色诱亚洲精品久久久久久| 国产午夜久久久久| 久久福利资源站| 欧美美女直播网站| 亚洲视频网在线直播| 国产精品一品视频| 日韩欧美高清一区| 日韩和欧美一区二区三区| 色88888久久久久久影院按摩| 国产日韩亚洲欧美综合| 美国十次综合导航| 7777精品伊人久久久大香线蕉超级流畅 | 欧美精品tushy高清| 中文字幕一区视频| 琪琪一区二区三区| 色综合网站在线| 国产亚洲欧美日韩日本| 五月激情综合网| 欧美日韩国产在线观看| 亚洲永久精品国产| 欧美亚洲综合另类| 亚洲一区二区在线视频| 91在线观看地址| 中文字幕亚洲欧美在线不卡| 成人在线一区二区三区| 国产亚洲精品精华液| 国产精品一区专区| 国产欧美1区2区3区| 国产乱码精品一品二品| 久久精品一二三| 国产精品69毛片高清亚洲| 国产欧美精品日韩区二区麻豆天美| 国产老妇另类xxxxx| 久久久久久99精品| 懂色av噜噜一区二区三区av| 中文字幕制服丝袜一区二区三区 | 日韩精品欧美成人高清一区二区| 91网站黄www| 一区在线观看免费| 在线中文字幕一区| 午夜天堂影视香蕉久久| 日韩三级视频在线看| 国产呦精品一区二区三区网站| 久久久久久影视| 91美女福利视频| 日本成人在线不卡视频| 久久亚区不卡日本| av中文一区二区三区| 亚洲午夜免费福利视频| 日韩一区二区三区免费观看| 国内久久精品视频| 亚洲人123区| 555夜色666亚洲国产免| 韩国精品久久久| 亚洲欧美一区二区久久| 欧美区一区二区三区| 国产一区二区精品在线观看| 一区免费观看视频| 欧美一区二区久久久| 高清视频一区二区| 五月天视频一区| 中文字幕第一区二区| 在线不卡一区二区| 成人a免费在线看| 免费三级欧美电影| 欧美电影免费提供在线观看| 99视频精品在线| 亚洲欧美偷拍卡通变态| 制服丝袜中文字幕亚洲| 激情久久久久久久久久久久久久久久| 国产精品国模大尺度视频| 欧美日韩高清一区| 风流少妇一区二区| 青娱乐精品在线视频| 国产精品夫妻自拍| 精品久久人人做人人爽| 欧美色综合网站| 99久久伊人精品| 精品一区二区三区视频| 一区二区三区中文字幕电影| 精品国产免费人成在线观看| 欧美午夜精品久久久| 不卡一区二区在线| 精品中文字幕一区二区| 天堂在线一区二区| 一区二区三区中文字幕在线观看| 国产欧美久久久精品影院| 日韩欧美成人午夜| 欧美一区二区三区爱爱| 欧美日本一区二区三区四区| 色成年激情久久综合| 不卡大黄网站免费看| 国产成人免费av在线| 黄色日韩三级电影| 日韩精品电影在线观看| 亚洲成人综合在线| 亚洲精品视频观看| 亚洲男同1069视频| 亚洲天堂av老司机| 国产精品国产精品国产专区不蜜 | 午夜伊人狠狠久久| 亚洲一级不卡视频| 午夜精品视频在线观看| 亚洲不卡一区二区三区| 亚洲不卡一区二区三区| 亚洲18女电影在线观看| 亚洲成人av在线电影| 亚洲福利视频一区二区| 亚洲线精品一区二区三区八戒| 亚洲一区二区成人在线观看| 午夜精品久久久久久久99水蜜桃| 亚洲午夜在线视频| 日韩国产精品久久久| 国产精品私人自拍| 国产精品不卡一区二区三区| 国产精品拍天天在线| 亚洲视频一二区| 偷拍与自拍一区| 精品亚洲国内自在自线福利| 国产精品一区三区| 成人免费视频网站在线观看| 91欧美一区二区| 欧美久久久久久久久中文字幕| 精品国产一区二区三区久久久蜜月| 精品av综合导航| 欧美一三区三区四区免费在线看| 欧美成人精品福利| 一区二区三区日韩| 国产1区2区3区精品美女| 91精品国产91久久综合桃花| 亚洲同性同志一二三专区|