LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-29-2003, 04:27 PM   #1
Crashed_Again
Senior Member
 
Registered: Dec 2002
Location: Atlantic City, NJ
Distribution: Ubuntu & Arch
Posts: 3,503

Rep: Reputation: 57
Snort :newbie:


Thanks to UnSpawn I decided to give Snort a shot. I installed the Snort tarball. Now I'm reading the online documentation and I want snort to run in Network Intrusion Detection Mode. I have no idea where to begin.

Do I have to write my own rules or are there default Snort rules already? How do I get Snort to run at startup and how will I know if there has been an attempted break in?

I also installed Barnyard even though I have no idea what it does. When I type barnyard in a shell I get this error:

Failed to open config file "/etc/snort/barnyard.conf"

There is no /etc/snort directory. What does baryard do anyway?
 
Old 01-29-2003, 07:02 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Re: Snort :newbie:

Thanks to UnSpawn I decided to give Snort a shot. I installed the Snort tarball. Now I'm reading the online documentation and I want snort to run in Network Intrusion Detection Mode. I have no idea where to begin.
A journey begins with the first step...

Do I have to write my own rules or are there default Snort rules already?
No. Your first rules came with the tarball and have the *.rules extension. Put them wherever you like, like /etc/snort-rules or /var/snort. Just make sure you reference them in the Snort config.
Update your rules with the CVS version available at the snort.org site. (make a wget cronjob out of it). I say CVS because on the snort mailinglist it seems we've discovered the "regular" rules tarball isn't current.

How do I get Snort to run at startup and how will I know if there has been an attempted break in?
Verify if you have a SYSV startscript in /etc/rc.d/init.d, edit the options if necessary. It's in the tarball contrib/redhat dir IIRC.
Make a link from /etc/rc.d/init.d/snort to /etc/rc.d/rcX.d/SYYsnort where X is the runlevel you want to run it in, and YY is the place in the startup sequence you want to start it as. You don't have to specify a /etc/rc.d/rc(0|6).d/K01snort because of libpcap Snort will die anyway when the link goes down.

I also installed Barnyard even though I have no idea what it does. When I type barnyard in a shell I get this error:
Failed to open config file "/etc/snort/barnyard.conf"

If your barnyard config isn't in that loc, use barnyard -c and specify location. If it isn't nowhere at all, check the tarball.

There is no /etc/snort directory.
Guess you gotta make it. Now I'm wondering how the hell did you manage to install a partial tarball? :-] If unsure, configure and make again, then run "make -n install > INSTALLER.LOG". This won't touch anything, just go tru the motions and spit out all it's sposed to do into the file for your perusal. Read and check where it goes wrong.

What does baryard do anyway?
Snort has many logging options, from ASCII (slow) to tcpdump and unified binary type logs (fast). To parse unified binary type logs into other formats (tcpdump, alert, db entries, csv) you run Barnyard.

Last edited by unSpawn; 01-29-2003 at 07:03 PM.
 
Old 01-29-2003, 07:07 PM   #3
Crashed_Again
Senior Member
 
Registered: Dec 2002
Location: Atlantic City, NJ
Distribution: Ubuntu & Arch
Posts: 3,503

Original Poster
Rep: Reputation: 57
Thanks UnSpawn. Once again you have sent me down another long and winding Linux road. I appreciate it. You are the man!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Error when starting up snort: bash:!/bin/sh/usr/local/bin/snort :Eent not found cynthia_thomas Linux - Software 1 11-11-2005 02:59 PM
snort failed: snort: symbol lookup error: undefined symbol: usmAES192PrivProtocol Emmanuel_uk Linux - Security 1 07-10-2005 10:29 AM
Snort Newbie Question kemplej Linux - Networking 1 05-21-2004 10:34 PM
Snort Newbie Question kemplej Linux - Software 0 05-19-2004 04:03 PM
!Snort<->Newbie TheIrish Linux - Security 1 11-05-2003 10:46 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:18 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration