安装完成
编写启动脚本:
mkdir /root/script
ifconfig查看网卡---lnc0为当前网卡名称
vi lnc0.sh
#!/bin/sh
case "$1" in
start)
if test -x /usr/local/bin/snort
then
#网卡进入混杂模式
ifconfig lnc0 promisc
#启动snort为daemon
/usr/local/bin/snort -c /usr/local/etc/snort.conf -i lnc0 -u root -D > /dev/null & echo -n
echo 'Snort has been started .........'
echo ""
fi
;;
stop)
/usr/bin/killall snort >/dev/null 2>&1 && echo -n 'Snort has been stopped....'
echo ""
;;
*)
echo "Usage: `basename $0` {start|stop}"
echo ""
exit 64
;;
esac
vi stop.IDS01.sh
#!/bin/sh
echo "Stopping SIDS01.................."
./lnc0.sh stop
echo "please waiting..."
sleep 3
/usr/local/sbin/apachectl stop
sleep 3
/usr/local/etc/rc.d/mysql-server stop
vi start.IDS01.sh
#!/bin/sh
#This script will start the MySQL server and Apache services
echo “I will first try to close all MySQL services and Apache services just in
echo “Starting MySQL services”
/usr/local/etc/rc.d/mysql-server start
echo “Staring Apache services”
/usr/local/sbin/apachectl start
sleep 2
/usr/local/libexec/idled -f /usr/local/etc/idled.cf
./lnc0.sh start
echo "Please waiting for 5-10s...,system is chang netcard's mode now."
sleep 2
#/usr/local/bin/snort -d -h 10.5.3.0/24 -l /var/log/snortlogs -c /usr/local/etc/snort.conf -s -D
/usr/local/bin/snort -c /usr/local/etc/snort.conf -i lnc0 -u root -D > /dev/null & echo -n
chmod 755 /root/scripts/*.sh
18)下载rules:
fetch http://www.snort.org/pub-bin/downloads.cgi/Download/vrt_pr/snortrules-pr-2.4.tar.gz
mkdir /usr/local/etc/snort_rules
mv snortrules-pr-2.4.tar.gz /usr/local/etc/snort_rules
cd /usr/local/etc/snort_rules
tar zxvf snortrules-pr-2.4.tar.gz
chmod -R 0755 chmod -R 0755 /usr/local/etc/snort_rules
19)启动idled、apache、mysql和snort,并使网卡进入混杂模式
/root/scripts/start.IDS01.sh
(第二篇)
liu1084 回复于:2006-08-11 10:24:07
构建入侵检测系统(IDS)(三)
20)遇到的问题:
1:mod_unique_id.so的问题:
解决方法:
vi /etc/rc.conf
添加:
hostname database
保存
vi /etc/hosts
127.0.0.1 localhost database database.domain.com
| 论坛热门帖子: | [lch203] 写得蛮好的linux学习笔记(10-21) [黑马制造] 学习java的30个目标(10-19) [笑傲股林] 做测试半年了,有点迷茫,应该再学些什么提高自己的测试水平和测试能力呢?(10-19) [udp8589] 大家用google的来吱一声? 用百度的~~也来报道下?(10-18) [沂偌掳兆] 本人总结的一些认为C++比较经典的书籍,希望对大家有用(10-18) |
| TAG标签: | 全文 网络 架构 攻击 安装 数据 服务器 echo 保存 include |
注册
个人空间
