728x90
๋ฐ์ํ
rules ๊ฒฝ๋ก
ls -l /etc/snort/rules/
ICMP ๊ฐ์ง ๋ฃฐ
# vi /etc/snort/rules/local.rules
alert icmp any any -> any any (msg:"ICMP Detected";sid:1000001;)
Snort ์คํ(Linux)
snort -c /etc/snort/rules/local.rules -i eth0
Snort ์คํ(Windows)
snort -c c:\Snort\rules\local.rules -l C:\Snort\log\
๋ก๊ทธ(alert) ํ์ธ
tail -f /var/log/snort/alert
์ฐธ๊ณ :
https://net123.tistory.com/580
Snort - 04. Snort ๋ฃฐ ๊ตฌ์ฑ ๋ฐ ํ ์คํธ
Snort - 04. Snort ๋ฃฐ ๊ตฌ์ฑ ๋ฐ ํ ์คํธ 1. ICMP ๋ฃฐ ์ค์ ๋ฐ Snort ํ ์คํธ root@Snort:~# vi /etc/snort/rules/local.rules # $Id: local.rules,v 1.11 2004/07/23 20:15:44 bmc Exp $ # ---------------- # LOCAL RULES # ---------------- # This file intentio
net123.tistory.com
728x90
๋ฐ์ํ
'๐์ ๋ณด๋ณด์ > ๋คํธ์ํฌ ๋ณด์' ์นดํ ๊ณ ๋ฆฌ์ ๋ค๋ฅธ ๊ธ
๋คํธ์ํฌ ๋ณด์ - WebRTC(IP leak issue), NAT, ICE, STUN, TURN (1) | 2024.04.05 |
---|---|
๋คํธ์ํฌ ๋ณด์ - NAC ์ฐํ ๊ด๋ จ Cheat Sheet (0) | 2024.03.28 |
๋คํธ์ํฌ ๋ณด์ - Snort ์นผ๋ฆฌ๋ฆฌ๋ ์ค 1.0 ์ค์น (0) | 2023.11.17 |
๋คํธ์ํฌ ๋ณด์ - Snort ์๋์ฐ ์ค์น (0) | 2023.11.17 |
๋คํธ์ํฌ ๋ณด์ - FTP ํจ์๋ธ ๋ชจ๋(PASV EPSV) (0) | 2023.10.12 |