SNORT - How to Install, Configure, and Create Rules

preview_player
Показать описание
I will be explaining how to install and configure Snort, an open source real-time IDS/IPS. I will also explain the basic structure of a Snort rule and demonstrate how to create one.

By Kody Immink

Comment out all rulesets with the following command:

Рекомендации по теме
Комментарии
Автор

NANO!!!! ugh i just spent an hour+ spinning my wheels trying to find this info only to check your video and had an answer 2 minutes in haha.

masterzen
Автор

Thank you for this structured and very helpful tutorial!

bloodshift
Автор

Awesome video! I like casually you do it. I hope this feedback is helpful.

ganeshpalaniappan
Автор

I did everything step by step on Ubuntu and it doesn't work when i type ebay in the browser it doesn't show anything in the console or when I'm using ftp it also doesn't show anything. I know it's been 7 years since video got released but maybe some of you had this same problem like me.

kraken
Автор

After I installed, the only thing showing up in the snort directory is rules. No config file or anything. Any ideas what may have happened? I did have it installed previously, but had removed it with the autoremove command as well as deleted the directory.

annaikonline
Автор

Hi Ed, Can you make a video of how to use snort on GNS3?

rddhi
Автор

Can we use snort to mitigate storage covert channels. if yes, what would be the script?

AakashGoyal
Автор

Hey man 10:18 When I tried "ftp 192.168.0.1", it showed "Connection Refused".
All well and good.
But snort console didn't show anything.
Can anyone help me with why this is happening?

Also, 192.168.0.1 is what my HOME_NET is set as in snort.conf

varungawande
Автор

im just too dum to understand any of this :(

imveryhungry