Gnome Home Mon compte Rechercher Forum Downloads FAQ Howto Pas encore enregistré? Devenez membre ici. (L'enregistrement est gratuit). 10/09/2010 - 14:31

Howto to install snort + oinkmaster + guardian on sme server 7.x
Dernière mise à jour : 2006-07-18 08:51:17 (16168 lectures)
[Imprimer la page | Envoyé à un ami]

Howto to install snort + oinkmaster + guardian + base on sme server 7.x

Author: MasterSleepy
Contributor:  
Release: SME Server 7.x
License: GPL


Problem: You want to install snort on sme server 7.x
Solution: Follow this Howto


STEP 1: Install Snort

Download and install the contrib

[root@server root]# wget "http://www.vanhees.cc/index.php?name=CmodsDownload&file=index&req=getit&lid=302"
[root@server root]# rpm -ivh smeserver-snort-2.6.0-1.i386.rpm

STEP 2:  Start service

Snort will be automatically activate when you restart server, or you can launch it manually

[root@server root]# service snortd restart

STEP 3:  Service option

You can activate or deactivate mysql logging

To deactive mysql plugin

[root@server root]# db configuration setprop snortd mysql disabled
[root@server root]# service snortd restart

To active mysql plugin

[root@server root]# db configuration setprop snortd mysql enabled
[root@server root]# service snortd restart

If http_inspect is to restrive, you can deactive it

[root@server root]# db configuration setprop snortd HttpInspect disabled
[root@server root]# service snortd restart

To activate http_inspect

[root@server root]# db configuration setprop snortd HttpInspect enabled
[root@server root]# service snortd restart

STEP 4: Install Oinkmaster

Oinkmaster can keep snort rules up-to-date by downloading new rules from internet.

Download and install the contrib

[root@server root]# wget "http://www.vanhees.cc/index.php?name=CmodsDownload&file=index&req=getit&lid=272"
[root@server root]# rpm -ivh smeserver-oinkmaster-1.2-1.noarch.rpm

STEP 5: Configure Oinkmaster

Oinkmaster can retrieve snort rules from different web site.
3 differents source have configure for this package:

  • Rules given with oincode
  • Community rules
  • Bleeding rules

Rules with oincode

You have to go to snort web site and register
http://www.snort.org/pub-bin/register.cgi
When you are registered, go to your user preferences
https://www.snort.org/reg-bin/userprefs.cgi
At the end of the page you have a table with title "Oink Code", clic button "Get Code".
Now you have a oinkcode that you can give to oinkmaster with the following command
[root@server root]# db configuration setprop oinkmaster code <code given>
[root@server root]# expand-template /etc/oinkmaster.conf

Community rules

Activated community rules to be downloaded with commandes
[root@server root]# db configuration setprop oinkmaster community enabled
[root@server root]# expand-template /etc/oinkmaster.conf

Bleeding rules

BEWARE I DON'T RECOMMAND USE OF BLEEDING RULES several problem have been rise due to that rules
Activated bleeding rules to be downloaded with commandes
[root@server root]# db configuration setprop oinkmaster bleeding enabled
[root@server root]# expand-template /etc/oinkmaster.conf
Oinkmaster will run every day!! If you want to change that for weekly
[root@server root]# mv /etc/cron.daily/02-oinkmaster /etc/cron.weekly/

STEP 6: Install guardian

When snort detect some alert, guardian will black list the ip during one day.

Download and install the contrib

[root@server root]# wget "http://www.vanhees.cc/index.php?name=CmodsDownload&file=index&req=getit&lid=274"
[root@server root]# rpm -ivh smeserver-guardiand-1.7-1.noarch.rpm

STEP 7: Configure guardian service

Guardian service can be deactive using

[root@server root]# db configuration set guardiand service status disabled

Guardian service can be active using

[root@server root]# db configuration set guardiand service status enabled

STEP 8: Install base

Download and install base rpm

[root@server root]# wget "http://www.vanhees.cc/index.php?name=CmodsDownload&file=index&req=getit&lid=276"
[root@server root]# rpm -ivh smeserver-base-1.2.2-1.noarch.rpm

go to url
https://<server-ip>/base


[Premier]  [Précédent]  [Retour à l'article principal]  [Suivant]  [Dernier]
[Imprimer la page | Envoyé à un ami]
Languages
minimizeclose
Langue préférée :

English Français
bottom_left bottom_right
Site
minimizeclose
bottom_left bottom_right
Staff Status
minimizeclose
Bienvenue visiteur

L'enregistrement est complètement gratuit et vous permettra d'avoir accès à toutes les parties du site
Enregistrement ici

Pseudo:


Mot de passe:


Se souvenir de moi

Membres:  Membres:
Dernier:  Nouveau aujourd'hui: 5
Dernier:  Nouveau hier: 6
Dernier:  Total: 759
Dernier:  Dernier:
inipseddy
Membres:  Connecté
Membres:  Membres: 0
Visiteurs:  Visiteurs: 3
Total:  Total: 3
Membres:  Membres en ligne
Aucun membre de connecté
bottom_left bottom_right
Vus il y a peu...
minimizeclose
arrow MasterSleepy

13:08:28 - 10.09.2010

arrow cedric

0:40:39 - 10.09.2010

arrow papangue

8:23:52 - 08.09.2010

arrow feeny

7:32:15 - 04.09.2010

arrow steveharvey27

7:48:00 - 31.08.2010

arrow Carpate

23:02:19 - 30.08.2010

arrow dfalt

7:49:50 - 30.08.2010

arrow immind

18:06:21 - 26.08.2010

arrow romu69

13:20:28 - 24.08.2010

arrow alarch

22:31:23 - 23.08.2010

bottom_left bottom_right
Translate
minimizeclose
google

bottom_left bottom_right
Liens
minimizeclose
bottom_left bottom_right
Visiteurs
minimizeclose
Total : 1140971
Aujourd'hui : 240
Connecté : 11
bottom_left bottom_right
Citations
minimizeclose

Il n'y a pas de bonheur parfait! dir l'homme quand sa belle-mèr mourut et qu'on lui présenta la note des pompes funèbre.
Jérôme K. Jérôme

bottom_left bottom_right
goes to top
Page created in 0,22223901748657 seconds.