Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 83 guests and 1 member online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow Toolsarrow Need help with Snort
EH-Net
May 26, 2012, 05:38:04 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Need help with Snort  (Read 3115 times)
0 Members and 1 Guest are viewing this topic.
zenlakin
Newbie
*
Offline Offline

Posts: 5


View Profile
« on: September 03, 2011, 07:46:40 PM »

Hello everyone. I am trying to get Snort up and running and from what I can tell it is running and I am able to get it to start and to show traffic in verbose mode but I can't for the life of me get any data to show in base or get any "test" rules that I have setup to fire at all... My install environment is as follows:

Windows 7 Ultimate host running Debian 6 in vmware. My vmware instance has 2 NIC's, eth0 is set to host only and eth1 is bridged. I have setup a test rule in local.rules to fire an alert anytime there is ICMP traffic within my HOME_NET and I have tried to ping both IP's assigned to my NIC's on the VM from my host and from the VM back to my host and the pings are successful however there is no alert that fires... Any thoughts?

Zen
Logged
Lubinski
Newbie
*
Offline Offline

Posts: 26


View Profile
« Reply #1 on: September 03, 2011, 09:27:26 PM »

Are you using barnyard2 to output? What does your snort.conf output line read?
Logged
zenlakin
Newbie
*
Offline Offline

Posts: 5


View Profile
« Reply #2 on: September 03, 2011, 10:52:38 PM »

I am not using barnyard. Just BASE via the web url (http://localhost/acidbase). I am not for sure what you are asking for in regards to the snort.conf output line...I will have to take a look at the conf file and see what that is set to but I didn't change anything in regards to output in that file so it would be whatever was default...
Logged
zenlakin
Newbie
*
Offline Offline

Posts: 5


View Profile
« Reply #3 on: September 04, 2011, 09:37:46 AM »

I have been doing some reading and I am thinking there is something wrong with the way eth1 is setup because if I am understanding things correctly, eth1 should not have an IP address since it should be running in promiscuous mode and only listening for traffic on the wire. I do have that interface setup in VMware as a Bridged connection but when I boot up my Debian install which is running snort, I see that eth0 and eth1 both have IP addresses assigned..
Logged
pseud0
Recruiters
Full Member
*
Offline Offline

Posts: 204



View Profile
« Reply #4 on: September 04, 2011, 02:44:06 PM »

Not assigning an IP is more an issue for remaining undetected than anything to do with functionality.  Out of curiosity is there any type of threshold set for the rule you're using?  Does it need to see more than X packets per Y seconds?  Does it need to hit more than X IPs or Y ports? 
Logged

CISSP, CISM, CISA, GCIH, CEH, HMFIC, KTHXBIROFLCOPTER
zenlakin
Newbie
*
Offline Offline

Posts: 5


View Profile
« Reply #5 on: September 06, 2011, 06:53:50 PM »

I still couldn't get it to work so I am starting over with a fresh VM with Debian 6. Anybody know of a good tutorial for setting up and configuring snort in a VM using Debian?
Logged
zenlakin
Newbie
*
Offline Offline

Posts: 5


View Profile
« Reply #6 on: September 06, 2011, 07:21:16 PM »

This is the site I am following only I have Debian in a VM

http://www.aboutdebian.com/snort.htm
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.241 seconds with 23 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.