Questions tagged [snort]

Snort is a software package used for network intrusion detection.

Snort is a software package used for network intrusion detection.

Snort is a free and open source network intrusion prevention system (NIPS) and network intrusion detection system (NIDS). It was created by Martin Roesch in 1998.

125 questions
-1
votes
1 answer

specify the order of IDS , Firewall , WAF

i have an ubuntu system and i want to implement iptables as firewall, modsecurity as WAF and snort as IDS in this system and i have a server behind this system and i want to protect the server with this system. i want when the packet recieves first…
Trudy
  • 1
-1
votes
1 answer

barnyard2 for snort permission denied

I installed barnyard2 for snort, but when i run command below this error appear. [root@localhost snort]# barnyard2 -c /etc/snort/barnyard2.conf -d /var/log/snort/ -f snort.log -w /etc/snort/bylog.waldo /etc/snort/gen-msg.map /etc/snort/sid-msg.map…
-1
votes
1 answer

Remote logging from snort to rsyslog

As part of a school project, we are supposed to run snort on a Ubuntu server in IDS mode and log the packets to rsyslog on a remote Ubuntu server. I have been searching for manuals/tutorials for a week now. I couldn't find any helpful links. Any…
Ashwin
  • 111
-2
votes
1 answer

VirtualBox Networking Lab Configuration

I'm creating a lab for a project that will test a network security defense product's effectiveness in detecting various attacks. I have a physical server with 32GB of RAM and VirtualBox to create the network. I have one Windows server as a domain…
DrDinosaur
  • 323
  • 2
  • 3
  • 11
-4
votes
2 answers

Portscan attacks from somewhere

I realize this is a lamer/beginner question, but I've been attacked by a couple of addresses in China and I'm not sure how to close the hole. My snort logs (yes I'm using snort! I see you are impressed) show things like this: TCP Portscan [**]…
bobobobo
  • 769
  • 6
  • 14
  • 26
1 2 3
8
9