Sunday, 21 April 2013

Snort little piggy

Install default Ubuntu 12.04 Server

sudo su

apt-get update
apt-get upgrade


Install SSH to enable remove admin

sudo apt-get install  openssh-server

From a putty session


apt-get install mysql-server nmap nbtscan apache2 php5 php5-mysql php5-gd libpcap0.8-dev libpcre3-dev g++ bison flex libpcap-ruby make zlib1g-dev libmysqld-dev libdnet libdnet-dev libpcre3 libpcre3-dev gcc make flex byacc bison linux-headers-generic libxml2-dev libdumbnet-dev zlib1g zlib1g-dev

Enter and confirm a MySQL password


mkdir /usr/local/src/snort
cd /usr/local/src/snort


wget http://www.snort.org/dl/snort-current/daq-2.0.0.tar.gz

tar -xvzf daq-2.0.0.tar.gz


cd daq-2.0.0
./configure

make
make install

cd /usr/local/src/snort


wget http://www.snort.org/dl/snort-current/snort-2.9.4.5.tar.gz
tar -zxvf snort-2.9.4.5.tar.gz


cd snort-2.9.4.5

./configure --prefix /usr/local/snort && make && make install

groupadd snort
useradd -g snort snort

ln -s /usr/local/snort/bin/snort /usr/sbin/
ln -s /usr/local/snort/etc /etc/snort


cd /usr/local/src/snort
wget -O snortrules-snapshot-2941.tar.gz http://www.snort.org/reg-rules/snortrules-snapshot-2941.tar.gz/9efdb56ce6e1409f2c3904c284bd1af8d506d6e4





--
Thanks

http://wiki.aanval.com/wiki/Community:Snort_2.9.2.3_Installation_Guide_for_Ubuntu_12.04,_with_Barnyard2,_Pulledpork,_and_Aanval#Setup_the_network_interface_you_will_be_using_for_sniffing_traffic_in_promiscuous_mode

https://github.com/da667/Autosnort


No comments:

Post a Comment