Tutorial Snort
Tutorial Snort
1.
$ sudo snort -v
Running in packet dump mode
--== Initializing Snort ==-Initializing Output Plugins!
pcap DAQ configured to passive.
Acquiring network traffic from "eth0".
Decoding Ethernet
--== Initialization Complete ==-,,_
-*> Snort! <*o" )~
Version 2.9.0.5 (Build 135)
''''
By
Martin
Roesch
&
The
Snort
http://www.snort.org/snort/snort-team
Copyright (C) 1998-2011 Sourcefire, Inc., et al.
Using libpcap version 1.1.1
Using PCRE version: 8.12 2011-01-15
Team:
2. Untuk mencatat rekaman packet ke dalam file teks, Snort bisa dijalankan dengan
memberikan perintah seperti
snort -dev -l ./log