Snort Implimentation
Just waiting on last part for my *nix system and was planning what packages etc will be installed.
My question is: How user friendly is snort? Will it take me days to work out and impliment or will it be fairly straight forward to use generally without to many user defined rules.
Im just looking through the documentation now and it doesnt look too bad just looking for input from people who have used it / are using it.
Cheers as always guys
PS: What distro did you run it from and was there any compatibilty issues etc.
My question is: How user friendly is snort? Will it take me days to work out and impliment or will it be fairly straight forward to use generally without to many user defined rules.
Im just looking through the documentation now and it doesnt look too bad just looking for input from people who have used it / are using it.
Cheers as always guys
PS: What distro did you run it from and was there any compatibilty issues etc.
Foolproof systems don't take into account the ingenuity of fools
Comments
-
Paul Boz Member Posts: 2,620 ■■■■■■■■□□I run snort via the auditor live CD, who's logo happens to be the same for this book:
http://www.amazon.com/Penetration-Testers-Open-Source-Toolkit/dp/B000FBHNGI
I recommend it.CCNP | CCIP | CCDP | CCNA, CCDA
CCNA Security | GSEC |GCFW | GCIH | GCIA
pbosworth@gmail.com
http://twitter.com/paul_bosworth
Blog: http://www.infosiege.net/ -
rossonieri#1 Member Posts: 799 ■■■□□□□□□□hi Sie,
there 2 distros of Snort :
1 that from this : http://www.snort.org
2 from this : http://snort-inline.sourceforge.net
the 1 that came from snort.org can be run as IDS/sniff and IPS/inline,
and the one that came from snort_inline which only runs in IPS/inline mode - incorporates a little different signature and config from the snort.org release.
by default Snort runs in GUI - unless you want to manage it with IDS Policy Manager from this : http://www.activeworx.org/programs/idspm
there are many graphical stat utility like BASE, ACID etc.
ps :
if you want to try inline - heres the link to great docs :
part I : http://linuxgazette.net/117/savage.html
part II : http://linuxgazette.net/118/savage.html
cheers.the More I know, that is more and More I dont know.