<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>System Network Programming Solution - Linux - windows - centos- security- cpanel - plesk -directadmin helm&#187; snort</title>
	<atom:link href="http://thegioinguonmo.com/tag/snort/feed/" rel="self" type="application/rss+xml" />
	<link>http://thegioinguonmo.com</link>
	<description>SHARING EVERYTHING</description>
	<lastBuildDate>Mon, 06 Feb 2012 09:45:09 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Intrusion Detection With BASE And Snort &#8211; Part4</title>
		<link>http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part4.html</link>
		<comments>http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part4.html#comments</comments>
		<pubDate>Sun, 25 Dec 2011 04:40:41 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[centos]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[setup]]></category>
		<category><![CDATA[snort]]></category>
		<category><![CDATA[Submit Query]]></category>

		<guid isPermaLink="false">http://thegioinguonmo.com/?p=48</guid>
		<description><![CDATA[BASE web page setup Open your favorite web browser and go to: http://www.example.com/base-1.2.5/setup If all is setup okay you should see the BASE Setup Program page: Click on Continue step 1 of 5: Enter the path to ADODB (/var/www/adodb): click on Submit Query step 2 of 5: Enter the needed info on the next screen: [...]]]></description>
			<content:encoded><![CDATA[<h3>BASE web page setup</h3>
<p>Open your favorite web browser and go to: http://www.example.com/base-1.2.5/setup<br />
If all is setup okay you should see the BASE Setup Program page:</p>
<p><img src="http://static.howtoforge.com/images/snort_base_debian/base0.png" alt="base0 Intrusion Detection With BASE And Snort   Part4" width="550" height="207" title="Intrusion Detection With BASE And Snort   Part4" /></p>
<p><strong>Click on Continue</strong></p>
<p><strong>step 1 of 5</strong>:<br />
Enter the path to ADODB (/var/www/adodb):</p>
<p><img src="http://static.howtoforge.com/images/snort_base_debian/base1.png" alt="base1 Intrusion Detection With BASE And Snort   Part4" width="550" height="141" title="Intrusion Detection With BASE And Snort   Part4" /><br />
<strong>click on Submit Query</strong></p>
<p><strong>step 2 of 5:</strong><br />
Enter the needed info on the next screen: (leave the Use Archive Database as is):</p>
<p><img src="http://static.howtoforge.com/images/snort_base_debian/base2.png" alt="base2 Intrusion Detection With BASE And Snort   Part4" width="550" height="330" title="Intrusion Detection With BASE And Snort   Part4" /><br />
<strong>click on Submit Query</strong></p>
<p><strong>step 3 of 5:</strong><br />
If you want to Use Authentication for the Base page you can do so here:</p>
<p><img src="http://static.howtoforge.com/images/snort_base_debian/base3.png" alt="base3 Intrusion Detection With BASE And Snort   Part4" width="550" height="188" title="Intrusion Detection With BASE And Snort   Part4" /></p>
<p><strong>click on Submit Query</strong></p>
<p><strong>step 4 of 5:</strong><br />
Click on Create BASE AG to create the database.</p>
<p><img src="http://static.howtoforge.com/images/snort_base_debian/base4a.png" alt="base4a Intrusion Detection With BASE And Snort   Part4" width="550" height="104" title="Intrusion Detection With BASE And Snort   Part4" /><br />
and after Create BASE AG<br />
<img src="http://static.howtoforge.com/images/snort_base_debian/base4b.png" alt="base4b Intrusion Detection With BASE And Snort   Part4" width="550" height="280" title="Intrusion Detection With BASE And Snort   Part4" /></p>
<p>Once done, click on Now continue to step 5&#8230;</p>
<p><img src="http://static.howtoforge.com/images/snort_base_debian/base5.png" alt="base5 Intrusion Detection With BASE And Snort   Part4" width="550" height="410" title="Intrusion Detection With BASE And Snort   Part4" /></p>
<p>To make the Graph&#8217;s from BASE work you will also need to install Image_Color, Image_Canvas and Image_Graph.<br />
To do this do:</p>
<p>pear install Image_Color<br />
pear install Image_Canvas-alpha<br />
pear install Image_Graph-alpha</p>
<p>That it for BASE!</p>
<p>If you want you can chmod the base-1.2.5 dir back to 775:</p>
<p>chmod 775 base-1.2.5</p>
<p>You can also delete the snorttemp directory, and all the files in it.</p>
<h3>Starting Snort</h3>
<p>To start SNORT and make BASE show you the Snort&#8217;s logged info, you will need to run:</p>
<p>/usr/local/bin/snort -c /etc/snort/snort.conf -i eth0 -g root -D</p>
<p>Now wait some time and see all the Snort alerts show up in BASE.</p>
<p><img src="http://static.howtoforge.com/images/snort_base_debian/alerts.png" alt="alerts Intrusion Detection With BASE And Snort   Part4" width="550" height="408" title="Intrusion Detection With BASE And Snort   Part4" /></p>
<h3>Links</h3>
<ul>
<li>BASE: <a rel="nofollow" target="_blank" href="http://secureideas.sourceforge.net/" target="_blank">http://secureideas.sourceforge.net</a></li>
<li>Snort: <a rel="nofollow" target="_blank" href="http://www.snort.org/" target="_blank">http://www.snort.org</a></li>
</ul>
<h4>Incoming search terms:</h4><ul><li><a href="http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part4.html" title="plesk snort how to">plesk snort how to</a> (1)</li><li><a href="http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part4.html" title="setup snort and base">setup snort and base</a> (1)</li><li><a href="http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part4.html" title="snort on plesk server">snort on plesk server</a> (1)</li><li><a href="http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part4.html" title="snort with plesk">snort with plesk</a> (1)</li></ul>]]></content:encoded>
			<wfw:commentRss>http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part4.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Intrusion Detection With BASE And Snort &#8211; Part3</title>
		<link>http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part3.html</link>
		<comments>http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part3.html#comments</comments>
		<pubDate>Sat, 24 Dec 2011 16:40:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[centos]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[snort]]></category>

		<guid isPermaLink="false">http://thegioinguonmo.com/?p=46</guid>
		<description><![CDATA[Installing Lets start with: LIBPCAP. Make sure that you are in the directory that you downloaded all files. cd /root/snorttemp cd into the libcap map: cd libpcap-0.9.4 and make / install LIBPCAP: ./configure make make install Next is PCRE. Again, make sure that you are in the directory that you downloaded all files. cd /root/snorttemp [...]]]></description>
			<content:encoded><![CDATA[<h3>Installing</h3>
<p>Lets start with: LIBPCAP.<br />
Make sure that you are in the directory that you downloaded all files.</p>
<p>cd /root/snorttemp</p>
<p>cd into the libcap map:</p>
<p>cd libpcap-0.9.4</p>
<p>and make / install LIBPCAP:</p>
<p>./configure<br />
make<br />
make install</p>
<p>Next is PCRE.<br />
Again, make sure that you are in the directory that you downloaded all files.</p>
<p>cd /root/snorttemp</p>
<p>cd into the PCRE map:</p>
<p>cd pcre-6.3</p>
<p>and make / install pce-6.3</p>
<p>./configure<br />
make<br />
make install</p>
<p>Now it time for Snort:<br />
Make sure that you are in the directory that you downloaded all files.</p>
<p>cd /root/snorttemp</p>
<p>cd into the snort map:</p>
<p>cd snort-2.6.0</p>
<p>and make / install Snort with some extra needed options!</p>
<p>./configure &#8211;enable-dynamicplugin &#8211;with-mysql<br />
make<br />
make install</p>
<p>Snort needs some maps, so letâ€™s create them:</p>
<p>mkdir /etc/snort<br />
mkdir /etc/snort/rules<br />
mkdir /var/log/snort</p>
<p>Moving the Snort files from the installation map to the just created maps.<br />
Make sure that you are in the directory that you downloaded all files.</p>
<p>cd /root/snorttemp</p>
<p>and cd into snort-2.6.0:</p>
<p>cd snort-2.6.0</p>
<p>and into the rules</p>
<p>cd rules</p>
<p>now we copy all files from the /rules into /etc/snort/rules</p>
<p>cp * /etc/snort/rules</p>
<p>We will do the same for the files in the install /etc folder:</p>
<p>cd ../etc<br />
cp * /etc/snort</p>
<h3>Fixing the snort.conf</h3>
<p>The /etc/snort/snort.conf needs some tuning to get it to work on your system!<br />
So cd into /etc/snort:</p>
<p>cd /etc/snort</p>
<p>and open snort.conf with nano (or any other &#8216;text&#8217; editor)</p>
<p>nano snort.conf</p>
<p>change &#8220;var HOME_NET any&#8221; to &#8220;var HOME_NET <strong>192.168.0.5/32</strong>&#8221;<br />
change &#8220;var EXTERNAL_NET any&#8221; to &#8220;var EXTERNAL_NET <strong>!$HOME_NET</strong>&#8221;<br />
change &#8220;var RULE_PATH ../rules&#8221; to &#8220;var RULE_PATH <strong>/etc/snort/rules</strong>&#8221;</p>
<p>As we made snort with the &#8216;&#8211;with-mysql&#8217; option and as BASE needs it, we also need to tell Snort what database to use.<br />
Scroll down till you see &#8220;<strong># output database</strong>&#8220;, and <strong>remove</strong> the <strong>#</strong> in front of the line for the MySQL.<br />
Now also change the &#8220;<strong>user</strong>&#8220;, &#8220;<strong>password</strong>&#8221; and &#8220;<strong>dbname</strong>&#8220;. <img src="http://static.howtoforge.com/images/snort_base_debian/hint.gif" alt="hint Intrusion Detection With BASE And Snort   Part3" width="16" height="16" align="texttop" title="Intrusion Detection With BASE And Snort   Part3" /> Make a note of this as you will need it later!<br />
Save the file and close &#8216;nano&#8217;</p>
<h3>Setting up the MySQL Database for Snort.</h3>
<p>There are many ways to create the snort database.<br />
The table layout can be found in the file create_mysql in the /root/snorttemp/snort-2.6.0/schemas directory.<br />
Whichever way you create the database, make sure the <strong>&#8216;user&#8217;</strong>, <strong>&#8216;password&#8217;</strong> and <strong>&#8216;dbame&#8217;</strong> are the same as the one you set in the /etc/snort/snort.conf file!</p>
<p>After creating you can test snort and see if you get any errors with:</p>
<p>snort -c /etc/snort/snort.conf</p>
<p>Exit the test with <strong>Ctrl+C</strong></p>
<p>If you get no error&#8217;s Snort is setup correct.</p>
<h3>Moving ADOdb and BASE</h3>
<p>Moving ADOdb:<br />
cd back to the download dir</p>
<p>cd /root/snorttemp/</p>
<p>and move adodb it to the root of the www map:</p>
<p>mv adodb /var/www</p>
<p>Next: BASE (Basic Analysis and Security Engine )<br />
Still in the download dir, we move the base dir into the 1st website map that you create with ISPconfig.</p>
<p>mv base-1.2.5 /var/www/www.example.com/web</p>
<p>and cd into /var/www/www.example.com/web</p>
<p>cd /var/www/www.example.com/web</p>
<p>To enable BASE to write the setup file we need to chmod the base-1.2.5 folder to 757:</p>
<p>chmod 757 base-1.2.5</p>
<h4>Incoming search terms:</h4><ul><li><a href="http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part3.html" title="snort base">snort base</a> (2)</li><li><a href="http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part3.html" title="do an snort">do an snort</a> (1)</li><li><a href="http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part3.html" title="install snort">install snort</a> (1)</li><li><a href="http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part3.html" title="mysql -u root -p -d snort &lt; create_mysql in freebsd">mysql -u root -p -d snort &lt; create_mysql in freebsd</a> (1)</li></ul>]]></content:encoded>
			<wfw:commentRss>http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part3.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Intrusion Detection With BASE And Snort &#8211; Part2</title>
		<link>http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part2.html</link>
		<comments>http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part2.html#comments</comments>
		<pubDate>Sat, 24 Dec 2011 04:40:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[centos]]></category>
		<category><![CDATA[download]]></category>
		<category><![CDATA[LIBPCAP]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[rm]]></category>
		<category><![CDATA[root]]></category>
		<category><![CDATA[snort]]></category>

		<guid isPermaLink="false">http://thegioinguonmo.com/?p=44</guid>
		<description><![CDATA[LIBPCAP Go to: http://www.tcpdump.org/ and select a download link for Libpcap (at time of writing this it is libpcap-0.9.4.tar.gz) cd back to the snorttemp map: cd /root/snorttemp and download the libpcap-0.9.4.tar.gz file: wget http://www.tcpdump.org/release/libpcap-0.9.4.tar.gz Untar the file: tar -xvzf libpcap-0.9.4.tar.gz Remove the file: rm libpcap-0.9.4.tar.gz BASE (Basic Analysis and Security Engine ) Go to: http://secureideas.sourceforge.net/ [...]]]></description>
			<content:encoded><![CDATA[<h4>LIBPCAP</h4>
<p>Go to: <a rel="nofollow" target="_blank" href="http://www.tcpdump.org/" target="_blank">http://www.tcpdump.org/</a> and select a download link for Libpcap (at time of writing this it is libpcap-0.9.4.tar.gz)<br />
cd back to the snorttemp map:</p>
<p>cd /root/snorttemp</p>
<p>and download the libpcap-0.9.4.tar.gz file:</p>
<p>wget http://www.tcpdump.org/release/libpcap-0.9.4.tar.gz</p>
<p>Untar the file:</p>
<p>tar -xvzf libpcap-0.9.4.tar.gz</p>
<p>Remove the file:</p>
<p>rm libpcap-0.9.4.tar.gz</p>
<h4>BASE (Basic Analysis and Security Engine )</h4>
<p>Go to: <a rel="nofollow" target="_blank" href="http://secureideas.sourceforge.net/" target="_blank">http://secureideas.sourceforge.net/</a> and download the latest release (at time of writing BASE 1.2.5 (sarah))<br />
cd back to the snorttemp map:</p>
<p>cd /root/snorttemp</p>
<p>and download the base-1.2.5.tar.gz file:</p>
<p>wget http://surfnet.dl.sourceforge.net/sourceforge/secureideas/base-1.2.5.tar.gz</p>
<p>Untar the file:</p>
<p>tar -xvzf base-1.2.5.tar.gz</p>
<p>Remove the file:</p>
<p>rm base-1.2.5.tar.gz</p>
<h4>ADOdb: (ADOdb Database Abstraction Library for PHP (and Python).)</h4>
<p>Go to: <a rel="nofollow" target="_blank" href="http://adodb.sourceforge.net/" target="_blank">http://adodb.sourceforge.net/</a> and download the latest release (at time of writing adodb-490-for-php)<br />
cd back to the snorttemp map:</p>
<p>cd /root/snorttemp</p>
<p>and download the adodb490.tgz file:</p>
<p>wget http://surfnet.dl.sourceforge.net/sourceforge/adodb/adodb490.tgz</p>
<p>Untar the file:</p>
<p>tar -xvzf adodb490.tgz</p>
<p>Remove the file:</p>
<p>rm adodb490.tgz</p>
<p>ls should now show the following directorys in /root/snorttemp:<br />
adodb, base-1.2.5, libpcap-0.9.4, pcre-6.3 and snort-2.6.0</p>
<p><img src="http://static.howtoforge.com/images/snort_base_debian/ls.gif" alt="ls Intrusion Detection With BASE And Snort   Part2" width="480" height="93" title="Intrusion Detection With BASE And Snort   Part2" /></p>
<h4>Incoming search terms:</h4><ul><li><a href="http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part2.html" title="adodb adodb490 tgz">adodb adodb490 tgz</a> (1)</li><li><a href="http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part2.html" title="pcap linux Intrusion">pcap linux Intrusion</a> (1)</li><li><a href="http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part2.html" title="PCAP linux cpanel">PCAP linux cpanel</a> (1)</li><li><a href="http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part2.html" title="openvz intrusion">openvz intrusion</a> (1)</li><li><a href="http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part2.html" title="nginx intrusion detection system">nginx intrusion detection system</a> (1)</li><li><a href="http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part2.html" title="nginx intrusion detection">nginx intrusion detection</a> (1)</li><li><a href="http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part2.html" title="linux intrusion solution">linux intrusion solution</a> (1)</li><li><a href="http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part2.html" title="install snort openvz">install snort openvz</a> (1)</li><li><a href="http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part2.html" title="adodb490 tgz">adodb490 tgz</a> (1)</li><li><a href="http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part2.html" title="snort openvz">snort openvz</a> (1)</li></ul>]]></content:encoded>
			<wfw:commentRss>http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part2.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Intrusion Detection With BASE And Snort &#8211; Part1</title>
		<link>http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part1.html</link>
		<comments>http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part1.html#comments</comments>
		<pubDate>Mon, 28 Nov 2011 04:45:48 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[centos]]></category>
		<category><![CDATA[download]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[root]]></category>
		<category><![CDATA[snort]]></category>
		<category><![CDATA[wget]]></category>

		<guid isPermaLink="false">http://thegioinguonmo.com/?p=42</guid>
		<description><![CDATA[This tutorial shows how to install and configure BASE (Basic Analysis and Security Engine) and the Snort intrusion detection system (IDS) on a Debian Sarge system. BASE provides a web front-end to query and analyze the alerts coming from a Snort IDS system. With BASE you can perform analysis of intrusions that Snort has detected [...]]]></description>
			<content:encoded><![CDATA[<p>This tutorial shows how to install and configure BASE (Basic Analysis and Security Engine) and the Snort intrusion detection system (IDS) on a Debian Sarge system. BASE provides a web front-end to query and analyze the alerts coming from a Snort IDS system. With BASE you can perform analysis of intrusions that Snort has detected on your network.</p>
<p>Scenario: A linux server running Debian Sarge 3.1 setup according to <a rel="nofollow" target="_blank" href="http://www.howtoforge.com/perfect_setup_debian_sarge">Falko&#8217;s &#8211; The Perfect Setup &#8211; Debian Sarge (3.1)</a>.<br />
Let&#8217;s assume we have one working website (www.example.com) and that the document root is: /var/www/www.example.com/web<br />
The IP of the server is 192.168.0.5 and it&#8217;s using eth0 as network interface name.</p>
<h3>Needed programs and files</h3>
<ul>
<li>Snort</li>
<li>Snort rules</li>
<li>PCRE (Perl Compatible Regular Expressions)</li>
<li>LIBPCAP</li>
<li>BASE (Basic Analysis and Security Engine)</li>
<li>ADOdb (ADOdb Database Abstraction Library for PHP (and Python).)</li>
</ul>
<h3>Downloading and untaring</h3>
<p>We need a temporary place for all the files that we are going to download, and untar.<br />
To keep things simple we will create a directory in the /root named snorttemp. (It&#8217;s obvious that this download directory can be any name and in anyplace)</p>
<p>cd /root<br />
mkdir snorttemp<br />
cd snorttemp</p>
<p>Now you need to get Snort.<br />
The latest version at the time of writing this is 2.6.0</p>
<p>wget http://www.snort.org/dl/current/snort-2.6.0.tar.gz</p>
<p>When the download is finished untar the file:</p>
<p>tar -xvzf snort-2.6.0.tar.gz</p>
<p>And letâ€™s remove the tar file:</p>
<p>rm snort-2.6.0.tar.gz</p>
<p>We also need the Snort rules!<br />
Go to: <a rel="nofollow" target="_blank" href="http://www.snort.org/pub-bin/downloads.cgi" target="_blank">http://www.snort.org/pub-bin/downloads.cgi</a> and scroll down till you see the &#8220;Sourcefire VRT Certified Rules &#8211; The Official Snort Ruleset (unregistered user release)&#8221; rules<br />
(If you are a member of the forum you can also download the &#8211; registered user release):</p>
<p>wget http://www.snort.org/pub-bin/downloads.cgi/Download/vrt_pr/snortrules-pr-2.4.tar.gz</p>
<p>Move the snortrules-pr-2.4.tar.gz into the snort-2.6.0 map:</p>
<p>mv snortrules-pr-2.4.tar.gz /root/snorttemp/snort-2.6.0</p>
<p>and cd into snort-2.6.0:</p>
<p>cd snort-2.6.0</p>
<p>Untar the snortrules-pr-2.4.tar.gz file:</p>
<p>tar -xvzf snortrules-pr-2.4.tar.gz</p>
<p>Remove the tar file:</p>
<p>rm snortrules-pr-2.4.tar.gz</p>
<p>We are done downloading the files needed to get Snort to work.</p>
<p>To make snort work with BASE, we need more!</p>
<h4>PCRE &#8211; Perl Compatible Regular Expressions.</h4>
<p>Go to: <a rel="nofollow" target="_blank" href="http://www.pcre.org/" target="_blank">http://www.pcre.org/</a> and select a download link for the pcre-6.3tar.gz file to download PCRE (at time of writing this it is pcre-6.3.tar.gz)<br />
cd back to the snorttemp map:</p>
<p>cd /root/snorttemp</p>
<p>and download the pcre-6.3.tar.gz file:</p>
<p>wget http://surfnet.dl.sourceforge.net/sourceforge/pcre/pcre-6.3.tar.gz</p>
<p>Untar the file:</p>
<p>tar -xvzf pcre-6.3.tar.gz</p>
<p>Remove the tar:</p>
<p>rm pcre-6.3.tar.gz</p>
<h4>Incoming search terms:</h4><ul><li><a href="http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part1.html" title="centos snort rules 2 4 download">centos snort rules 2 4 download</a> (1)</li><li><a href="http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part1.html" title="DirectAdmin spamassassin CentOS 5 0">DirectAdmin spamassassin CentOS 5 0</a> (1)</li><li><a href="http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part1.html" title="front end snort">front end snort</a> (1)</li><li><a href="http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part1.html" title="snort rule regulra ex">snort rule regulra ex</a> (1)</li><li><a href="http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part1.html" title="wget script sourcefire">wget script sourcefire</a> (1)</li></ul>]]></content:encoded>
			<wfw:commentRss>http://thegioinguonmo.com/os/linux/intrusion-detection-with-base-and-snort-part1.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Served from: thegioinguonmo.com @ 2012-02-07 10:52:19 -->
