Unit 6: Snort 6.1 Snort Snort Sniffer and Packet Logger Demos

>> I've opened up a Windows command line interface as administrator
and navigated to the C snort bin directory.
Let's type snort dash H. We'll pipe it some more to see the snort help.
In this demo, we're going to use dash D, dump the application layer.
Dash E, display the second layer header info.
Dash I, listen on interface.
Dash V, be verbose.
And dash uppercase W, lists available interfaces.
[silence]
We're going to use snort in sniffer mode to capture packets
from the network and send output to the console.
Snort dash uppercase W shows us a list of interfaces to choose from.
I'm going to pick interface three.
Snort dash V dash I3.
We'll start snort with verbose output from interface three.
[silence]
No preprocessors configured for policy zero is just a warning.
We'll enable preprocessors later.
I'm going to open up another Windows command line interface.
Observe the captured packets.
[silence]
We're going to send a continuous ping to the Google public DNS server.
[silence]
Notice the information being displayed by snort.
[silence]
We're going to press control C to stop and analyze the results.
[silence]
This time we'll add the D option to dump the application layer data.
Our continuous ping is still going.
Notice the letters of the alphabet, the 32 bytes of data sent by Windows in an ICMP echo request.
[silence]
This time we'll run it with the E option, which is used to display the second layer header info.
Our continuous ping is still going.
[silence]
Notice the MAC addresses and other layer two information displayed.
[silence]

 

Snort Packet Logger Mode

>> With our continuous ping still running --
-- let's use the L option, log to directory to run snort in packet logger mode.
[silence]
We're also going to open up a browser and go to www.rit.edu.
[silence]
Let's stop this with control C and go to C snort log.
We're going to open up this file with Wireshark.
[silence]
Snort has captured the packets.

转载于:https://www.cnblogs.com/sec875/articles/10028748.html

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值