在Ubuntu上安装Snort及配置已经不止一次了,也参考了不少文章,故写下此经验总结:
主要参考http://www.howtoforge.com/intrusion-detection-with-snort-mysql-apache2-on-ubuntu-7.10
因为以上网址说的非常详细,所以只说说我在安装配置过程中遇到的问题。
Ps:在我们开发Snort时,需要在配置阶段添加参数: ./configure --enable-dynamicplugin --enable-debug --with-mysql
1、在12. Time to test Snort中可能会出现“detection”要二选一,直接编辑snort.conf(273行)注释其中一个detection
2、同时要注释snort.conf内所有dynamicdetection的相关行
3、然后在最后"14. BASE Setup via the web."访问localhost/www/web/base-1.3.8会出现
Warning: include_once(Mail.php) [function.include-once]: failed to open stream: No such file or directory in /var/www/web/base-php4/includes/base_action.inc.php on line 29
Warning: include_once() [function.include]: Failed opening 'Mail.php' for inclusion (include_path='.:/usr/share/php') in /var/www/web/base-php4/includes/base_action.inc.php on line 29
Warning: include_once(Mail/mime.php) [function.include-once]: failed to open stream: No such file or directory in /var/www/web/base-php4/includes/base_action.inc.php on line 30
Warning: include_once() [function.include]: Failed opening 'Mail/mime.php' for inclusion (include_path='.:/usr/share/php') in /var/www/web/base-php4/includes/base_action.inc.php on line 30
Warning: Cannot modify header information - headers already sent by (output started at /var/www/web/base-php4/includes/base_action.inc.php:29) in /var/www/web/base-php4/base_common.php on line 1077
解决方法:
It was resolve by installing the following:
pear install Mail
pear install Mail_Mime
4、在语言界面选择上有可能出现simplechinese的问题:只要将simplechinese.php最后一行的空行去掉即可