The Open Source Network
Intrusion Detection System
Por Alex Rodrigues - alex(arroba)bsbnet.com
e Paulo Sergio -
pauloss@brfree.com.br
Atualizado em
27/02/2006 10:02
Links relativos ao Snort (Links about Snort)
Snort - www.snort.org
Apache - http://www.apache.org/
OpenSSL - http://www.openssl.org/
MOD SSL - http://www.modssl.org/
Acid - http://www.andrew.cmu.edu/~rdanyliw/snort/snortacid.html
Aanval Console - Snort IDS Console - http://www.aanval.com
MySql - http://www.mysql.com/ - http://mysql.mirror.anlx.net/Downloads/MySQL-3.23/
AdoDB - http://php.weblogs.com/adodb
PhPlot - http://www.phplot.com
SnortSnarf - http://www.silicondefense.com/software/snortsnarf/
WhiteHats - www.whitehats.com
PHP - http://www.php.net/
Perl - http://perl.apache.org
Demarc - www.demarc.org
Estatísticas do Snort - http://www.lug-burghausen.org/projects/index.html#snort-stat
Snort WebMin Interface - http://msbnetworks.net/snort/
SnortReport - http://www.circuitsmaximus.com
JPGraph - www.aditus.nu/jpgraph
Scanners de vulnerabilidades
Stealth Http Scanner - http://www.hideaway.net/Server_Security/Software/Stealth/stealth.html
Languard - www.languard.com
Cabo UTP para Sniffers - http://personal.ie.cuhk.edu.hk/~msng0/sniffing_cable/index.htm
HogWash - http://hogwash.sourceforge.net
PHP MySQL Admin - http://www.phpmyadmin.net/index.php?dl=2
PHP Nuke:
Ntop - http://voxel.dl.sourceforge.net/sourceforge/ntop/ntop-3.0.tgz
Wireless
Netstumbler - http://www.netstumbler.com/download.php?op=getit&lid=22
Ferramentas: http://www.networkintrusion.co.uk/wireless.htm
1 - Instale o Red Hat 7.3 com a opção padrão, escolhendo server, sem módulos adicionais e sem regras de firewall.
2 - Download - Baixe todos esses arquivos para o diretório /tmp.
Programa Principal
Vision Snort Rules - http://www.whitehats.com/ids/vision18.conf.gz
Snort Rules - http://www.snort.org/dl/rules/snortrules-stable.tar.gz
Programas dependentes (dependents software and modules)
AdoDB - http://internap.dl.sourceforge.net/sourceforge/adodb/adodb454.tgz
PhPlot - http://cesnet.dl.sourceforge.net/sourceforge/phplot/phplot-4.4.6.tar.gz
Gd- http://www.boutell.com/gd/http/gd-2.0.28.tar.gz ou http://www.boutell.com/gd/http/gd-1.8.4.tar.gz
Acid - http://www.andrew.cmu.edu/~rdanyliw/snort/acid-0.9.6b23.tar.gz
JPGraph - http://members.chello.se/jpgraph/jpgdownloads/jpgraph-1.16.tar.gz
MySQL
http://downloads.mysql.com/archives/mysql-3.23/MySQL-3.23.48-1.i386.rpm
http://downloads.mysql.com/archives/mysql-3.23/MySQL-client-3.23.48-1.i386.rpm
http://downloads.mysql.com/archives/mysql-3.23/MySQL-devel-3.23.48-1.i386.rpm
http://downloads.mysql.com/archives/mysql-3.23/MySQL-shared-3.23.48-1.i386.rpm
Gerenciadores do Snort
SnortReport - http://www.circuitsmaximus.com/snortreport/snortreport-1.11.tar.gz
SnortSnarf - http://www.snort.org/downloads/SnortSnarf-010821.1.tar.gz
Demarc - http://www.demarc.org/downloads/demarc-105/demarc-1.05-RC1.tar.gz
SnortSnarf - http://www.silicondefense.com/software/snortsnarf/SnortSnarf-010821.1.tar.gz
Analizadores de Tráfego
3 - Instale o Mysql nesta ordem usando o package manager:
MySQL-3.23/MySQL-3.23.48-1.i386.rpm
MySQL-client-3.23.48-1.i386.rpm
MySQL-devel-3.23.48-1.i386.rpm
MySQL-shared-3.23.48-1.i386.rpm
4 - Instale o LIBPCAP
5 - Instale o Snort
6 - Prepare o mysql para trabalhar com o snort.
7 - Instale o apache e PHP4.
8 - Instale a Interface Acid
9 - Execute o snort