SNORT Workshop : How to Install, Configure, and Create Rules

  Рет қаралды 55,243

Hack eXPlorer

Hack eXPlorer

Күн бұрын

In this series of lab exercises, we will demonstrate various techniques in writing Snort rules, from basic rules syntax to writing rules aimed at detecting specific types of attacks. We will also examine some basic approaches to rules performance analysis and optimization.
Rules and commands used
SNORPY
snorpy.com/
github.com/chr...
handlers.sans....
#Snort #CyberHomeLab #IDS

Пікірлер: 98
@cybercdh
@cybercdh 3 жыл бұрын
Fantastic video; such a clear explanation, great detail, well paced and really easy to follow along. Nice work! Looking forward to seeing more content.
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
Thank you colin, your work was an inspiration, for starting this 😁
@syedaliameer9301
@syedaliameer9301 2 жыл бұрын
I have seen more than 10 videos on youtube but none matches with yours. The ease of explanation has literally saved a lot of my time. Thanks u. Subscribed & waiting for more and more future contenct. Please make a series on Splunk & Linux rules if possible
@Generation-VisionNouvelle
@Generation-VisionNouvelle 2 жыл бұрын
Amazing Explanation. Good Job ! You just got another subscriber.
@manuareraa5395
@manuareraa5395 3 жыл бұрын
The tutorial was really good, especially for beginners.
@jeremiahdurotola5921
@jeremiahdurotola5921 3 жыл бұрын
Brilliant, absolutely brilliant. Best explanation ever.
@No-nw2gi
@No-nw2gi 3 жыл бұрын
thank you so much for your tutorial, it was extremely helpful
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
You are welcome 👍
@ukeshsai2140
@ukeshsai2140 2 жыл бұрын
Thanks for the clear explanation. Can you please advice, how can we trigger mail or something once we detected threads
@kevmeister1234
@kevmeister1234 4 жыл бұрын
Excellent Video, thanks very much. Very engaging and informative, and I learnt a lot! Thanks.
@HackeXPlorer
@HackeXPlorer 4 жыл бұрын
Thankyou for the feedback kevin.
@itsmejithinpjose
@itsmejithinpjose 3 жыл бұрын
Very easy to understand. Thank you so much!
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
Thankyou for the feedback 👍
@kanavgandhi9120
@kanavgandhi9120 2 жыл бұрын
Very well explained! Thank you sir
@sarahal-shehri6494
@sarahal-shehri6494 Жыл бұрын
You are a lifesaver thank you so much
@darkness3038
@darkness3038 2 жыл бұрын
Thank you very much for the video ! I have a question : where can I get your PPT please ?
@selvin9845
@selvin9845 2 жыл бұрын
Will this work actively in real time?... So could you be running any Snort rule in the background while you're working on something else on you computer? CAN YOU GET OPERATING SYSTEM FINGERPRINT FROM SOURCE IP? CAN YOU TRACE THE SOURCE IP?
@sappanyou4jesus
@sappanyou4jesus 3 жыл бұрын
Thank you for teaching Can I have a guide or slides of installation and tutorials on KZbin?
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
Yes, soon
@sappanyou4jesus
@sappanyou4jesus 3 жыл бұрын
@@HackeXPlorer Thanks, I'll wait and see.
@vedxcas3981
@vedxcas3981 2 жыл бұрын
Very well explained! Really cleared my queries : )
@hectorvido
@hectorvido 2 жыл бұрын
This was extremely useful, thank you!
@kushagravarma8
@kushagravarma8 Жыл бұрын
Hi ! Thanks for the tutorial , I have been trying to listen on the port 1883 . but nothing seems to work , could you please help I want to detect mqtt protocol via snort
@vbarval
@vbarval 4 жыл бұрын
Nice video and learn a lot about Snort. Could you please make the next video on NIPS so we can learn about how to prevent attack? Thank you so much!
@HackeXPlorer
@HackeXPlorer 4 жыл бұрын
Hi Vineet, actually Snort can work as an IPS or and IDS, its only where and how you setup in the network. Check the following document. www.snort.org › documentsPDF Snort IPS Tutorial
@vbarval
@vbarval 3 жыл бұрын
@@HackeXPlorer Awesome. Thank you!
@flopfliepvlier
@flopfliepvlier 3 жыл бұрын
When I go to /var/log/snort, my local address folder with the logs is not there. Also when I do something else on my local network, nothing pops up. Only when I do something on the VM where snort is installed that I get output. Do you maybe know why? Also very usefull video, super easy to understand and well explained!
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
I think your VM network mode is "local host only", you have change it to bridged mode. However this will still not work, as all your traffic will not be passed to the snort ip. This is a network levval configuration. You might need to buy a special switch Google about span port/traps You will get the idea 💡
@To-mos
@To-mos 3 жыл бұрын
6:10 "sudo !!" will save you some time
@techtat4333
@techtat4333 3 жыл бұрын
Thankyou for the great explanation. I need some advice, when i install and run snort this comes up " Could not get lock /var/lib/dpkg/lock-frontend - open (11: Resource temporarily unavailable) Unable to acquire the dpkg frontend lock (/var/lib/dpkg/lock-frontend), is another process using it? What should i do ? :/
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
You can do couple of things Sun the command with SUDO im front. Or simply reboot and try again. It will work
@shwetamittal2971
@shwetamittal2971 3 жыл бұрын
Thank you for such a good content. Where I can find your slides?
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
Thanks Shwetha, ill post the slide on my site soon. Hackexplorer.net
@kanizfatema3814
@kanizfatema3814 3 жыл бұрын
@@HackeXPlorer excellent video, very well organised and provided details. I was also looking for the slides please.
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
@@kanizfatema3814 www.slideshare.net/HishanShouketh/snort-home-lab-workshop
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
www.slideshare.net/HishanShouketh/snort-home-lab-workshop
@kanizfatema3814
@kanizfatema3814 3 жыл бұрын
@@HackeXPlorer Thank you so much. You are an amazing teacher
@xbaleks4609
@xbaleks4609 2 жыл бұрын
thanks for this tutorial, nice workk !
@HackeXPlorer
@HackeXPlorer 2 жыл бұрын
Thanks 🙏
@manfrombritain6816
@manfrombritain6816 2 жыл бұрын
perfection
@danu45924
@danu45924 4 жыл бұрын
Great session
@HackeXPlorer
@HackeXPlorer 4 жыл бұрын
Thankyou Nadeev.
@roshansha7937
@roshansha7937 2 жыл бұрын
My case sniffing interface configuration menu not appears, when installation going on there is default interface is not set
@Archer797
@Archer797 2 жыл бұрын
I followed the video carefully but when I try to test the snort.conf file, I get the following error. Log Directory is getting set as eth0. I checked in the snort.conf file and set the path for "config logdir:" as /var/log/snort. This is not helping. Log directory = eth0 ERROR: OpenAlertFile() => fopen() alert file eth0/snort.alert.fast: No such file or directory Fatal Error, Quitting..
@donpetts9626
@donpetts9626 3 жыл бұрын
Great video... thank you :)
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
You are welcome
@SuperChelseaSW6
@SuperChelseaSW6 4 жыл бұрын
Nice content sir. Is there a snort appliance hardware to deploy in real world?
@HackeXPlorer
@HackeXPlorer 4 жыл бұрын
The Snort IPS feature enables Intrusion Prevention System (IPS) or Intrusion Detection System (IDS) for branch offices on Cisco 4000 Series Integrated Services Routers and Cisco Cloud Services Router 1000v Series. This feature uses the open source Snort solution to enable IPS and IDS
@SuperChelseaSW6
@SuperChelseaSW6 4 жыл бұрын
@@HackeXPlorer what do u think on cisco firepower ?
@HackeXPlorer
@HackeXPlorer 4 жыл бұрын
@@SuperChelseaSW6 yes , its an NG (next gen ) firewall, the box offers more that firewall all functions.Stateful firewall, Application Visibility and Control, NGIPS, Advanced Malware Protection, URL filtering, DDos, also research on thr fortinet stuff
@silentmodesec
@silentmodesec 3 жыл бұрын
What a explanation!
@adilhussaingujjar
@adilhussaingujjar 3 жыл бұрын
i'm getting an error: "error spo_unified2.c(323) Couldn't open enp0s3/snort.log: no such file or directory"
@muhammadnoraiz615
@muhammadnoraiz615 3 жыл бұрын
Good effort
@CatKin76
@CatKin76 3 жыл бұрын
Fabulous video, it has helped me now I need to start simulating dos and ddos in vm environment using snort to show me how snort can detect or prevent attacks, do you have any videos to help with this ? :-) and thanks again this was really helpful
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
Ya i am planning on some videos
@hikmatullahkarimi5959
@hikmatullahkarimi5959 3 жыл бұрын
Great work
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
Thankyou Hikamath 👍
@ninaworld6174
@ninaworld6174 2 жыл бұрын
You work in windows or Linux? and can you do a video explain how we get the IP address from BD(BD connected with snort) by rqt t SQL in java 🥺..or can you help if you have time in my homework we can talk in social media if you have .. please
@ninaworld6174
@ninaworld6174 2 жыл бұрын
Please how can we linked snort with MySQL and create table (have IP Addresses)
@HackeXPlorer
@HackeXPlorer 2 жыл бұрын
Yup , this is possible . try the following www.hackers-arise.com/post/2018/05/29/snort-ids-for-hackers-part-3-sending-intrusion-alerts-to-mysql
@youcefchabane7922
@youcefchabane7922 3 жыл бұрын
thanks for this video, can you share a pdf documents of the process of installation, thanks very much
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
Here you go, this is a similar installation www.cloudsavvyit.com/6424/how-to-use-the-snort-intrusion-detection-system-on-linux/
@keshavrajput952
@keshavrajput952 2 жыл бұрын
That's nice but final step is not working . 😕 Snort does not give any alert when I try to put wrong password. Any idea ?
@HackeXPlorer
@HackeXPlorer 2 жыл бұрын
I think you are talking about the FTP password, check your rule again.
@manikdivya1412
@manikdivya1412 3 жыл бұрын
Hi Sir. Can you please make a video on how to drop the packets using snort on windows. I have tried the same but it says inline mode have to be enabled on windows. Which seems to be a pretty difficult task. Any help would be appreciated. Thanks.
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
Thankyou for the suggestion, let me check
@muruga403
@muruga403 4 жыл бұрын
Thanks
@HackeXPlorer
@HackeXPlorer 4 жыл бұрын
You are welcome Muvi.
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
@@khanjra you will find your answer here, snort use the file-image property to detect image files. and you can find it in any type of traffic. github.com/codecat007/snort-rules/blob/master/snortrules-snapshot-29150/rules/file-image.rules
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
@@khanjra here you go , alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"GIF File detected"; content:"GET"; content:".gif"; sid:1000005; rev:1;) - and in the git just serch for the file extention you will find many more examples like this.
@amithkumarthatikonda9249
@amithkumarthatikonda9249 3 жыл бұрын
@@khanjra hi meimoon
@amithkumarthatikonda9249
@amithkumarthatikonda9249 3 жыл бұрын
Can you help me with snort I have installed snort by giving network subnet to capture all traffic in our network bt it's not alerting for all the machines , it's alerting for the machine where I have installed snort do you any idea please
@argosctifl2457
@argosctifl2457 2 жыл бұрын
And the remote alert (email) ?
@dhrubasaha08
@dhrubasaha08 3 жыл бұрын
Hey I tried to use snort to prevent DDOS on my game server, I can't figure out how should I stop on a specific udp port!
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
Sorry, you cannot stop DDOS from this service. only dettect
@dhrubasaha08
@dhrubasaha08 3 жыл бұрын
@@HackeXPlorer okay ..could you please make a video on ddos protection! It's a huge headache in gameserver community(Rust,minecraft,csgo)..tgere is no solution available on internet....game server are very much prone to ddos...mostly hosted on linux based vm...but a lot of hosting providers do provide ddis protection .
@tanujpandey9870
@tanujpandey9870 3 жыл бұрын
Hello sir, the last rule of FTP failed login attempt is not giving an alert. Can you please help?
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
Share the rule here.
@jamesbond-cx2uh
@jamesbond-cx2uh 3 жыл бұрын
Stuck at commencing packet processing. Anyone has any idea how to solve this problem?
@NguyenCuong-rw9zr
@NguyenCuong-rw9zr 3 жыл бұрын
ERROR: Can't start DAQ (-1) - ens33: That device is not up! How can you fix?
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
www.linuxquestions.org/questions/linux-newbie-8/help-me-snort-error-can%27t-start-daq-1-socket-operation-not-permitted-4175634845/
@theleanman9558
@theleanman9558 2 жыл бұрын
Can anybody help me I can’t get snort to work at all on my Ubuntu system please reply if you can help
@wassemalaa-iddin9147
@wassemalaa-iddin9147 2 жыл бұрын
If anyone can help me, how can I save the output of the captured packets? thank you
@HackeXPlorer
@HackeXPlorer 2 жыл бұрын
Check the last part of this video itshows you how to save a capture using tcpdump kzbin.info/www/bejne/rqqpfYxnqMZ3npI
@kasunathukorala9808
@kasunathukorala9808 3 жыл бұрын
how can i turn on promiscuous mode in vmware workstation
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
Hi Kasun, one of my friend used the local host adapter in VM ware workstation and the sniffing had worked for him.without any configuration. Adapter 1 : host only(sniffing) Adapter 2 : NAT
@kasunathukorala9808
@kasunathukorala9808 3 жыл бұрын
@@HackeXPlorer thank you for your response
@gauravchauhan8953
@gauravchauhan8953 Жыл бұрын
Jab Ubuntu mai hi karna tha tou video title mai nhi batai j arhi thi ye baat
@linxploit
@linxploit 2 жыл бұрын
# apt-get install snort E: Unable to locate package snort
@mafujaakhtar9876
@mafujaakhtar9876 Жыл бұрын
Couldn't understand properly
@sandeepreddyvutakanti1189
@sandeepreddyvutakanti1189 3 жыл бұрын
Found Musa lol😂😂
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
Musa ?
@amithkumarthatikonda9249
@amithkumarthatikonda9249 3 жыл бұрын
Hi sir
@HackeXPlorer
@HackeXPlorer 3 жыл бұрын
Hi Amith
@amithkumarthatikonda9249
@amithkumarthatikonda9249 3 жыл бұрын
@@HackeXPlorer sir I have configured home network as our public server IP x.x.x.0/24 for home network , but snort receiving/capturing alerts for only the machine where I have installed can you help me how to receive the alerts for all the public ip servers
@amithkumarthatikonda9249
@amithkumarthatikonda9249 3 жыл бұрын
@@HackeXPlorer along with that please provide me your email id sir
Snort 3 - Rule Writing (with labs)
30:46
Cisco Talos Intelligence Group
Рет қаралды 21 М.
Cybersecurity Project: How To Install an IDS (Snort)
26:24
VAMPIRE DESTROYED GIRL???? 😱
00:56
INO
Рет қаралды 8 МЛН
Когда отец одевает ребёнка @JaySharon
00:16
История одного вокалиста
Рет қаралды 14 МЛН
Ouch.. 🤕⚽️
00:25
Celine Dept
Рет қаралды 12 МЛН
Analyzing HTTP and FTP Traffic with Snort | TryHackMe Snort Challenge - The Basics
25:06
Motasem Hamdan | Cyber Security & Tech
Рет қаралды 21 М.
Creating SNORT Rules
38:52
Computer and Network Security
Рет қаралды 130 М.
How to Install and Configure Snort 3.0 on Ubuntu
21:29
Free Education Academy - FreeEduHub
Рет қаралды 24 М.
Set Up Snort in PFSense From Scratch (IDS and IPS)
19:29
RedBlue Labs
Рет қаралды 3,8 М.
Snort 2 - Introduction to Rule Writing
19:00
Cisco Talos Intelligence Group
Рет қаралды 25 М.
Mastering Wireshark: The Complete Tutorial!
54:30
Hacker Joe
Рет қаралды 288 М.
Snort 3 (IPS) - Installation, Configuration and creating Local Rules
47:36
GD Networking Newbie
Рет қаралды 13 М.
Структура файлов и каталогов в Linux
20:28
Aleksey Samoilov
Рет қаралды 407 М.
Snort 101
8:46
Cisco Talos Intelligence Group
Рет қаралды 89 М.
VAMPIRE DESTROYED GIRL???? 😱
00:56
INO
Рет қаралды 8 МЛН