HOW TO INSTALL & CONFIGURE SNORT IDS ON UBUNTU

Поделиться
HTML-код
  • Опубликовано: 14 дек 2024

Комментарии • 35

  • @cvtfstudios_netdaman7930
    @cvtfstudios_netdaman7930 Год назад +1

    great tutorial my brother - i was able to install and configure Snort on ubuntu 22.x. I applied the 2 rules that worked perfectly, I am researching IDS for university so your tutorial has been very helpful. Keep up the tut's your a soldier... Big ups.
    😀

    • @techwithkazim9180
      @techwithkazim9180  9 месяцев назад

      You are welcome. I'm glad that you found the tutorial helpful

  • @cristofmanama5125
    @cristofmanama5125 Год назад +2

    excellent, how to setting up ips snort?

    • @techwithkazim9180
      @techwithkazim9180  Год назад +2

      Set Snort 'detection mode' in snort.conf file to 'ips', then write rules to block or reject traffic

    • @cristofmanama5125
      @cristofmanama5125 Год назад

      Thanks a lot👍@@techwithkazim9180

  • @shousuke6057
    @shousuke6057 28 дней назад

    in 7:21 why my vm said that it failed to fetch?

    • @techwithkazim9180
      @techwithkazim9180  28 дней назад

      Did you do "sudo apt-get update" first?

    • @shousuke6057
      @shousuke6057 28 дней назад

      @techwithkazim9180 no I enter the apt-get install first and the output was failed to fetch, then I try to enter the apt-get update and it said 'failed to fetch' and 'some index files failed to download. They have been ignored or old ones used instead'

    • @shousuke6057
      @shousuke6057 28 дней назад

      I realized that in 5:35 that my enp0s8 shows only inet6, the normal inet is not there

  • @RamandeepKaur-ly1kk
    @RamandeepKaur-ly1kk 5 месяцев назад

    Great Tutorial. Where is log file stored and how can I check that?

    • @techwithkazim9180
      @techwithkazim9180  5 месяцев назад

      @@RamandeepKaur-ly1kk You can check the /var/log/suricata/ directory for the eve.json logs or the fast.log

  • @regasaputraabinyahamas5926
    @regasaputraabinyahamas5926 Год назад

    I am newbie, the article is very good, permission to copy and paste to reference my blog, thank you very much

    • @techwithkazim9180
      @techwithkazim9180  Год назад

      Granted. But please do not forget to reference my channel in your blog, thank you

  • @collectionsforyou3209
    @collectionsforyou3209 6 месяцев назад +1

    Bro u are awesom i setup the first ids by seeing your vedio early i am tried the suricat but i got more errors will you able to put vedio for suricata

    • @techwithkazim9180
      @techwithkazim9180  6 месяцев назад +1

      I will consider a tut for Suricata. You can subscribe to my channel so you get the notification as soon as I drop the tut for Suricata

    • @techwithkazim9180
      @techwithkazim9180  6 месяцев назад

      Here is my new video on using Suricata as an IDS and IPS
      ruclips.net/video/8Q3Nhyvh-1I/видео.html
      Enjoy! And please like it and share it. Thanks

  • @omobolajiakeem138
    @omobolajiakeem138 2 месяца назад +1

    Great my teacher

  • @aragon5956
    @aragon5956 10 месяцев назад

    Amazing but is there a modification for .lua files ?

    • @techwithkazim9180
      @techwithkazim9180  9 месяцев назад

      Not at the moment. But I will look into that in the near future

  • @eshenwarawita1228
    @eshenwarawita1228 Год назад

    bro what if i want to use snort in a separate vm which sits in the middle between 2 devices (possibly a kali linux machine and a metasploitable)?

    • @techwithkazim9180
      @techwithkazim9180  Год назад +1

      Ensure Snort is listening on the network interface that the metaspoitable and kali vm are both on

    • @eshenwarawita1228
      @eshenwarawita1228 Год назад

      thanks alot it workked@@techwithkazim9180

  • @sundayachi1300
    @sundayachi1300 8 месяцев назад

    How can I use this snort to test for false positives

    • @techwithkazim9180
      @techwithkazim9180  5 месяцев назад

      Generate legitimate traffic and monitor the alerts afterwards. This helps you to update or rewrite the rules correctly.

  • @jencyw5389
    @jencyw5389 Год назад

    视频带上中国字幕就好了

  • @theAlmightyGod09
    @theAlmightyGod09 5 месяцев назад

    Please,I got an error message when i run "sudo snort -A console -q -i -c /etc/snort/snort.conf -k ascii.
    the error is "unknown command line checksum option: ascii".I will appreciate you response on this. Thank you.

    • @techwithkazim9180
      @techwithkazim9180  5 месяцев назад

      1. Did you replace "" with the network interface Snort is listening on?
      2. The last part of the command is "-K ascii" and not a lower case k
      3. If the 2 options above doesn't work, please screenshot the command you entered plus the error you're getting.

    • @theAlmightyGod09
      @theAlmightyGod09 5 месяцев назад +1

      @techwithkazim9180 Thank you for your prompt response and videos.
      1. I actually insert the interface.
      2.I used the small letter "k".
      I will try it again and revert back.
      Thank you always.

    • @theAlmightyGod09
      @theAlmightyGod09 5 месяцев назад +1

      @techwithkazim9180 I finally replaced lower case k with higher case K, and it worked expressly.
      Thank you so much.

    • @techwithkazim9180
      @techwithkazim9180  5 месяцев назад

      @@theAlmightyGod09 You're welcome

    • @theAlmightyGod09
      @theAlmightyGod09 5 месяцев назад

      ​@@techwithkazim9180subscribed and notification on.