| 标题 | 阅读 | 评论 | 转发 | 发布日期 | |
|---|---|---|---|---|---|
| RHEL4系统中JDK+Tomcat开发环境的简单实现 | 1549 | 0 | 0 | 2007-06-14 | |
| 使用Linux+Zebra构建软路由系统 | 1830 | 0 | 1 | 2007-06-03 | |
| Linux下Helix流媒体服务器的架设 | 2038 | 2 | 0 | 2007-06-02 | |
| 基于Ubuntu6.06的zebra安装 | 1379 | 0 | 1 | 2007-06-02 | |
| Samba服务器简单配置 | 1318 | 0 | 0 | 2007-06-02 | |
| 单台Split DNS分离解析服务配置 | 1166 | 0 | 0 | 2007-06-02 | |
| Sendmail电子邮件系统的简单架设 | 1651 | 0 | 0 | 2007-06-02 | |
| 在RHEL4系统中搭建DNS服务器 | 826 | 0 | 0 | 2007-06-02 | |
| Qmail电子邮件服务器简单架设[二] | 1252 | 0 | 0 | 2007-06-02 | |
| Qmail电子邮件服务器简单架设[一] | 1326 | 0 | 0 | 2007-06-02 | |
| Apache+Mysql+Php整合安装 | 882 | 0 | 0 | 2007-06-02 |
chinaunix网友2009-05-05 10:02
在配置文件snort.conf中加入下列一行 alert tcp any any -> any any (flags:S; msg:"SYN Packets Alert!"; sid:20081122客户访问在网页上可以产生报警,并在mysql数据库中可以看到报警的记录存入,去掉后该行后,利用常见扫描软件如Languard、bluescan、nmap -sS Server_IP扫描等均不报警,请请您帮忙看看,使用哪个工具进行扫描或攻击才可以让其报警, 另在启动过程中出现下列警告,请帮忙看看是否正常 Warning: 'ignore_any_rules' option for Stream5 UDP disabled because of UDP rule with flow or flowbits option Warning: flowbits key 'Backdoor.Bersek.Init' is set but not ever checked. Warning: flowbits key 'wmf.download' is set but not ever checked. Warning: flowbits key 'snipernet' is set but not ever checked. Warning: flowbits key 'backup_file.request' is set but not ever checked. Warning: flowbits key 'Mantis_Notify2' is set but not ever checked. Warning: flowbits key 'MinicomLite' is set but not ever checked. Warning: flowbits key 'emf.request' is set but not ever checked. 另外请推荐在SNORT网页下载那个库比较适用谢谢了 msn:navywang@msn.com