Solved

Snort sensor is not showing in ACID?

Posted on 2004-10-13
3
486 Views
Last Modified: 2012-06-21
I am new to Snort so I maight be not seeing something very basic.
I am running Snort on Windows 2000 Professional.
That is Snort 2.2.0, Acid 0.9.6b, Adodb 4.5.2, PHP 4.3.9, Mysql 4.0.21, Winpcap 3.0

When I run Snort (snort –v)  Acid is showing that sensor = 0 ?? Why is this?
In the same time I can tell that Snort is running, it is showing it’s activity in DOS and in Task Manager.
Snort.conf  “var HOME_NET” VARIABLE is set to “any”.

I did all the configuration as required except I did not edit adodb configuration file but not sure if this is connected with the problem. I red that this version of Adodb doesn’t need editing but finds adodb path automatically.

Is Winpcap misbehaving? Ther is an error at the end of Snort report. I will include Snort output bellow:

“Snort received 1671 packets
    Analyzed: 1671(100.000%)
    Dropped: 0(0.000%)
=======================================================
Breakdown by protocol:
    TCP: 33         (1.975%)
    UDP: 8          (0.479%)
   ICMP: 1626       (97.307%)
    ARP: 2          (0.120%)
  EAPOL: 0          (0.000%)
   IPv6: 0          (0.000%)
    IPX: 0          (0.000%)
  OTHER: 0          (0.000%)
DISCARD: 0          (0.000%)
=======================================================
10/13-15:05:50.897424 172.16.10.1 -> Action Stats:
ALERTS: 0
LOGGED: 0
PASSED: 0
=======================================================
172.16.10.2
ICMP TTL:128 TOS:0x0 ID:4062 IpLen:20 DgmLen:60
Type:8  Code:0  ID:768   Seq:33541  ECHO
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=

10/13-15:05:50.897475 172.16.10.2 -> 172.16.10.1
ICMP TTL:128 TOS:0x0 ID:17140 IpLen:20 DgmLen:60
Type:0  Code:0  ID:768  Seq:33541  ECHO REPLY
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=

pcap_loop: read error: PacketReceivePacket failed
Run time for packet processing was 428.446000 seconds”

Would you have any idea why is sensor not showing in ACID?

Thanks a lot,

marty

0
Comment
Question by:howei
  • 2
3 Comments
 
LVL 6

Accepted Solution

by:
knoxj81 earned 75 total points
ID: 12312561
Marty,

I would recommend setting up a IDS box per these intructions for your first time. It will help you in understanding the basic setup steps.

http://www.winsnort.com/modules.php?op=modload&name=Sections&file=index

It has guides for both windows or linux. mysql or mssql. apache or IIS. you choose the setup you want, and the guides show you how to get it up and running.

EXTRA NOTE:
I was using snort also, but it occured that the latest version of PHP isn't compatible with ACID. So check out this front-end:

http://www.aanval.com/?op=pub_openAanval

Good Luck,

Jorden

0
 

Author Comment

by:howei
ID: 12362791
Jorden,

thank you so much for this links and info. I was not aware of winsnort.

Howei
0
 
LVL 6

Expert Comment

by:knoxj81
ID: 12362904
FYI, if you'd like to see what aanval looks like goto the link above and try there demo. very nice and free just like ACID.
0

Featured Post

New My Cloud Pro Series - organize everything!

With space to keep virtually everything, the My Cloud Pro Series offers your team the network storage to edit, save and share production files from anywhere with an internet connection. Compatible with both Mac and PC, you're able to protect your content regardless of OS.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Adups vulnerability 5 94
Computer performance snapshot  -baseline evaulation 7 94
IT Contract Fee 17 132
SQL 2012 database restore problem 6 67
Article by: btan
Provide an easy one stop to quickly get the relevant information on common asked question on Ransomware in Expert Exchange.
By this time the large percentage of day-to-day transactions have shifted to mobile banking; here are some overriding areas QAs must investigate while testing mobile banking apps.  
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…

896 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now