• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1428
  • Last Modified:

how to set an email alert for ftp and ssh login in snort

Dear Experts:

I am having RHEL5 and snort is installed configured and working fine similary for front end installed base, this is also fine now iam looking for an email alert configuration in snort , the server is accessed from nay users through the ftp and some through the ssh, iam looking for an alert mail when somebody login through the ftp or ssh , please please help me how to configure this in the snort. somewhere i read it can be done in the local.rules file but i missed that doc, please help in this, thank you.
0
D_wathi
Asked:
D_wathi
  • 4
  • 2
1 Solution
 
GiladnCommented:
you are looking for something like this:

alert tcp any any -> any any 21 (content:"user root";)

now you want an email alert which is NOT what snort can do, you need a program to monitor snort and alert via email
lie 'swatch' or 'logcheck'

try reading the following link for understanding the process :


http://blackflag.wordpress.com/2006/01/24/how-to-email-alerting-for-the-snort-intrusion-detection-system/

0
 
D_wathiAuthor Commented:
Sir, thanks for the help, now i understood alert is not dependent on snort .

By adding the following line in the .bash_profile, if any body login then iam getting mail.
echo 'ALERT - Root Shell Access on:' `date` `who` | mail -s "Alert: Root Access from `who | cut -d"(" -f2 | cut -d")" -f1`" user@example.com

similarly iam looking for an alert if the users login through the ftp i mean login as ftp, if any user login using ftp service then i should get an email alert, please help


0
 
D_wathiAuthor Commented:
Sir,

if we add the below line to the local.rules file will i get an email alert
 alert tcp any any -> any any 21 (content:"user root";)

Please suggest.
0
Improved Protection from Phishing Attacks

WatchGuard DNSWatch reduces malware infections by detecting and blocking malicious DNS requests, improving your ability to protect employees from phishing attacks. Learn more about our newest service included in Total Security Suite today!

 
GiladnCommented:
In that way you will get an alert in log not via email, read whitin the link I've posted to make it email on alert..
0
 
D_wathiAuthor Commented:
Sir, Thanks for the reply , while going through the link got to know it requires SnortSlinger hence as mentioned in the link tried to access http://www.venom600.org/code/SnortSlinger but this link is not accessible, please suggest me frowm where i can download the SnortSlinger.

Thanks in advance.
0
 
D_wathiAuthor Commented:
Sir, now the snort , barnyard and swatch got installed successfully,  iam looking for the automatic email alert for the ftp logins ,with the help of experts exchange got to know with the below mentioned alert command automatic email alert is possible but i have no idea where to put these lines i mean in which file i have to add this, please help.

alert tcp $EXTERNAL_NET any -> $HOME_NET 21 (msg:"FTP USER login"; flow:to_server,established,no_stream; content:"USER"; nocase; relative; pcre:"/^USER\s[^\n]{1,100}/smi"; classtype:log-login)


0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Managing Security & Risk at the Speed of Business

Gartner Research VP, Neil McDonald & AlgoSec CTO, Prof. Avishai Wool, discuss the business-driven approach to automated security policy management, its benefits and how to align security policy management with business processes to address today's security challenges.

  • 4
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now