Re: Something may wrong with my configuration, someone can help me???Please tell where my configuration was wrong!
"Steven Baigal \(sbaigal\) via Snort-users" <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <BL0PR11MB2898B87A3FC373E6E8E9E388B36D9@BL0PR11MB2898.namprd11.prod.outlook.com> |
I don’t see binder configuration from you snort.lua file. Try to add: wizard = default_wizard From: Snort-users <[email protected]> on behalf of wuhenzhiyue via Snort-users <[email protected]> Date: Monday, December 6, 2021 at 1:20 PM To: [email protected] <[email protected]> Subject: [Snort-users] Something may wrong with my configuration, someone can help me???Please tell where my configuration was wrong! Hello anybody When i used snort 3.1.0.0 or 3.1.10.0 to capture file or match file_type with ftp and NFQUEUE in inline mode, it don't work! I don't know why. There is no any error., i also tried to get file from http pcap, but nothing happened. This's my usage and configs which deferent from default: 1. iptabes config: iptables -t mangle -A INPUT -p tcp -j NFQUEUE 2. ftp server in my host(just input without forward): vsfpt 3. start snort command: snort -Q --daq nfq --daq-var queue_maxlen=655350 -c /usr/local/etc/snort/snort.lua --tweaks security -A alert_fast -R /.../local.rules --wall-all -l /home/../snortLog -v 4. local.rules config: ....... alert tcp any any <> any any (msg: "Test.... "; file_type: "RAR"; sid: 30; rev: 1;) alert tcp any any <> any any (msg: "1111111111"; service: ftp-data; ftp_data; file_type: "RAR"; sid: 31; rev: 1) ...... 5. snort.lua config: active = {device = "ens33", } detection = {pcre_override = true, pcre_enable = true,} trace = { output = stdout, modules = { file_id = { all = 1, } } } stream = {} stream.file_cache = { cap_weight = 65525, idle_timeout = 180 } stream_ip = {} stream_tcp = {} stream_udp = {} stream_icmp = {} stream_user = {} stream_file = {upload = true} ...... http_inspect = {} http2_inspect = {} ...... normalizer = { ip4 = {base = false}, tcp = {ips = true, ecn = 'stream'} } ...... telnet = { encryted_traffic = true, chech_encryted = true, normalize = true } dce_smb = { smb_file_inspection = 'on', smb_file_depth = 0, } ...... ftp_server = default_ftp_server ftp_client = {} ftp_data = {} file_id = { enable_signature = true, enable_type = true, enable_capture = true, trace_type = true, trace_signature = true, trace_stream = true, --include('file_magic.lua') is configured by defualt file_rules = file_magic, file_policy = { {when = {file_type_id = 21}, use = {verdict = 'log', enable_file_capture = true}}, {when = {file_type_id = 30}, use = {verdict = 'log', enable_file_capture = true}}, {when = {file_type_id = 320}, use = {verdict = 'log', enable_file_capture = true}} } --defualt type_depth = 56384, signature_depth = 10485760, max_files_cashed = 65535, show_data_depth = 1000, capture_memcap = 100, capture_max_size = 10485760, } ...... ips = { mode = 'inline'. variables = default_variables } reject = {reset = "both", control = "all"} ...... alert_fast = {file = true} alert_syslog = { facility = 'user', level = 'warning' } log_codecs = {file = true} log_hext = {file = true, raw = true} file_log = { log_pkt_time = true, log_sys_time = false } 6. security.lua config: arp_spoof = nil ftp_server.check_encrypted = true detection = { pcre_match_limit = 3500, pcre_match_recursion = 3500 } ........ http_inspect.unzip = true ...... port_scan = nil ....... stream_ip.min_frag_length = 100 stream_ip.max_overlaps = 0 stream_ip.max_frags = 8192 stream_ip.policy = linux stream_ip.session_timeout = 30 stream_ip.min_ttl = 1 stream_ip.min_frag_length = 0 stream.ip_frags_only = false stream.held_packet_timeout = 1000 stream_max_flows = 476288 stream_pruning_timeout = 30 stream_tcp.overla_limit = 0 stream_tcp.max_pdu = 4380 stream_tcp.max_window = 0 stream_tcp.track_only = false stream_tcp.policy = linux stream_tcp.show_rebuilt_packets = true stream_tcp.reassemble_async = true stream_user.session_timeout = 30 stream.ip_cache = {cap_weight = 11000, idle_timeout = 180 } stream.tcp_cache = {cap_weight = 65535, idle_timeout = 3600} stream.ip_cache = {cap_weight = 11000, idle_timeout = 180 } stream.file_cache = {cap_weight = 64, idle_timeout = 180 } stream_tcp.queue_limit = {max_bytes = 10485760, max_segments = 2621} stream_tcp.small_segments = {count = 3, maximum_size = 150} ...... Best regards , Weiran _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette