<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Case &#187; oinkmaster</title>
	<atom:link href="http://case.net.ru/tag/oinkmaster/feed/" rel="self" type="application/rss+xml" />
	<link>http://case.net.ru</link>
	<description>Just another technical weblog</description>
	<lastBuildDate>Sun, 29 Jan 2012 08:48:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Oinkmaster &#8211; автоматизация обновления правил Snort</title>
		<link>http://case.net.ru/2009/05/05/oinkmaster/</link>
		<comments>http://case.net.ru/2009/05/05/oinkmaster/#comments</comments>
		<pubDate>Tue, 05 May 2009 10:50:06 +0000</pubDate>
		<dc:creator>Case</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[oinkmaster]]></category>
		<category><![CDATA[snort]]></category>

		<guid isPermaLink="false">http://case.net.ru/?p=496</guid>
		<description><![CDATA[Установка: 1 2 3 4 5 $ cd /usr/ports/security/oinkmaster $ make install clean $ cd /usr/local/etc/ $ cp oinkmaster.conf.sample oinkmaster.conf $ chmod 644 oinkmaster.conf В файле oinkmaster.conf указываем расположение правил для snort&#8217;a, а так же добавляем отключенные правила: 1 2 3 4 url = file:///tmp/snortrules.tar.gz disablesid 1 disablesid 2 disablesid 3 Заходим на snort.org, регистрируемся [...]]]></description>
			<content:encoded><![CDATA[<p>Установка:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
</pre></td><td class="code"><pre class="bash" style="font-family:monospace;">$ <span style="color: #7a0874; font-weight: bold;">cd</span> <span style="color: #000000; font-weight: bold;">/</span>usr<span style="color: #000000; font-weight: bold;">/</span>ports<span style="color: #000000; font-weight: bold;">/</span>security<span style="color: #000000; font-weight: bold;">/</span>oinkmaster
$ <span style="color: #c20cb9; font-weight: bold;">make</span> <span style="color: #c20cb9; font-weight: bold;">install</span> clean
$ <span style="color: #7a0874; font-weight: bold;">cd</span> <span style="color: #000000; font-weight: bold;">/</span>usr<span style="color: #000000; font-weight: bold;">/</span>local<span style="color: #000000; font-weight: bold;">/</span>etc<span style="color: #000000; font-weight: bold;">/</span>
$ <span style="color: #c20cb9; font-weight: bold;">cp</span> oinkmaster.conf.sample oinkmaster.conf
$ <span style="color: #c20cb9; font-weight: bold;">chmod</span> <span style="color: #000000;">644</span> oinkmaster.conf</pre></td></tr></table></div>

<p>В файле oinkmaster.conf указываем расположение правил для snort&#8217;a, а так же добавляем отключенные правила:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
</pre></td><td class="code"><pre class="bash" style="font-family:monospace;">url = <span style="color: #c20cb9; font-weight: bold;">file</span>:<span style="color: #000000; font-weight: bold;">///</span>tmp<span style="color: #000000; font-weight: bold;">/</span>snortrules.tar.gz
disablesid <span style="color: #000000;">1</span>
disablesid <span style="color: #000000;">2</span>
disablesid <span style="color: #000000;">3</span></pre></td></tr></table></div>

<p>Заходим на snort.org, регистрируемся и скачиваем бесплатные правила месячной давности.</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
</pre></td><td class="code"><pre class="bash" style="font-family:monospace;">$ <span style="color: #c20cb9; font-weight: bold;">wget</span> <span style="color: #660033;">-O</span> <span style="color: #000000; font-weight: bold;">/</span>tmp<span style="color: #000000; font-weight: bold;">/</span>snortrules.tar.gz http:<span style="color: #000000; font-weight: bold;">//</span>www.snort.org<span style="color: #000000; font-weight: bold;">/</span>pub-bin<span style="color: #000000; font-weight: bold;">/</span>downloads.cgi<span style="color: #000000; font-weight: bold;">/</span>Download<span style="color: #000000; font-weight: bold;">/</span>vrt_os<span style="color: #000000; font-weight: bold;">/</span>snortrules-snapshot-2.8.tar.gz</pre></td></tr></table></div>

<p>Запускаем oinkmaster:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
</pre></td><td class="code"><pre class="bash" style="font-family:monospace;">$ oinkmaster <span style="color: #660033;">-o</span> <span style="color: #000000; font-weight: bold;">/</span>usr<span style="color: #000000; font-weight: bold;">/</span>local<span style="color: #000000; font-weight: bold;">/</span>etc<span style="color: #000000; font-weight: bold;">/</span>snort<span style="color: #000000; font-weight: bold;">/</span>rules<span style="color: #000000; font-weight: bold;">/</span></pre></td></tr></table></div>

<p>Получим большой лог чего добавлено и удалено из правил.</p>
<p>Если делать по хорошему &#8211; то конечно же нужна платная подписка на правила + автоматизация процесса обновления.</p>
]]></content:encoded>
			<wfw:commentRss>http://case.net.ru/2009/05/05/oinkmaster/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
<!-- WP Super Cache is installed but broken. The path to wp-cache-phase1.php in wp-content/advanced-cache.php must be fixed! -->
