⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 install

📁 入侵检测系统.linux下与MySql连用的例子
💻
字号:
   The "generic" notes for putting this thing together are below.  Here's the short version.1.) *** Make sure you have libpcap installed!!! ***2.) ./configure3.) make4.) make install5.) Create a sample rules file (if you want to use rules, check out the     included snort.conf file)6.) snort -?7.) If you've used previous versions of Snort, you may need to rewrite your    rules to make them compliant to the rules format.  See     http://www.snort.org/writing_snort_rules.htm for more information. 8.) Have fun!   Any questions?  Send them to roesch@clark.net or sign up on the snort-usersmailing list at http://snort.sourceforge.net!Snort Configure-time switches============================='--with-snmp'     Enable SNMP alerting code.'--enable-idmef'     Enable the IDMEF XML output plugin.     `--enable-smbalerts'     Enable the SMB alerting code, which is somewhat unsafe as it executes     a popen() call from within the program (which runs at root privs).     You've been warned, use it with caution!`--enable-flexresp'     Enable the 'Flexible Response' code, that allows you to     cancel hostile connections on IP-level when a rule matches.     When you enable this feature, you also need the 'libnet'-library     that can be found at http://www.packetfactory.net/libnet.      See README.FLEXRESP for details.     This function is still ALPHA, so use with caution.`--with-libpq-includes=DIR'     Set the include directories for Postgres SQL database support to DIR.`--with-libpq-libraries=DIR'     Set the library directories for Postgres SQL database support to DIR.       Setting both of these values enables the Postgres output plugin module.`--with-libpcap-includes=DIR'     If the configuration script can't find the libpcap include files on its      own, the path can be set manually with this switch.`--with-libpcap-libraries=DIR'     If the configuration script can't find the libpcap library files on its      own, the path can be set manually with this switch.Basic Installation==================   These are generic installation instructions.   The `configure' shell script attempts to guess correct values forvarious system-dependent variables used during compilation.  It usesthose values to create a `Makefile' in each directory of the package.It may also create one or more `.h' files containing system-dependentdefinitions.  Finally, it creates a shell script `config.status' thatyou can run in the future to recreate the current configuration, a file`config.cache' that saves the results of its tests to speed upreconfiguring, and a file `config.log' containing compiler output(useful mainly for debugging `configure').   If you need to do unusual things to compile the package, please tryto figure out how `configure' could check whether to do them, and maildiffs or instructions to the address given in the `README' so they canbe considered for the next release.  If at some point `config.cache'contains results you don't want to keep, you may remove or edit it.   The file `configure.in' is used to create `configure' by a programcalled `autoconf'.  You only need `configure.in' if you want to changeit or regenerate `configure' using a newer version of `autoconf'.The simplest way to compile this package is:  1. `cd' to the directory containing the package's source code and type     `./configure' to configure the package for your system.  If you're     using `csh' on an old version of System V, you might need to type     `sh ./configure' instead to prevent `csh' from trying to execute     `configure' itself.     Running `configure' takes awhile.  While running, it prints some     messages telling which features it is checking for.  2. Type `make' to compile the package.  3. Optionally, type `make check' to run any self-tests that come with     the package.  4. Type `make install' to install the programs and any data files and     documentation.  5. You can remove the program binaries and object files from the     source code directory by typing `make clean'.  To also remove the     files that `configure' created (so you can compile the package for     a different kind of computer), type `make distclean'.  There is     also a `make maintainer-clean' target, but that is intended mainly     for the package's developers.  If you use it, you may have to get     all sorts of other programs in order to regenerate files that came     with the distribution.Compilers and Options=====================   Some systems require unusual options for compilation or linking thatthe `configure' script does not know about.  You can give `configure'initial values for variables by setting them in the environment.  Usinga Bourne-compatible shell, you can do that on the command line likethis:     CC=c89 CFLAGS=-O2 LIBS=-lposix ./configureOr on systems that have the `env' program, you can do it like this:     env CPPFLAGS=-I/usr/local/include LDFLAGS=-s ./configureCompiling For Multiple Architectures====================================   You can compile the package for more than one kind of computer at thesame time, by placing the object files for each architecture in theirown directory.  To do this, you must use a version of `make' thatsupports the `VPATH' variable, such as GNU `make'.  `cd' to thedirectory where you want the object files and executables to go and runthe `configure' script.  `configure' automatically checks for thesource code in the directory that `configure' is in and in `..'.   If you have to use a `make' that does not supports the `VPATH'variable, you have to compile the package for one architecture at a timein the source code directory.  After you have installed the package forone architecture, use `make distclean' before reconfiguring for anotherarchitecture.Installation Names==================   By default, `make install' will install the package's files in`/usr/local/bin', `/usr/local/man', etc.  You can specify aninstallation prefix other than `/usr/local' by giving `configure' theoption `--prefix=PATH'.   You can specify separate installation prefixes forarchitecture-specific files and architecture-independent files.  If yougive `configure' the option `--exec-prefix=PATH', the package will usePATH as the prefix for installing programs and libraries.Documentation and other data files will still use the regular prefix.   In addition, if you use an unusual directory layout you can giveoptions like `--bindir=PATH' to specify different values for particularkinds of files.  Run `configure --help' for a list of the directoriesyou can set and what kinds of files go in them.   If the package supports it, you can cause programs to be installedwith an extra prefix or suffix on their names by giving `configure' theoption `--program-prefix=PREFIX' or `--program-suffix=SUFFIX'.Optional Features=================   Some packages pay attention to `--enable-FEATURE' options to`configure', where FEATURE indicates an optional part of the package.They may also pay attention to `--with-PACKAGE' options, where PACKAGEis something like `gnu-as' or `x' (for the X Window System).  The`README' should mention any `--enable-' and `--with-' options that thepackage recognizes.   For packages that use the X Window System, `configure' can usuallyfind the X include and library files automatically, but if it doesn't,you can use the `configure' options `--x-includes=DIR' and`--x-libraries=DIR' to specify their locations.   The following configuration switches are available for Snort:`--enable-smbalerts'     Enable the SMB alerting code, which is somewhat unsafe as it executes     a popen() call from within the program (which runs at root privs).     You've been warned, use it with caution!`--enable-flexresp'     Enable the 'Flexible Response' code, that allows you to     cancel hostile connections on IP-level when a rule matches.     When you enable this feature, you also need the 'libnet'-library     that can be found at http://www.packetfactory.net/libnet.     See README.FLEXRESP for details.     This function is still ALPHA, so use with caution.Specifying the System Type==========================   There may be some features `configure' can not figure outautomatically, but needs to determine by the type of host the packagewill run on.  Usually `configure' can figure that out, but if it printsa message saying it can not guess the host type, give it the`--host=TYPE' option.  TYPE can either be a short name for the systemtype, such as `sun4', or a canonical name with three fields:     CPU-COMPANY-SYSTEMSee the file `config.sub' for the possible values of each field.  If`config.sub' isn't included in this package, then this package doesn'tneed to know the host type.   If you are building compiler tools for cross-compiling, you can alsouse the `--target=TYPE' option to select the type of system they willproduce code for and the `--build=TYPE' option to select the type ofsystem on which you are compiling the package.Sharing Defaults================   If you want to set default values for `configure' scripts to share,you can create a site shell script called `config.site' that givesdefault values for variables like `CC', `cache_file', and `prefix'.`configure' looks for `PREFIX/share/config.site' if it exists, then`PREFIX/etc/config.site' if it exists.  Or, you can set the`CONFIG_SITE' environment variable to the location of the site script.A warning: not all `configure' scripts look for a site script.Operation Controls==================   `configure' recognizes the following options to control how itoperates.`--cache-file=FILE'     Use and save the results of the tests in FILE instead of     `./config.cache'.  Set FILE to `/dev/null' to disable caching, for     debugging `configure'.`--help'     Print a summary of the options to `configure', and exit.`--quiet'`--silent'`-q'     Do not print messages saying which checks are being made.  To     suppress all normal output, redirect it to `/dev/null' (any error     messages will still be shown).`--srcdir=DIR'     Look for the package's source code in directory DIR.  Usually     `configure' can determine that directory automatically.`--version'     Print the version of Autoconf used to generate the `configure'     script, and exit.`configure' also accepts some other, not widely useful, options.Platform Specific Notes=======================* Linux:  With kernels 2.2.x and higher you may get `snort [pid] uses obsolete (PF_INET, SOCK_PACKET)' warnings. This is because you use some older implementation of libpcap library and you need an upgrade. The recent version of libpcap could be found at www.tcpdump.org page.  On linux with kernels 2.2.x and higher you may also get feature to  monitor several interfaces down to network level (session + TCP + IP) if you  link your snort with the lattest version of libpcap which incorporates  Sebastian Krahmer's patch for interface 'any'.  (Consult http://www.tcpdump.org for details).* IRIX[ noticed by Scott A. McIntyre <scott@whoi.edu>] There's problem with GCC on IRIX platform which causes certain missbehaviourof snort.>From the SGI web site:Gcc does not correctly pass/return structures which are smaller than 16bytes and which are         not 8 bytes. The problem is very involved and difficult to fix.It affects a number of other targets also, but irix6 is affected         the most, because it is a 64 bit target, and 4 byte structuresare common. The exact problem is that structures are being         padded at the wrong end, e.g. a 4 byte structure is loaded intothe lower 4 bytes of the register when it should be loaded         into the upper 4 bytes of the register.          Gcc is consistent with itself, but not consistent with the SGIC compiler [and the SGI supplied runtime libraries], so the         only failures that can happen are when there are libraryfunctions that take/return such structures. There are very few         such library functions. I can only recall seeing a few of them:inet_ntoa, inet_aton, inet_lnaof,         inet_netof, and semctl.          A possible workaround: if you have a program that callsinet_ntoa and friends or semctl, and your kernel supports         64-bit binaries (i.e. uname -a prints IRIX64 rather than justIRIX), then you may compile with gcc -mabi=64 to         workaround this problem. More information is available at:http://freeware.sgi.com/2000Feb/Installable/gcc-2.8.1-sgipl2.html* SunOS Similar problem with GCC has been noticed on SunOS4.x platforms which causessnort to SIGBUS at certain places. Please use naitive C compiler instead.

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -