<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>DalianSky&#039;s Blog &#187; 网络安全</title>
	<atom:link href="http://blog.daliansky.net/category/network-security/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.daliansky.net</link>
	<description>正在修建中的空中楼阁</description>
	<lastBuildDate>Tue, 10 Jan 2012 04:31:40 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>架设FreeBSD6.2+PF防DDOS 攻击的网站</title>
		<link>http://blog.daliansky.net/%e6%9e%b6%e8%ae%befreebsd62pf%e9%98%b2ddos-%e6%94%bb%e5%87%bb%e7%9a%84%e7%bd%91%e7%ab%99.html</link>
		<comments>http://blog.daliansky.net/%e6%9e%b6%e8%ae%befreebsd62pf%e9%98%b2ddos-%e6%94%bb%e5%87%bb%e7%9a%84%e7%bd%91%e7%ab%99.html#comments</comments>
		<pubDate>Fri, 21 Nov 2008 12:10:48 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[网络安全]]></category>
		<category><![CDATA[bsd]]></category>
		<category><![CDATA[pf]]></category>
		<category><![CDATA[syn]]></category>
		<category><![CDATA[攻击]]></category>
		<category><![CDATA[防范]]></category>

		<guid isPermaLink="false">http://blog.daliansky.net/?p=205</guid>
		<description><![CDATA[现网站和外挂经常带arp和ddos攻击,本来用ros做网吧路由器顶不住ddos，只能换FB6.2+pf,前几天用FB6.1+PF，人多时出watchdog timeout,老大说用FB6.2可能不会出了，那就装起测测看，下面是安装步骤，操作一个写一个， cd /usr/src/sys/i386/conf cp GERENIC PFOK ee FFOK 修改并加入下面东东 复制内容到剪贴板代码: ident PFOK device pf device pflog device pfsync options ALTQ options ALTQ_CBQ options ALTQ_RED options ALTQ_RIO options ALTQ_HFSC options ALTQ_PRIQ options ALTQ_NOPCC options PANIC_REBOOT_WAIT_TIME=0 options DEVICE_POLLING options HZ=2000 options IPSTEALTH # options RANDOM_IP_ID options TCP_DROP_SYNFIN config PFOK cd /usr/src/sys/i386/compile/PFOK make depend make make install [...]]]></description>
			<content:encoded><![CDATA[<p>现网站和外挂经常带<a onclick="tagshow(event, 'arp');" href="javascript:;" target="_self"><span style="text-decoration: underline;"><strong><span style="color: #656d77;">arp</span></strong></span></a>和<a onclick="tagshow(event, 'ddos');" href="javascript:;" target="_self"><span style="text-decoration: underline;"><strong><span style="color: #656d77;">ddos</span></strong></span></a><span class='wp_keywordlink_affiliate'><a href="http://blog.daliansky.net/tag/%e6%94%bb%e5%87%bb" title="查看 攻击 中的全部文章" target="_blank">攻击</a></span>,本来用ros做网吧路由器顶不住ddos，只能换FB6.2+<span class='wp_keywordlink_affiliate'><a href="http://blog.daliansky.net/tag/pf" title="查看 pf 中的全部文章" target="_blank">pf</a></span>,前几天用FB6.1+PF，人多时出watchdog timeout,老大说用FB6.2可能不会出了，那就装起测测看，下面是<a onclick="tagshow(event, '%E5%AE%89%E8%A3%85');" href="javascript:;" target="_self"><span style="text-decoration: underline;"><strong><span style="color: #656d77;">安装</span></strong></span></a>步骤，操作一个写一个，</p>
<p>cd /usr/src/sys/i386/conf<br />
cp GERENIC PFOK<br />
ee FFOK</p>
<p>修改并加入下面东东<br />
复制内容到剪贴板代码:<br />
ident PFOK<br />
device <span class='wp_keywordlink_affiliate'><a href="http://blog.daliansky.net/tag/pf" title="查看 pf 中的全部文章" target="_blank">pf</a></span><br />
device <span class='wp_keywordlink_affiliate'><a href="http://blog.daliansky.net/tag/pf" title="查看 pf 中的全部文章" target="_blank">pf</a></span>log<br />
device pf<span class='wp_keywordlink_affiliate'><a href="http://blog.daliansky.net/tag/syn" title="查看 syn 中的全部文章" target="_blank">syn</a></span>c<br />
options ALTQ<br />
options ALTQ_CBQ<br />
options ALTQ_RED<br />
options ALTQ_RIO<br />
options ALTQ_HFSC<br />
options ALTQ_PRIQ<br />
options ALTQ_NOPCC<br />
options PANIC_REBOOT_WAIT_TIME=0<br />
options DEVICE_POLLING<br />
options HZ=2000<br />
options IPSTEALTH<br />
# options RANDOM_IP_ID<br />
options TCP_DROP_SYNFIN<br />
config PFOK<br />
cd /usr/src/sys/i386/compile/PFOK<br />
make depend<br />
make<br />
make install<br />
reboot</p>
<p>ee /etc/sysctl.conf</p>
<p>net.inet.ip.forwarding=1<br />
net.inet.ip.fastforwarding=1<br />
net.inet.tcp.drop_<span class='wp_keywordlink_affiliate'><a href="http://blog.daliansky.net/tag/syn" title="查看 syn 中的全部文章" target="_blank">syn</a></span>fin=1<br />
net.inet.tcp.sendspace=65536<br />
net.inet.tcp.recvspace=65536<br />
#net.inet.udp.sendspace=65535<br />
net.inet.udp.maxdgram=65535<br />
net.local.stream.sendspace=65535<br />
net.inet.tcp.rfc1323=1<br />
#net.inet.tcp.rfc1644=1<br />
net.inet.tcp.rfc3042=1<br />
net.inet.tcp.rfc3390=1<br />
kern.ipc.maxsockbuf=2097152<br />
kern.maxfiles=65536<br />
kern.maxfilesperproc=32768<br />
kern.polling.enable=1<br />
kern.polling.burst_max=500<br />
kern.ipc.somaxconn=2048<br />
kern.ipc.nmbclusters=32768<br />
net.inet.tcp.delayed_ack=0<br />
net.inet.icmp.icmplim=100<br />
net.inet.icmp.icmplim_output=0<br />
net.inet.tcp.drop_synfin=1</p>
<p>ee /boot/loader.conf<br />
autobootdelay=&#8221;2&#8243;</p>
<p>ee /etc/rc.conf<br />
sendmail_enable=&#8221;NONE&#8221;<br />
sendmail_submit_enable=&#8221;NO&#8221;<br />
sendmail_outbound_enable=&#8221;NO&#8221;<br />
sendmail_msp_queue_enable=&#8221;NO&#8221;<br />
clear_tmp_enable=&#8221;YES&#8221;<br />
update_motd=&#8221;NO&#8221;<br />
tcp_drop_synfin=&#8221;YES&#8221;<br />
#icmp_drop_redirect=&#8221;YES&#8221;<br />
#icmp_log_redirect=&#8221;YES&#8221;<br />
#log_in_vain=&#8221;YES&#8221;<br />
#accounting_enable=&#8221;YES&#8221;<br />
pf_enable=&#8221;YES&#8221;<br />
pf_rules=&#8221;/etc/pf.conf&#8221;<br />
pf_flags=&#8221;"<br />
#pflog_enable=&#8221;YES&#8221;<br />
#pflog_logfile=&#8221;/var/log/pflog&#8221;<br />
这里我就加了句pf_enable=&#8221;YES&#8221;</p>
<p>uname -a<br />
<a onclick="tagshow(event, 'FreeBSD');" href="javascript:;" target="_self"><span style="text-decoration: underline;"><strong><span style="color: #656d77;">FreeBSD</span></strong></span></a> pf.com 6.2-RC1 FreeBSD 6.2-RC1 #0: Thu Nov 23 04:20:46 CST 2006<a href="mailto:sshpf@pf.com"><span style="text-decoration: underline;"><span style="color: #656d77;">sshpf@pf.com</span></span></a>:/usr/src/sys/i386/compile/PFOK i386</p>
<p>我的pf.conf</p>
<p>#pfctl -e -F all -f /etc/pf.conf</p>
<p>#只重新load过滤规则<br />
#pfctl -F rules -Rf /etc/pf.conf</p>
<p>#pfctl -f /etc/pf.conf # 重新加载pf.conf 设定档<br />
#pfctl -nf /etc/pf.conf # 确认<a onclick="tagshow(event, '%E8%AF%AD%E6%B3%95');" href="javascript:;" target="_self"><span style="text-decoration: underline;"><strong><span style="color: #656d77;">语法</span></strong></span></a>有无符合，但不载入<br />
#pfctl -Nf /etc/pf.conf # 只加载 NAT 的设定档<br />
#pfctl -Rf /etc/pf.conf # 只加载防火墙的过滤设定档</p>
<p>#pfctl -sn # 显示现阶段 NAT 的规则<br />
#pfctl -sr # 显示现阶段过滤的规则<br />
#pfctl -ss # 显示现阶段封包运作状态<br />
#pfctl -si # 显示现阶段过滤封包的统计资料<br />
#pfctl -sa # 显示现阶段所有统计的数据<br />
复制内容到剪贴板代码:<br />
ext_if=&#8221;rl0&#8243;<br />
#edu_if=&#8221;"<br />
int_if=&#8221;fxp0&#8243;</p>
<p>ext_addr=&#8221;192.168.1.51&#8243;</p>
<p>int_net=&#8221;172.16.0.0/16&#8243;<br />
ext_net = &#8220;192.168.0.0/16&#8243;<br />
loop = &#8220;{lo0, 127.0.0.1}&#8221;<br />
OpenPorts = &#8220;{21, 22, 80, 88, 4899}&#8221;<br />
InsideManagerIPs = &#8220;{172.16.0.100}&#8221;<br />
InsiteManagerOpenPorts = &#8220;{21, 22, 23, 24, 25, 80, 4899}&#8221;<br />
priv_nets = &#8220;{ 127.0.0.0/8, 192.168.0.0/16, 172.16.0.0/12}&#8221; # 定义符合 RFC 1918 私有IP 部份<br />
tcp_services = &#8220;{ 22, 88, 4899, 123 }&#8221; # 定义对外服务的端口<br />
icmp_types = &#8220;echoreq&#8221; # 定义icmp类型</p>
<p>## down inactive connection quickly<br />
set optimization aggressive</p>
<p># Normalization: reassemble fragments and resolve or reduce traffic ambiguities.<br />
scrub in all</p>
<p>nat on $ext_if from $int_net to any -&gt; ($ext_if)<br />
#nat on $ext_if from $int_net to $ext_net -&gt; ($ext_if)</p>
<p>#web server map<br />
#rdr pass on $ext_if proto tcp from any to $ext_if port {www,3389,4899,7745} -&gt; $web_server</p>
<p>#&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-以下防DOS<span class='wp_keywordlink_affiliate'><a href="http://blog.daliansky.net/tag/%e6%94%bb%e5%87%bb" title="查看 攻击 中的全部文章" target="_blank">攻击</a></span>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
#每个IP最大可以有120个非并发的连接（为局域网用户访问本站考虑）<br />
#每个IP最大连接建立的速率小于每秒8个<br />
#单个IP的最大持续连接数 30<br />
#违反以上规则，把这个ip添加到&lt;abusive_hosts&gt;表中<br />
table &lt;abusive_hosts&gt; persist #维持一个持续的表<br />
block in quick from &lt;abusive_hosts&gt; #阻止表中的ip<br />
pass in on $int_if inet proto tcp from any to $int_if flags S/SA keep state \<br />
(source-track rule,max-src-conn 100, max-src-conn-rate 15/3,max-src-states 30,overload &lt;abusive_hosts&gt; flush, src.track 1)</p>
<p>LSassVirusPort = &#8220;{445, 135, 139, 593, 512, 5554, 9996, 9995}&#8221;<br />
block quick on $int_if inet proto tcp from any to any port $LSassVirusPort</p>
<p>BitTorrentPort= &#8220;{ 512, 2049, 4662, 6880, 6881, 6882, 6883, 6884, 6885, 6886, 6887, 6888, 6889, \<br />
6890, 8880, 8881, 8882, 8883, 8884, 8885, 8886, 8887, 8888, 8889, 8890, 6969, 10700, 21881}&#8221;<br />
block quick on $int_if inet proto tcp from any to any port $BitTorrentPort<br />
block quick on $int_if inet proto tcp from any port $BitTorrentPort to any<br />
block quick on $ext_if inet proto tcp from any to any port $BitTorrentPort<br />
block quick on $ext_if inet proto tcp from any port $BitTorrentPort to any</p>
<p>#gameClientPorts = &#8220;{4002, 2000, 3838, 4410, 4210, 4230, 5005, 4290, 10010 }&#8221;<br />
#GameDenyClients =&#8221;{192.168.128.0/24, 192.168.132.0/24}&#8221;<br />
#GameServerIps = &#8220;{204.251.15.167, 61.152.93.145}&#8221;<br />
#block quick on $int_if inet proto tcp from $GameDenyClients to any port $gameClientPorts<br />
#block quick on $ext_if from $GameServerIps to $GameDenyClients<br />
#block quick on $int_if from $GameDenyClients to $GameServerIps</p>
<p>denyserverips = &#8220;{202.108.193.21}&#8221;<br />
block quick on $int_if from any to $denyserverips</p>
<p>#LSassVirusIp =&#8221;{192.168.1.194}&#8221;<br />
#block quick on $int_if from $LSassVirusIp to any</p>
<p><a class="a2a_button_google_reader" href="http://www.addtoany.com/add_to/google_reader?linkurl=http%3A%2F%2Fblog.daliansky.net%2F%25e6%259e%25b6%25e8%25ae%25befreebsd62pf%25e9%2598%25b2ddos-%25e6%2594%25bb%25e5%2587%25bb%25e7%259a%2584%25e7%25bd%2591%25e7%25ab%2599.html&amp;linkname=%E6%9E%B6%E8%AE%BEFreeBSD6.2%2BPF%E9%98%B2DDOS%20%E6%94%BB%E5%87%BB%E7%9A%84%E7%BD%91%E7%AB%99" title="Google Reader" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/reader.png" width="16" height="16" alt="Google Reader"/></a><a class="a2a_button_google_bookmarks" href="http://www.addtoany.com/add_to/google_bookmarks?linkurl=http%3A%2F%2Fblog.daliansky.net%2F%25e6%259e%25b6%25e8%25ae%25befreebsd62pf%25e9%2598%25b2ddos-%25e6%2594%25bb%25e5%2587%25bb%25e7%259a%2584%25e7%25bd%2591%25e7%25ab%2599.html&amp;linkname=%E6%9E%B6%E8%AE%BEFreeBSD6.2%2BPF%E9%98%B2DDOS%20%E6%94%BB%E5%87%BB%E7%9A%84%E7%BD%91%E7%AB%99" title="Google Bookmarks" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/google.png" width="16" height="16" alt="Google Bookmarks"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblog.daliansky.net%2F%25e6%259e%25b6%25e8%25ae%25befreebsd62pf%25e9%2598%25b2ddos-%25e6%2594%25bb%25e5%2587%25bb%25e7%259a%2584%25e7%25bd%2591%25e7%25ab%2599.html&amp;linkname=%E6%9E%B6%E8%AE%BEFreeBSD6.2%2BPF%E9%98%B2DDOS%20%E6%94%BB%E5%87%BB%E7%9A%84%E7%BD%91%E7%AB%99" title="Facebook" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fblog.daliansky.net%2F%25e6%259e%25b6%25e8%25ae%25befreebsd62pf%25e9%2598%25b2ddos-%25e6%2594%25bb%25e5%2587%25bb%25e7%259a%2584%25e7%25bd%2591%25e7%25ab%2599.html&amp;linkname=%E6%9E%B6%E8%AE%BEFreeBSD6.2%2BPF%E9%98%B2DDOS%20%E6%94%BB%E5%87%BB%E7%9A%84%E7%BD%91%E7%AB%99" title="Twitter" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_yahoo_bookmarks" href="http://www.addtoany.com/add_to/yahoo_bookmarks?linkurl=http%3A%2F%2Fblog.daliansky.net%2F%25e6%259e%25b6%25e8%25ae%25befreebsd62pf%25e9%2598%25b2ddos-%25e6%2594%25bb%25e5%2587%25bb%25e7%259a%2584%25e7%25bd%2591%25e7%25ab%2599.html&amp;linkname=%E6%9E%B6%E8%AE%BEFreeBSD6.2%2BPF%E9%98%B2DDOS%20%E6%94%BB%E5%87%BB%E7%9A%84%E7%BD%91%E7%AB%99" title="Yahoo Bookmarks" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/yahoo.png" width="16" height="16" alt="Yahoo Bookmarks"/></a><a class="a2a_button_myspace" href="http://www.addtoany.com/add_to/myspace?linkurl=http%3A%2F%2Fblog.daliansky.net%2F%25e6%259e%25b6%25e8%25ae%25befreebsd62pf%25e9%2598%25b2ddos-%25e6%2594%25bb%25e5%2587%25bb%25e7%259a%2584%25e7%25bd%2591%25e7%25ab%2599.html&amp;linkname=%E6%9E%B6%E8%AE%BEFreeBSD6.2%2BPF%E9%98%B2DDOS%20%E6%94%BB%E5%87%BB%E7%9A%84%E7%BD%91%E7%AB%99" title="MySpace" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/myspace.png" width="16" height="16" alt="MySpace"/></a><a class="a2a_button_hotmail" href="http://www.addtoany.com/add_to/hotmail?linkurl=http%3A%2F%2Fblog.daliansky.net%2F%25e6%259e%25b6%25e8%25ae%25befreebsd62pf%25e9%2598%25b2ddos-%25e6%2594%25bb%25e5%2587%25bb%25e7%259a%2584%25e7%25bd%2591%25e7%25ab%2599.html&amp;linkname=%E6%9E%B6%E8%AE%BEFreeBSD6.2%2BPF%E9%98%B2DDOS%20%E6%94%BB%E5%87%BB%E7%9A%84%E7%BD%91%E7%AB%99" title="Hotmail" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/live.png" width="16" height="16" alt="Hotmail"/></a><a class="a2a_button_yahoo_mail" href="http://www.addtoany.com/add_to/yahoo_mail?linkurl=http%3A%2F%2Fblog.daliansky.net%2F%25e6%259e%25b6%25e8%25ae%25befreebsd62pf%25e9%2598%25b2ddos-%25e6%2594%25bb%25e5%2587%25bb%25e7%259a%2584%25e7%25bd%2591%25e7%25ab%2599.html&amp;linkname=%E6%9E%B6%E8%AE%BEFreeBSD6.2%2BPF%E9%98%B2DDOS%20%E6%94%BB%E5%87%BB%E7%9A%84%E7%BD%91%E7%AB%99" title="Yahoo Mail" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/yahoo.png" width="16" height="16" alt="Yahoo Mail"/></a><a class="a2a_button_wordpress" href="http://www.addtoany.com/add_to/wordpress?linkurl=http%3A%2F%2Fblog.daliansky.net%2F%25e6%259e%25b6%25e8%25ae%25befreebsd62pf%25e9%2598%25b2ddos-%25e6%2594%25bb%25e5%2587%25bb%25e7%259a%2584%25e7%25bd%2591%25e7%25ab%2599.html&amp;linkname=%E6%9E%B6%E8%AE%BEFreeBSD6.2%2BPF%E9%98%B2DDOS%20%E6%94%BB%E5%87%BB%E7%9A%84%E7%BD%91%E7%AB%99" title="WordPress" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/wordpress.png" width="16" height="16" alt="WordPress"/></a><a class="a2a_button_yahoo_messenger" href="http://www.addtoany.com/add_to/yahoo_messenger?linkurl=http%3A%2F%2Fblog.daliansky.net%2F%25e6%259e%25b6%25e8%25ae%25befreebsd62pf%25e9%2598%25b2ddos-%25e6%2594%25bb%25e5%2587%25bb%25e7%259a%2584%25e7%25bd%2591%25e7%25ab%2599.html&amp;linkname=%E6%9E%B6%E8%AE%BEFreeBSD6.2%2BPF%E9%98%B2DDOS%20%E6%94%BB%E5%87%BB%E7%9A%84%E7%BD%91%E7%AB%99" title="Yahoo Messenger" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/yim.png" width="16" height="16" alt="Yahoo Messenger"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblog.daliansky.net%2F%25e6%259e%25b6%25e8%25ae%25befreebsd62pf%25e9%2598%25b2ddos-%25e6%2594%25bb%25e5%2587%25bb%25e7%259a%2584%25e7%25bd%2591%25e7%25ab%2599.html&amp;title=%E6%9E%B6%E8%AE%BEFreeBSD6.2%2BPF%E9%98%B2DDOS%20%E6%94%BB%E5%87%BB%E7%9A%84%E7%BD%91%E7%AB%99" id="wpa2a_2"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a></p><hr />
<p><small>© admin for <a href="http://blog.daliansky.net">DalianSky&#039;s Blog</a>, 2008. |
<a href="http://blog.daliansky.net/%e6%9e%b6%e8%ae%befreebsd62pf%e9%98%b2ddos-%e6%94%bb%e5%87%bb%e7%9a%84%e7%bd%91%e7%ab%99.html">Permalink</a> |
<a href="http://blog.daliansky.net/%e6%9e%b6%e8%ae%befreebsd62pf%e9%98%b2ddos-%e6%94%bb%e5%87%bb%e7%9a%84%e7%bd%91%e7%ab%99.html#comments">No comment</a> |
Add to
<a href="http://del.icio.us/post?url=http://blog.daliansky.net/%e6%9e%b6%e8%ae%befreebsd62pf%e9%98%b2ddos-%e6%94%bb%e5%87%bb%e7%9a%84%e7%bd%91%e7%ab%99.html&title=架设FreeBSD6.2+PF防DDOS 攻击的网站">del.icio.us</a>
<br/>
Post tags: <a href="http://blog.daliansky.net/tag/bsd" rel="tag">bsd</a>, <a href="http://blog.daliansky.net/tag/pf" rel="tag">pf</a>, <a href="http://blog.daliansky.net/tag/syn" rel="tag">syn</a>, <a href="http://blog.daliansky.net/tag/%e6%94%bb%e5%87%bb" rel="tag">攻击</a>, <a href="http://blog.daliansky.net/tag/%e9%98%b2%e8%8c%83" rel="tag">防范</a><br/>
</small></p>
<p><small>Feed enhanced by <a href='http://planetozh.com/blog/my-projects/wordpress-plugin-better-feed-rss/'>Better Feed</a> from  <a href='http://planetozh.com/blog/'>Ozh</a></small></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.daliansky.net/%e6%9e%b6%e8%ae%befreebsd62pf%e9%98%b2ddos-%e6%94%bb%e5%87%bb%e7%9a%84%e7%bd%91%e7%ab%99.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>在 Ubuntu 7.10 上部署 Snort 入侵检测系统[转帖]</title>
		<link>http://blog.daliansky.net/%e5%9c%a8-ubuntu-710-%e4%b8%8a%e9%83%a8%e7%bd%b2-snort-%e5%85%a5%e4%be%b5%e6%a3%80%e6%b5%8b%e7%b3%bb%e7%bb%9f%e8%bd%ac%e5%b8%96.html</link>
		<comments>http://blog.daliansky.net/%e5%9c%a8-ubuntu-710-%e4%b8%8a%e9%83%a8%e7%bd%b2-snort-%e5%85%a5%e4%be%b5%e6%a3%80%e6%b5%8b%e7%b3%bb%e7%bb%9f%e8%bd%ac%e5%b8%96.html#comments</comments>
		<pubDate>Sat, 07 Jun 2008 08:17:06 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[网络安全]]></category>

		<guid isPermaLink="false">http://blog.daliansky.net/?p=39</guid>
		<description><![CDATA[作者：杨文博 &#60;http://blog.solrex.cn&#62; 地址：http://blog.solrex.cn/articles/implement-snort-ids-on-ubuntu-710.html 最后更新时间：2007年12月05日20点47分 摘要： 这份文档主要描述了我在 Ubuntu 7.10 上安装部署 Snort 入侵检测系统和 acid 基于 PHP 的网页入侵检测数据库分析控制台的过程。 目录 1. 介绍 2. 安装过程 3. 总结 4. 参考文章 1. 介绍 Snort 是一款非常优秀的开源主机入侵检测系统软件，可以用来对主机的网络状况进行记录、分析和报警，并且支持用户自定义规则库。Snort 在 Windows 平台和 Linux 平台上均可运行，详细介绍请访问 Snort 的官方网站：http://www.snort.org 。 Snort的默认记录是存放在 log 文本文件中，而为了观察监控方便起见，一般使用 acidbase 这个网页控制台来查看(好像 MySQL 的 phpmyadmin)。所以整个过程需要：安装 snort 和相应包；安装 LAMP(Linux, Apache, MySQL, PHP) 服务器；在MySQL数据库中建立好Snort数据库并配置 Snort 使其将 log 存放在 [...]]]></description>
			<content:encoded><![CDATA[<h3></h3>
<p>作者：杨文博 &lt;<a href="http://blog.solrex.cn/">http://blog.solrex.cn</a>&gt;<br />
地址：<a href="http://blog.solrex.cn/articles/implement-snort-ids-on-ubuntu-710.html" target="_blank">http://blog.solrex.cn/articles/implement-snort-ids-on-ubuntu-710.html</a></p>
<p>最后更新时间：2007年12月05日20点47分</p>
<blockquote><p>摘要：</p>
<p>这份文档主要描述了我在 Ubuntu 7.10 上安装部署 Snort 入侵检测系统和 acid 基于 PHP 的网页入侵检测数据库分析控制台的过程。</p></blockquote>
<p>目录</p>
<p>1. 介绍<br />
2. 安装过程<br />
3. 总结<br />
4. 参考文章</p>
<p>1. 介绍</p>
<p>Snort 是一款非常优秀的开源主机入侵检测系统软件，可以用来对主机的网络状况进行记录、分析和报警，并且支持用户自定义规则库。Snort 在 Windows 平台和 Linux 平台上均可运行，详细介绍请访问 Snort 的官方网站：http://www.snort.org 。</p>
<p>Snort的默认记录是存放在 log 文本文件中，而为了观察监控方便起见，一般使用 acidbase 这个网页控制台来查看(好像 MySQL 的 phpmyadmin)。所以整个过程需要：安装 snort 和相应包；安装 LAMP(Linux, Apache, MySQL, PHP) 服务器；在MySQL数据库中建立好Snort数据库并配置 Snort 使其将 log 存放在 MySQL 数据库中；为基于 PHP 的入侵检测数据库分析控制台 (acidbase) 配置好数据库连接。</p>
<p>2. 安装过程</p>
<p>[安装LAMP，Snort和一些软件库]</p>
<p>由于 Ubuntu 是 Debian 系的 Linux，安装软件非常简单，而且 Ubuntu 在中国科技大学有镜像，在教育网和科技网下载速度非常快(2~6M/s)，就省掉了出国下载安装包的麻烦，只需要一个命令即可在几十秒钟内安装好所有软 件。这里使用 Ubuntu 默认命令行软件包管理器 apt 来进行安装。</p>
<p>$ sudo apt-get install libpcap0.8-dev libmysqlclient15-dev mysql-client-5.0 mysql-server-5.0 bison flex apache2 libapache2-mod-php5 php5-gd php5-mysql libphp-adodb php-pear pcregrep snort snort-rules-default</p>
<p>需要注意的是在安装 MySQL 数据库时会弹出设置 MySQL 根用户口令的界面，临时设置其为“test”。</p>
<p>[在 MySQL 数据库中为 Snort 建立数据库]</p>
<p>Ubuntu 软件仓库中有一个默认的软件包 snort-mysql 提供辅助功能，用软件包管理器下载安装这个软件包。</p>
<p>$ sudo apt-get install snort-mysql</p>
<p>安装好之后查看帮助文档：</p>
<p>$ less /usr/share/doc/snort-mysql/README-database.Debian</p>
<p>根据帮助文档中的指令，在 MySQL 中建立 Snort 的数据库用户和数据库。所使用的命令如下：</p>
<p>$ mysql –u root –p</p>
<p>在提示符处输入口令 test.</p>
<p>mysql&gt; CREATE DATABASE snort;<br />
mysql&gt; grant CREATE, INSERT, SELECT, UPDATE on snort.* to snort@localhost;<br />
mysql&gt; grant CREATE, INSERT, SELECT, UPDATE on snort.* to snort;<br />
mysql&gt; SET PASSWORD FOR snort@localhost=PASSWORD(&#8216;snort-db&#8217;);<br />
mysql&gt; exit</p>
<p>以上命令的功能是在 MySQL 数据库中建立一个 snort 数据库，并建立一个 snort 用户来管理这个数据库，设置 snort 用户的口令为 snort-db。</p>
<p>然后根据 README-database.Debian 中的指示建立 snort 数据库的结构。</p>
<p>$ cd /usr/share/doc/snort-mysql<br />
$ zcat create_mysql.gz | mysql -u snort -D snort -psnort-db</p>
<p>这样就为 snort 在 MySQL 中建立了数据库的结构，其中包括各个 snort 需要使用的表。</p>
<p>[设置 snort 把 log 文件输出到 MySQL 数据库中]</p>
<p>修改 Snort 的配置文件：/etc/snort/snort.conf</p>
<p>$ sudo vim /etc/snort/snort.conf</p>
<p>在配置文件中将 HOME_NET 有关项注释掉，然后将 HOME_NET 设置为本机 IP 所在网络，将 EXTERNAL_NET 相关项注释掉，设置其为非本机网络，如下所示：</p>
<p>#var HOME_NET any<br />
var HOME_NET 210.77.8.0/16<br />
#var EXTERNAL_NET any<br />
var EXTERNAL_NET !$HOME_NET</p>
<p>将 output database 相关项注释掉，将日志输出设置到 MySQL 数据库中，如下所示：</p>
<p>output database: log, mysql, user=snort password=snort-db dbname=snort host=localhost<br />
#output database: log, mysql</p>
<p>这样，snort 就不再向 /var/log/snort 目录下的文件写记录了，转而将记录存放在 MySQL 的snort数据库中。这时候可以测试一下 Snort 工作是否正常：</p>
<p>$ sudo snort -c /etc/snort/snort.conf</p>
<p>如果出现一个用 ASCII 字符画出的小猪，那么 Snort 工作就正常了，可以使用 Ctrl-C 退出；如果 Snort 异常退出，就需要查明以上配置的正确性了。</p>
<p>[测试 Web 服务器 Apache 和 PHP 是否工作正常]</p>
<p>配置 apache 的 php 模块，添加 msql 和 gd 的扩展。</p>
<p>$ sudo vim /etc/php5/apache2/php.ini<br />
extension=msql.so<br />
extension=gd.so</p>
<p>重新启动 apache</p>
<p>$ /etc/init.d/apache2 restart</p>
<p>在/var/www/目录下新建一个文本文件test.php</p>
<p>$ sudo vim /var/www/test.php</p>
<p>输入内容：</p>
<p>&lt;?php<br />
phpinfo();<br />
?&gt;</p>
<p>然后在浏览器中输入 http://localhost/test.php，如果配置正确的话，就会出现 PHP INFO 的经典界面，就标志着 LAMP 工作正常。</p>
<p>[安装和配置 acid-base]</p>
<p>安装 acid-base 很简单，使用 Ubuntu 软件包管理器下载安装即可：</p>
<p>$ sudo apt-get install acidbase</p>
<p>安装过程中需要输入 acidbase 选择使用的数据库，这里选 MySQL，根用户口令 test，和 acid-base 的口令(貌似也可以跳过不设置)。</p>
<p>将acidbase从安装目录中拷贝到www目录中，也可以直接在apache中建立一个虚拟目录指向安装目录，这里拷贝过来主要是为了安全性考虑。</p>
<p>sudo cp –R /usr/share/acidbase/ /var/www/</p>
<p>因为 acidbase 目录下的 base_conf.php 原本是一个符号链接指向 /etc/acidbase/ 下的base_conf.php，为了保证权限可控制，我们要删除这个链接并新建 base_conf.php 文件。</p>
<p>$ rm base_conf.php<br />
$ touch base_conf.php</p>
<p>暂时将 /var/www/acidbase/ 目录权限改为所有人可写，主要是为了配置 acidbase 所用。</p>
<p>$ sudo chmod 757 acidbase/</p>
<p>现在就可以开始配置 acid-base 了，在浏览器地址栏中输入 http://localhost/acidbase，就会转入安装界面，然后就点击 continue 一步步地进行安装：</p>
<p>选择语言为 english，adodb 的路径为：/usr/share/php/adodb；选择数据库为 MySQL，数据库名为 snort，数据库主机为 localhost，数据库用户名为 snort 的口令为 snort-db；设置 acidbase 系统管理员用户名和口令，设置系统管理员用户名为 admin，口令为 test。然后一路继续下去，就能安装完成了。</p>
<p>安装完成后就可以进入登录界面，输入用户名和口令，进入 acidbase 系统。</p>
<p>这里需要将 acidbase 目录的权限改回去以确保安全性，然后在后台启动 snort，就表明 snort 入侵检测系统的安装完成并正常启动了：</p>
<p>$ sudo chmod 775 acidbase/<br />
$ sudo snort -c /etc/snort/snort.conf -i eth0 –D</p>
<p>[检查入侵检测系统工作状况，更改入侵检测规则]</p>
<p>正常情况下在一个不安全的网络中，登录 acidbase 后一会儿就能发现网络攻击。如果没有发现网络攻击，可以添加更严格的规则使得正常的网络连接也可能被报攻击，以测试 Snort IDS 的工作正确性，比如在 /etc/snort/rules/web-misc.rules 的最后添加下面的话：</p>
<p>$ sudo vi /etc/snort/rules/web-misc.rules<br />
alert tcp any :1024 -&gt; $HTTP_SERVER 500:</p>
<p>这一行的意思是：对从任何地址小于 1024 端口向本机 500 以上端口发送的 tcp 数据包都报警。杀死 Snort 的后台进程并重新启动，就应该能检测到正常的包也被当作攻击了。</p>
<p>$ sudo kill `pgrep snort`<br />
$ sudo snort –c /etc/snort/snort.conf –i eth0 -D</p>
<p>3. 总结</p>
<p>使用 Ubuntu 部署 Snort 入侵检测系统和网页控制台是相当容易的，因为 Ubuntu 提供了很方便的软件包安装功能，只是有时候定制性能太差，需要用户手动去寻找软件包的安装位置。</p>
<p>4. 参考文章</p>
<p>http://www.howtoforge.com/intrusion-detection-with-snort-mysql-apache2-on-ubuntu-7.10</p>
<p><a class="a2a_button_google_reader" href="http://www.addtoany.com/add_to/google_reader?linkurl=http%3A%2F%2Fblog.daliansky.net%2F%25e5%259c%25a8-ubuntu-710-%25e4%25b8%258a%25e9%2583%25a8%25e7%25bd%25b2-snort-%25e5%2585%25a5%25e4%25be%25b5%25e6%25a3%2580%25e6%25b5%258b%25e7%25b3%25bb%25e7%25bb%259f%25e8%25bd%25ac%25e5%25b8%2596.html&amp;linkname=%E5%9C%A8%20Ubuntu%207.10%20%E4%B8%8A%E9%83%A8%E7%BD%B2%20Snort%20%E5%85%A5%E4%BE%B5%E6%A3%80%E6%B5%8B%E7%B3%BB%E7%BB%9F%5B%E8%BD%AC%E5%B8%96%5D" title="Google Reader" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/reader.png" width="16" height="16" alt="Google Reader"/></a><a class="a2a_button_google_bookmarks" href="http://www.addtoany.com/add_to/google_bookmarks?linkurl=http%3A%2F%2Fblog.daliansky.net%2F%25e5%259c%25a8-ubuntu-710-%25e4%25b8%258a%25e9%2583%25a8%25e7%25bd%25b2-snort-%25e5%2585%25a5%25e4%25be%25b5%25e6%25a3%2580%25e6%25b5%258b%25e7%25b3%25bb%25e7%25bb%259f%25e8%25bd%25ac%25e5%25b8%2596.html&amp;linkname=%E5%9C%A8%20Ubuntu%207.10%20%E4%B8%8A%E9%83%A8%E7%BD%B2%20Snort%20%E5%85%A5%E4%BE%B5%E6%A3%80%E6%B5%8B%E7%B3%BB%E7%BB%9F%5B%E8%BD%AC%E5%B8%96%5D" title="Google Bookmarks" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/google.png" width="16" height="16" alt="Google Bookmarks"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblog.daliansky.net%2F%25e5%259c%25a8-ubuntu-710-%25e4%25b8%258a%25e9%2583%25a8%25e7%25bd%25b2-snort-%25e5%2585%25a5%25e4%25be%25b5%25e6%25a3%2580%25e6%25b5%258b%25e7%25b3%25bb%25e7%25bb%259f%25e8%25bd%25ac%25e5%25b8%2596.html&amp;linkname=%E5%9C%A8%20Ubuntu%207.10%20%E4%B8%8A%E9%83%A8%E7%BD%B2%20Snort%20%E5%85%A5%E4%BE%B5%E6%A3%80%E6%B5%8B%E7%B3%BB%E7%BB%9F%5B%E8%BD%AC%E5%B8%96%5D" title="Facebook" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fblog.daliansky.net%2F%25e5%259c%25a8-ubuntu-710-%25e4%25b8%258a%25e9%2583%25a8%25e7%25bd%25b2-snort-%25e5%2585%25a5%25e4%25be%25b5%25e6%25a3%2580%25e6%25b5%258b%25e7%25b3%25bb%25e7%25bb%259f%25e8%25bd%25ac%25e5%25b8%2596.html&amp;linkname=%E5%9C%A8%20Ubuntu%207.10%20%E4%B8%8A%E9%83%A8%E7%BD%B2%20Snort%20%E5%85%A5%E4%BE%B5%E6%A3%80%E6%B5%8B%E7%B3%BB%E7%BB%9F%5B%E8%BD%AC%E5%B8%96%5D" title="Twitter" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_yahoo_bookmarks" href="http://www.addtoany.com/add_to/yahoo_bookmarks?linkurl=http%3A%2F%2Fblog.daliansky.net%2F%25e5%259c%25a8-ubuntu-710-%25e4%25b8%258a%25e9%2583%25a8%25e7%25bd%25b2-snort-%25e5%2585%25a5%25e4%25be%25b5%25e6%25a3%2580%25e6%25b5%258b%25e7%25b3%25bb%25e7%25bb%259f%25e8%25bd%25ac%25e5%25b8%2596.html&amp;linkname=%E5%9C%A8%20Ubuntu%207.10%20%E4%B8%8A%E9%83%A8%E7%BD%B2%20Snort%20%E5%85%A5%E4%BE%B5%E6%A3%80%E6%B5%8B%E7%B3%BB%E7%BB%9F%5B%E8%BD%AC%E5%B8%96%5D" title="Yahoo Bookmarks" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/yahoo.png" width="16" height="16" alt="Yahoo Bookmarks"/></a><a class="a2a_button_myspace" href="http://www.addtoany.com/add_to/myspace?linkurl=http%3A%2F%2Fblog.daliansky.net%2F%25e5%259c%25a8-ubuntu-710-%25e4%25b8%258a%25e9%2583%25a8%25e7%25bd%25b2-snort-%25e5%2585%25a5%25e4%25be%25b5%25e6%25a3%2580%25e6%25b5%258b%25e7%25b3%25bb%25e7%25bb%259f%25e8%25bd%25ac%25e5%25b8%2596.html&amp;linkname=%E5%9C%A8%20Ubuntu%207.10%20%E4%B8%8A%E9%83%A8%E7%BD%B2%20Snort%20%E5%85%A5%E4%BE%B5%E6%A3%80%E6%B5%8B%E7%B3%BB%E7%BB%9F%5B%E8%BD%AC%E5%B8%96%5D" title="MySpace" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/myspace.png" width="16" height="16" alt="MySpace"/></a><a class="a2a_button_hotmail" href="http://www.addtoany.com/add_to/hotmail?linkurl=http%3A%2F%2Fblog.daliansky.net%2F%25e5%259c%25a8-ubuntu-710-%25e4%25b8%258a%25e9%2583%25a8%25e7%25bd%25b2-snort-%25e5%2585%25a5%25e4%25be%25b5%25e6%25a3%2580%25e6%25b5%258b%25e7%25b3%25bb%25e7%25bb%259f%25e8%25bd%25ac%25e5%25b8%2596.html&amp;linkname=%E5%9C%A8%20Ubuntu%207.10%20%E4%B8%8A%E9%83%A8%E7%BD%B2%20Snort%20%E5%85%A5%E4%BE%B5%E6%A3%80%E6%B5%8B%E7%B3%BB%E7%BB%9F%5B%E8%BD%AC%E5%B8%96%5D" title="Hotmail" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/live.png" width="16" height="16" alt="Hotmail"/></a><a class="a2a_button_yahoo_mail" href="http://www.addtoany.com/add_to/yahoo_mail?linkurl=http%3A%2F%2Fblog.daliansky.net%2F%25e5%259c%25a8-ubuntu-710-%25e4%25b8%258a%25e9%2583%25a8%25e7%25bd%25b2-snort-%25e5%2585%25a5%25e4%25be%25b5%25e6%25a3%2580%25e6%25b5%258b%25e7%25b3%25bb%25e7%25bb%259f%25e8%25bd%25ac%25e5%25b8%2596.html&amp;linkname=%E5%9C%A8%20Ubuntu%207.10%20%E4%B8%8A%E9%83%A8%E7%BD%B2%20Snort%20%E5%85%A5%E4%BE%B5%E6%A3%80%E6%B5%8B%E7%B3%BB%E7%BB%9F%5B%E8%BD%AC%E5%B8%96%5D" title="Yahoo Mail" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/yahoo.png" width="16" height="16" alt="Yahoo Mail"/></a><a class="a2a_button_wordpress" href="http://www.addtoany.com/add_to/wordpress?linkurl=http%3A%2F%2Fblog.daliansky.net%2F%25e5%259c%25a8-ubuntu-710-%25e4%25b8%258a%25e9%2583%25a8%25e7%25bd%25b2-snort-%25e5%2585%25a5%25e4%25be%25b5%25e6%25a3%2580%25e6%25b5%258b%25e7%25b3%25bb%25e7%25bb%259f%25e8%25bd%25ac%25e5%25b8%2596.html&amp;linkname=%E5%9C%A8%20Ubuntu%207.10%20%E4%B8%8A%E9%83%A8%E7%BD%B2%20Snort%20%E5%85%A5%E4%BE%B5%E6%A3%80%E6%B5%8B%E7%B3%BB%E7%BB%9F%5B%E8%BD%AC%E5%B8%96%5D" title="WordPress" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/wordpress.png" width="16" height="16" alt="WordPress"/></a><a class="a2a_button_yahoo_messenger" href="http://www.addtoany.com/add_to/yahoo_messenger?linkurl=http%3A%2F%2Fblog.daliansky.net%2F%25e5%259c%25a8-ubuntu-710-%25e4%25b8%258a%25e9%2583%25a8%25e7%25bd%25b2-snort-%25e5%2585%25a5%25e4%25be%25b5%25e6%25a3%2580%25e6%25b5%258b%25e7%25b3%25bb%25e7%25bb%259f%25e8%25bd%25ac%25e5%25b8%2596.html&amp;linkname=%E5%9C%A8%20Ubuntu%207.10%20%E4%B8%8A%E9%83%A8%E7%BD%B2%20Snort%20%E5%85%A5%E4%BE%B5%E6%A3%80%E6%B5%8B%E7%B3%BB%E7%BB%9F%5B%E8%BD%AC%E5%B8%96%5D" title="Yahoo Messenger" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/yim.png" width="16" height="16" alt="Yahoo Messenger"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblog.daliansky.net%2F%25e5%259c%25a8-ubuntu-710-%25e4%25b8%258a%25e9%2583%25a8%25e7%25bd%25b2-snort-%25e5%2585%25a5%25e4%25be%25b5%25e6%25a3%2580%25e6%25b5%258b%25e7%25b3%25bb%25e7%25bb%259f%25e8%25bd%25ac%25e5%25b8%2596.html&amp;title=%E5%9C%A8%20Ubuntu%207.10%20%E4%B8%8A%E9%83%A8%E7%BD%B2%20Snort%20%E5%85%A5%E4%BE%B5%E6%A3%80%E6%B5%8B%E7%B3%BB%E7%BB%9F%5B%E8%BD%AC%E5%B8%96%5D" id="wpa2a_4"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a></p><hr />
<p><small>© admin for <a href="http://blog.daliansky.net">DalianSky&#039;s Blog</a>, 2008. |
<a href="http://blog.daliansky.net/%e5%9c%a8-ubuntu-710-%e4%b8%8a%e9%83%a8%e7%bd%b2-snort-%e5%85%a5%e4%be%b5%e6%a3%80%e6%b5%8b%e7%b3%bb%e7%bb%9f%e8%bd%ac%e5%b8%96.html">Permalink</a> |
<a href="http://blog.daliansky.net/%e5%9c%a8-ubuntu-710-%e4%b8%8a%e9%83%a8%e7%bd%b2-snort-%e5%85%a5%e4%be%b5%e6%a3%80%e6%b5%8b%e7%b3%bb%e7%bb%9f%e8%bd%ac%e5%b8%96.html#comments">5 comments</a> |
Add to
<a href="http://del.icio.us/post?url=http://blog.daliansky.net/%e5%9c%a8-ubuntu-710-%e4%b8%8a%e9%83%a8%e7%bd%b2-snort-%e5%85%a5%e4%be%b5%e6%a3%80%e6%b5%8b%e7%b3%bb%e7%bb%9f%e8%bd%ac%e5%b8%96.html&title=在 Ubuntu 7.10 上部署 Snort 入侵检测系统[转帖]">del.icio.us</a>
<br/>
Post tags: <br/>
</small></p>
<p><small>Feed enhanced by <a href='http://planetozh.com/blog/my-projects/wordpress-plugin-better-feed-rss/'>Better Feed</a> from  <a href='http://planetozh.com/blog/'>Ozh</a></small></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.daliansky.net/%e5%9c%a8-ubuntu-710-%e4%b8%8a%e9%83%a8%e7%bd%b2-snort-%e5%85%a5%e4%be%b5%e6%a3%80%e6%b5%8b%e7%b3%bb%e7%bb%9f%e8%bd%ac%e5%b8%96.html/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Snort入侵检测系统安装与配置</title>
		<link>http://blog.daliansky.net/snort%e5%85%a5%e4%be%b5%e6%a3%80%e6%b5%8b%e7%b3%bb%e7%bb%9f%e5%ae%89%e8%a3%85%e4%b8%8e%e9%85%8d%e7%bd%ae.html</link>
		<comments>http://blog.daliansky.net/snort%e5%85%a5%e4%be%b5%e6%a3%80%e6%b5%8b%e7%b3%bb%e7%bb%9f%e5%ae%89%e8%a3%85%e4%b8%8e%e9%85%8d%e7%bd%ae.html#comments</comments>
		<pubDate>Sat, 07 Jun 2008 07:50:03 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[网络安全]]></category>

		<guid isPermaLink="false">http://blog.daliansky.net/?p=38</guid>
		<description><![CDATA[第1章 Snort简介 第2章 软件列表 第3章 Snort 安装与配置 第4章 Snort的操作与使用 第5章 常见问题与解决方法 第1章 Snort简介 Snort是一个免费的IDS(入侵监测系统)软件。它的一些源代码是从著名的tcpdump软件发展而来的。它是一个基于libpcap包的网络监控软件，可以作为一个十分有效的网络入侵监测系统。它能够监测多种网络攻击和探测，例如：缓冲器溢出攻击，端口扫描，CGI攻击，SMB探测等等。Snort具有实时的告警能力，将告警记入一个特别的告警文件&#8211;系统日志，或者将告警信息通过samba转发给另一台Windows PC机。 Snort首先根据远端的ip地址建立目录,然后将检测到的包以tcpdump的二进制格式记录或者以自身的解码形式存储到这些目录中.这样一来,你就可以使用snort来监测或过滤你所需要的包. snort是一个轻量级的入侵检测系统，它具有截取网络数据报文，进行网络数据实时分析、报警,以及日志的能力。snort的报文截取代码是基于libpcap库的，继承了libpcap库的平台兼容性。它能够进行协议分析，内容搜索/匹配，能够用来检测各种攻击和探测，例如：缓冲区溢出、隐秘端口扫描、CGI攻击、SMB探测、OS指纹特征检测等等。snort使用一种灵活的规则语言来描述网络数据报文，因此可以对新的攻击作出快速地翻译。snort具有实时报警能力。可以将报警信息写到syslog、指定的文件、UNIX套接字或者使用WinPopup消息。snort具有良好的扩展能力。它支持插件体系，可以通过其定义的接口，很方便地加入新的功能。snort还能够记录网络数据，其日志文件可以是tcpdump格式，也可以是解码的ASCII格式。 第2章 软件列表 软件名称 功能简述 正式网址 软件版本 Snort 网络入侵探测器 www.snort.org/ 1.8.6 Libpcap Snort所依赖的网络抓包库 www.tcpdump.org/ 0.7.1 MySQL 入侵事件数据库 www.mysql.org/ 3.23.49 Apache Web服务器 www.apache.org/ 1.3.24 Mod_ssl 为Apache提供SSL加密功能的模块 www.modssl.org/ 2.8.8 OpenSSL 开放源代码的SSL加密库，为mod_ssl所依赖 www.openssl.org/ 0.9.6d MM 为Apache的模块提供共享内存服务 www.engelschall.com/ 1.1.3 ACID 基于Web的入侵事件数据库分析控制台 www.cert.org/kb/aircert/ 0.9.6b21 [...]]]></description>
			<content:encoded><![CDATA[<div id="art" style="margin: 15px;">
<div>
<div>
<h1 style="margin: 17pt 0cm 16.5pt;">
<p class="MsoToc1" style="margin: 0cm 0cm 0pt; line-height: 150%;"><span style="font-family: 宋体;" lang="EN-US"><span class="MsoHyperlink"><span><span style="font-size: small;"><span style="color: #0000ff;"><span lang="EN-US"><span lang="EN-US">第1</span></span><span lang="EN-US"><span lang="EN-US">章</span></span></span><span style="color: windowtext; text-decoration: none;"><span> </span></span><span style="color: #0000ff;">Snort</span><span lang="EN-US"><span lang="EN-US"><span style="color: #0000ff;">简介</span></span></span></span></span></span></span></p>
<p class="MsoToc1" style="margin: 0cm 0cm 0pt; line-height: 150%;"><span class="MsoHyperlink"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span style="color: #0000ff;"><span lang="EN-US"><span lang="EN-US">第2</span></span><span lang="EN-US"><span lang="EN-US">章</span></span></span><span style="color: windowtext; text-decoration: none;"><span> </span></span><span lang="EN-US"><span lang="EN-US"><span style="color: #0000ff;">软件列表</span></span></span></span></span></span></p>
<p class="MsoToc1" style="margin: 0cm 0cm 0pt; line-height: 150%;"><span class="MsoHyperlink"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span style="color: #0000ff;"><span lang="EN-US"><span lang="EN-US">第3</span></span><span lang="EN-US"><span lang="EN-US">章</span></span></span><span style="color: windowtext; text-decoration: none;"><span> </span></span><span style="color: #0000ff;">Snort <span lang="EN-US"><span lang="EN-US">安装与配置</span></span></span></span></span></span></p>
<p class="MsoToc1" style="margin: 0cm 0cm 0pt; line-height: 150%;"><span class="MsoHyperlink"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span style="color: #0000ff;"><span lang="EN-US"><span lang="EN-US">第4</span></span><span lang="EN-US"><span lang="EN-US">章</span></span></span><span style="color: windowtext; text-decoration: none;"><span> </span></span><span style="color: #0000ff;">Snort<span lang="EN-US"><span lang="EN-US">的<span lang="EN-US">操作与使用</span></span></span></span></span></span></span></p>
<p class="MsoToc1" style="margin: 0cm 0cm 0pt; line-height: 150%;"><span class="MsoHyperlink"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span style="color: #0000ff;"><span lang="EN-US"><span lang="EN-US">第5</span></span><span lang="EN-US"><span lang="EN-US">章</span></span></span><span style="color: windowtext; text-decoration: none;"><span> </span></span><span lang="EN-US"><span lang="EN-US"><span style="color: #0000ff;">常见问题与解决方法</span></span></span></span></span></span></p>
<p class="MsoToc1" style="margin: 0cm 0cm 0pt; line-height: 150%;"><span class="MsoHyperlink"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span lang="EN-US"></span></span></span></span></p>
<p><a name="_Toc45019022"><span lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></a></h1>
<p style="margin: 17pt 0cm 16.5pt;">
<h1 style="margin: 17pt 0cm 16.5pt 21.6pt; text-indent: -21.6pt; text-align: center;"><span><span style="font-family: Times New Roman;"><span lang="EN-US"><span>第1章<span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"><span style="font-size: x-large;"> </span></span></span></span><span lang="EN-US">Snort</span></span></span><span><span style="font-family: 宋体;">简介</span></span></h1>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span lang="EN-US"><span style="font-family: Times New Roman; font-size: small;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 31.5pt; line-height: 150%;"><span style="font-size: small;"><span class="line1"><span lang="EN-US"><span style="font-family: Times New Roman;">Snort</span></span></span><span class="line1"><span style="font-family: 宋体;">是一个免费的</span><span lang="EN-US"><span style="font-family: Times New Roman;">IDS(</span></span></span><span class="line1"><span style="font-family: 宋体;">入侵监测系统</span><span lang="EN-US"><span style="font-family: Times New Roman;">)</span></span></span><span class="line1"><span style="font-family: 宋体;">软件。它的一些源代码是从著名的</span><span lang="EN-US"><span style="font-family: Times New Roman;">tcpdump</span></span></span><span class="line1"><span style="font-family: 宋体;">软件发展而来的。它是一个基于</span><span lang="EN-US"><span style="font-family: Times New Roman;">libpcap</span></span></span><span class="line1"><span style="font-family: 宋体;">包的网络监控软件，可以作为一个十分有效的网络入侵监测系统。它能够监测多种网络攻击和探测，例如：缓冲器溢出攻击，端口扫描，</span><span lang="EN-US"><span style="font-family: Times New Roman;">CGI</span></span></span><span class="line1"><span style="font-family: 宋体;">攻击，</span><span lang="EN-US"><span style="font-family: Times New Roman;">SMB</span></span></span><span class="line1"><span style="font-family: 宋体;">探测等等。</span><span lang="EN-US"><span style="font-family: Times New Roman;">Snort</span></span></span><span class="line1"><span style="font-family: 宋体;">具有实时的告警能力，将告警记入一个特别的告警文件</span><span lang="EN-US"><span style="font-family: Times New Roman;">&#8211;</span></span></span><span class="line1"><span style="font-family: 宋体;">系统日志，或者将告警信息通过</span><span lang="EN-US"><span style="font-family: Times New Roman;">samba</span></span></span><span class="line1"><span style="font-family: 宋体;">转发给另一台</span><span lang="EN-US"><span style="font-family: Times New Roman;">Windows PC</span></span></span><span class="line1"><span style="font-family: 宋体;">机。</span></span></span><span lang="EN-US"><br />
</span><span style="font-size: small;"><span class="line1"><span style="font-family: 宋体;"> </span><span lang="EN-US"><span style="font-family: Times New Roman;">Snort</span></span></span><span class="line1"><span style="font-family: 宋体;">首先根据远端的</span><span lang="EN-US"><span style="font-family: Times New Roman;">ip</span></span></span><span class="line1"><span style="font-family: 宋体;">地址建立目录</span><span lang="EN-US"><span style="font-family: Times New Roman;">,</span></span></span><span class="line1"><span style="font-family: 宋体;">然后将检测到的包以</span><span lang="EN-US"><span style="font-family: Times New Roman;">tcpdump</span></span></span><span class="line1"><span style="font-family: 宋体;">的二进制格式记录或者以自身的解码形式存储到这些目录中</span><span lang="EN-US"><span style="font-family: Times New Roman;">.</span></span></span><span class="line1"><span style="font-family: 宋体;">这样一来</span><span lang="EN-US"><span style="font-family: Times New Roman;">,</span></span></span><span class="line1"><span style="font-family: 宋体;">你就可以使用</span><span lang="EN-US"><span style="font-family: Times New Roman;">snort</span></span></span><span class="line1"><span style="font-family: 宋体;">来监测或过滤你所需要的包</span><span lang="EN-US"><span style="font-family: Times New Roman;">.</span></span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 34.5pt; line-height: 150%;"><span style="font-size: 11.5pt; line-height: 150%;" lang="EN-US"><span style="font-family: Times New Roman;">snort</span></span><span style="font-size: 11.5pt; line-height: 150%; font-family: 宋体;">是一个轻量级的入侵检测系统，它具有截取网络数据报文，进行网络数据实时分析、报警</span><span style="font-size: 11.5pt; line-height: 150%;" lang="EN-US"><span style="font-family: Times New Roman;">,</span></span><span style="font-size: 11.5pt; line-height: 150%; font-family: 宋体;">以及日志的能力。</span><span style="font-size: 11.5pt; line-height: 150%;" lang="EN-US"><span style="font-family: Times New Roman;">snort</span></span><span style="font-size: 11.5pt; line-height: 150%; font-family: 宋体;">的报文截取代码是基于</span><span style="font-size: 11.5pt; line-height: 150%;" lang="EN-US"><span style="font-family: Times New Roman;">libpcap</span></span><span style="font-size: 11.5pt; line-height: 150%; font-family: 宋体;">库的，继承了</span><span style="font-size: 11.5pt; line-height: 150%;" lang="EN-US"><span style="font-family: Times New Roman;">libpcap</span></span><span style="font-size: 11.5pt; line-height: 150%; font-family: 宋体;">库的平台兼容性。它能够进行协议分析，内容搜索</span><span style="font-size: 11.5pt; line-height: 150%;" lang="EN-US"><span style="font-family: Times New Roman;">/</span></span><span style="font-size: 11.5pt; line-height: 150%; font-family: 宋体;">匹配，能够用来检测各种攻击和探测，例如：缓冲区溢出、隐秘端口扫描、</span><span style="font-size: 11.5pt; line-height: 150%;" lang="EN-US"><span style="font-family: Times New Roman;">CGI</span></span><span style="font-size: 11.5pt; line-height: 150%; font-family: 宋体;">攻击、</span><span style="font-size: 11.5pt; line-height: 150%;" lang="EN-US"><span style="font-family: Times New Roman;">SMB</span></span><span style="font-size: 11.5pt; line-height: 150%; font-family: 宋体;">探测、</span><span style="font-size: 11.5pt; line-height: 150%;" lang="EN-US"><span style="font-family: Times New Roman;">OS</span></span><span style="font-size: 11.5pt; line-height: 150%; font-family: 宋体;">指纹特征检测等等。</span><span style="font-size: 11.5pt; line-height: 150%;" lang="EN-US"><span style="font-family: Times New Roman;">snort</span></span><span style="font-size: 11.5pt; line-height: 150%; font-family: 宋体;">使用一种灵活的规则语言来描述网络数据报文，因此可以对新的攻击作出快速地翻译。</span><span style="font-size: 11.5pt; line-height: 150%;" lang="EN-US"><span style="font-family: Times New Roman;">snort</span></span><span style="font-size: 11.5pt; line-height: 150%; font-family: 宋体;">具有实时报警能力。可以将报警信息写到</span><span style="font-size: 11.5pt; line-height: 150%;" lang="EN-US"><span style="font-family: Times New Roman;">syslog</span></span><span style="font-size: 11.5pt; line-height: 150%; font-family: 宋体;">、指定的文件、</span><span style="font-size: 11.5pt; line-height: 150%;" lang="EN-US"><span style="font-family: Times New Roman;">UNIX</span></span><span style="font-size: 11.5pt; line-height: 150%; font-family: 宋体;">套接字或者使用</span><span style="font-size: 11.5pt; line-height: 150%;" lang="EN-US"><span style="font-family: Times New Roman;">WinPopup</span></span><span style="font-size: 11.5pt; line-height: 150%; font-family: 宋体;">消息。</span><span style="font-size: 11.5pt; line-height: 150%;" lang="EN-US"><span style="font-family: Times New Roman;">snort</span></span><span style="font-size: 11.5pt; line-height: 150%; font-family: 宋体;">具有良好的扩展能力。它支持插件体系，可以通过其定义的接口，很方便地加入新的功能。</span><span style="font-size: 11.5pt; line-height: 150%;" lang="EN-US"><span style="font-family: Times New Roman;">snort</span></span><span style="font-size: 11.5pt; line-height: 150%; font-family: 宋体;">还能够记录网络数据，其日志文件可以是</span><span style="font-size: 11.5pt; line-height: 150%;" lang="EN-US"><span style="font-family: Times New Roman;">tcpdump</span></span><span style="font-size: 11.5pt; line-height: 150%; font-family: 宋体;">格式，也可以是解码的</span><span style="font-size: 11.5pt; line-height: 150%;" lang="EN-US"><span style="font-family: Times New Roman;">ASCII</span></span><span style="font-size: 11.5pt; line-height: 150%; font-family: 宋体;">格式。</span></p>
<p><strong><span style="font-size: 22pt; line-height: 240%; font-family: 'Times New Roman';" lang="EN-US"><br style="page-break-before: always;" /></span></strong></p>
<h1 style="margin: 17pt 0cm 16.5pt 21.6pt; text-indent: -21.6pt; text-align: center;"><a name="_Toc45019023"><span lang="EN-US"><span><span style="font-family: Times New Roman;">第2章<span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"><span style="font-size: x-large;"> </span></span></span></span></span><span style="font-family: 宋体;">软件列表</span></a></h1>
<table class="MsoNormalTable" style="width: 100%;" border="0" cellspacing="1" cellpadding="0" width="100%">
<tbody>
<tr>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #009999 none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-size: 9pt; font-family: 宋体;">软件名称</span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #009999 none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-size: 9pt; font-family: 宋体;">功能简述</span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #009999 none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-size: 9pt; font-family: 宋体;">正式网址</span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #009999 none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-size: 9pt; font-family: 宋体;">软件版本</span><span style="font-family: Times New Roman;"><span style="font-size: 9pt;"> </span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></span></p>
</td>
</tr>
<tr>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-family: Times New Roman;"><span style="font-size: 9pt;" lang="EN-US">Snort</span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-size: 9pt; font-family: 宋体;">网络入侵探测器</span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-size: 9pt;" lang="EN-US"><a href="http://www.snort.org/" target="_blank"><span style="font-size: 10.5pt;"><span style="font-family: Times New Roman; color: #0000ff;">www.snort.org/</span></span></a></span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-family: Times New Roman;"><span style="font-size: 9pt;" lang="EN-US">1.8.6 </span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></span></p>
</td>
</tr>
<tr>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-family: Times New Roman;"><span style="font-size: 9pt;" lang="EN-US">Libpcap</span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-size: 9pt;" lang="EN-US"><span style="font-family: Times New Roman;">Snort</span></span><span style="font-size: 9pt; font-family: 宋体;">所依赖的网络抓包库</span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-size: 9pt;" lang="EN-US"><a href="http:///" target="_blank"><span style="font-size: 10.5pt;"><span style="font-family: Times New Roman; color: #0000ff;">www.tcpdump.org/</span></span></a></span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-family: Times New Roman;"><span style="font-size: 9pt;" lang="EN-US">0.7.1 </span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></span></p>
</td>
</tr>
<tr>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-family: Times New Roman;"><span style="font-size: 9pt;" lang="EN-US">MySQL</span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-size: 9pt; font-family: 宋体;">入侵事件数据库</span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-size: 9pt;" lang="EN-US"><a href="http://www.mysql.org/" target="_blank"><span style="font-size: 10.5pt;"><span style="font-family: Times New Roman; color: #0000ff;">www.mysql.org/</span></span></a></span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-family: Times New Roman;"><span style="font-size: 9pt;" lang="EN-US">3.23.49 </span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></span></p>
</td>
</tr>
<tr>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-family: Times New Roman;"><span style="font-size: 9pt;" lang="EN-US">Apache</span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-size: 9pt;" lang="EN-US"><span style="font-family: Times New Roman;">Web</span></span><span style="font-size: 9pt; font-family: 宋体;">服务器</span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-size: 9pt;" lang="EN-US"><a href="http://www.apache.org/" target="_blank"><span style="font-size: 10.5pt;"><span style="font-family: Times New Roman; color: #0000ff;">www.apache.org/</span></span></a></span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-family: Times New Roman;"><span style="font-size: 9pt;" lang="EN-US">1.3.24 </span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></span></p>
</td>
</tr>
<tr>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-family: Times New Roman;"><span style="font-size: 9pt;" lang="EN-US">Mod_ssl</span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-size: 9pt; font-family: 宋体;">为</span><span style="font-size: 9pt;" lang="EN-US"><span style="font-family: Times New Roman;">Apache</span></span><span style="font-size: 9pt; font-family: 宋体;">提供</span><span style="font-size: 9pt;" lang="EN-US"><span style="font-family: Times New Roman;">SSL</span></span><span style="font-size: 9pt; font-family: 宋体;">加密功能的模块</span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-size: 9pt;" lang="EN-US"><a href="http://www.modssl.org/" target="_blank"><span style="font-size: 10.5pt;"><span style="font-family: Times New Roman; color: #0000ff;">www.modssl.org/</span></span></a></span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-family: Times New Roman;"><span style="font-size: 9pt;" lang="EN-US">2.8.8 </span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></span></p>
</td>
</tr>
<tr>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-family: Times New Roman;"><span style="font-size: 9pt;" lang="EN-US">OpenSSL</span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-size: 9pt; font-family: 宋体;">开放源代码的</span><span style="font-size: 9pt;" lang="EN-US"><span style="font-family: Times New Roman;">SSL</span></span><span style="font-size: 9pt; font-family: 宋体;">加密库，为</span><span style="font-size: 9pt;" lang="EN-US"><span style="font-family: Times New Roman;">mod_ssl</span></span><span style="font-size: 9pt; font-family: 宋体;">所依赖</span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-size: 9pt;" lang="EN-US"><a href="http://www.openssl.org/" target="_blank"><span style="font-size: 10.5pt;"><span style="font-family: Times New Roman; color: #0000ff;">www.openssl.org/</span></span></a></span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-family: Times New Roman;"><span style="font-size: 9pt;" lang="EN-US">0.9.6d </span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></span></p>
</td>
</tr>
<tr>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-family: Times New Roman;"><span style="font-size: 9pt;" lang="EN-US">MM</span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-size: 9pt; font-family: 宋体;">为</span><span style="font-size: 9pt;" lang="EN-US"><span style="font-family: Times New Roman;">Apache</span></span><span style="font-size: 9pt; font-family: 宋体;">的模块提供共享内存服务</span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-size: 9pt;" lang="EN-US"><a href="http://www.engelschall.com/" target="_blank"><span style="font-size: 10.5pt;"><span style="font-family: Times New Roman; color: #0000ff;">www.engelschall.com/</span></span></a></span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-family: Times New Roman;"><span style="font-size: 9pt;" lang="EN-US">1.1.3 </span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></span></p>
</td>
</tr>
<tr>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-family: Times New Roman;"><span style="font-size: 9pt;" lang="EN-US">ACID</span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-size: 9pt; font-family: 宋体;">基于</span><span style="font-size: 9pt;" lang="EN-US"><span style="font-family: Times New Roman;">Web</span></span><span style="font-size: 9pt; font-family: 宋体;">的入侵事件数据库分析控制台</span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-size: 9pt;" lang="EN-US"><a href="http://www.cert.org/kb/aircert/" target="_blank"><span style="font-size: 10.5pt;"><span style="font-family: Times New Roman; color: #0000ff;">www.cert.org/kb/aircert/</span></span></a></span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-family: Times New Roman;"><span style="font-size: 9pt;" lang="EN-US">0.9.6b21 </span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></span></p>
</td>
</tr>
<tr>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-family: Times New Roman;"><span style="font-size: 9pt;" lang="EN-US">PHP</span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-size: 9pt;" lang="EN-US"><span style="font-family: Times New Roman;">ACID</span></span><span style="font-size: 9pt; font-family: 宋体;">的实现语言</span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-size: 9pt;" lang="EN-US"><a href="http://www.php.net/" target="_blank"><span style="font-size: 10.5pt;"><span style="font-family: Times New Roman; color: #0000ff;">www.php.net/</span></span></a></span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-family: Times New Roman;"><span style="font-size: 9pt;" lang="EN-US">4.0.6 </span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></span></p>
</td>
</tr>
<tr>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-family: Times New Roman;"><span style="font-size: 9pt;" lang="EN-US">GD</span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-size: 9pt; font-family: 宋体;">被</span><span style="font-size: 9pt;" lang="EN-US"><span style="font-family: Times New Roman;">PHP</span></span><span style="font-size: 9pt; font-family: 宋体;">用来即时生成</span><span style="font-size: 9pt;" lang="EN-US"><span style="font-family: Times New Roman;">PNG</span></span><span style="font-size: 9pt; font-family: 宋体;">和</span><span style="font-size: 9pt;" lang="EN-US"><span style="font-family: Times New Roman;">JPG</span></span><span style="font-size: 9pt; font-family: 宋体;">图像的库</span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-size: 9pt;" lang="EN-US"><a href="http://www.boutell.com/gd/" target="_blank"><span style="font-size: 10.5pt;"><span style="font-family: Times New Roman; color: #0000ff;">www.boutell.com/gd/</span></span></a></span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-family: Times New Roman;"><span style="font-size: 9pt;" lang="EN-US">1.8.4 </span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></span></p>
</td>
</tr>
<tr>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-family: Times New Roman;"><span style="font-size: 9pt;" lang="EN-US">ADODB</span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-size: 9pt; font-family: 宋体;">为</span><span style="font-size: 9pt;" lang="EN-US"><span style="font-family: Times New Roman;">ACID</span></span><span style="font-size: 9pt; font-family: 宋体;">提供便捷的数据库接口</span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-size: 9pt;" lang="EN-US"><a href="http://php.weblogs.com/ADODB" target="_blank"><span style="font-size: 10.5pt;"><span style="font-family: Times New Roman; color: #0000ff;">php.weblogs.com/ADODB</span></span></a></span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-family: Times New Roman;"><span style="font-size: 9pt;" lang="EN-US">2.00 </span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></span></p>
</td>
</tr>
<tr>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-family: Times New Roman;"><span style="font-size: 9pt;" lang="EN-US">PHPlot</span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-size: 9pt;" lang="EN-US"><span style="font-family: Times New Roman;">ACID</span></span><span style="font-size: 9pt; font-family: 宋体;">所依赖的制图库</span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-size: 9pt;" lang="EN-US"><a href="http://www.phplot.com/" target="_blank"><span style="font-size: 10.5pt;"><span style="font-family: Times New Roman; color: #0000ff;">www.phplot.com/</span></span></a></span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></p>
</td>
<td style="border: medium none #d4d0c8; padding: 1.5pt; background: #efefef none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" valign="top">
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt;"><span style="font-family: Times New Roman;"><span style="font-size: 9pt;" lang="EN-US">4.4.6 </span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></span></p>
</td>
</tr>
</tbody>
</table>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span lang="EN-US"><span style="font-family: Times New Roman; font-size: small;"> </span></span></p>
<p><strong><span style="font-size: 22pt; line-height: 240%; font-family: 'Times New Roman';" lang="EN-US"><br style="page-break-before: always;" /></span></strong></p>
<h1 style="margin: 17pt 0cm 16.5pt 21.6pt; text-indent: -21.6pt; text-align: center;"><a name="_Toc45019024"><span style="font-family: Times New Roman;"><span lang="EN-US"><span>第3章<span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"><span style="font-size: x-large;"> </span></span></span></span><span lang="EN-US">Snort </span></span></a><span><span style="font-family: 宋体;">安装与配置</span></span><span style="font-family: Times New Roman;"> </span></h1>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span lang="EN-US"><span style="font-family: Times New Roman; font-size: small;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;"><span style="font-size: small;">在正式进行软件安装之前，请检查系统，确保拥有符合<span lang="EN-US">ANSI</span>标准的<span lang="EN-US">C/C++</span>编译器等软件开发工具。<span lang="EN-US"> </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-size: small;"><span style="font-family: 宋体;" lang="EN-US">1</span><span style="font-family: 宋体;">．安装入侵事件数据库<span lang="EN-US">MySQL </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;"><span style="font-size: small;">首先，以超级用户的身份登录系统，创建<span lang="EN-US">MySQL </span>用户和<span lang="EN-US">MySQL</span>用户组<span lang="EN-US">; </span>然后，以<span lang="EN-US">MySQL</span>身份登录，按照缺省配置将<span lang="EN-US">MySQL</span>安装在<span lang="EN-US">/usr/local</span>目录下；接下来，将源代码树中的缺省配置文件<span lang="EN-US">My.cnf</span>拷贝到<span lang="EN-US">/etc</span>目录下；再用超级用户身份执行源码树中<span lang="EN-US">Scripts</span>目录下的可执行脚本文件<span lang="EN-US">Mysql_install_db</span>创建初始数据库<span lang="EN-US">; </span>随后，用<span lang="EN-US">/etc/init.d/mysql.server</span>命令启动数据库服务器，使用<span lang="EN-US">/usr/local/bin/mysqladmin</span>程序改变数据库管理员的口令。<span lang="EN-US"> </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-size: small;"><span style="font-family: 宋体;" lang="EN-US">2</span><span style="font-family: 宋体;">．安装<span lang="EN-US">Snort </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;"><span style="font-size: small;">首先安装<span lang="EN-US">Snort</span>所依赖的网络抓包库<span lang="EN-US">Libpcap</span>，将其按照缺省配置安装在<span lang="EN-US">/usr/local</span>目录下之后，开始正式安装<span lang="EN-US">Snort</span>。<span lang="EN-US"> </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span>#gzip -d -c snort-1.8.6.tar.gz | tar xvf -</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span>#cd snort-1.8.6</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span>#./configure &#8211;prefix=/usr/local &#8211;with-mysql=/usr/local </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span>&#8211;with-libpcap-includes=/usr/local \</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span>&#8211;with-libpcap-libraries=/usr/local</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span>#make</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span>#make install</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;"><span style="font-size: small;">安装完毕后，将源码树中的<span lang="EN-US">Snort.conf</span>文件、<span lang="EN-US">Classification.config</span>文件和规则文件（<span lang="EN-US">*.rules</span>）拷贝到系统的<span lang="EN-US">/etc</span>目录下。<span lang="EN-US"> </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;"><span style="font-size: small;">按照下列步骤配置<span lang="EN-US">Snort</span>，以便将其捕获的网络信息输出到<span lang="EN-US">MySQL</span>数据库。<span lang="EN-US"> </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;"><span style="font-size: small;">（<span lang="EN-US">1</span>）创建<span lang="EN-US">Snort</span>入侵事件数据库和存档数据库。<span lang="EN-US"> </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;">#/usr/local/bin/mysqladmin -u root -p create snort </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;">#/usr/local/bin/mysqladmin -u root -p create snort_archive </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;"><span style="font-size: small;">（<span lang="EN-US">2</span>）执行<span lang="EN-US">Snort</span>源码树下<span lang="EN-US">Contrib</span>目录下的<span lang="EN-US">Create_mysql SQL</span>脚本文件，创建相关表。<span lang="EN-US"> </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;">#/usr/local/bin/mysql -u root -D snort -p &lt; create_mysql </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;">#/usr/local/bin/mysql -u root -D snort_archive -p &lt; create_mysql </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;"><span style="font-size: small;">（<span lang="EN-US">3</span>）编辑<span lang="EN-US">/etc/snort.conf</span>文件，在<span lang="EN-US">Output Plugin </span>段中加入如下一行：<span lang="EN-US"> </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;">output database: alert, mysql, user=root password=abc123 dbname=snort host=localhost </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-size: small;"><span style="font-family: 宋体;" lang="EN-US">3</span><span style="font-family: 宋体;">．安装<span lang="EN-US">Web</span>服务器<span lang="EN-US">Apache </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;"><span style="font-size: small;">（<span lang="EN-US">1</span>）安装<span lang="EN-US">MM</span>库<span lang="EN-US"> </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;"><span style="font-size: small;">按照缺省配置将<span lang="EN-US">MM</span>库安装在<span lang="EN-US">/usr/local</span>目录下。<span lang="EN-US"> </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;"><span style="font-size: small;">（<span lang="EN-US">2</span>）安装<span lang="EN-US">OpenSSL </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;"><span style="font-size: small;">按照缺省设置将<span lang="EN-US">OpenSSL</span>安装在<span lang="EN-US">/usr/local</span>目录下。<span lang="EN-US"> </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;"><span style="font-size: small;">（<span lang="EN-US">3</span>）为<span lang="EN-US">Apache</span>扩展<span lang="EN-US">mod_ssl</span>代码<span lang="EN-US"> </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span>#gzip -d -c apache-1.3.24.tar.gz | tar xvf -</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span>#gzip -d -c mod_ssl-2.8.8-1.3.24.tar.gz | tar xvf -</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span>#cd mod_ssl-2.8.8-1.3.24</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span>#./configure &#8211;with-apache=apache-1.3.24</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;"><span style="font-size: small;">该命令运行成功之后，会有提示说明已经成功扩展了<span lang="EN-US">Apache</span>的源代码。<span lang="EN-US"> </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;"><span style="font-size: small;">（<span lang="EN-US">4</span>）安装<span lang="EN-US">Apache </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span>#cd ../apache-1.3.24</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span>#SSL_BASE=/usr/local EAPI_MM=/usr/local \</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span><span> </span>./configure &#8211;enable-module=so </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span><span> </span>&#8211;enable-module=ssl &#8211;prefix=/usr/local</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span>#make</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span>#make certificate</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span>#make install</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;"><span style="font-size: small;">其中，<span lang="EN-US">Make certificate</span>命令是为<span lang="EN-US">mod_ssl</span>生成所需的安全证书，按照提示输入相应信息即可。这样，<span lang="EN-US">Apache</span>就被安装在<span lang="EN-US">/usr/local</span>目录下。<span lang="EN-US"> </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-size: small;"><span style="font-family: 宋体;" lang="EN-US">4</span><span style="font-family: 宋体;">．安装实现语言<span lang="EN-US">PHP </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;"><span style="font-size: small;">按照缺省配置，将为<span lang="EN-US">PHP</span>提供即时生成<span lang="EN-US">PNG</span>和<span lang="EN-US">JPG</span>图像功能的<span lang="EN-US">GD</span>库安装到<span lang="EN-US">/usr/local</span>目录下<span lang="EN-US">; </span>然后采用<span lang="EN-US">PHP</span>的<span lang="EN-US">Apache DSO</span>安装模式将其安装到<span lang="EN-US">/usr/local/libexec</span>目录，成为<span lang="EN-US">Apache</span>的动态共享模块。另外，不要忘记把对<span lang="EN-US">MySQL</span>的支持和<span lang="EN-US">GD</span>库也编译到模块里。<span lang="EN-US"> </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-size: small;"><span style="font-family: 宋体;" lang="EN-US">5</span><span style="font-family: 宋体;">．安装分析控制台<span lang="EN-US">ACID </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;"><span style="font-size: small;">该部分的安装工作具体包括<span lang="EN-US">3</span>个软件包：<span lang="EN-US">Adodb200.tar.gz</span>、<span lang="EN-US">Phplot-4.4.6.tar.gz</span>和<span lang="EN-US">Acid-0.9.6b21.tar.gz</span>。安装过程十分简单，只需分别将这<span lang="EN-US">3</span>个软件包解压缩并展开在<span lang="EN-US">Apache</span>服务器的文档根目录下即可。<span lang="EN-US"> </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;"><span style="font-size: small;">然后开始配置工作。转到<span lang="EN-US">Acid-0.9.6b21</span>目录下编辑<span lang="EN-US">ACID</span>的配置文件<span lang="EN-US">Acid_conf.php</span>，给下列变量赋值：<span lang="EN-US"> </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span>$Dblib_path=&#8221;../adodb200&#8243;</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span>$DBtype=&#8221;mysql&#8221;</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span>$alert_dbname=&#8221;snort&#8221;</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span>$alert_host=&#8221;localhost&#8221;</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span>$alert_port=&#8221;3306&#8243;</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span>$alert_user=&#8221;root&#8221;</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span>$alert_password=&#8221;abc123&#8243;</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span>$archive_dbname=&#8221;snort_archive&#8221;</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span>$archive_host=&#8221;localhost&#8221;</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span>$archive_port=&#8221;3306&#8243;</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span>$archive_user=&#8221;root&#8221;</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span>$archive_password=&#8221;abc123&#8243;</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span>$ChartLib_path=&#8221;../phplot-4.4.6&#8243;</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span>$Chart_file_format=&#8221;png&#8221;</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;"><span> </span>$portscan_file=&#8221;/var/log/snort/portscan.log&#8221;</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;"><span style="font-size: small;">至此，网络入侵检测系统的软件安装工作结束。<span lang="EN-US"> </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-size: small;"><span style="color: #ff6600; font-family: 宋体;">三、系统部署及运行</span><span style="font-family: 宋体;" lang="EN-US"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;"><span style="font-size: small;">本系统被部署在网络服务器所处的<span lang="EN-US">DMZ</span>区，用来监控来自互联网和内网的网络流量。负责监控的网络探测器<span lang="EN-US">Snort</span>使用无<span lang="EN-US">IP</span>地址的网卡进行监听，以保证<span lang="EN-US">NIDS</span>自身的安全<span lang="EN-US">; </span>通过另一块网卡接入内网，并为其分配内网所使用的私有<span lang="EN-US">IP</span>地址，以便从内网访问分析控制台程序<span lang="EN-US">ACID</span>。通过启用<span lang="EN-US">Apache</span>服务器的用户身份验证和访问控制机制，并结合<span lang="EN-US">SSL</span>，保证系统的访问安全。<span lang="EN-US"> </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;"><span style="font-size: small;">另外，部署<span lang="EN-US">NIDS</span>的关键是应当保证系统的监听网卡所连接的设备端口能够<span lang="EN-US">“</span>看到<span lang="EN-US">”</span>受监控网段的全部网络流量。在共享式网络中，这不是问题，但在交换式网络中，由于交换机的每个端口拥有自己的冲突域，因此无法捕获除广播和组播之外的网络流量，这就要求交换机提供监控端口，本网络使用的是<span lang="EN-US">Cisco Catalyst</span>系列交换机，其监控端口是通过端口的<span lang="EN-US">SPAN</span>特性来实现的，用交换机管理软件启用该特性即可。<span lang="EN-US"> </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;"><span style="font-size: small;">为了运行该系统，以超级用户身份执行下列命令：<span lang="EN-US"> </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;">#/etc/init.d/mysql.server start </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;">#/usr/local/bin/snort -c /etc/snort.conf -l /var/log/snort -I elx0 -D </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;">#/usr/local/bin/apachectl sslstart </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;"><span style="font-size: small;">这样，<span lang="EN-US">NIDS</span>已开始运行，然后在内网的管理<span lang="EN-US">PC</span>机上启动浏览器，在地址栏中键入：<span lang="EN-US">https://192.168.1.8/acid-0.9.6b21/</span>，其中<span lang="EN-US">192.168.1.8</span>是为该<span lang="EN-US">NIDS</span>内网网卡分配的<span lang="EN-US">IP</span>地址。首次运行时，控制台会提示用户对入侵事件数据库进行扩展，按照提示扩展完毕后，控制台主界面出现。如图<span lang="EN-US">1</span>所示。<span lang="EN-US"> </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: center;" align="center"><span style="font-family: 宋体;" lang="EN-US"><br />
</span><span style="font-family: 宋体;"><span style="font-size: small;">图<span lang="EN-US">1 </span>一天之内的报警频率<span lang="EN-US"> </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;"><span style="font-size: small;">主界面里显示的信息包括：触发安全规则的网络流量中各种协议所占的比例、警报的数量、入侵主机和目标主机的<span lang="EN-US">IP</span>地址及端口号等。<span lang="EN-US">ACID</span>控制台还提供强大的搜索功能，用户可根据时间、<span lang="EN-US">IP</span>地址、端口号、协议类型以及数据净荷（<span lang="EN-US">payload</span>）等多种条件的灵活组合，在入侵事件数据库中进行查询，以帮助网管人员进行分析。<span lang="EN-US"> </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;"><span style="font-size: small;">入侵特征库是否丰富对一个<span lang="EN-US">NIDS</span>非常重要，本系统同时支持多种有影响的入侵特征库，包括<span lang="EN-US">CERT/CC</span>、<span lang="EN-US">arachNIDS</span>和<span lang="EN-US">CVE</span>等。在警报中除了列出入侵事件的命名外，还有到相应入侵特征库的<span lang="EN-US">Web</span>链接，如果某个警报存在多个命名，则同时予以列出，以便参考。网络管理人员可通过这些链接去查找在线入侵特征库，以便获得关于特定入侵事件更加详细的信息和相应的解决办法。<span lang="EN-US"> </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-family: 宋体;"><span style="font-size: small;">应用<span lang="EN-US">ACID</span>提供的制图功能可以直观地对网络入侵事件进行分析，而生成的图表又可进一步丰富网管人员编制的报告。例如<span lang="EN-US">ACID</span>分析控制台可以按用户指定的时间段生成入侵事件的频率图，如图<span lang="EN-US">2</span>所示。<span lang="EN-US"> </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 14pt; text-align: center;" align="center"><span style="font-family: 宋体;" lang="EN-US"><br />
</span><span style="font-family: 宋体;"><span style="font-size: small;">图<span lang="EN-US">2 </span>一周报警频率<span lang="EN-US"> </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-size: small;"><span style="color: #ff6600; font-family: 宋体;">结束语</span><span style="font-family: 宋体;" lang="EN-US"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21.6pt; line-height: 14pt; text-align: left;" align="left"><span style="font-size: small;"><span style="font-family: 宋体;">网络安全是一个复杂的问题，只依靠<span lang="EN-US">1</span>～<span lang="EN-US">2</span>种网络安全产品是不能解决问题的，必须综合应用多种安全技术，并将其功能有机地整合到一起，进而构成统一的网络安全基础设施。</span><span style="font-size: 9pt; font-family: 宋体;" lang="EN-US"></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span lang="EN-US"><span style="font-family: Times New Roman; font-size: small;"> </span></span></p>
<p><strong><span style="font-size: 22pt; line-height: 240%; font-family: 'Times New Roman';" lang="EN-US"><br style="page-break-before: always;" /></span></strong></p>
<h1 style="margin: 17pt 0cm 16.5pt 21.6pt; text-indent: -21.6pt; text-align: center;"><a name="_Toc45019025"><span style="font-family: Times New Roman;"><span lang="EN-US"><span>第4章<span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"><span style="font-size: x-large;"> </span></span></span></span><span lang="EN-US">Snort</span></span></a><span><span style="font-family: 宋体;">的操作与使用</span></span></h1>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;">Snort</span></span><span style="font-family: 宋体;"><span style="font-size: small;">采取命令行方式运行。格式为：<span lang="EN-US">snort -[options] &lt;filters&gt;</span>。<span lang="EN-US">options</span>中可选的参数很多，下面逐一介绍。</span><span lang="EN-US"><br />
</span><span style="font-size: small;">首先介绍<span lang="EN-US">-[options]</span>的内容：</span><span lang="EN-US"><br />
<span style="font-size: small;">-A &lt;alert&gt; </span></span><span style="font-size: small;">设置告警方式为<span lang="EN-US">full,fast</span>或者<span lang="EN-US">none</span>。 在<span lang="EN-US">full</span>方式下，<span lang="EN-US">Snort</span>将传统的告警信息格式写入告警文件，告警内容比较详细。在<span lang="EN-US">fast</span>方式下，<span lang="EN-US">Snort</span>只将告警时间，告警内容，告警<span lang="EN-US">IP</span>地址和端口号写入文件。在<span lang="EN-US">none</span>方式下，系统将关闭告警功能。</span><span lang="EN-US"><br />
<span style="font-size: small;">-a </span></span><span style="font-size: small;">显示<span lang="EN-US">ARP</span>包</span><span lang="EN-US"><br />
<span style="font-size: small;">-b </span></span><span style="font-size: small;">以<span lang="EN-US">tcpdump</span>的格式将数据包记入日志。 所有的数据包将以二进制格式记入名为<span lang="EN-US">snort.log</span>的文件中。这个选项提高了<span lang="EN-US">snort</span>的操作速度，因为直接已二进制存储，省略了转换为文本文件的时间，通过<span lang="EN-US">-b</span>选项的设置，<span lang="EN-US">snort</span>可以在<span lang="EN-US">100Mbps</span>的网络上正常工作。</span><span lang="EN-US"><br />
<span style="font-size: small;">-c &lt;cf&gt; </span></span><span style="font-size: small;">使用配置文件<span lang="EN-US">&lt;cf&gt;</span>。这是一个规则文件。文件内容主要控制系统哪些包需要记入日志，哪些包需要告警，哪些包可以忽略等。</span><span lang="EN-US"><br />
<span style="font-size: small;">-C </span></span><span style="font-size: small;">仅抓取包中的<span lang="EN-US">ASCII</span>字符</span><span lang="EN-US"><br />
<span style="font-size: small;">-d </span></span><span style="font-size: small;">抓取应用层的数据包</span><span lang="EN-US"><br />
<span style="font-size: small;">-D </span></span><span style="font-size: small;">在守护模式下运行<span lang="EN-US">Snort</span>。告警信息发送至<span lang="EN-US">/var/log/snort.alert</span>，除非特别配置。</span><span lang="EN-US"><br />
<span style="font-size: small;">-e </span></span><span style="font-size: small;">显示和记录网络层数据包头信息</span><span lang="EN-US"><br />
<span style="font-size: small;">-F &lt;bpf&gt; </span></span><span style="font-size: small;">从文件<span lang="EN-US">&lt;bpf&gt;</span>中读取<span lang="EN-US">BPF</span>过滤信息。</span><span lang="EN-US"><br />
<span style="font-size: small;">-h &lt;hn&gt; </span></span><span style="font-size: small;">设置<span lang="EN-US">&lt;hn&gt;(C</span>类<span lang="EN-US">IP</span>地址<span lang="EN-US">)</span>为内部网络<span lang="EN-US">.</span>当使用这个开关时<span lang="EN-US">,</span>所有从外部的流量将会有一个方向箭头指向右边<span lang="EN-US">,</span>所有从内部的流量将会有一个左箭头<span lang="EN-US">.</span>这个选项没有太大的作用<span lang="EN-US">,</span>但是可以使显示的包的信息格式比较容易察看</span><span style="font-size: small;"><span lang="EN-US">.<br />
-i &lt;if&gt; </span>使用网络接口文件<span lang="EN-US"> &lt;if&gt;</span>。</span><span lang="EN-US"><br />
<span style="font-size: small;">-l &lt;ld&gt; </span></span><span style="font-size: small;">将包信息记录到目录<span lang="EN-US">&lt;ld&gt;</span>下。设置日志记录的分层目录结构，按接收包的<span lang="EN-US">IP</span>地址将抓取的包存储在相应的目录下。</span><span lang="EN-US"><br />
<span style="font-size: small;">-M &lt;wkstn&gt; </span></span><span style="font-size: small;">向<span lang="EN-US">&lt;wkstn</span>〉文件中的工作站发送<span lang="EN-US">WinPopup</span>消息。<span lang="EN-US">&lt;wkstn&gt;</span>文件格式非常简单。文件的每一行包含一个目的地址的<span lang="EN-US">SMB</span>名。</span><span lang="EN-US"><br />
<span style="font-size: small;">-n &lt;num&gt; </span></span><span style="font-size: small;">处理完<span lang="EN-US">&lt;num&gt;</span>包后退出。</span><span lang="EN-US"><br />
<span style="font-size: small;">-N </span></span><span style="font-size: small;">关闭日志功能。告警功能仍然工作。</span><span lang="EN-US"><br />
<span style="font-size: small;">-o </span></span><span style="font-size: small;">改变应用于包的规则的顺序。标准的应用顺序是：<span lang="EN-US">Alert-&gt;Pass-&gt;Log</span>；采用<span lang="EN-US">-o</span>选项后，顺序改为：<span lang="EN-US">Pass-&gt;Alert-&gt;Log</span>，允许用户避免使用冗长的<span lang="EN-US">BPF</span>命令行来过滤告警规则。</span><span lang="EN-US"><br />
<span style="font-size: small;">-p </span></span><span style="font-size: small;">关闭混杂模式的嗅探（<span lang="EN-US">sniffing</span>）。这个选项在网络严重拥塞时十分有效。</span><span lang="EN-US"><br />
<span style="font-size: small;">-r &lt;tf&gt; </span></span><span style="font-size: small;">读取<span lang="EN-US">tcpdump</span>生成的文件<span lang="EN-US">&lt;tf&gt;</span>。<span lang="EN-US">Snort</span>将读取和处理这个文件。例如：当你已经得到了一个<span lang="EN-US">Shadow</span>文件或者<span lang="EN-US">tcpdump</span>格式的文件，想处理文件包含的内容时，这个选项就很有用了。</span><span lang="EN-US"><br />
<span style="font-size: small;">-s </span></span><span style="font-size: small;">将告警信息记录到系统日志。在其他的平台下，日志文件可以出现在<span lang="EN-US">/var/log/secure, /var/log/messages</span>目录里。</span><span lang="EN-US"><br />
<span style="font-size: small;">-S ,n=v&gt; </span></span><span style="font-size: small;">设置变量<span lang="EN-US">n</span>的值为<span lang="EN-US">v</span>。这个选项可以用命令行的方式设置<span lang="EN-US">Snort</span>规则文件中的变量。例如：如果要给<span lang="EN-US">Snort</span>规则文件中的变量<span lang="EN-US">HOME_NET</span>赋值，就可以在命令行下采用这个选项。</span><span lang="EN-US"><br />
<span style="font-size: small;">-v </span></span><span style="font-size: small;">将包信息显示到终端时，采用详细模式。这种模式存在一个问题：它的显示速度比较慢，如果你是在<span lang="EN-US">IDS</span>网络中使用<span lang="EN-US">Snort</span>，最好不要采用详细模式，否则会丢失部分包信息。</span><span lang="EN-US"><br />
<span style="font-size: small;">-V </span></span><span style="font-size: small;">显示版本号，并退出。</span><span lang="EN-US"><br />
<span style="font-size: small;">-x </span></span><span style="font-size: small;">当收到骚扰<span lang="EN-US">IPX</span>包时，显示相关信息。</span><span lang="EN-US"><br />
<span style="font-size: small;">-</span></span><span style="font-size: small;">？ 显示使用摘要，并退出。</span><span lang="EN-US"><br />
</span><span style="font-size: small;">下面介绍一下<span lang="EN-US">&lt; filters &gt;</span>的内容：</span><span lang="EN-US"><br />
</span><span style="font-size: small;">这里的<span lang="EN-US">&#8220;filters&#8221;</span>与<span lang="EN-US">TCPDump</span>中的<span lang="EN-US">filter</span>相同，是标准的<span lang="EN-US">BPF</span>格式的过滤器。一般来说，你可以指定过滤器的主机，网络或者协议，还可以给出逻辑表达式，定制特定的过滤器。例如：</span><span lang="EN-US"><br />
<span style="font-size: small;">[root@ice snort-1.6]# ./snort -h 192.168.1.0/24 -d -v host 192.168.1.1<br />
</span></span><span style="font-size: small;">表示记录从主机<span lang="EN-US">192.168.1.1</span>发送和接收的所有包信息。</span><span lang="EN-US"><br />
<span style="font-size: small;">[root@ice snort-1.6]# ./snort -h 192.168.1.0/24 -d -v net 192.168.1 and not host 192.168.1.1<br />
</span></span><span style="font-size: small;">表示记录子网<span lang="EN-US">192.168.1</span>中从<span lang="EN-US">192.168.1.0</span>到<span lang="EN-US">192.168.1.24</span>的所有主机接收和发送的包信息，但不包括<span lang="EN-US">192.168.1.1</span>的信息。</span><span lang="EN-US"><br />
</span><span style="font-size: small;">在<span lang="EN-US">1.3</span>版本中，你可以使用选项<span lang="EN-US">-F</span>从文件中读入自己的<span lang="EN-US">BPF</span>过滤器。</span><span lang="EN-US"><br />
</span><span style="font-size: small;">前面将常提到规则文件，先面简单介绍一下规则。详细的内容可以从下面的站点得到。</span><span lang="EN-US"><br />
<span style="font-size: small;">http://www.clark.net/~roesch/snort_rules.html </span></span><span style="font-size: small;">。系统生成的告警信息都记录在<span lang="EN-US">alert.log</span>文件中。你可以简单的使用<span lang="EN-US">&#8220;tail -f&#8221;</span>查看日志信息。同时这些日志信息还被记录在系统日志中，其缺省的目录是<span lang="EN-US">/var/log/snort.</span>你可以使用<span lang="EN-US">-L</span>选项来指定特定的目录<span lang="EN-US">.</span>如果你设置了<span lang="EN-US">smbalert</span>功能<span lang="EN-US">,</span>那么这些告警就可以通过<span lang="EN-US">smbclient</span>在<span lang="EN-US">windows</span>的机子上弹出一个对话框</span><span style="font-size: small;"><span lang="EN-US">.<br />
</span>实际上<span lang="EN-US">,</span>在使用<span lang="EN-US">snort</span>的过程中<span lang="EN-US">,</span>大家一定感受到规则<span lang="EN-US">(rules)</span>文件的重要性<span lang="EN-US">.</span>如何构造高效全面的规则文件就成了重点<span lang="EN-US">.</span>下面我们就介绍一下该文件</span><span style="font-size: small;"><span lang="EN-US">.<br />
</span>在该文件中<span lang="EN-US">,</span>一条规则必须在一行中<span lang="EN-US">,</span>符号<span lang="EN-US">#</span>是注释行<span lang="EN-US">.</span>所有的<span lang="EN-US">ip</span>地址和端口号都要使用数字形式<span lang="EN-US">,</span>系统并不支持名字服务<span lang="EN-US">.</span>一条规则的格式如下<span lang="EN-US">:</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-align: left;" align="left"><span style="font-family: 宋体;" lang="EN-US"><span style="font-size: small;">func proto src_ip/mask src_port_range -&gt; dst_ip/mask dst_port_range (options)<br />
</span></span><span style="font-family: 宋体;"><span style="font-size: small;">动作 协议 源地址 源端口 目标地址 目标端口<span lang="EN-US"> (</span>选项</span><span style="font-size: small;"><span lang="EN-US">)<br />
</span>动作包括三类<span lang="EN-US">:</span>告警<span lang="EN-US">(alert),</span>日志<span lang="EN-US">(log)</span>和通行<span lang="EN-US">(pass).</span>表明<span lang="EN-US">snort</span>对包的三种处理方式</span><span style="font-size: small;"><span lang="EN-US">.<br />
</span>在源<span lang="EN-US">/</span>目的地址<span lang="EN-US">/</span>端口中可以使用<span lang="EN-US">any</span>来代表任意的地址或端口<span lang="EN-US">.</span>还可以使用符号<span lang="EN-US">!</span>来表明取非运算<span lang="EN-US">.</span>同时<span lang="EN-US">,</span>在目的和源地址之间可以使用标识符<span lang="EN-US">&lt;&gt;</span>来指明方向</span><span style="font-size: small;"><span lang="EN-US">.<br />
</span>选项包括</span><span style="font-size: small;"><span lang="EN-US">:<br />
1. msg &#8212;&#8212;-</span>将要放入<span lang="EN-US">alert</span>或<span lang="EN-US">log</span>文件中的输出信息</span><span style="font-size: small;"><span lang="EN-US">;<br />
2. flags&#8212;&#8212;-tcp</span>协议中的标志<span lang="EN-US">,</span>如<span lang="EN-US">SYN,ACK</span>等等<span lang="EN-US">,</span>如果是<span lang="EN-US">0</span>则表明全部标志</span><span style="font-size: small;"><span lang="EN-US">.<br />
3. ttl &#8212;&#8212;-</span>在<span lang="EN-US">ip</span>包中的<span lang="EN-US">ttl</span>值<span lang="EN-US">,</span>有利于识别<span lang="EN-US">traceroute</span>包</span><span style="font-size: small;"><span lang="EN-US">.<br />
4. content&#8212;-</span>数据包的应用层<span lang="EN-US">,</span>查找缓冲区溢出攻击</span><span style="font-size: small;"><span lang="EN-US">.<br />
5. itype&#8212;&#8212;-icmp</span>包的类型</span><span style="font-size: small;"><span lang="EN-US">;<br />
6. icode&#8212;&#8212;-icmp</span>包的编码</span><span style="font-size: small;"><span lang="EN-US">;<br />
7. minfrag&#8212;-</span>最小的分片的有效载荷大小</span><span style="font-size: small;"><span lang="EN-US">.<br />
8. seg&#8212;&#8212;&#8212;tcp</span>包中的顺序号</span><span style="font-size: small;"><span lang="EN-US">;<br />
9. ack &#8212;&#8212;&#8211;tcp</span>包中的响应号</span><span style="font-size: small;"><span lang="EN-US">;<br />
10. id &#8212;&#8212;ip </span>包中分片的序号</span><span style="font-size: small;"><span lang="EN-US">;<br />
.<br />
11. logto&#8212;</span>指定特殊的存放告警信息的文件</span><span style="font-size: small;"><span lang="EN-US">;<br />
12. dsize&#8212;</span>指定特定的包的长度</span><span style="font-size: small;"><span lang="EN-US">;<br />
13. offset&#8212;</span>在包中查找一定字节内容</span><span style="font-size: small;"><span lang="EN-US">;<br />
14. depth&#8212;</span>在数据包中仅仅查找<span lang="EN-US">depth</span>字节</span><span style="font-size: small;"><span lang="EN-US">.<br />
15. ipopts&#8212;</span>查找一个特定的<span lang="EN-US">ip</span>选项<span lang="EN-US">.</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-align: left;" align="left"><span style="font-family: 宋体;"><span style="font-size: small;">下面我们就举一些例子来说明规则的作用</span><span style="font-size: small;"><span lang="EN-US">:<br />
1. </span>下面这条规则记录了所有登录到一个特定主机的数据包</span><span style="font-size: small;"><span lang="EN-US">:<br />
log tcp any any -&gt; 192.168.1.1/32 23<br />
2. </span>在第一条的基础上记录了双向的流量</span><span style="font-size: small;"><span lang="EN-US">.<br />
log tcp any any &lt;&gt; 192.168.1.1/32 23<br />
3. </span>这一条规则记录了所有到达你的本地主机的<span lang="EN-US">icmp</span>数据包</span><span style="font-size: small;"><span lang="EN-US">.<br />
log icmp any any -&gt; 192.168.1.0/24 any<br />
4. </span>这条规则允许双向的从你的机子到其他站点的<span lang="EN-US">http</span>包</span><span style="font-size: small;"><span lang="EN-US">.<br />
pass tcp any 80 &lt;&gt; 192.168.1.0/24 any<br />
5.</span>这条告警规则显示了本地主机对其他主机的<span lang="EN-US">111</span>端口的访问<span lang="EN-US">,</span>并在<span lang="EN-US">log</span>中显示端口影射调用<span lang="EN-US">(&#8216;portmapper call&#8217;)</span>信息</span><span style="font-size: small;"><span lang="EN-US">:<br />
alert tcp 192.168.1.0/24 any -&gt; any 111 (msg:&#8221;Portmapper call&#8221;;)<br />
6.</span>记录其他任意地址的小于<span lang="EN-US">1024</span>端口访问本地小于<span lang="EN-US">1024</span>端口的流量</span><span style="font-size: small;"><span lang="EN-US">:<br />
log tcp any :1024 -&gt; 192.168.1.0/24 :1024<br />
7.</span>这条规则将会发现<span lang="EN-US">SYN FIN</span>扫描</span><span style="font-size: small;"><span lang="EN-US">:<br />
alert tcp any any -&gt; 192.168.1.0/24 any (msg:&#8221;SYN-FIN scan!&#8221;; flags: SF;)<br />
8.</span>这条规则将会发现空<span lang="EN-US">tcp</span>扫描</span><span style="font-size: small;"><span lang="EN-US">:<br />
alert tcp any any -&gt; 192.168.1.0/24 any (msg:&#8221;Null scan!&#8221;; flags: 0;)<br />
9.</span>这条规则将会发现<span lang="EN-US">Queso fingerprint</span>扫描</span><span style="font-size: small;"><span lang="EN-US">:<br />
alert tcp any any -&gt; 192.168.1.0/24 any (msg:&#8221;Queso fingerprint&#8221;;flags: S12;)<br />
10.</span>这条规则将进行基于内容的查找以发现溢出攻击</span><span style="font-size: small;"><span lang="EN-US">:<br />
alert tcp any any -&gt; 192.168.1.0/24 143 (msg:&#8221;IMAP Buffer overflow!&#8221;; content:&#8221;|90E8 C0FF FFFF|/bin/sh&#8221;;)<br />
11.</span>这条规则将会发现<span lang="EN-US">PHF</span>攻击</span><span style="font-size: small;"><span lang="EN-US">:<br />
alert tcp any any -&gt; 192.168.1.0/24 80 (msg:&#8221;PHF attempt&#8221;; content:&#8221;/cgi-bin/phf&#8221;;)<br />
12.</span>这条规则将会发现<span lang="EN-US">traceroute</span>包</span><span style="font-size: small;"><span lang="EN-US">:<br />
alert udp any any -&gt; 192.168.1.0/24 any (msg:&#8221;Traceroute&#8221;; ttl:1;)<br />
13.</span>这条规则将会发现其他主机对本地发出的<span lang="EN-US">icmp</span>包</span><span style="font-size: small;"><span lang="EN-US">.<br />
alert udp any any -&gt; 192.168.1.0/24 any (msg:&#8221;Traceroute&#8221;; ttl:1;)<br />
14.</span>这条规则发现<span lang="EN-US">nmap</span>的<span lang="EN-US">tcp </span>的<span lang="EN-US">ping</span>扫描</span><span lang="EN-US"><br />
<span style="font-size: small;">alert tcp any any -&gt; 192.168.1.0/24 any (flags: A; ack: 0; msg:&#8221;NMAP TCP ping!&#8221;;)<br />
15.</span></span><span style="font-size: small;">这条规则将会发现源路由的数据包<span lang="EN-US">(</span>源路由攻击</span><span lang="EN-US"><span style="font-size: small;">):<br />
alert tcp any any -&gt; any any (ipopts: lsrr; msg: &#8220;Source Routed packet!&#8221;;)</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-align: left;" align="left"><span style="font-size: small;"><span style="font-family: 宋体;">由于<span lang="EN-US">snort</span>也在不断的发展着<span lang="EN-US">,</span>许多功能正在被开发出来<span lang="EN-US">,</span>如果需要详细的信息<span lang="EN-US">,</span>需要大家随时关注它的发展<span lang="EN-US">.</span>希望以上的介绍会对大家有所帮助<span lang="EN-US">,</span>利用<span lang="EN-US">snort</span>可以建立一个有效的<span lang="EN-US">IDS</span>系统<span lang="EN-US">.</span></span></span></p>
</div>
</div>
</div>
<p><a class="a2a_button_google_reader" href="http://www.addtoany.com/add_to/google_reader?linkurl=http%3A%2F%2Fblog.daliansky.net%2Fsnort%25e5%2585%25a5%25e4%25be%25b5%25e6%25a3%2580%25e6%25b5%258b%25e7%25b3%25bb%25e7%25bb%259f%25e5%25ae%2589%25e8%25a3%2585%25e4%25b8%258e%25e9%2585%258d%25e7%25bd%25ae.html&amp;linkname=Snort%E5%85%A5%E4%BE%B5%E6%A3%80%E6%B5%8B%E7%B3%BB%E7%BB%9F%E5%AE%89%E8%A3%85%E4%B8%8E%E9%85%8D%E7%BD%AE" title="Google Reader" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/reader.png" width="16" height="16" alt="Google Reader"/></a><a class="a2a_button_google_bookmarks" href="http://www.addtoany.com/add_to/google_bookmarks?linkurl=http%3A%2F%2Fblog.daliansky.net%2Fsnort%25e5%2585%25a5%25e4%25be%25b5%25e6%25a3%2580%25e6%25b5%258b%25e7%25b3%25bb%25e7%25bb%259f%25e5%25ae%2589%25e8%25a3%2585%25e4%25b8%258e%25e9%2585%258d%25e7%25bd%25ae.html&amp;linkname=Snort%E5%85%A5%E4%BE%B5%E6%A3%80%E6%B5%8B%E7%B3%BB%E7%BB%9F%E5%AE%89%E8%A3%85%E4%B8%8E%E9%85%8D%E7%BD%AE" title="Google Bookmarks" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/google.png" width="16" height="16" alt="Google Bookmarks"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblog.daliansky.net%2Fsnort%25e5%2585%25a5%25e4%25be%25b5%25e6%25a3%2580%25e6%25b5%258b%25e7%25b3%25bb%25e7%25bb%259f%25e5%25ae%2589%25e8%25a3%2585%25e4%25b8%258e%25e9%2585%258d%25e7%25bd%25ae.html&amp;linkname=Snort%E5%85%A5%E4%BE%B5%E6%A3%80%E6%B5%8B%E7%B3%BB%E7%BB%9F%E5%AE%89%E8%A3%85%E4%B8%8E%E9%85%8D%E7%BD%AE" title="Facebook" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fblog.daliansky.net%2Fsnort%25e5%2585%25a5%25e4%25be%25b5%25e6%25a3%2580%25e6%25b5%258b%25e7%25b3%25bb%25e7%25bb%259f%25e5%25ae%2589%25e8%25a3%2585%25e4%25b8%258e%25e9%2585%258d%25e7%25bd%25ae.html&amp;linkname=Snort%E5%85%A5%E4%BE%B5%E6%A3%80%E6%B5%8B%E7%B3%BB%E7%BB%9F%E5%AE%89%E8%A3%85%E4%B8%8E%E9%85%8D%E7%BD%AE" title="Twitter" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_yahoo_bookmarks" href="http://www.addtoany.com/add_to/yahoo_bookmarks?linkurl=http%3A%2F%2Fblog.daliansky.net%2Fsnort%25e5%2585%25a5%25e4%25be%25b5%25e6%25a3%2580%25e6%25b5%258b%25e7%25b3%25bb%25e7%25bb%259f%25e5%25ae%2589%25e8%25a3%2585%25e4%25b8%258e%25e9%2585%258d%25e7%25bd%25ae.html&amp;linkname=Snort%E5%85%A5%E4%BE%B5%E6%A3%80%E6%B5%8B%E7%B3%BB%E7%BB%9F%E5%AE%89%E8%A3%85%E4%B8%8E%E9%85%8D%E7%BD%AE" title="Yahoo Bookmarks" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/yahoo.png" width="16" height="16" alt="Yahoo Bookmarks"/></a><a class="a2a_button_myspace" href="http://www.addtoany.com/add_to/myspace?linkurl=http%3A%2F%2Fblog.daliansky.net%2Fsnort%25e5%2585%25a5%25e4%25be%25b5%25e6%25a3%2580%25e6%25b5%258b%25e7%25b3%25bb%25e7%25bb%259f%25e5%25ae%2589%25e8%25a3%2585%25e4%25b8%258e%25e9%2585%258d%25e7%25bd%25ae.html&amp;linkname=Snort%E5%85%A5%E4%BE%B5%E6%A3%80%E6%B5%8B%E7%B3%BB%E7%BB%9F%E5%AE%89%E8%A3%85%E4%B8%8E%E9%85%8D%E7%BD%AE" title="MySpace" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/myspace.png" width="16" height="16" alt="MySpace"/></a><a class="a2a_button_hotmail" href="http://www.addtoany.com/add_to/hotmail?linkurl=http%3A%2F%2Fblog.daliansky.net%2Fsnort%25e5%2585%25a5%25e4%25be%25b5%25e6%25a3%2580%25e6%25b5%258b%25e7%25b3%25bb%25e7%25bb%259f%25e5%25ae%2589%25e8%25a3%2585%25e4%25b8%258e%25e9%2585%258d%25e7%25bd%25ae.html&amp;linkname=Snort%E5%85%A5%E4%BE%B5%E6%A3%80%E6%B5%8B%E7%B3%BB%E7%BB%9F%E5%AE%89%E8%A3%85%E4%B8%8E%E9%85%8D%E7%BD%AE" title="Hotmail" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/live.png" width="16" height="16" alt="Hotmail"/></a><a class="a2a_button_yahoo_mail" href="http://www.addtoany.com/add_to/yahoo_mail?linkurl=http%3A%2F%2Fblog.daliansky.net%2Fsnort%25e5%2585%25a5%25e4%25be%25b5%25e6%25a3%2580%25e6%25b5%258b%25e7%25b3%25bb%25e7%25bb%259f%25e5%25ae%2589%25e8%25a3%2585%25e4%25b8%258e%25e9%2585%258d%25e7%25bd%25ae.html&amp;linkname=Snort%E5%85%A5%E4%BE%B5%E6%A3%80%E6%B5%8B%E7%B3%BB%E7%BB%9F%E5%AE%89%E8%A3%85%E4%B8%8E%E9%85%8D%E7%BD%AE" title="Yahoo Mail" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/yahoo.png" width="16" height="16" alt="Yahoo Mail"/></a><a class="a2a_button_wordpress" href="http://www.addtoany.com/add_to/wordpress?linkurl=http%3A%2F%2Fblog.daliansky.net%2Fsnort%25e5%2585%25a5%25e4%25be%25b5%25e6%25a3%2580%25e6%25b5%258b%25e7%25b3%25bb%25e7%25bb%259f%25e5%25ae%2589%25e8%25a3%2585%25e4%25b8%258e%25e9%2585%258d%25e7%25bd%25ae.html&amp;linkname=Snort%E5%85%A5%E4%BE%B5%E6%A3%80%E6%B5%8B%E7%B3%BB%E7%BB%9F%E5%AE%89%E8%A3%85%E4%B8%8E%E9%85%8D%E7%BD%AE" title="WordPress" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/wordpress.png" width="16" height="16" alt="WordPress"/></a><a class="a2a_button_yahoo_messenger" href="http://www.addtoany.com/add_to/yahoo_messenger?linkurl=http%3A%2F%2Fblog.daliansky.net%2Fsnort%25e5%2585%25a5%25e4%25be%25b5%25e6%25a3%2580%25e6%25b5%258b%25e7%25b3%25bb%25e7%25bb%259f%25e5%25ae%2589%25e8%25a3%2585%25e4%25b8%258e%25e9%2585%258d%25e7%25bd%25ae.html&amp;linkname=Snort%E5%85%A5%E4%BE%B5%E6%A3%80%E6%B5%8B%E7%B3%BB%E7%BB%9F%E5%AE%89%E8%A3%85%E4%B8%8E%E9%85%8D%E7%BD%AE" title="Yahoo Messenger" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/yim.png" width="16" height="16" alt="Yahoo Messenger"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblog.daliansky.net%2Fsnort%25e5%2585%25a5%25e4%25be%25b5%25e6%25a3%2580%25e6%25b5%258b%25e7%25b3%25bb%25e7%25bb%259f%25e5%25ae%2589%25e8%25a3%2585%25e4%25b8%258e%25e9%2585%258d%25e7%25bd%25ae.html&amp;title=Snort%E5%85%A5%E4%BE%B5%E6%A3%80%E6%B5%8B%E7%B3%BB%E7%BB%9F%E5%AE%89%E8%A3%85%E4%B8%8E%E9%85%8D%E7%BD%AE" id="wpa2a_6"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a></p><hr />
<p><small>© admin for <a href="http://blog.daliansky.net">DalianSky&#039;s Blog</a>, 2008. |
<a href="http://blog.daliansky.net/snort%e5%85%a5%e4%be%b5%e6%a3%80%e6%b5%8b%e7%b3%bb%e7%bb%9f%e5%ae%89%e8%a3%85%e4%b8%8e%e9%85%8d%e7%bd%ae.html">Permalink</a> |
<a href="http://blog.daliansky.net/snort%e5%85%a5%e4%be%b5%e6%a3%80%e6%b5%8b%e7%b3%bb%e7%bb%9f%e5%ae%89%e8%a3%85%e4%b8%8e%e9%85%8d%e7%bd%ae.html#comments">1354 comments</a> |
Add to
<a href="http://del.icio.us/post?url=http://blog.daliansky.net/snort%e5%85%a5%e4%be%b5%e6%a3%80%e6%b5%8b%e7%b3%bb%e7%bb%9f%e5%ae%89%e8%a3%85%e4%b8%8e%e9%85%8d%e7%bd%ae.html&title=Snort入侵检测系统安装与配置">del.icio.us</a>
<br/>
Post tags: <br/>
</small></p>
<p><small>Feed enhanced by <a href='http://planetozh.com/blog/my-projects/wordpress-plugin-better-feed-rss/'>Better Feed</a> from  <a href='http://planetozh.com/blog/'>Ozh</a></small></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.daliansky.net/snort%e5%85%a5%e4%be%b5%e6%a3%80%e6%b5%8b%e7%b3%bb%e7%bb%9f%e5%ae%89%e8%a3%85%e4%b8%8e%e9%85%8d%e7%bd%ae.html/feed</wfw:commentRss>
		<slash:comments>1354</slash:comments>
		</item>
		<item>
		<title>Serv-U安全设置教程</title>
		<link>http://blog.daliansky.net/serv-u%e5%ae%89%e5%85%a8%e8%ae%be%e7%bd%ae%e6%95%99%e7%a8%8b.html</link>
		<comments>http://blog.daliansky.net/serv-u%e5%ae%89%e5%85%a8%e8%ae%be%e7%bd%ae%e6%95%99%e7%a8%8b.html#comments</comments>
		<pubDate>Mon, 02 Jun 2008 12:41:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[网络安全]]></category>
		<category><![CDATA[serv-u ftp server 安全 教程]]></category>

		<guid isPermaLink="false">http://blog.daliansky.net/?p=37</guid>
		<description><![CDATA[作为一款精典的FTP服务器软件，SERV－U一直被大部分管理员所使用，它简单的安装和配置以及强大的管理功能的人性化也一直被管理员们称颂。但是随着使用者越来越多，该软件的安全问题也逐渐显露出来。 首 先是SERV-U的SITE CHMOD漏洞和Serv-U MDTM漏洞，即利用一个账号可以轻易的得到SYSTEM权限。其次是Serv-u的本地溢出漏洞，即Serv-U有一个默认的管理用户（用户名： localadministrator，密码：#&#124;@$ak#.&#124;k;0@p），任何人只要通过一个能访问本地端口43958的账号就可以随意增删账号和 执行任意内部和外部命令。 此时，人们才开始重视起SERV－U的安全来，并采取了一些相关措施，如修改SERV－U的管理端口、账号和密码 等。但是，修改后的内容还是保留在ServUDaemon.exe文件里，因此下载后用如UltraEdit之类的16进制编辑软件就可以很轻易的获取到 修改后的端口、账号和密码。 从SERV－U6.0.0.2开始，该软件有了登录密码功能，这样如果加了管理密码，并且设置比较妥善的话，SERV－U将会比原来安全的多。现在我们就开始SERV－U的设置之旅，采用版本是SERV－U 6.0.0.2。 古语有云，千尺之台始于垒土，设置SERV－U的安全就从安装开始。这篇文章主要是写SERV－U的安全设置，所以不会花费太多的功夫来介绍安装，只说一下要点。 SERV －U默认是安装在C:/Program Files/Serv-U目录下的，我们最好做一下变动。例如改为：D:/u89327850mx8utu432X$ UY32x211936890co7v23x1t3（图1）这样的路径，如果安装盘符WEB用户不能浏览的话，他便很难猜到安装的路径。当然，安装后会在 桌面和开始菜单上生成快捷方式，建议删除，因为一般不会使用到它。可能你要问了，那应该怎样进入SERV－U的设置界面呢？其实很简单，双击下右角任务栏里的Tray Monitor小图标来启动SERV－U的管理界面。 图1：修改安装的目录 安装的时候只选前2项就可以了，后面的2个是说明和在线帮助文件。(见图2) 图2：安装时候只需要选择前2项 下图是生成的开始菜单组里的文件夹的名字，建议更改成比较不像SERV－U的名字，或者是删除该文件夹。(见图3) 图3：更改安装后生成开始菜单组里文件夹的名字 安装完成后会出现一个向导让你建立一个域和账号。在这里点Cancel取消向导。用向导生成的账号会带来一些问题，所以下面采用手工方式建立域和账号。(见图4) 图4：点Cancel取消向导 然后点选Start automatically(system service)前面的选项，接着点下边的Start Server按钮把SERV－U加入系统服务，这样就可以随系统启动了，不用每次都手工启动。(见图5) 图5：把SERV－U加入服务 接下来就会出现如图6的界面。通过点击Set/Change Password设置一个密码。 图6：点击Set/Change Password设置密码 然后会出现如图7的界面。因为是第一次使用，所以是没有密码的，也就是说原来的密码为空。不用在 old password里输入字符，直接在下面的New password和Repeat new password里输入同样的密码再点OK就可以了。这里建议设置一个足够复杂的密码，以防止别人暴力破解。自己记不得也没有关系，只要把 ServUDaemon.ini里的LocalSetupPassword=这一行清除并保存，再次运行ServUAdmin.exe就不会提示你输入密 码登录了。 图7：设置和更改密码界面 下面就到了该对SERV－U进行安全设置的时候了。首先建立一个WINDOWS账号SSERVU，密码也需要足够的复杂。密码要记住，如果记不住就暂时保存在一个文件里，一会儿还要用到。(见图8) 图8：建立一个WINDOWS账号 建好账号以后，双击建好的用户编辑用户属性，从“隶属于”里删除USERS组。 图9：从隶属于里删除USERS组 从“终端服务配置文件”选项里取消“允许登录到终端服务器（W）”的选择，然后点击确定继续我们的设置。（见图10） 图10：取消“允许登录到终端服务器” 这里我们已经建好了账号，该设置服务里的账号了。现在就要用到刚才建立的这个账号，密码还没有忘记吧，马上就要用到了。 在开始菜单的管理工具里找到“服务”点击打开。在“Serv-U FTP Server服务”上点右键，选择属性继续。 然后点击“登录”进入登录账号选择界面。选择刚才建立的系统账号名，并在下面重复输入2次该账号的密码（就是刚才让你记住的那个），然后点“应用”，再次点确定，完成服务的设置。（见图11） [...]]]></description>
			<content:encoded><![CDATA[<p align="left">作为一款精典的FTP<strong class="kgb" style="border: 0px none; margin: 0px; padding: 0px; color: #0000ff; font-weight: normal; text-decoration: underline;" onclick="javascript:window.open(&quot;http://pagead2.googlesyndication.com/pagead/iclk?sa=l&amp;ai=BUMSnX-lDSLDVO5Gu6QOq5PHMCq3TgDvtnJaNBcCNtwGgnAEQARgBIM-BhwooFDgAUJTvt7P______wFgneHSgaQFoAGj2vX-A7IBDHd3dy5qYjUxLm5ldMgBAdoBJGh0dHA6Ly93d3cuamI1MS5uZXQvYXJ0aWNsZS83MDE1Lmh0bYACAagDAegD2AXoAw2IBAGQBAGYBAA&amp;num=1&amp;adurl=http://www.edong.com/v8/delicatedserver/&amp;client=ca-pub-3578421812762734&quot;);GgKwClickStat(&quot;服务器&quot;,&quot;www.edong.com&quot;,&quot;afc&quot;,&quot;2000086427&quot;);" onmouseover="isShowAds = false;isShowAds2 = false;isShowGg = true;InTextAds_GgLayer=&quot;_u670D_u52A1_u5668&quot;;KeyGate_ads.ShowGgAds(this,&quot;_u670D_u52A1_u5668&quot;,event)" onmouseout="isShowGg = false;InTextAds_GgLayer=&quot;_u670D_u52A1_u5668&quot;"><span><a id="hl_7" class="qs_highlight1" style="font-size: 1em;" onclick="_write_cookie('click839',7);" onmouseover="window.clearTimeout(_ht[7]);qs_show_frame(event,this,7);" onmouseout="_on_div[7]=false;_ht[7]=window.setTimeout('qs_is_on_div(7)',500);" href="http://clk.qunsee.com/click/click.php?cpid=4462&amp;ads_id=839&amp;pid=99000416&amp;cid=420&amp;url=http%3A//www.smarter.com.cn/search.php%3Fq%3D%25BC%25D2%25B5%25E7%26source%3Dqunsee_cn_keyword_%25BC%25D2%25B5%25E7&amp;k=%u670D%u52A1&amp;s=http%3A//www.jb51.net/article/7015.htm&amp;rn=635665&amp;v=1&amp;ref=http%3A//www.google.cn/search%3Fq%3Dserv-u+%25E5%25AE%2589%25E5%2585%25A8+%25E6%2595%2599%25E7%25A8%258B%26ie%3Dutf-8%26oe%3Dutf-8%26aq%3Dt%26rls%3Dcom.ubuntu%3Azh-CN%3Aunofficial%26client%3Dfirefox-a&amp;province=%u8FBD%u5B81&amp;city=%u5927%u8FDE" target="_blank">服务</a></span>器</strong>软件，SERV－U一直被大部分管理员所使用，它简单的安装和配置以及强大的管理<span><a id="hl_10" class="qs_highlight1" style="font-size: 1em;" onclick="_write_cookie('click800',10);" onmouseover="window.clearTimeout(_ht[10]);qs_show_frame(event,this,10);" onmouseout="_on_div[10]=false;_ht[10]=window.setTimeout('qs_is_on_div(10)',500);" href="http://clk.qunsee.com/click/click.php?cpid=4462&amp;ads_id=800&amp;pid=99000416&amp;cid=420&amp;url=http%3A//www.smarter.com.cn/gift-1010/category/utilitygift-8/%26source%3Dqunsee_cn&amp;k=%u529F%u80FD&amp;s=http%3A//www.jb51.net/article/7015.htm&amp;rn=349520&amp;v=1&amp;ref=http%3A//www.google.cn/search%3Fq%3Dserv-u+%25E5%25AE%2589%25E5%2585%25A8+%25E6%2595%2599%25E7%25A8%258B%26ie%3Dutf-8%26oe%3Dutf-8%26aq%3Dt%26rls%3Dcom.ubuntu%3Azh-CN%3Aunofficial%26client%3Dfirefox-a&amp;province=%u8FBD%u5B81&amp;city=%u5927%u8FDE" target="_blank">功能</a></span>的人性化也一直被管理员们称颂。但是随着使用者越来越多，该软件的安全问题也逐渐显露出来。<br />
首 先是SERV-U的SITE CHMOD漏洞和Serv-U MDTM漏洞，即利用一个账号可以轻易的得到SYSTEM权限。其次是Serv-u的本地溢出漏洞，即Serv-U有一个默认的管理用户（用户名： localadministrator，密码：#|@$ak#.|k;0@p），任何人只要通过一个能访问本地端口43958的账号就可以随意增删账号和 执行任意内部和外部命令。<br />
此时，人们才开始重视起SERV－U的安全来，并采取了一些相关措施，如修改SERV－U的管理端口、账号和密码 等。但是，修改后的内容还是保留在ServUDaemon.exe文件里，因此下载后用如UltraEdit之类的16进制编辑软件就可以很轻易的获取到 修改后的端口、账号和密码。<br />
从SERV－U6.0.0.2开始，该软件有了登录密码功能，这样如果加了管理密码，并且设置比较妥善的话，SERV－U将会比原来安全的多。现在我们就开始SERV－U的设置之旅，采用版本是SERV－U 6.0.0.2。<br />
古语有云，千尺之台始于垒土，设置SERV－U的安全就从安装开始。这篇文章主要是写SERV－U的<a href="http://www.jb51.net/list/list_12_1.htm" target="_blank"><span style="color: red;">安全设置</span></a>，所以不会花费太多的功夫来介绍安装，只说一下要点。<br />
SERV －U默认是安装在C:/Program Files/Serv-U目录下的，我们最好做一下变动。例如改为：D:/u89327850mx8utu432X$ UY32x211936890co7v23x1t3（图1）这样的路径，如果安装盘符WEB用户不能浏览的话，他便很难猜到安装的路径。当然，安装后会在 桌面和开始菜单上生成<span><a id="hl_1" class="qs_highlight1" style="font-size: 1em;" onclick="_write_cookie('click838',1);" onmouseover="window.clearTimeout(_ht[1]);qs_show_frame(event,this,1);" onmouseout="_on_div[1]=false;_ht[1]=window.setTimeout('qs_is_on_div(1)',500);" href="http://clk.qunsee.com/click/click.php?cpid=4462&amp;ads_id=838&amp;pid=99000416&amp;cid=420&amp;url=http%3A//www.smarter.com.cn/search.php%3Fq%3D%25CD%25F8%25C2%25E7%26source%3Dqunsee_cn_keyword_%25CD%25F8%25C2%25E7&amp;k=%u5FEB%u6377&amp;s=http%3A//www.jb51.net/article/7015.htm&amp;rn=806035&amp;v=1&amp;ref=http%3A//www.google.cn/search%3Fq%3Dserv-u+%25E5%25AE%2589%25E5%2585%25A8+%25E6%2595%2599%25E7%25A8%258B%26ie%3Dutf-8%26oe%3Dutf-8%26aq%3Dt%26rls%3Dcom.ubuntu%3Azh-CN%3Aunofficial%26client%3Dfirefox-a&amp;province=%u8FBD%u5B81&amp;city=%u5927%u8FDE" target="_blank">快捷</a></span><span><a id="hl_8" class="qs_highlight1" style="font-size: 1em;" onclick="_write_cookie('click835',8);" onmouseover="window.clearTimeout(_ht[8]);qs_show_frame(event,this,8);" onmouseout="_on_div[8]=false;_ht[8]=window.setTimeout('qs_is_on_div(8)',500);" href="http://clk.qunsee.com/click/click.php?cpid=4462&amp;ads_id=835&amp;pid=99000416&amp;cid=420&amp;url=http%3A//www.smarter.com.cn/search.php%3Fq%3D%25BB%25AF%25D7%25B1%25C6%25B7%26source%3Dqunsee_cn_keyword_%25BB%25AF%25D7%25B1%25C6%25B7&amp;k=%u65B9%u5F0F&amp;s=http%3A//www.jb51.net/article/7015.htm&amp;rn=714952&amp;v=1&amp;ref=http%3A//www.google.cn/search%3Fq%3Dserv-u+%25E5%25AE%2589%25E5%2585%25A8+%25E6%2595%2599%25E7%25A8%258B%26ie%3Dutf-8%26oe%3Dutf-8%26aq%3Dt%26rls%3Dcom.ubuntu%3Azh-CN%3Aunofficial%26client%3Dfirefox-a&amp;province=%u8FBD%u5B81&amp;city=%u5927%u8FDE" target="_blank">方式</a></span>，建议删除，因为一般不会使用到它。可能你要问了，那应该怎样进入SERV－U的设置界面呢？其实很简单，双击下右角任务栏里的Tray Monitor小图标来启动SERV－U的管理界面。</p>
<div><img style="width: 378px; height: 277px;" src="http://www.jb51.net/upload/2007214112448539.jpg" border="0" alt="" hspace="0" width="378" height="277" /><br />
<strong>图1：修改安装的目录</strong></div>
<p align="left">
安装的时候只选前2项就可以了，后面的2个是说明和<span><a id="hl_11" class="qs_highlight1" style="font-size: 1em;" onclick="_write_cookie('click731',11);" onmouseover="window.clearTimeout(_ht[11]);qs_show_frame(event,this,11);" onmouseout="_on_div[11]=false;_ht[11]=window.setTimeout('qs_is_on_div(11)',500);" href="http://clk.qunsee.com/click/click.php?cpid=12&amp;ads_id=731&amp;pid=99000416&amp;cid=420&amp;url=http%3A//www.fh21.com.cn&amp;k=%u5728%u7EBF&amp;s=http%3A//www.jb51.net/article/7015.htm&amp;rn=166530&amp;v=1&amp;ref=http%3A//www.google.cn/search%3Fq%3Dserv-u+%25E5%25AE%2589%25E5%2585%25A8+%25E6%2595%2599%25E7%25A8%258B%26ie%3Dutf-8%26oe%3Dutf-8%26aq%3Dt%26rls%3Dcom.ubuntu%3Azh-CN%3Aunofficial%26client%3Dfirefox-a&amp;province=%u8FBD%u5B81&amp;city=%u5927%u8FDE" target="_blank">在线</a></span>帮助文件。(见图2)</p>
<div><img style="width: 480px; height: 356px;" src="http://www.jb51.net/upload/2007214112448518.jpg" border="0" alt="" hspace="0" width="480" height="356" /><br />
<strong>图2：安装时候只<span><a id="hl_2" class="qs_highlight1" style="font-size: 1em;" onclick="_write_cookie('click801',2);" onmouseover="window.clearTimeout(_ht[2]);qs_show_frame(event,this,2);" onmouseout="_on_div[2]=false;_ht[2]=window.setTimeout('qs_is_on_div(2)',500);" href="http://clk.qunsee.com/click/click.php?cpid=4462&amp;ads_id=801&amp;pid=99000416&amp;cid=420&amp;url=http%3A//www.smarter.com.cn/gift-1010/category/utilitygift-8/%26source%3Dqunsee_cn&amp;k=%u9700%u8981&amp;s=http%3A//www.jb51.net/article/7015.htm&amp;rn=77915&amp;v=1&amp;ref=http%3A//www.google.cn/search%3Fq%3Dserv-u+%25E5%25AE%2589%25E5%2585%25A8+%25E6%2595%2599%25E7%25A8%258B%26ie%3Dutf-8%26oe%3Dutf-8%26aq%3Dt%26rls%3Dcom.ubuntu%3Azh-CN%3Aunofficial%26client%3Dfirefox-a&amp;province=%u8FBD%u5B81&amp;city=%u5927%u8FDE" target="_blank">需要</a></span><span><a id="hl_6" class="qs_highlight1" style="font-size: 1em;" onclick="_write_cookie('click832',6);" onmouseover="window.clearTimeout(_ht[6]);qs_show_frame(event,this,6);" onmouseout="_on_div[6]=false;_ht[6]=window.setTimeout('qs_is_on_div(6)',500);" href="http://clk.qunsee.com/click/click.php?cpid=4462&amp;ads_id=832&amp;pid=99000416&amp;cid=420&amp;url=http%3A//www.smarter.com.cn/search.php%3Fq%3D%25C6%25FB%25B3%25B5%26source%3Dqunsee_cn_keyword_%25C6%25FB%25B3%25B5&amp;k=%u9009%u62E9&amp;s=http%3A//www.jb51.net/article/7015.htm&amp;rn=991495&amp;v=1&amp;ref=http%3A//www.google.cn/search%3Fq%3Dserv-u+%25E5%25AE%2589%25E5%2585%25A8+%25E6%2595%2599%25E7%25A8%258B%26ie%3Dutf-8%26oe%3Dutf-8%26aq%3Dt%26rls%3Dcom.ubuntu%3Azh-CN%3Aunofficial%26client%3Dfirefox-a&amp;province=%u8FBD%u5B81&amp;city=%u5927%u8FDE" target="_blank">选择</a></span>前2项</strong></div>
<p align="left">
下图是生成的开始菜单组里的<strong class="kgb" style="border: 0px none; margin: 0px; padding: 0px; color: #0000ff; font-weight: normal; text-decoration: underline;" onclick="javascript:window.open(&quot;http://pagead2.googlesyndication.com/pagead/iclk?sa=l&amp;ai=BSPVVX-lDSLDVO5Gu6QOq5PHMCrHEti7h7oibA8CNtwGQvwUQChgKIM-BhwooFDgAUI6KwP0BYJ3h0oGkBaAB39aC_QOyAQx3d3cuamI1MS5uZXTIAQHaASRodHRwOi8vd3d3LmpiNTEubmV0L2FydGljbGUvNzAxNS5odG2AAgGpAnTrXDjWMoE-qAMB6APYBegDDYgEAZAEAZgEAA&amp;num=10&amp;adurl=http://www.trueimage.cn&amp;client=ca-pub-3578421812762734&quot;);GgKwClickStat(&quot;文件夹&quot;,&quot;www.trueimage.cn&quot;,&quot;afc&quot;,&quot;2000086427&quot;);" onmouseover="isShowAds = false;isShowAds2 = false;isShowGg = true;InTextAds_GgLayer=&quot;_u6587_u4EF6_u5939&quot;;KeyGate_ads.ShowGgAds(this,&quot;_u6587_u4EF6_u5939&quot;,event)" onmouseout="isShowGg = false;InTextAds_GgLayer=&quot;_u6587_u4EF6_u5939&quot;">文件夹</strong>的名字，建议更改成比较不像SERV－U的名字，或者是删除该文件夹。(见图3)</p>
<div><img style="width: 479px; height: 353px;" src="http://www.jb51.net/upload/2007214112449675.jpg" border="0" alt="" hspace="0" width="479" height="353" /><br />
<strong>图3：更改安装后生成开始菜单组里文件夹的名字</strong></div>
<p align="left">
安装完成后会出现一个向导让你建立一个域和账号。在这里点Cancel取消向导。用向导生成的账号会带来一些问题，所以下面采用手工方式建立域和账号。(见图4)</p>
<div><img style="width: 499px; height: 237px;" src="http://www.jb51.net/upload/2007214112449411.jpg" border="0" alt="" hspace="0" width="499" height="237" /><br />
<strong>图4：点Cancel取消向导</strong></div>
<p align="left">
然后点选Start automatically(system service)前面的选项，接着点下边的Start Server按钮把SERV－U加入<span><a id="hl_0" class="qs_highlight1" style="font-size: 1em;" onclick="_write_cookie('click830',0);" onmouseover="window.clearTimeout(_ht[0]);qs_show_frame(event,this,0);" onmouseout="_on_div[0]=false;_ht[0]=window.setTimeout('qs_is_on_div(0)',500);" href="http://clk.qunsee.com/click/click.php?cpid=4462&amp;ads_id=830&amp;pid=99000416&amp;cid=420&amp;url=http%3A//www.smarter.com.cn/search.php%3Fq%3D%25B9%25C9%25C6%25B1%26source%3Dqunsee_cn_keyword_%25B9%25C9%25C6%25B1&amp;k=%u7CFB%u7EDF&amp;s=http%3A//www.jb51.net/article/7015.htm&amp;rn=887791&amp;v=1&amp;ref=http%3A//www.google.cn/search%3Fq%3Dserv-u+%25E5%25AE%2589%25E5%2585%25A8+%25E6%2595%2599%25E7%25A8%258B%26ie%3Dutf-8%26oe%3Dutf-8%26aq%3Dt%26rls%3Dcom.ubuntu%3Azh-CN%3Aunofficial%26client%3Dfirefox-a&amp;province=%u8FBD%u5B81&amp;city=%u5927%u8FDE" target="_blank">系统</a></span><strong class="kgb" style="border: 0px none; margin: 0px; padding: 0px; color: #0000ff; font-weight: normal; text-decoration: underline;" onclick="javascript:window.open(&quot;http://pagead2.googlesyndication.com/pagead/iclk?sa=l&amp;ai=BUMSnX-lDSLDVO5Gu6QOq5PHMCq3TgDvtnJaNBcCNtwGgnAEQARgBIM-BhwooFDgAUJTvt7P______wFgneHSgaQFoAGj2vX-A7IBDHd3dy5qYjUxLm5ldMgBAdoBJGh0dHA6Ly93d3cuamI1MS5uZXQvYXJ0aWNsZS83MDE1Lmh0bYACAagDAegD2AXoAw2IBAGQBAGYBAA&amp;num=1&amp;adurl=http://www.edong.com/v8/delicatedserver/&amp;client=ca-pub-3578421812762734&quot;);GgKwClickStat(&quot;服务&quot;,&quot;www.edong.com&quot;,&quot;afc&quot;,&quot;2000086427&quot;);" onmouseover="isShowAds = false;isShowAds2 = false;isShowGg = true;InTextAds_GgLayer=&quot;_u670D_u52A1&quot;;KeyGate_ads.ShowGgAds(this,&quot;_u670D_u52A1&quot;,event)" onmouseout="isShowGg = false;InTextAds_GgLayer=&quot;_u670D_u52A1&quot;">服务</strong>，这样就可以随系统启动了，不用每次都手工启动。(见图5)<br />
<img style="width: 432px; height: 291px;" src="http://www.jb51.net/upload/2007214112449751.jpg" border="0" alt="" hspace="0" width="432" height="291" /></p>
<div>
<strong>图5：把SERV－U加入服务</strong></div>
<p align="left">
接下来就会出现如图6的界面。通过点击Set/Change Password设置一个密码。</p>
<div><img style="width: 428px; height: 291px;" src="http://www.jb51.net/upload/2007214112449757.jpg" border="0" alt="" hspace="0" width="428" height="291" /><br />
<strong>图6：点击Set/Change Password设置密码</strong></div>
<p align="left">
然后会出现如图7的界面。因为是第一次使用，所以是没有密码的，也就是说原来的密码为空。不用在 old password里输入字符，直接在下面的New password和Repeat new password里输入同样的密码再点OK就可以了。这里建议设置一个足够复杂的密码，以防止别人暴力破解。自己记不得也没有关系，只要把 ServUDaemon.ini里的LocalSetupPassword=这一行清除并保存，再次运行ServUAdmin.exe就不会提示你输入密 码登录了。<br />
<img style="width: 390px; height: 229px;" src="http://www.jb51.net/upload/2007214112449210.jpg" border="0" alt="" hspace="0" width="390" height="229" /></p>
<div>
<strong>图7：设置和更改密码界面</strong></div>
<p align="left">
下面就到了该对SERV－U进行<a href="http://www.jb51.net/list/list_12_1.htm" target="_blank"><span style="color: red;">安全设置</span></a>的时候了。首先建立一个WINDOWS账号SSERVU，密码也需要足够的复杂。密码要记住，如果记不住就暂时保存在一个文件里，一会儿还要用到。(见图8)<br />
<img style="width: 380px; height: 346px;" src="http://www.jb51.net/upload/2007214112449672.jpg" border="0" alt="" hspace="0" width="380" height="346" /></p>
<div>
<strong>图8：建立一个WINDOWS账号</strong></div>
<p align="left">
建好账号以后，双击建好的用户编辑用户属性，从“隶属于”里删除USERS组。</p>
<div><img style="width: 399px; height: 456px;" src="http://www.jb51.net/upload/2007214112449430.jpg" border="0" alt="" hspace="0" width="399" height="456" /><br />
<strong>图9：从隶属于里删除USERS组</strong></div>
<p align="left">
从“终端服务配置文件”选项里取消“允许登录到终端服务器（W）”的选择，然后点击确定继续我们的设置。（见图10）</p>
<div><img style="width: 398px; height: 458px;" src="http://www.jb51.net/upload/2007214112449536.jpg" border="0" alt="" hspace="0" width="398" height="458" /><br />
<strong>图10：取消“允许登录到终端服务器”</strong></div>
<p align="left">
这里我们已经建好了账号，该设置服务里的账号了。现在就要用到刚才建立的这个账号，密码还没有忘记吧，马上就要用到了。<br />
在开始菜单的管理工具里找到“服务”点击打开。在“Serv-U FTP Server服务”上点右键，选择属性继续。<br />
然后点击“登录”进入登录账号选择界面。选择刚才建立的系统账号名，并在下面重复输入2次该账号的密码（就是刚才让你记住的那个），然后点“应用”，再次点确定，完成服务的设置。（见图11）</p>
<div><img style="width: 404px; height: 423px;" src="http://www.jb51.net/upload/2007214112449985.jpg" border="0" alt="" hspace="0" width="404" height="423" /><br />
<strong>图11：更改启动和登录SRV－U的账号密码</strong></div>
<p align="left">
接下来要先使用FTP管理工具建立一个域，再建立一个账号，建好后选择保存在<a href="http://www.jb51.net/list/list_90_1.htm" target="_blank"><span style="color: red;">注册表</span></a>。（见图12）</p>
<div><img style="width: 507px; height: 224px;" src="http://www.jb51.net/upload/2007214112449132.jpg" border="0" alt="" hspace="0" width="507" height="224" /><br />
<strong>图12：FTP用户密码保存到<a href="http://www.jb51.net/list/list_90_1.htm" target="_blank"><span style="color: red;">注册表</span></a>里</strong></div>
<p align="left">
打开<a href="http://www.jb51.net/list/list_90_1.htm" target="_blank"><span style="color: red;">注册表</span></a>来测试相应的权限，否则SERV－U是没办法启动的。在开始－＞运行里输入regedt32点“确定”继续。<br />
找 到[HKEY_LOCAL_MACHINE/SOFTWARE/Cat Soft]分支。在上面点右键，选择权限，然后点高级，取消允许父项的继承权限传播到该对象和所有子对象，包括那些在此明确定义的项目，点击“应用”继 续，接着删除所有的账号。再次点击“确定”按钮继续。这时会弹出对话框<span><a id="hl_9" class="qs_highlight1" style="font-size: 1em;" onclick="_write_cookie('click842',9);" onmouseover="window.clearTimeout(_ht[9]);qs_show_frame(event,this,9);" onmouseout="_on_div[9]=false;_ht[9]=window.setTimeout('qs_is_on_div(9)',500);" href="http://clk.qunsee.com/click/click.php?cpid=4462&amp;ads_id=842&amp;pid=99000416&amp;cid=420&amp;url=http%3A//www.smarter.com.cn/search.php%3Fq%3D%25B5%25E7%25CA%25D3%26source%3Dqunsee_cn_keyword_%25B5%25E7%25CA%25D3&amp;k=%u663E%u793A&amp;s=http%3A//www.jb51.net/article/7015.htm&amp;rn=756653&amp;v=1&amp;ref=http%3A//www.google.cn/search%3Fq%3Dserv-u+%25E5%25AE%2589%25E5%2585%25A8+%25E6%2595%2599%25E7%25A8%258B%26ie%3Dutf-8%26oe%3Dutf-8%26aq%3Dt%26rls%3Dcom.ubuntu%3Azh-CN%3Aunofficial%26client%3Dfirefox-a&amp;province=%u8FBD%u5B81&amp;city=%u5927%u8FDE" target="_blank">显示</a></span>“您拒绝了所有用户访问Cat Soft。没有人能访问 Cat Soft，而且只有所有者才能更改权限。您要继续吗？”，点击“是”继续。接着点击添加按钮<span><a id="hl_5" class="qs_highlight1" style="font-size: 1em;" onclick="_write_cookie('click830',5);" onmouseover="window.clearTimeout(_ht[5]);qs_show_frame(event,this,5);" onmouseout="_on_div[5]=false;_ht[5]=window.setTimeout('qs_is_on_div(5)',500);" href="http://clk.qunsee.com/click/click.php?cpid=4462&amp;ads_id=830&amp;pid=99000416&amp;cid=420&amp;url=http%3A//www.smarter.com.cn/search.php%3Fq%3D%25B9%25C9%25C6%25B1%26source%3Dqunsee_cn_keyword_%25B9%25C9%25C6%25B1&amp;k=%u589E%u52A0&amp;s=http%3A//www.jb51.net/article/7015.htm&amp;rn=3567&amp;v=1&amp;ref=http%3A//www.google.cn/search%3Fq%3Dserv-u+%25E5%25AE%2589%25E5%2585%25A8+%25E6%2595%2599%25E7%25A8%258B%26ie%3Dutf-8%26oe%3Dutf-8%26aq%3Dt%26rls%3Dcom.ubuntu%3Azh-CN%3Aunofficial%26client%3Dfirefox-a&amp;province=%u8FBD%u5B81&amp;city=%u5927%u8FDE" target="_blank">增加</a></span>我们建立的SSERVU账号到该子键的权限列表里，并给予完全控制权限。到这里<a href="http://www.jb51.net/list/list_90_1.htm" target="_blank"><span style="color: red;">注册表</span></a>已经设置完了。但还不能重新启动SERV－U，因为安装目录还没设置。<br />
现在就来设置一下，只保留你的管理账号和SSERVU账号，并给予除了完全控制外的所有权限。（见图13）</p>
<div><img style="width: 342px; height: 360px;" src="http://www.jb51.net/upload/2007214112449715.jpg" border="0" alt="" hspace="0" width="342" height="360" /><br />
<strong>图13：SERV－U安装目录权限设置</strong></div>
<p align="left">
现在，在服务里重启Serv-U FTP Server服务就可以正常启动了。当然，到这里还没有完全设置完，你的FTP用户因为没有权限还是登录不了的，所以还要设置一下目录的权限。<br />
假 设你有一个WEB目录，路径是d:/web。那么在这个目录的“安全设定”里除了管理员和IIS用户都删除掉，再加入SSERVU账号，切记SYSTEM 账号也删除掉。为什么要这样设置呢？因为现在已经是用SSERVU账号启动的SERV－U，而不是用SYSTEM权限启动的了，所以访问目录不再是用 SYSTEM而是用SSERVU，此时SYSTEM已经没有用了，这样就算真的溢出也不可能得到SYSTEM权限。另外，WEB目录所在盘的根目录还要设 置允许SSERV－U账号的浏览和读取权限，并确认在高级里设置只有该文件夹。（见图14）</p>
<div><img style="width: 513px; height: 369px;" src="http://www.jb51.net/upload/2007214112449367.jpg" border="0" alt="" hspace="0" width="513" height="369" /><br />
<strong>图14：WEB目录所在盘的权限设置</strong></div>
<p align="left">
至此，设置全部结束。现在的SERV－U设置是配合IIS设置的，因为和IIS使用不同的账号， WEB用户就不可能访问SERV－U的目录，并且WEB目录没有给予SYSTEM权限，所以SYSTEM账号也同样访问不了WEB目录，也就是说，即使使用<a href="http://www.jb51.net/list/list_113_1.htm" target="_blank"><span style="color: red;">MSSQL</span></a>得到备份的权限也不能备份SHELL到你的WEB目录。你可以安全的使用SERV－U了。</p>
<p><a class="a2a_button_google_reader" href="http://www.addtoany.com/add_to/google_reader?linkurl=http%3A%2F%2Fblog.daliansky.net%2Fserv-u%25e5%25ae%2589%25e5%2585%25a8%25e8%25ae%25be%25e7%25bd%25ae%25e6%2595%2599%25e7%25a8%258b.html&amp;linkname=Serv-U%E5%AE%89%E5%85%A8%E8%AE%BE%E7%BD%AE%E6%95%99%E7%A8%8B" title="Google Reader" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/reader.png" width="16" height="16" alt="Google Reader"/></a><a class="a2a_button_google_bookmarks" href="http://www.addtoany.com/add_to/google_bookmarks?linkurl=http%3A%2F%2Fblog.daliansky.net%2Fserv-u%25e5%25ae%2589%25e5%2585%25a8%25e8%25ae%25be%25e7%25bd%25ae%25e6%2595%2599%25e7%25a8%258b.html&amp;linkname=Serv-U%E5%AE%89%E5%85%A8%E8%AE%BE%E7%BD%AE%E6%95%99%E7%A8%8B" title="Google Bookmarks" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/google.png" width="16" height="16" alt="Google Bookmarks"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblog.daliansky.net%2Fserv-u%25e5%25ae%2589%25e5%2585%25a8%25e8%25ae%25be%25e7%25bd%25ae%25e6%2595%2599%25e7%25a8%258b.html&amp;linkname=Serv-U%E5%AE%89%E5%85%A8%E8%AE%BE%E7%BD%AE%E6%95%99%E7%A8%8B" title="Facebook" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fblog.daliansky.net%2Fserv-u%25e5%25ae%2589%25e5%2585%25a8%25e8%25ae%25be%25e7%25bd%25ae%25e6%2595%2599%25e7%25a8%258b.html&amp;linkname=Serv-U%E5%AE%89%E5%85%A8%E8%AE%BE%E7%BD%AE%E6%95%99%E7%A8%8B" title="Twitter" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_yahoo_bookmarks" href="http://www.addtoany.com/add_to/yahoo_bookmarks?linkurl=http%3A%2F%2Fblog.daliansky.net%2Fserv-u%25e5%25ae%2589%25e5%2585%25a8%25e8%25ae%25be%25e7%25bd%25ae%25e6%2595%2599%25e7%25a8%258b.html&amp;linkname=Serv-U%E5%AE%89%E5%85%A8%E8%AE%BE%E7%BD%AE%E6%95%99%E7%A8%8B" title="Yahoo Bookmarks" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/yahoo.png" width="16" height="16" alt="Yahoo Bookmarks"/></a><a class="a2a_button_myspace" href="http://www.addtoany.com/add_to/myspace?linkurl=http%3A%2F%2Fblog.daliansky.net%2Fserv-u%25e5%25ae%2589%25e5%2585%25a8%25e8%25ae%25be%25e7%25bd%25ae%25e6%2595%2599%25e7%25a8%258b.html&amp;linkname=Serv-U%E5%AE%89%E5%85%A8%E8%AE%BE%E7%BD%AE%E6%95%99%E7%A8%8B" title="MySpace" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/myspace.png" width="16" height="16" alt="MySpace"/></a><a class="a2a_button_hotmail" href="http://www.addtoany.com/add_to/hotmail?linkurl=http%3A%2F%2Fblog.daliansky.net%2Fserv-u%25e5%25ae%2589%25e5%2585%25a8%25e8%25ae%25be%25e7%25bd%25ae%25e6%2595%2599%25e7%25a8%258b.html&amp;linkname=Serv-U%E5%AE%89%E5%85%A8%E8%AE%BE%E7%BD%AE%E6%95%99%E7%A8%8B" title="Hotmail" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/live.png" width="16" height="16" alt="Hotmail"/></a><a class="a2a_button_yahoo_mail" href="http://www.addtoany.com/add_to/yahoo_mail?linkurl=http%3A%2F%2Fblog.daliansky.net%2Fserv-u%25e5%25ae%2589%25e5%2585%25a8%25e8%25ae%25be%25e7%25bd%25ae%25e6%2595%2599%25e7%25a8%258b.html&amp;linkname=Serv-U%E5%AE%89%E5%85%A8%E8%AE%BE%E7%BD%AE%E6%95%99%E7%A8%8B" title="Yahoo Mail" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/yahoo.png" width="16" height="16" alt="Yahoo Mail"/></a><a class="a2a_button_wordpress" href="http://www.addtoany.com/add_to/wordpress?linkurl=http%3A%2F%2Fblog.daliansky.net%2Fserv-u%25e5%25ae%2589%25e5%2585%25a8%25e8%25ae%25be%25e7%25bd%25ae%25e6%2595%2599%25e7%25a8%258b.html&amp;linkname=Serv-U%E5%AE%89%E5%85%A8%E8%AE%BE%E7%BD%AE%E6%95%99%E7%A8%8B" title="WordPress" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/wordpress.png" width="16" height="16" alt="WordPress"/></a><a class="a2a_button_yahoo_messenger" href="http://www.addtoany.com/add_to/yahoo_messenger?linkurl=http%3A%2F%2Fblog.daliansky.net%2Fserv-u%25e5%25ae%2589%25e5%2585%25a8%25e8%25ae%25be%25e7%25bd%25ae%25e6%2595%2599%25e7%25a8%258b.html&amp;linkname=Serv-U%E5%AE%89%E5%85%A8%E8%AE%BE%E7%BD%AE%E6%95%99%E7%A8%8B" title="Yahoo Messenger" rel="nofollow" target="_blank"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/icons/yim.png" width="16" height="16" alt="Yahoo Messenger"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblog.daliansky.net%2Fserv-u%25e5%25ae%2589%25e5%2585%25a8%25e8%25ae%25be%25e7%25bd%25ae%25e6%2595%2599%25e7%25a8%258b.html&amp;title=Serv-U%E5%AE%89%E5%85%A8%E8%AE%BE%E7%BD%AE%E6%95%99%E7%A8%8B" id="wpa2a_8"><img src="http://blog.daliansky.net/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a></p><hr />
<p><small>© admin for <a href="http://blog.daliansky.net">DalianSky&#039;s Blog</a>, 2008. |
<a href="http://blog.daliansky.net/serv-u%e5%ae%89%e5%85%a8%e8%ae%be%e7%bd%ae%e6%95%99%e7%a8%8b.html">Permalink</a> |
<a href="http://blog.daliansky.net/serv-u%e5%ae%89%e5%85%a8%e8%ae%be%e7%bd%ae%e6%95%99%e7%a8%8b.html#comments">5 comments</a> |
Add to
<a href="http://del.icio.us/post?url=http://blog.daliansky.net/serv-u%e5%ae%89%e5%85%a8%e8%ae%be%e7%bd%ae%e6%95%99%e7%a8%8b.html&title=Serv-U安全设置教程">del.icio.us</a>
<br/>
Post tags: <a href="http://blog.daliansky.net/tag/serv-u-ftp-server-%e5%ae%89%e5%85%a8-%e6%95%99%e7%a8%8b" rel="tag">serv-u ftp server 安全 教程</a><br/>
</small></p>
<p><small>Feed enhanced by <a href='http://planetozh.com/blog/my-projects/wordpress-plugin-better-feed-rss/'>Better Feed</a> from  <a href='http://planetozh.com/blog/'>Ozh</a></small></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.daliansky.net/serv-u%e5%ae%89%e5%85%a8%e8%ae%be%e7%bd%ae%e6%95%99%e7%a8%8b.html/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>
<!-- WP Super Cache is installed but broken. The path to wp-cache-phase1.php in wp-content/advanced-cache.php must be fixed! -->
