【技巧】2003 Server 安裝 Snort 傻瓜專用(不傻勿進)



贊助商連結


bx2aa
2008-11-23, 02:10 PM
2008/11/23
修改 autosetup.bat 為選擇作業系統 1.繁體中文 2.英文
增加 winrar380.exe ===> 自動安裝 wrar380.exe
修正 snort.exe ===> 自動安裝 Snort_2_8_1_Installer.exe 於英文系統中失效問題

2008/11/27
修改 autosetup.bat 判斷已安裝 WinRAR 則開始安裝
若未安裝 WinRAR, 判斷 wrar380.exe wrar380sc.exe wrar380tc.exe 存在則安裝
若未安裝也未發現 wrar380.exe wrar380sc.exe wrar380tc.exe 其中之ㄧ 則不安裝退出結束 autosetup.bat
增加 runSnort.exe snort.bat snort.vbs
------------------------------------------------------------------------------------
準備軟體:
WinRAR
http://rarlab.com/
http://rarlab.com/rar/wrar380tc.exe
http://www.rarsoft.com/rar/wrar380tc.exe
http://rarlab.com/rar/wrar380.exe

APACHE
http://www.apache.org/
http://ftp.twaren.net/Unix/Web/apache/httpd/binaries/win32/apache_2.2.10-win32-x86-no_ssl.msi

MySQL
http://dev.mysql.com/
http://kenpo.msun.edu/download/database/mysql-5.0.51a-win32/mysql-5.0.51a-win32.zip

PHP
http://www.php.net/
http://cn.php.net/distributions/php-5.2.5-Win32.zip

WinPCAP
http://www.winpcap.org/
http://www.winpcap.org/install/default.htm
http://www.winpcap.org/install/bin/WinPcap_4_0_2.exe

Snort
http://www.snort.org/
http://www.snort.org/dl/
http://www.snort.org/dl/binaries/win32/old/Snort_2_8_1_Installer.exe

Snort Signature (ps: snortrules-snapshot-CURRENT.tar.gz 需註冊才能 Download )
http://www.snort.org/vrt/
http://www.snort.org/pub-bin/downloads.cgi
http://www.snort.org/pub-bin/downloads.cgi/Download/vrt_os/snortrules-snapshot-CURRENT.tar.gz

ACID
http://www.andrew.cmu.edu/user/rdanyliw/snort/snortacid.html
http://acidlab.sourceforge.net/acid-0.9.6b23.tar.gz

ADODB
http://adodb.sourceforge.net/
http://sourceforge.net/project/showfiles.php?group_id=42718
http://jaist.dl.sourceforge.net/sourceforge/adodb/adodb504.tgz

JPGRAPH
http://www.aditus.nu/jpgraph/index.php
http://www.aditus.nu/jpgraph/jpdownload.php
http://hem.bredband.net/jpgraph2/jpgraph-2.3.3.tar.gz

GNU utilities for native Win32
http://sourceforge.net/projects/unxutils
http://sourceforge.net/project/showfiles.php?group_id=9328&package_id=9393&release_id=490307
http://downloads.sourceforge.net/unxutils/UnxUtils.zip?modtime=1172730504&big_mirror=0

Snort IDS 所需檔案清單:
apache_2.2.10-win32-x86-no_ssl.msi
mysql-5.0.51a-win32.zip
php-5.2.5-Win32.zip
WinPcap_4_0_2.exe
Snort_2_8_1_Installer.exe
snortrules-snapshot-CURRENT.tar.gz
acid-0.9.6b23.tar.gz
adodb504.tgz
jpgraph-2.3.3.tar.gz

額外所需檔案:
wrar380tc.exe
UnxUtils.zip

使用方法:
將下載的所有檔案與附件內的所有檔案放在一個目錄內
點選 autosetup.bat
然後耐心等候約 6 分鐘.

測試環境:
於 VMWare 內安裝
2003 Server Chinese Traditional
2003 Server English
Windows XP Profession English
Windows XP Profession CHS
Windows XP Profession CHT

安裝前檢查項目:
2003 Server 須先開啟 IE 能正常開啟, 不會跳出 "新增連線" 畫面, 則可開始執行 autosetup.bat

建議設定項目:
將網卡的 TCP/IP 協定取消勾選

第二次執行 c:\ids\runsnort.exe

要查閱入侵日誌
以 IE 瀏覽
http://localhost/acid/acid_main.php

贊助商連結


bx2aa
2008-11-23, 04:15 PM
英文版 XP Profession 裏安裝 Snort 過程影片.