# cd /usr/local/oinkmaster/ # cp -p oinkmaster.conf oinkmaster-bleedingsnort.conf # vi oinkmaster-bleedingsnort.conf url を以下に変更 url = http://www.bleedingsnort.com/bleeding.rules.tar.gz #
# vi /etc/snort/snort.conf
/etc/snort/snort.conf
以下を追加 # bleedingsnort rules include $RULE_PATH/bleeding.conf include $RULE_PATH/bleeding-attack_response.rules include $RULE_PATH/bleeding-dos.rules include $RULE_PATH/bleeding-drop.rules include $RULE_PATH/bleeding-dshield.rules include $RULE_PATH/bleeding-exploit.rules include $RULE_PATH/bleeding-game.rules include $RULE_PATH/bleeding-inappropriate.rules include $RULE_PATH/bleeding-malware.rules include $RULE_PATH/bleeding-p2p.rules include $RULE_PATH/bleeding-policy.rules include $RULE_PATH/bleeding-scan.rules include $RULE_PATH/bleeding-virus.rules include $RULE_PATH/bleeding-web.rules include $RULE_PATH/bleeding.rules #include $RULE_PATH/bleeding-drop-BLOCK.rules #include $RULE_PATH/bleeding-dshield-BLOCK.rules
# vi /usr/local/oinkmaster/rule-update
/usr/local/oinkmaster/rule-update
#!/bin/sh OINKDIR="/usr/local/oinkmaster" RULEDIR="/etc/snort/rules" ## VRT Rule $OINKDIR/oinkmaster.pl -o $RULEDIR -C $OINKDIR/oinkmaster.conf -b /etc/snort/rules/Backup -Q chown -R snort:snort /etc/snort/ ## Bleedingsnort $OINKDIR/oinkmaster.pl -o $RULEDIR -C $OINKDIR/oinkmaster-bleedingsnort.conf -b /etc/snort/rules/Backup -Q cd $RULEDIR /bin/cp sid-msg.map sid-msg.map.orig /bin/cat bleeding-sid-msg.map sid-msg.map.orig | sort -u > sid-msg.map chown -R snort:snort /etc/snort/
# crontab -e 5 0 * * * /usr/local/oinkmaster/rule-update >/dev/null 2>&1 # # /usr/local/oinkmaster/rule-update # /etc/init.d/snort restart Stopping snort [ OK ] Starting snort [ OK ] #