SnortSnarf
203
The following command extracts data from MySQL database running on the
localhost
. It uses a user name
rr
and password
rr78x
to login to the database.
snortsnarf.pl rr:rr78x@snort@localhost d /var/www/html/snortsnarf
To get data from a database, you have to define the following parameters on the
command line:
Database user name
Password
Database name
Host where database server is running
Port number for the database server. By default the port number is 3306 and
this parameter is optional.
The general format of defining these parameters is:
user:passwd@dbname@host:port
You can run SnortSnarf from a cron script on a periodic basis. Figure 6 15 shows
the main page created by SnortSnarf. It provides basic information about alert data.
Figure 6 16 shows the information about a particular alert that is displayed when
you click a link as shown in Figure 6 15.
Figure 6 17 shows a screen shot for searching whois databases or DNS lookup
when you need to get more information about an IP address.
footer
Our partners:
PHP: Hypertext Preprocessor Cheap Web Hosting
JSP Web Hosting
Ontario Web Hosting
Jsp Web Hosting
Cheapest Web Hosting
Java Hosting
Cheapest Hosting
Visionwebhosting.net Business web hosting division of Vision Web Hosting Inc.. All rights reserved