Snort不会放弃流量或阻止网站

发布于 2025-01-24 03:03:26 字数 670 浏览 0 评论 0 原文

我使用此Snort规则来阻止网站,但没有阻止网站。我已经对模式进行了内联,但仍然无法正常工作。谁能在这方面帮我吗?这对我真的很有帮助。顺便说一句,我在虚拟盒中将Snort安装在Ubuntu OS中。尽管在下面的屏幕截图中,您可以看到它表明它已经删除了数据包,但实际上我仍然可以浏览网站。谢谢。

这是规则:drop http $ home_net any -> 34.102.136.180 $ http_ports(msg:“ dropping cacket'; flow:to_server,已建立; http_uri; http_uri; metadata:service http;优先级:1; sid:1; sid:10000001; rev; rev:1; 1; 1;)>

命令我使用了:sudo snort -q -c/usr/local/etc/snort/snort.lua -r/usr/local/local/etc/rules/local.rules/local.rules -i enp0s3 -a arter_ arter_ arter_ arter_ arter_ a realiv_fast -s 65535 -k none

I used this snort rule to block a website but it is not blocking the website. I already made the mode inline but still it is not working. Can anyone help me in this regard?? It would be really helpful for me. BTW I installed snort in ubuntu OS in Virtual box. Although in below screenshot you can see that it is showing that it already dropped the packet but actually i still can browse the website. Thanks.

here is the rule: drop http $HOME_NET any -> 34.102.136.180 $HTTP_PORTS (msg:"Dropping packets"; flow:to_server,established; http_uri; metadata: service http; priority:1; sid:10000001; rev:1; )>

Command I used: sudo snort -Q -c /usr/local/etc/snort/snort.lua -R /usr/local/etc/rules/local.rules -i enp0s3 -A alert_fast -s 65535 -k none

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。
列表为空,暂无数据
我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
原文