Tải bản đầy đủ (.docx) (15 trang)

hướng dẫn cài giao diện ossec lên ossim

Bạn đang xem bản rút gọn của tài liệu. Xem và tải ngay bản đầy đủ của tài liệu tại đây (44.25 KB, 15 trang )

SSH Secure Shell 3.2.9 (Build 283)
Copyright (c) 2000-2003 SSH Communications Security Corp - />This copy of SSH Secure Shell is a non-commercial version.
This version does not include PKI and PKCS #11 functionality.
Linux opensourcesim 2.6.31.6 #1 SMP Wed Nov 18 11:13:05 UTC 2009 i686
=========================================================================
{{ AlienVault OSSIM Installer }}
Profiles: Server Sensor Framework Database
=========================================================================
Read the file /root/README.txt
More news at
The AlienVault Team.
You have new mail.
Last login: Wed Sep 8 13:52:47 2010
opensourcesim:~# apt-get install build -essential
E: Command line option 'e' [from -essential] is not known.
opensourcesim:~# sudo apt-get install lynx
Reading package lists Done
Building dependency tree
Reading state information Done
lynx is already the newest version.
0 upgraded, 0 newly installed, 0 to remove and 2 not upgraded.
opensourcesim:~# lynx google.com
HTTP request sent; waiting for response.
Exiting via interrupt: 2
opensourcesim:~# mysql -u root -p
Enter password:
Welcome to the MySQL monitor. Commands end with ; or \g.
Your MySQL connection id is 967
Server version: 5.0.51a-24+lenny4 (Debian)
Type 'help;' or '\h' for help. Type '\c' to clear the buffer.
mysql> exit


Bye
You have new mail in /var/mail/root
opensourcesim:~# /var/ossec/bin
-bash: /var/ossec/bin: is a directory
opensourcesim:~# /var/ossec/
active-response/ etc/ rules/ tmp/
agentless/ logs/ .ssh/ var/
bin/ queue/ stats/
opensourcesim:~# /var/ossec/bin/
-bash: /var/ossec/bin/: is a directory
opensourcesim:~#
opensourcesim:~# cd /var/ossec/bin
opensourcesim:/var/ossec/bin# sudo apt-get install build-essential
Reading package lists Done
Building dependency tree
Reading state information Done
The following extra packages will be installed:
dpkg-dev g++ g++-4.3 libstdc++6-4.3-dev
Suggested packages:
debian-keyring g++-multilib g++-4.3-multilib gcc-4.3-doc libstdc++6-4.3-dbg
libstdc++6-4.3-doc
The following NEW packages will be installed:
build-essential dpkg-dev g++ g++-4.3 libstdc++6-4.3-dev
0 upgraded, 5 newly installed, 0 to remove and 2 not upgraded.
Need to get 5582kB of archives.
After this operation, 20.4MB of additional disk space will be used.
Do you want to continue [Y/n]? y
Get:1 lenny/main libstdc++6-4.3-dev 4.3.2-1.1 [1389kB]
Get:2 lenny/main g++-4.3 4.3.2-1.1 [3414kB]
Get:3 lenny/main g++ 4:4.3.2-2 [1368B]

Get:4 lenny/main dpkg-dev 1.14.29 [771kB]
Get:5 lenny/main build-essential 11.4 [7118B]
Fetched 5582kB in 2min49s (32.9kB/s)
Selecting previously deselected package libstdc++6-4.3-dev.
(Reading database 52168 files and directories currently installed.)
Unpacking libstdc++6-4.3-dev (from /libstdc++6-4.3-dev_4.3.2-1.1_i386.deb)
Selecting previously deselected package g++-4.3.
Unpacking g++-4.3 (from /g++-4.3_4.3.2-1.1_i386.deb)
Selecting previously deselected package g++.
Unpacking g++ (from /g++_4%3a4.3.2-2_i386.deb)
Selecting previously deselected package dpkg-dev.
Unpacking dpkg-dev (from /dpkg-dev_1.14.29_all.deb)
Selecting previously deselected package build-essential.
Unpacking build-essential (from /build-essential_11.4_i386.deb)
Processing triggers for man-db
Setting up dpkg-dev (1.14.29)
Setting up libstdc++6-4.3-dev (4.3.2-1.1)
Setting up g++-4.3 (4.3.2-1.1)
Setting up g++ (4:4.3.2-2)
Setting up build-essential (11.4)
You have new mail in /var/mail/root
opensourcesim:/var/ossec/bin#
opensourcesim:/var/ossec/bin# cd
opensourcesim:~# sudo apt-get install automake
Reading package lists Done
Building dependency tree
Reading state information Done
The following extra packages will be installed:
autoconf autotools-dev m4
Suggested packages:

autobook autoconf-archive autoconf-doc autoconf2.13 gettext gnu-standards
libtool
The following NEW packages will be installed:
autoconf automake autotools-dev m4
0 upgraded, 4 newly installed, 0 to remove and 2 not upgraded.
Need to get 1278kB of archives.
After this operation, 4178kB of additional disk space will be used.
Do you want to continue [Y/n]? y
Get:1 lenny/main m4 1.4.11-1 [217kB]
Get:2 lenny/main autoconf 2.61-8 [448kB]
Get:3 lenny/main autotools-dev 20080123.1 [63.0kB]
Get:4 lenny/main automake 1:1.10.1-3 [550kB]
Fetched 1278kB in 17s (72.9kB/s)
Selecting previously deselected package m4.
(Reading database 53059 files and directories currently installed.)
Unpacking m4 (from /archives/m4_1.4.11-1_i386.deb)
Selecting previously deselected package autoconf.
Unpacking autoconf (from /autoconf_2.61-8_all.deb)
Selecting previously deselected package autotools-dev.
Unpacking autotools-dev (from /autotools-dev_20080123.1_all.deb)
Selecting previously deselected package automake.
Unpacking automake (from /automake_1%3a1.10.1-3_all.deb)
Processing triggers for man-db
Setting up m4 (1.4.11-1)
Setting up autoconf (2.61-8)
Setting up autotools-dev (20080123.1)
Setting up automake (1:1.10.1-3)
opensourcesim:~# sudo apt-get install checkinstall
Reading package lists Done
Building dependency tree

Reading state information Done
Suggested packages:
gettext
The following NEW packages will be installed:
checkinstall
0 upgraded, 1 newly installed, 0 to remove and 2 not upgraded.
Need to get 112kB of archives.
After this operation, 557kB of additional disk space will be used.
Get:1 lenny/main checkinstall 1.6.1-8 [112kB]
Fetched 112kB in 6s (16.8kB/s)
Selecting previously deselected package checkinstall.
(Reading database 53338 files and directories currently installed.)
Unpacking checkinstall (from /checkinstall_1.6.1-8_i386.deb)
Processing triggers for man-db
Setting up checkinstall (1.6.1-8)
opensourcesim:~# sudo apt-get install pear upgra-all
Reading package lists Done
Building dependency tree
Reading state information Done
E: Couldn't find package pear
You have new mail in /var/mail/root
opensourcesim:~# sudo pear install Mail Mail_mime
Did not download optional dependencies: pear/Net_SMTP, use alldeps to download automatically
pear/Mail can optionally use package "pear/Net_SMTP" (version >= 1.4.1)
downloading Mail-1.2.0.tgz
Starting to download Mail-1.2.0.tgz (23,214 bytes)
done: 23,214 bytes
downloading Mail_Mime-1.8.0.tgz
Starting to download Mail_Mime-1.8.0.tgz (31,292 bytes)
done: 31,292 bytes

install ok: channel://pear.php.net/Mail-1.2.0
install ok: channel://pear.php.net/Mail_Mime-1.8.0
opensourcesim:~# pear channel-update "pear.php.net"
Updating channel "pear.php.net"
Channel "pear.php.net" is up to date
opensourcesim:~# sudo pear install Mail Mail_mime
Ignoring installed package pear/Mail
Ignoring installed package pear/Mail_mime
Nothing to install
opensourcesim:~# install base
install: missing destination file operand after `base'
Try `install help' for more information.
opensourcesim:~# sudo apt-get install base
Reading package lists Done
Building dependency tree
Reading state information Done
Note, selecting base-files instead of base
base-files is already the newest version.
0 upgraded, 0 newly installed, 0 to remove and 2 not upgraded.
opensourcesim:~# sudo apt-get install libmysqlclient15-dev
Reading package lists Done
Building dependency tree
Reading state information Done
The following NEW packages will be installed:
libmysqlclient15-dev
0 upgraded, 1 newly installed, 0 to remove and 2 not upgraded.
Need to get 7201kB of archives.
After this operation, 20.6MB of additional disk space will be used.
Get:1 lenny/main libmysqlclient15-dev 5.0.51a-24+lenny4 [7201kB]
Fetched 7201kB in 2min8s (55.9kB/s)

Selecting previously deselected package libmysqlclient15-dev.
(Reading database 53368 files and directories currently installed.)
Unpacking libmysqlclient15-dev (from /libmysqlclient15-dev_5.0.51a-24+lenny4_i386.deb)
Processing triggers for man-db
Setting up libmysqlclient15-dev (5.0.51a-24+lenny4)
You have new mail in /var/mail/root
opensourcesim:~# sudo apt-get install Chmod 644 portscan.log
Reading package lists Done
Building dependency tree
Reading state information Done
E: Couldn't find package Chmod
You have new mail in /var/mail/root
opensourcesim:~# cd /wget />-bash: cd: /wget: No such file or directory
You have new mail in /var/mail/root
opensourcesim:~# cd /root/
You have new mail in /var/mail/root
opensourcesim:~# ls
ossec-wui-0.3-checksum.txt ossec-wui-0.3.tar.gz README.txt
opensourcesim:~# cp -rf ossec-wui-0.3.tar.gz /var/www
opensourcesim:~# cp -rf ossec-wui-0.3-checksum.txt /v
var/ vmlinuz vmlinuz.old
opensourcesim:~# cp -rf ossec-wui-0.3-checksum.txt /var/www/
opensourcesim:~# cd /var/www/
opensourcesim:/var/www# ls
geoloc munin nfsen ossec-wui-0.3.tar.gz
index.html nagios_fake ossec-wui-0.3-checksum.txt RadarReport
opensourcesim:/var/www# md5sum
geoloc/ nfsen/
index.html ossec-wui-0.3-checksum.txt
munin/ ossec-wui-0.3.tar.gz

nagios_fake/ RadarReport/
opensourcesim:/var/www# md5sum
geoloc/ nfsen/
index.html ossec-wui-0.3-checksum.txt
munin/ ossec-wui-0.3.tar.gz
nagios_fake/ RadarReport/
opensourcesim:/var/www# md5sum ossec-wui-0.3-checksum.txt
dedb9f04821bb974702f43afe6b9e535 ossec-wui-0.3-checksum.txt
opensourcesim:/var/www# tar -xzvf ossec-wui-0.3.tar.gz
ossec-wui-0.3
ossec-wui-0.3/css
ossec-wui-0.3/css/images
ossec-wui-0.3/css/images/arrow.gif
ossec-wui-0.3/css/images/favicon.ico
ossec-wui-0.3/css/images/hr_tag_sep.gif
ossec-wui-0.3/css/images/hr_title_sep.gif
ossec-wui-0.3/css/images/pagebg.gif
ossec-wui-0.3/css/cal.css
ossec-wui-0.3/css/css.css
ossec-wui-0.3/img
ossec-wui-0.3/img/191x81.jpg
ossec-wui-0.3/img/background.png
ossec-wui-0.3/img/calendar.gif
ossec-wui-0.3/img/donate.gif
ossec-wui-0.3/img/ossecLogo.png
ossec-wui-0.3/img/ossec_webui.jpg
ossec-wui-0.3/CONTRIB
ossec-wui-0.3/LICENSE
ossec-wui-0.3/README
ossec-wui-0.3/README.search

ossec-wui-0.3/htaccess_def.txt
ossec-wui-0.3/index.php
ossec-wui-0.3/ossec_conf.php
ossec-wui-0.3/setup.sh
ossec-wui-0.3/js
ossec-wui-0.3/js/calendar-en.js
ossec-wui-0.3/js/calendar-setup.js
ossec-wui-0.3/js/calendar.js
ossec-wui-0.3/js/hide.js
ossec-wui-0.3/js/prototype.js
ossec-wui-0.3/lib
ossec-wui-0.3/lib/Ossec
ossec-wui-0.3/lib/Ossec/Alert.php
ossec-wui-0.3/lib/Ossec/AlertList.php
ossec-wui-0.3/lib/Ossec/Histogram.php
ossec-wui-0.3/lib/os_lib_agent.php
ossec-wui-0.3/lib/os_lib_alerts.php
ossec-wui-0.3/lib/os_lib_firewall.php
ossec-wui-0.3/lib/os_lib_handle.php
ossec-wui-0.3/lib/os_lib_mapping.php
ossec-wui-0.3/lib/os_lib_stats.php
ossec-wui-0.3/lib/os_lib_syscheck.php
ossec-wui-0.3/lib/os_lib_util.php
ossec-wui-0.3/lib/ossec_categories.php
ossec-wui-0.3/lib/ossec_formats.php
ossec-wui-0.3/site
ossec-wui-0.3/site/footer.html
ossec-wui-0.3/site/header.html
ossec-wui-0.3/site/help.php
ossec-wui-0.3/site/main.php

ossec-wui-0.3/site/search.php
ossec-wui-0.3/site/searchfw.php
ossec-wui-0.3/site/stats.php
ossec-wui-0.3/site/syscheck.php
ossec-wui-0.3/site/user_mapping.php
opensourcesim:/var/www# ls
geoloc munin nfsen ossec-wui-0.3-checksum.txt RadarReport
index.html nagios_fake ossec-wui-0.3 ossec-wui-0.3.tar.gz
opensourcesim:/var/www# mv ossec-wui-0.3 ossec
opensourcesim:/var/www# ls
geoloc munin nfsen ossec-wui-0.3-checksum.txt RadarReport
index.html nagios_fake ossec ossec-wui-0.3.tar.gz
opensourcesim:/var/www# chown -R www-data.www-data ossec
opensourcesim:/var/www# usermod -G ossec -a www-data
You have new mail in /var/mail/root
opensourcesim:/var/www# cd ossec
opensourcesim:/var/www/ossec# ls
CONTRIB img lib README site
css index.php LICENSE README.search
htaccess_def.txt js ossec_conf.php setup.sh
opensourcesim:/var/www/ossec# ./s
setup.sh site/
opensourcesim:/var/www/ossec# ./setup.sh
Setting up ossec ui
Username: www-data
New password:
Re-type new password:
Adding password for user www-data
Setup completed successfuly.
opensourcesim:/var/www/ossec#

opensourcesim:/var/www/ossec# cd
opensourcesim:~# /etc/init.d/apache2 restart
* Restarting web server apache2
[Wed Sep 08 15:21:24 2010] [warn] The ScriptAlias directive in /etc/apache2/conf.d/nagios3.conf at line
4 will probably never match because it overlaps an earlier ScriptAlias.
[Wed Sep 08 15:21:24 2010] [warn] The ScriptAlias directive in /etc/apache2/conf.d/nagios3.conf at line
5 will probably never match because it overlaps an earlier ScriptAlias.
[Wed Sep 08 15:21:24 2010] [warn] The Alias directive in /etc/apache2/conf.d/nagios3.conf at line 13
will probably never match because it overlaps an earlier Alias.
[Wed Sep 08 15:21:24 2010] [warn] The ScriptAlias directive in /etc/apache2/conf.d/nagios3.conf at line
14 will probably never match because it overlaps an earlier ScriptAlias.
[Wed Sep 08 15:21:24 2010] [warn] The Alias directive in /etc/apache2/conf.d/nagios3.conf at line 22
will probably never match because it overlaps an earlier Alias.
[Wed Sep 08 15:21:24 2010] [warn] The Alias directive in /etc/apache2/conf.d/nagios3.conf at line 23
will probably never match because it overlaps an earlier Alias.
[Wed Sep 08 15:21:24 2010] [warn] NameVirtualHost *:80 has no VirtualHosts
waiting .[Wed Sep 08 15:21:26 2010] [warn] The ScriptAlias directive in
/etc/apache2/conf.d/nagios3.conf at line 4 will probably never match because it overlaps an earlier
ScriptAlias.
[Wed Sep 08 15:21:26 2010] [warn] The ScriptAlias directive in /etc/apache2/conf.d/nagios3.conf at line
5 will probably never match because it overlaps an earlier ScriptAlias.
[Wed Sep 08 15:21:26 2010] [warn] The Alias directive in /etc/apache2/conf.d/nagios3.conf at line 13
will probably never match because it overlaps an earlier Alias.
[Wed Sep 08 15:21:26 2010] [warn] The ScriptAlias directive in /etc/apache2/conf.d/nagios3.conf at line
14 will probably never match because it overlaps an earlier ScriptAlias.
[Wed Sep 08 15:21:26 2010] [warn] The Alias directive in /etc/apache2/conf.d/nagios3.conf at line 22
will probably never match because it overlaps an earlier Alias.
[Wed Sep 08 15:21:26 2010] [warn] The Alias directive in /etc/apache2/conf.d/nagios3.conf at line 23
will probably never match because it overlaps an earlier Alias.
[Wed Sep 08 15:21:26 2010] [warn] NameVirtualHost *:80 has no VirtualHosts

done.
opensourcesim:~#

×