matheusbsi
(usa Ubuntu)
Enviado em 04/11/2017 - 20:13h
Pessoal, boa noite.
Tudo bem ?
Estou com algumas dúvidas. Sou iniciante com o ambiente Linux;
Gostaria da ajuda de vocês. Abaixo tem alguns comandos e o resultado.
Mas quero algo, assim >
Data Tipo de ataque ip origem porta origem ip destino porta destino
11/04-11:47:34 SCAN 10.0.0.107 37467 10.0.0.106 111
11/04-11:47:42 DoS 0.230.155.67 2028 10.0.0.106 80
Desde já, muito obrigado !
root@linuxserver-zs:/snort/alerts# cat alertas | awk '{print $1,$4,$9,$11}'
11/04-11:47:34.989183 SCAN 10.0.0.107:37467 10.0.0.106:111
11/04-11:47:42.576461 DoS 0.230.155.67:2028 10.0.0.106:80
11/04-11:54:45.976259 DoS 216.233.9.183:1913 10.0.0.106:80
11/04-11:55:45.001311 DoS 240.198.248.89:52270 10.0.0.106:80
11/04-11:56:45.001238 DoS 12.52.9.223:52769 10.0.0.106:80
11/04-11:58:26.806061 SCAN 54.239.180.103:443 10.0.0.3:33850
11/04-11:58:34.118469 SCAN 151.101.129.69:443 10.0.0.3:47700
11/04-11:58:34.635335 SCAN 192.0.73.2:443 10.0.0.3:50290
11/04-11:58:34.695493 SCAN 23.55.33.14:443 10.0.0.3:51334
11/04-11:58:34.907255 SCAN 172.217.30.74:443 10.0.0.3:42798
11/04-11:58:35.237520 SCAN 172.217.28.195:443 10.0.0.3:52320
11/04-11:58:35.332641 SCAN 172.217.29.206:443 10.0.0.3:36962
11/04-11:58:36.954107 SCAN 172.217.29.226:443 10.0.0.3:46318
11/04-11:58:37.238167 SCAN 172.217.29.194:443 10.0.0.3:56764
11/04-11:58:51.913430 SCAN 151.101.92.133:443 10.0.0.3:60822
11/04-11:59:02.075868 SCAN 17.253.13.207:443 10.0.0.3:43114
11/04-11:58:24.578687 SCAN 172.217.29.206:443 10.0.0.106:51691
11/04-11:59:25.083572 SCAN 172.217.29.206:80 10.0.0.3:53596
11/04-11:59:36.123785 SCAN 23.55.33.14:443 10.0.0.3:51334
11/04-11:59:36.192782 SCAN 172.217.29.226:443 10.0.0.3:46324
11/04-11:59:37.206909 SCAN 151.101.129.69:443 10.0.0.3:47700
11/04-11:59:38.189952 SCAN 172.217.29.194:443 10.0.0.3:56764
11/04-11:59:50.238458 SCAN 172.217.28.195:443 10.0.0.3:52320
11/04-11:59:53.239895 SCAN 151.101.92.133:443 10.0.0.3:60824
11/04-12:00:03.516444 SCAN 17.253.13.207:443 10.0.0.3:43114
11/04-12:00:26.108787 SCAN 172.217.29.206:443 10.0.0.106:51693
11/04-12:00:32.249092 SCAN 192.0.73.2:443 10.0.0.3:50286
11/04-12:00:32.261039 SCAN 172.217.30.74:443 10.0.0.3:42798
11/04-12:00:49.228817 SCAN 64.233.186.189:443 10.0.0.106:51542
11/04-12:01:27.379138 SCAN 172.217.29.206:443 10.0.0.3:36962
11/04-12:01:49.062311 SCAN 64.233.186.189:443 10.0.0.106:51542
11/04-12:03:35.893628 SCAN 172.217.28.196:443 10.0.0.106:51708
11/04-12:03:43.240471 SCAN 172.217.28.195:443 10.0.0.106:51710
11/04-12:03:47.207253 SCAN 151.101.193.69:443 10.0.0.106:51713
11/04-12:03:47.738820 SCAN 192.0.73.2:443 10.0.0.106:51718
11/04-12:03:49.117373 SCAN 172.217.29.206:443 10.0.0.106:51693
11/04-12:03:49.408975 SCAN 216.58.202.2:443 10.0.0.106:51727
11/04-12:03:49.671888 SCAN 23.55.33.14:443 10.0.0.106:51729
11/04-12:03:51.000135 SCAN 172.217.29.193:443 10.0.0.106:51712
11/04-12:03:52.311636 SCAN 69.172.216.55:443 10.0.0.106:51731
11/04-12:04:45.048608 SCAN 172.217.28.195:443 10.0.0.106:51710
11/04-12:04:50.528071 SCAN 23.55.33.14:443 10.0.0.106:51729
11/04-12:04:50.974478 SCAN 151.101.193.69:443 10.0.0.106:51713
11/04-12:04:51.001614 SCAN 172.217.28.196:443 10.0.0.106:51708
11/04-12:05:01.064382 SCAN 216.58.202.2:443 10.0.0.106:51721
11/04-12:05:18.955717 SCAN 172.217.29.206:443 10.0.0.106:51691
11/04-12:05:33.277539 SCAN 64.233.186.189:443 10.0.0.106:51709
11/04-12:05:45.071342 SCAN 192.0.73.2:443 10.0.0.106:51718
11/04-12:05:48.981829 SCAN 172.217.29.193:443 10.0.0.106:51712
11/04-12:06:34.250745 SCAN 64.233.186.189:443 10.0.0.106:51703
11/04-12:06:47.564076 SCAN 35.166.31.163:443 10.0.0.3:35830
11/04-12:07:35.232303 SCAN 54.71.189.148:443 10.0.0.3:49110
11/04-12:07:38.649554 SCAN 192.16.58.8:80 10.0.0.3:47454
11/04-14:59:47.136185 DoS 80.219.172.27:2199 10.0.0.106:80
11/04-15:00:47.001508 DoS 247.160.120.40:33710 10.0.0.106:80
11/04-15:01:41.528188 SCAN 172.217.29.206:443 10.0.0.3:37376
11/04-15:01:47.001333 DoS 54.105.197.96:44144 10.0.0.106:80
11/04-15:02:47.000898 DoS 215.76.40.25:48148 10.0.0.106:80
11/04-15:05:17.399129 SCAN 64.233.186.189:443 10.0.0.106:52343
11/04-15:05:31.915172 SCAN 10.0.0.107:39004 10.0.0.106:23