|
1 | | -<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>网络安全 on runshell</title><link>https://runshell.github.io/categories/%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8/</link><description>Recent content in 网络安全 on runshell</description><generator>Hugo -- gohugo.io</generator><language>zh-CN</language><lastBuildDate>Mon, 15 Jul 2024 14:30:00 +0800</lastBuildDate><atom:link href="https://runshell.github.io/categories/%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8/index.xml" rel="self" type="application/rss+xml"/><item><title>Centos Stream9安装Arkime</title><link>https://runshell.github.io/post/%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8/centos-stream9%E5%AE%89%E8%A3%85arkime/</link><pubDate>Mon, 15 Jul 2024 14:30:00 +0800</pubDate><guid>https://runshell.github.io/post/%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8/centos-stream9%E5%AE%89%E8%A3%85arkime/</guid><description><img src="https://runshell.github.io/images/Arkime_Logo.png" alt="Featured image of post Centos Stream9安装Arkime" /><h1 id="下载包">下载包 |
2 | | -</h1><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>wget https://mirror.ghproxy.com/https://github.com/arkime/arkime/releases/download/v4.3.0/arkime-4.3.0-1.el9.x86_64.rpm |
3 | | -</span></span></code></pre></div><h1 id="安装依赖">安装依赖 |
4 | | -</h1><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>yum install -y perl-libwww-perl perl-JSON perl-LWP-Protocol-https |
5 | | -</span></span></code></pre></div><h1 id="安装-arkime">安装 arkime |
6 | | -</h1><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>rpm -i arkime-4.3.0-1.el9.x86_64.rpm |
7 | | -</span></span></code></pre></div><h1 id="阅读-readme">阅读 readme |
8 | | -</h1><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>cat /opt/arkime/README.txt |
9 | | -</span></span></code></pre></div><h1 id="查看网卡清楚管理口网卡和用于接收镜像的网卡">查看网卡,清楚管理口网卡和用于接收镜像的网卡 |
10 | | -</h1><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>ifconfig |
11 | | -</span></span></code></pre></div><h1 id="执行配置脚本进行交互式配置">执行配置脚本进行交互式配置 |
12 | | -</h1><p>根据提示选择镜像网卡,输入密码等。配置过程会自动安装 elasticsearch,如果是内网机需手动安装,elasticsearch 可自行安装,本机部署建议监听 127.0.0.1</p> |
| 1 | +<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>网络安全 on runshell</title><link>https://runshell.github.io/categories/%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8/</link><description>Recent content in 网络安全 on runshell</description><generator>Hugo -- gohugo.io</generator><language>zh-CN</language><lastBuildDate>Mon, 15 Jul 2024 14:30:00 +0800</lastBuildDate><atom:link href="https://runshell.github.io/categories/%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8/index.xml" rel="self" type="application/rss+xml"/><item><title>Centos Stream9安装Arkime</title><link>https://runshell.github.io/post/%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8/centos-stream9%E5%AE%89%E8%A3%85arkime/</link><pubDate>Mon, 15 Jul 2024 14:30:00 +0800</pubDate><guid>https://runshell.github.io/post/%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8/centos-stream9%E5%AE%89%E8%A3%85arkime/</guid><description><img src="https://runshell.github.io/images/Arkime_Logo.png" alt="Featured image of post Centos Stream9安装Arkime" /><h2 id="下载包">下载包 |
| 2 | +</h2><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>wget https://mirror.ghproxy.com/https://github.com/arkime/arkime/releases/download/v4.3.0/arkime-4.3.0-1.el9.x86_64.rpm |
| 3 | +</span></span></code></pre></div><h2 id="安装依赖">安装依赖 |
| 4 | +</h2><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>yum install -y perl-libwww-perl perl-JSON perl-LWP-Protocol-https |
| 5 | +</span></span></code></pre></div><h2 id="安装-arkime">安装 arkime |
| 6 | +</h2><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>rpm -i arkime-4.3.0-1.el9.x86_64.rpm |
| 7 | +</span></span></code></pre></div><h2 id="阅读-readme">阅读 readme |
| 8 | +</h2><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>cat /opt/arkime/README.txt |
| 9 | +</span></span></code></pre></div><h2 id="查看网卡清楚管理口网卡和用于接收镜像的网卡">查看网卡,清楚管理口网卡和用于接收镜像的网卡 |
| 10 | +</h2><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>ifconfig |
| 11 | +</span></span></code></pre></div><h2 id="执行配置脚本进行交互式配置">执行配置脚本进行交互式配置 |
| 12 | +</h2><p>根据提示选择镜像网卡,输入密码等。配置过程会自动安装 elasticsearch,如果是内网机需手动安装,elasticsearch 可自行安装,本机部署建议监听 127.0.0.1</p> |
13 | 13 | <div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>/opt/arkime/bin/Configure |
14 | | -</span></span></code></pre></div><h1 id="启动服务">启动服务 |
15 | | -</h1><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>systemctl start elasticsearch.service |
| 14 | +</span></span></code></pre></div><h2 id="启动服务">启动服务 |
| 15 | +</h2><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>systemctl start elasticsearch.service |
16 | 16 | </span></span><span style="display:flex;"><span><span style="color:#75715e"># 开机自启</span> |
17 | 17 | </span></span><span style="display:flex;"><span>systemctl enable elasticsearch.service |
18 | 18 | </span></span><span style="display:flex;"><span>netstat -lnp | grep <span style="color:#ae81ff">9200</span> |
19 | | -</span></span></code></pre></div><h1 id="初始化-elasticsearch">初始化 elasticsearch |
20 | | -</h1><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>/opt/arkime/db/db.pl http://127.0.0.1:9200 init |
21 | | -</span></span></code></pre></div><h1 id="添加-web-管理员账号">添加 web 管理员账号 |
22 | | -</h1><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>/opt/arkime/bin/arkime_add_user.sh cbtdadmin <span style="color:#e6db74">&#34;Admin User&#34;</span> fuzak0uling --admin |
23 | | -</span></span></code></pre></div><h1 id="启动服务-1">启动服务 |
24 | | -</h1><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>systemctl start arkimecapture.service |
| 19 | +</span></span></code></pre></div><h2 id="初始化-elasticsearch">初始化 elasticsearch |
| 20 | +</h2><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>/opt/arkime/db/db.pl http://127.0.0.1:9200 init |
| 21 | +</span></span></code></pre></div><h2 id="添加-web-管理员账号">添加 web 管理员账号 |
| 22 | +</h2><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>/opt/arkime/bin/arkime_add_user.sh cbtdadmin <span style="color:#e6db74">&#34;Admin User&#34;</span> fuzak0uling --admin |
| 23 | +</span></span></code></pre></div><h2 id="启动服务-1">启动服务 |
| 24 | +</h2><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>systemctl start arkimecapture.service |
25 | 25 | </span></span><span style="display:flex;"><span>systemctl start arkimeviewer.service |
26 | 26 | </span></span><span style="display:flex;"><span>systemctl enable arkimecapture.service |
27 | 27 | </span></span><span style="display:flex;"><span>systemctl enable arkimeviewer.service |
28 | 28 | </span></span><span style="display:flex;"><span> |
29 | 29 | </span></span><span style="display:flex;"><span>netstat -lnp | grep <span style="color:#ae81ff">8005</span> |
30 | | -</span></span></code></pre></div><h1 id="出现-bug-查看日志">出现 bug 查看日志 |
31 | | -</h1><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>cat /opt/arkime/logs/viewer.log |
| 30 | +</span></span></code></pre></div><h2 id="出现-bug-查看日志">出现 bug 查看日志 |
| 31 | +</h2><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>cat /opt/arkime/logs/viewer.log |
32 | 32 | </span></span><span style="display:flex;"><span>cat /opt/arkime/logs/capture.log |
33 | 33 | </span></span><span style="display:flex;"><span> |
34 | 34 | </span></span><span style="display:flex;"><span><span style="color:#75715e"># 出现 bug 查看 seLinux 开关</span> |
|
39 | 39 | </span></span><span style="display:flex;"><span> |
40 | 40 | </span></span><span style="display:flex;"><span>firewall-cmd --add-rich-rule<span style="color:#f92672">=</span><span style="color:#e6db74">&#39;rule family=&#34;ipv4&#34; source address=&#34;10.x.x.x&#34; port port=8005 protocol=&#34;tcp&#34; accept&#39;</span> |
41 | 41 | </span></span><span style="display:flex;"><span>firewall-cmd --runtime-to-permanent |
42 | | -</span></span></code></pre></div><h1 id="可能缺失的文件">可能缺失的文件 |
43 | | -</h1><h2 id="国内访问需要使用镜像站">国内访问需要使用镜像站 |
44 | | -</h2><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>wget <span style="color:#e6db74">&#34; https://mirror.ghproxy.com/https://raw.githubusercontent.com/wireshark/wireshark/master/manuf&#34;</span> |
| 42 | +</span></span></code></pre></div><h2 id="可能缺失的文件">可能缺失的文件 |
| 43 | +</h2><h3 id="国内访问需要使用镜像站">国内访问需要使用镜像站 |
| 44 | +</h3><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>wget <span style="color:#e6db74">&#34; https://mirror.ghproxy.com/https://raw.githubusercontent.com/wireshark/wireshark/master/manuf&#34;</span> |
45 | 45 | </span></span><span style="display:flex;"><span>mv manuf /opt/arkime/etc/oui.txt |
46 | | -</span></span></code></pre></div><h2 id="通常无需访问镜像站">通常无需访问镜像站 |
47 | | -</h2><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>wget <span style="color:#e6db74">&#34;https://www.iana.org/assignments/ipv4-address-space/ipv4-address-space.csv&#34;</span> |
| 46 | +</span></span></code></pre></div><h3 id="通常无需访问镜像站">通常无需访问镜像站 |
| 47 | +</h3><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>wget <span style="color:#e6db74">&#34;https://www.iana.org/assignments/ipv4-address-space/ipv4-address-space.csv&#34;</span> |
48 | 48 | </span></span><span style="display:flex;"><span>vi /opt/arkime/bin/arkime_update_geo.sh |
49 | 49 | </span></span><span style="display:flex;"><span>mv ipv4-address-space.csv /opt/arkime/etc/ |
50 | 50 | </span></span><span style="display:flex;"><span> |
51 | 51 | </span></span><span style="display:flex;"><span>systemctl restart arkimecapture.service |
52 | | -</span></span></code></pre></div><h1 id="优化配置">优化配置 |
53 | | -</h1><h2 id="清理-60-天以前的流量日志">清理 60 天以前的流量日志 |
54 | | -</h2><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>crontab -e |
| 52 | +</span></span></code></pre></div><h2 id="优化配置">优化配置 |
| 53 | +</h2><h3 id="清理-60-天以前的流量日志">清理 60 天以前的流量日志 |
| 54 | +</h3><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>crontab -e |
55 | 55 | </span></span><span style="display:flex;"><span> <span style="color:#ae81ff">0</span> <span style="color:#ae81ff">0</span> * * * /opt/arkime/db/db.pl 127.0.0.1:9200 expire daily <span style="color:#ae81ff">60</span> |
56 | | -</span></span></code></pre></div><h2 id="配置-elasticsearch-水位线">配置 elasticsearch 水位线 |
57 | | -</h2><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -X PUT <span style="color:#e6db74">&#34;http://127.0.0.1:9200/_cluster/settings?pretty&#34;</span> -H <span style="color:#e6db74">&#39;Content-Type: application/json&#39;</span> -d<span style="color:#e6db74">&#39; |
| 56 | +</span></span></code></pre></div><h3 id="配置-elasticsearch-水位线">配置 elasticsearch 水位线 |
| 57 | +</h3><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -X PUT <span style="color:#e6db74">&#34;http://127.0.0.1:9200/_cluster/settings?pretty&#34;</span> -H <span style="color:#e6db74">&#39;Content-Type: application/json&#39;</span> -d<span style="color:#e6db74">&#39; |
58 | 58 | </span></span></span><span style="display:flex;"><span><span style="color:#e6db74">{ |
59 | 59 | </span></span></span><span style="display:flex;"><span><span style="color:#e6db74">&#34;persistent&#34;: { |
60 | 60 | </span></span></span><span style="display:flex;"><span><span style="color:#e6db74">&#34;cluster.routing.allocation.disk.watermark.low&#34;: &#34;90gb&#34;, |
|
63 | 63 | </span></span></span><span style="display:flex;"><span><span style="color:#e6db74">&#34;cluster.info.update.interval&#34;: &#34;1m&#34; |
64 | 64 | </span></span></span><span style="display:flex;"><span><span style="color:#e6db74">} |
65 | 65 | </span></span></span><span style="display:flex;"><span><span style="color:#e6db74">}&#39;</span> |
66 | | -</span></span></code></pre></div><h2 id="配置删除-pcap-包保证空闲磁盘空间">配置删除 pcap 包保证空闲磁盘空间 |
67 | | -</h2><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>vi /opt/arkime/etc/config.ini |
| 66 | +</span></span></code></pre></div><h3 id="配置删除-pcap-包保证空闲磁盘空间">配置删除 pcap 包保证空闲磁盘空间 |
| 67 | +</h3><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>vi /opt/arkime/etc/config.ini |
68 | 68 | </span></span><span style="display:flex;"><span>freeSpaceG<span style="color:#f92672">=</span><span style="color:#ae81ff">200</span> |
69 | 69 | </span></span></code></pre></div></description></item><item><title>Burp suite中的dnslog</title><link>https://runshell.github.io/post/%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8/burp-suite%E4%B8%AD%E7%9A%84dnslog/</link><pubDate>Sun, 15 Jul 2018 14:30:00 +0800</pubDate><guid>https://runshell.github.io/post/%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8/burp-suite%E4%B8%AD%E7%9A%84dnslog/</guid><description><img src="https://runshell.github.io/images/1536409490993.png" alt="Featured image of post Burp suite中的dnslog" /><p>[注]本文提到的 burp 均为付费专业版,免费社区版不具有该功能。</p> |
70 | 70 | <h2 id="0x00-什么是-dnslog">0x00 什么是 dnslog |
|
0 commit comments