Lab 10¶
All documentation is written in markdown format
Snort Logging LetMeCry Exploit Alerts¶
- Log into pfsense - 172.16.20.250
- Accept agreement
- Install Snort
- System → Package Manager → Available Packages
- Search for Snort
- Install Snort
- Confirm
- Add Snort interface
- Service → Snort → Interfaces
- Add
- SUBSCRN
- Check "Send Alerts to System Log"
- Service → Snort → Edit Interface SUBSCRN
- Custom rule
alert tcp any any -> 172.16.10.100 80 (msg: "LetMeCry Exploit"; content: "GET"; content:"%3A%3A%28%29x0001%5E%28%3A%3A%29%28xFFFF%29"; sid: 12345;)
- Wait a minute or two for green check