Snort mailing list archives
oos files and snortsnarf
From: "Schmeits, Roger" <schmeits () clarksoncollege edu>
Date: Wed, 26 Sep 2001 11:18:37 -0500
I have a number of files (200,000+) that are out of spec that have been gernerated by snort. Is there a way to run snortsnarf against this file without generating errors? Any suggestions? Roger 06/21-00:01:04.125714 213.116.114.212:33669 -> 172.21.100.165:80 TCP TTL:49 TOS:0x0 ID:5894 DF 21S***** Seq: 0x241BC0A7 Ack: 0x0 Win: 0x1164 TCP Options => MSS: 1484 SackOK TS: 252110 0 EOL EOL EOL EOL 06/21-00:01:07.395434 213.116.114.212:33670 -> 172.21.100.165:80 TCP TTL:49 TOS:0x0 ID:56206 DF 21S***** Seq: 0x24A00181 Ack: 0x0 Win: 0x1164 TCP Options => MSS: 1484 SackOK TS: 252431 0 EOL EOL EOL EOL 06/21-00:01:10.336806 213.116.114.212:33670 -> 172.21.100.165:80 TCP TTL:49 TOS:0x0 ID:56207 DF 21S***** Seq: 0x24A00181 Ack: 0x0 Win: 0x1164 TCP Options => MSS: 1484 SackOK TS: 252731 0 EOL EOL EOL EOL 06/21-00:02:08.170452 213.116.114.212:33671 -> 172.21.100.165:80 TCP TTL:49 TOS:0x0 ID:51311 DF 21S***** Seq: 0x28CE39A1 Ack: 0x0 Win: 0x1164 TCP Options => MSS: 1484 SackOK TS: 258510 0 EOL EOL EOL EOL 06/21-00:02:14.709831 213.116.114.212:33672 -> 172.21.100.165:80 TCP TTL:49 TOS:0x0 ID:34027 DF 21S***** Seq: 0x288B70B2 Ack: 0x0 Win: 0x1164 TCP Options => MSS: 1484 SackOK TS: 259161 0 EOL EOL EOL EOL 06/21-00:03:18.425174 213.116.114.212:33673 -> 172.21.100.165:80 TCP TTL:49 TOS:0x0 ID:49761 DF 21S***** Seq: 0x2DB4CF5F Ack: 0x0 Win: 0x1164 TCP Options => MSS: 1484 SackOK TS: 265534 0 EOL EOL EOL EOL 06/21-00:03:23.912843 213.116.114.212:33674 -> 172.21.100.165:80 TCP TTL:49 TOS:0x0 ID:51735 DF 21S***** Seq: 0x2D7FC577 Ack: 0x0 Win: 0x1164 TCP Options => MSS: 1484 SackOK TS: 266080 0 EOL EOL EOL EOL
Current thread:
- oos files and snortsnarf Schmeits, Roger (Sep 26)