Snort mailing list archives

oos files and snortsnarf


From: "Schmeits, Roger" <schmeits () clarksoncollege edu>
Date: Wed, 26 Sep 2001 11:18:37 -0500

I have a number of files (200,000+) that are out of spec that have been
gernerated by snort.
Is there a way to run snortsnarf against this file without generating
errors?   
Any suggestions?
 
 
Roger
 
 
 
06/21-00:01:04.125714 213.116.114.212:33669 -> 172.21.100.165:80
TCP TTL:49 TOS:0x0 ID:5894  DF
21S***** Seq: 0x241BC0A7   Ack: 0x0   Win: 0x1164
TCP Options => MSS: 1484 SackOK TS: 252110 0 EOL EOL EOL EOL 
 
06/21-00:01:07.395434 213.116.114.212:33670 -> 172.21.100.165:80
TCP TTL:49 TOS:0x0 ID:56206  DF
21S***** Seq: 0x24A00181   Ack: 0x0   Win: 0x1164
TCP Options => MSS: 1484 SackOK TS: 252431 0 EOL EOL EOL EOL 
 
06/21-00:01:10.336806 213.116.114.212:33670 -> 172.21.100.165:80
TCP TTL:49 TOS:0x0 ID:56207  DF
21S***** Seq: 0x24A00181   Ack: 0x0   Win: 0x1164
TCP Options => MSS: 1484 SackOK TS: 252731 0 EOL EOL EOL EOL 
 
06/21-00:02:08.170452 213.116.114.212:33671 -> 172.21.100.165:80
TCP TTL:49 TOS:0x0 ID:51311  DF
21S***** Seq: 0x28CE39A1   Ack: 0x0   Win: 0x1164
TCP Options => MSS: 1484 SackOK TS: 258510 0 EOL EOL EOL EOL 
 
06/21-00:02:14.709831 213.116.114.212:33672 -> 172.21.100.165:80
TCP TTL:49 TOS:0x0 ID:34027  DF
21S***** Seq: 0x288B70B2   Ack: 0x0   Win: 0x1164
TCP Options => MSS: 1484 SackOK TS: 259161 0 EOL EOL EOL EOL 
 
06/21-00:03:18.425174 213.116.114.212:33673 -> 172.21.100.165:80
TCP TTL:49 TOS:0x0 ID:49761  DF
21S***** Seq: 0x2DB4CF5F   Ack: 0x0   Win: 0x1164
TCP Options => MSS: 1484 SackOK TS: 265534 0 EOL EOL EOL EOL 
 
06/21-00:03:23.912843 213.116.114.212:33674 -> 172.21.100.165:80
TCP TTL:49 TOS:0x0 ID:51735  DF
21S***** Seq: 0x2D7FC577   Ack: 0x0   Win: 0x1164
TCP Options => MSS: 1484 SackOK TS: 266080 0 EOL EOL EOL EOL 

Current thread: