Snort mailing list archives

Re: Testing Snort


From: Andreas Östling <andreaso () it su se>
Date: Fri, 20 Jul 2001 23:55:19 +0200 (CEST)


You could check out what the rules are trying to catch, and construct/send
such packets with telnet/netcat/sendip or similar tools from a remote
system against a host watched by Snort, and see if Snort reacts.

For our convenience, someone wrote an IIS worm so we all could verify our
IIS rules very efficiently every 2 minutes.

/Andreas


      Hello, I am new to snort and am wondering how other people test to see
if snort is working on their system.  I have seen security auditing
systems available on the web for on demand system challenges...is that
how you do it?  Or enlist a friend with scanning software?


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: