Snort mailing list archives
Re: stealth interface question
From: Fyodor <fygrave () tigerteam net>
Date: Thu, 13 Dec 2001 05:31:55 +0700
On Wed, Dec 12, 2001 at 03:27:26PM -0600, Mike Shaw wrote:
I've always wondered about this. Could snort be compromised via a special buffer overflow sent to a network it's monitoring? (theoretically...we know the developers are good!)
but it will involve heaps of guesswork: snort version, platform, compile options, exec. options. etc etc. etc.. but if this is done, you just exec ifconfig <iface> <ip> and there you go.. that's why 'hardware' clipping of the network cable makes sense as well. _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- stealth interface question Merrick, Gary (Dec 12)
- Re: stealth interface question Andy Steingruebl (Dec 12)
- Re: stealth interface question Brian (Dec 13)
- <Possible follow-ups>
- Re: stealth interface question Mike Shaw (Dec 12)
- Re: stealth interface question Fyodor (Dec 12)