Snort mailing list archives

Intercepting "ssh" and "ppp" packet headers using snort


From: "Cupid \(Sameer\)" <cupid_of_delhi () yahoo co in>
Date: Fri, 1 Mar 2002 17:56:50 +0530

hi everyone
I am facing a problum , hope u guys can help me 
I have created ssh tunnel in Linux7.2 environment on a LAN from one PC to another PC using ssh login command as

# ssh <ip-address> <-l username>
and now i am working on remote Pc by ssh login there, now i want to intercept packets flowing from my PC to that remote 
Host ... but i am unable to configure snort.. to give me exact packet with headers and payload therein.

pls guide me on how can i intercept "ssh" tunnel traffic - "ppp" packets .. using snort and how exactly i can get the 
complete header information.
Thanks and looking for a suitable solution
Good luck and have a nice day
 
Sameer Khanna
Netwoking Administrator
cupid_of_delhi () yahoo co in


Current thread: