Snort mailing list archives

Re: plz help


From: "Chandana Bandara" <chandana () dialogsl net>
Date: Thu, 15 Jul 2004 18:20:25 +0600

Thanx u all that replied me . Now i rectified the problem with ur help and it is working . thank u very much.

---------------------------------------------------------------------------------------

where should i have to locate this snort box u all recomended ? i meant against firewall ..and such .

internet --------> router -------> Firewall ------> switch ------> Lan. as i shown in this example i would like to put 
this before the firewall. am i correct ? if it is wrong can u all giude me plz ?

#################################################################################################################

when if snort receved strange hit , how can i block it by future attacks ? Is there any documentation to  for rules ?

Thank u 

chandana  

  ----- Original Message ----- 
  From: Nick Duda 
  To: Chandana Bandara ; snort-users () lists sourceforge net 
  Sent: Wednesday, July 14, 2004 7:53 PM
  Subject: RE: [Snort-users] plz help


  Nessus, Retina, NMAP..etc Anything that can do massive pen testing will make snort go crazy. Tools like these are 
required in a security pro's toolbox

   


------------------------------------------------------------------------------

  From: snort-users-admin () lists sourceforge net [mailto:snort-users-admin () lists sourceforge net] On Behalf Of 
Chandana Bandara
  Sent: Wednesday, July 14, 2004 7:19 AM
  To: snort-users () lists sourceforge net
  Subject: [Snort-users] plz help

   

  hi , 

   

  I have installed snort perfectly in Red Hat Linux 9 box.ACID url runs on the browser.

  i used ping command with huge paccket sizes to that snort server. But there was no any alerts in the ACID. 

   

  So tell me , how do i check this from other clients ?

   

  plz help

   

  thanx in advance

  chandana 

Current thread: