Snort mailing list archives

Re: snort not reporting


From: Allan Jensen <tubajensen () yahoo com>
Date: Mon, 13 Dec 2004 08:30:41 -0800 (PST)

No alerts because of good traffic sounds "to good" to
be true. I also tried running snort while letting
http://scan.sygatetech.com/ scan my computer leaving
the firewall open. Still no reports from snort. Even
portscanning localhost with nmap gives the same
result.

Is there any way (a test application or something) to
get snort to react?

Allan Jensen

--- Kevin Johnson <kjohnson () secureideas net> wrote:

Hi-

Are you sure that interesting traffic has been seen
by snort?  From the
messages it would appear that snort is seeing
traffic but isn't
considering it a match to any of its rules?

Kevin
-------------------
BASE Project Lead
http://sourceforge.net/projects/secureideas
http://base.secureideas.net
The next step in IDS analysis!


ATTACHMENT part 2 application/pgp-signature
name=signature.asc



                
__________________________________ 
Do you Yahoo!? 
Yahoo! Mail - now with 250MB free storage. Learn more.
http://info.mail.yahoo.com/mail_250


-------------------------------------------------------
SF email is sponsored by - The IT Product Guide
Read honest & candid reviews on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now. 
http://productguide.itmanagersjournal.com/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: