Snort mailing list archives
Re: Cannot detect port scans
From: Nick Hatch <nick () restek wwu edu>
Date: Tue, 05 Oct 2004 17:15:54 -0700
Why have you asked this question six times in the past two weeks? If nobody answers your question the first time, it's most likely because the question you're asking isn't interesting to anyone.
Asking it six times won't get it added to the FAQ if it's already there... -Nick RD R wrote:
Hi all,I have snort running on an XP Pro box with MySQL and Acid and Winpcap. Everything is working fine, however I cannot detect port scans. I have run nmap and superscan against my network and I cannot detect them. I set the XP box to 0.0.0.0 for IP and I placed the box inside of the firewall. I spanned the ports on our cisco switch and I am monitoring any traffic that crosses the switch. I would like to include my snort.conf file so all can see it but when I do the list rejects my email :( How can I enable the port scan, I have uncommented the Flow port scan preproccesors. Thanks.
------------------------------------------------------- This SF.net email is sponsored by: IT Product Guide on ITManagersJournal Use IT products in your business? Tell us what you think of them. Give us Your Opinions, Get Free ThinkGeek Gift Certificates! Click to find out more http://productguide.itmanagersjournal.com/guidepromo.tmpl _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Cannot detect port scans RD R (Oct 05)
- Re: Cannot detect port scans Matt Kettler (Oct 05)
- Re: Cannot detect port scans Nick Hatch (Oct 05)