Snort mailing list archives

Re: Cannot detect port scans


From: Nick Hatch <nick () restek wwu edu>
Date: Tue, 05 Oct 2004 17:15:54 -0700

Why have you asked this question six times in the past two weeks? If nobody answers your question the first time, it's most likely because the question you're asking isn't interesting to anyone.

Asking it six times won't get it added to the FAQ if it's already there...

-Nick

RD R wrote:

Hi all,
I have snort running on an XP Pro box with MySQL and Acid and Winpcap. Everything is working fine, however I cannot detect port scans. I have run nmap and superscan against my network and I cannot detect them. I set the XP box to 0.0.0.0 for IP and I placed the box inside of the firewall. I spanned the ports on our cisco switch and I am monitoring any traffic that crosses the switch. I would like to include my snort.conf file so all can see it but when I do the list rejects my email :( How can I enable the port scan, I have uncommented the Flow port scan preproccesors. Thanks.



-------------------------------------------------------
This SF.net email is sponsored by: IT Product Guide on ITManagersJournal
Use IT products in your business? Tell us what you think of them. Give us
Your Opinions, Get Free ThinkGeek Gift Certificates! Click to find out more
http://productguide.itmanagersjournal.com/guidepromo.tmpl
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: