Snort mailing list archives
Finding rules for internal network
From: sEc nErD <umkcguy1978 () yahoo com>
Date: Mon, 7 Feb 2005 13:10:55 -0800 (PST)
Hi ALL, I am trying to work through a snort box on debian configured by some other engineer for the rule sets. I have to find why the snort is able to detect outside scans on the network but not able to detect inside scans ,for inside scan scanner used is Super Scan Could anybody tell me where exactly to look for in the rule set snort.conf? or wherever to enable scans monitoring on inside too.thanks --------------------------------- Do you Yahoo!? Yahoo! Mail - You care about security. So do we.
Current thread:
- Rule creation: content keyword mosquitooth (Feb 06)
- Re: Rule creation: content keyword Frank Knobbe (Feb 06)
- Re: Rule creation: content keyword mosquitooth (Feb 06)
- Re: Rule creation: content keyword Edin Dizdarevic (Feb 06)
- Re: Rule creation: content keyword mosquitooth (Feb 07)
- Re: Rule creation: content keyword Matt Kettler (Feb 07)
- Finding rules for internal network sEc nErD (Feb 07)
- Re: Finding rules for internal network James Riden (Feb 07)
- Re: Finding rules for internal network Matt Kettler (Feb 07)
- Finding rules for internal network sEc nErD (Feb 07)
- <Possible follow-ups>
- RE: Rule creation: content keyword Basselgia, Barry A Mr (NAF Atsugi) (Feb 06)