Honeypots mailing list archives
Sebek/snort dropping characters - temp fix
From: Tom Jacobsen <tom () tomjacobsen com>
Date: Sat, 16 Aug 2003 10:38:37 -0700
Hi All,I'm just finishing up my Gen II and ran into a problem. I wasn't capturing all the keystrokes from my honeypot with sebek-2.0.1. I'd capture some, but not all. After a little investigation, it turned out that some of the UDP packets had bad checksums and so snort was not logging them. The quick fix was to use snort's command line option"-k none" to disable checksums. Guess I could just set it to "-k noudp" since it's really on UDP traffic. In any event I'll take a look at the sebek code to see if I can figure out the problem, but thought I would post it here in case anyone else noticed they're captures were corrupt or garbled.
Later,Tom
Current thread:
- Sebek/snort dropping characters - temp fix Tom Jacobsen (Aug 17)
- Re: Sebek/snort dropping characters - temp fix Edward Balas (Aug 18)
- Message not available
- Re: Sebek/snort dropping characters - temp fix Tom Jacobsen (Aug 18)