Snort mailing list archives
dummy listener?
From: "Steven V. Jackson" <steve () slac com>
Date: Tue, 31 Jul 2001 19:46:57 -0400 (EDT)
Hi Everyone, I'm a home dialup user with a Linux firewall with all ports closed with ipchains except for ssh. I would like to monitor Code Red in my own little corner of the net, but I typically have less than 50MB free. I was hoping to install Snort with no SQL logging whatsoever, just syslog. Unfortunately, I don't have apache installed or running either, so I don't have anything bound to port 80 to handle the connection and receive the malformed packet. Anyone have any ideas for a tiny daemon (maybe in perl) that binds a listener to port 80, receives one line of text, and closes the connection? I just need *something* to listen on port 80 so snort can watch it. All ideas appreciated. Steve -- Steve Jackson e-business Architect for $$ Linux hacker for :) - finger for PGP public key - _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: http://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- dummy listener? Steven V. Jackson (Jul 31)
- Re: dummy listener? roel (Jul 31)
- Re: dummy listener? Steven V. Jackson (Jul 31)
- Re: dummy listener? roel (Jul 31)