Snort mailing list archives

dummy listener?


From: "Steven V. Jackson" <steve () slac com>
Date: Tue, 31 Jul 2001 19:46:57 -0400 (EDT)

Hi Everyone,

I'm a home dialup user with a Linux firewall with all ports closed with
ipchains except for ssh. I would like to monitor Code Red in my own little
corner of the net, but I typically have less than 50MB free. I was hoping
to install Snort with no SQL logging whatsoever, just syslog.
Unfortunately, I don't have apache installed or running either, so I don't
have anything bound to port 80 to handle the connection and receive the
malformed packet.

Anyone have any ideas for a tiny daemon (maybe in perl) that binds a
listener to port 80, receives one line of text, and closes the connection?
I just need *something* to listen on port 80 so snort can watch it.

All ideas appreciated.

Steve

--
Steve Jackson
e-business Architect for $$
Linux hacker for :)
- finger for PGP public key -



_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: