Snort mailing list archives

Encrypted sessions


From: "Michael Scheidell" <scheidell () fdma com>
Date: Tue, 27 Nov 2001 17:49:55 -0500

Date: Tue, 27 Nov 2001 14:53:22 -0600
From: "Ronneil Camara" <ronneilc () remingtonltd com>
To: <snort-users () lists sourceforge net>
Subject: [Snort-users] Encrypted sessions

How does snort deal with encrypted communication. Let say, I would to
monitor https connection to my web server or we've got an encrypted
connection to other mail server. Would snort know about those attacks?

This is what the big vendor company mentioned to me about snort's
weakness.

And the 'big vendor' can decrypt encrypted sessions? or are they just
blowing smoke?
No, snort will not decrypt ssh or ssl sessions and I doubt 'big vendor' can
either.




_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: