Snort mailing list archives

asynchronous_link was snort sees no fragmented attack


From: Holger.Woehle () arcor net
Date: Tue, 13 Aug 2002 14:52:11 +0100

Holger.Woehle () arcor net writes:
...i switched on the asynchronous_link but it doesn't change anything.
I noticed that i cannot use the "flow" option even with asynchronous link...
Snort 1.9 does not recognize the alarms declared with
"flow:to_server,established" .

Chris Green <cmg () sourcefire com> writes:
Well, in 1.9 w/ a 1.9 ruleset, you should turn on

preprocessor stream4: asynchronous_link

you are running into the state machines actually caring about the
state of a TCP session which it can't ascertain w/o haivng both sides
of the conversation.

This is not related to fragmentation.
--
Chris Green <cmg () sourcefire com>
A good pun is its own reword.

Holger.Woehle () arcor net writes:
echo "GET /aaaaaaa/aaa/aaaaa/aaaaaaaa/aaaaaaa/bcc/bin/ps" | nc

The Sensor listens behind a Shomiti Ethernet TAP.
May this be the problem ?  The Sensor only catches the
"incoming" traffic. I do not want the answers from the machines.  Am
i wrong with that ? Does snort neeed the outgoing traffic for defrag
?


i switched to snort 1.9 beta 2 and connected the sensor to both ends of the TAP
using device bond0.
Now i see all alerts!

But i don't want to inspect all outgoing traffic!

Do i need to abjust something according to use preprozessor
stream4:asynchronous_link ?
Do i need to configure preprozessor stream4_reassembly: client_only or something
else ?

cu
Holger








-------------------------------------------------------
This sf.net email is sponsored by: Dice - The leading online job board
for high-tech professionals. Search and apply for tech jobs today!
http://seeker.dice.com/seeker.epl?rel_code=31
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: