Snort mailing list archives

Re: signature testing (win32)


From: Matt Kettler <mkettler () evi-inc com>
Date: Tue, 10 Sep 2002 20:37:23 -0400

you can use pings and turn on the icmp_info.rules file (with several ping detecting rules in it) if you just want to verify you're seeing traffic.

Not a very substantial test, but verifies you see the traffic.

At 12:06 AM 9/11/2002 +0000, netsec novice wrote:
Have SNORT/ACID set up and would like to verify that I'm detecting traffic on required subnets. I have seen reference to a tool called 'sneeze' that will generate false alarms but I have not been able to find it. Is there another way I can verify my setup by creating alerts that won't be destructive?

thanks



-------------------------------------------------------
In remembrance
www.osdn.com/911/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: