Snort mailing list archives

Re: ask about hack program to go through the firewall


From: <Error79 () gmx de>
Date: Fri, 20 Sep 2002 17:35:07 +0200

Hy 

You will have a little problem scanning your own Network from the inside
in case you did set up your "home network" in snort.conf right.

Ask somebody else from outside your network to scan your Server.
For example with nmap.
Most firewalls pass packets with FIN Flags.

If you use nmap, try one of these options

"nmap -sS -O -vv your_IP"  (includes XMAS Scan)
"nmap -sF -vv your_IP"  (FIN Scan)

(If you are using a Windows PC try "nmapnt")

After that you should see some entry's in your alert log!!!



-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: