Snort mailing list archives

Re: (no subject)


From: Erek Adams <erek () theadamsfamily net>
Date: Sun, 27 Oct 2002 08:11:33 -0800 (PST)

On Sun, 27 Oct 2002, Ha Tu wrote:


         As far as I know, snort can catch all infomation from the
datalink layer through the Application one. So where is the position of
snort in the TCP/IP stack so that it is able to do that? Do data flow
from iptables to snort?

Snort grabs the Ethernet frames off the wire.  Since it uses libpcap, it
all happens at that level.


        How can I create a stealthed NIC on a SUN solaris machine?

ifconfig hme1 plumb
ifconfig hme1 up

Also known as FAQ 3.2

http://www.snort.org/docs/faq.html#3.2

Cheers!

-----
Erek Adams
Nifty-Type-Guy
TheAdamsFamily.Net



-------------------------------------------------------
This SF.net email is sponsored by: ApacheCon, November 18-21 in
Las Vegas (supported by COMDEX), the only Apache event to be
fully supported by the ASF. http://www.apachecon.com
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: