Snort mailing list archives

Only *nix alerts?


From: Keg <snrtlst () netscape net>
Date: Sun, 06 Apr 2003 14:26:14 -0400

Snort 1.9.1 on RH8
I scan network segment protected with Snort using Nessus. I actually have scanned only 2 boxes on that network - one Linux box and one NT box. The alerts I see in Snort are almost all unix-related-namely: squid proxy attempt, scan proxy attempt 8080, tftp get password, snmp get alerts, ASF access, amanda version request, DDOS mstream, xdmp query, samba client access, etc I don't see any windows-related alerts, which should be produced in tons by nessus scanning., cause it runs a lot of windows-related test vuln scripts.
Question:
1. Why I don't see windows-related alerts, any ideas?
2. Generally speaking, nessus runs more than 1000 different scripts for vuln tests, should I see the similar number of UNIQUE alerts in snort? In my understanding, snort should be aware of the most atack attemts or queries nessus produces...

Thanks.
--
Your favorite stores, helpful shopping tools and great gift ideas. Experience the convenience of buying online with Shop@Netscape! http://shopnow.netscape.com/



-------------------------------------------------------
This SF.net email is sponsored by: ValueWeb: Dedicated Hosting for just $79/mo with 500 GB of bandwidth! No other company gives more support or power for your dedicated server
http://click.atdmt.com/AFF/go/sdnxxaff00300020aff/direct/01/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: