Snort mailing list archives

RE: a lot of Loopback traffic being logged.


From: Harry Bloomberg <hbloomb () acconnect com>
Date: Thu, 22 Apr 2004 14:26:55 -0400 (EDT)

On Thu, 22 Apr 2004, Chuck Holley wrote:

OK, I think im on to something.  I do not use the -i option, only -c to look
at the conf.  in the conf I have for "HOME_NET 192.168.10.0/24" and a little
further down I have "HOME_NET any"

   We are forcing Snort to listen to one real port only with the -i
option, and we're also seeing a *lot* of packets with a source of
127.0.0.1:80.  This was confirmed by one of our network guys who plugged another
packet sniffer into the Snort port.  This seems to be real traffic, and
we're baffled by the source.

Harry Bloomberg



-------------------------------------------------------
This SF.net email is sponsored by: The Robotic Monkeys at ThinkGeek
For a limited time only, get FREE Ground shipping on all orders of $35
or more. Hurry up and shop folks, this offer expires April 30th!
http://www.thinkgeek.com/freeshipping/?cpg=12297
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: