Snort mailing list archives

RE: SNORT Newbie


From: "Adam Kliarsky" <360air () comcast net>
Date: Sun, 13 Feb 2005 22:37:32 -0800

Snort alerts based on traffic patterns it sees, so you'll need to review the
alert and correlate it w/ what's happening on your system (running
processes, inbound/outbound traffic etc).
Looking at the alert you provided an attempt was made to install "Whackjob",
a front-end application for NetBus, on your system. According to Packet
Storm, Whackjob would install a binary called Game.exe (NetBus server) on
your system.
http://packetstormsecurity.org/trojans/whackjob17.readme
As in all IDS deployments, there are always false positives w/ standard
installs, so you need to do some due diligence and research the alerts you
are seeing.
Good luck
Adam


-----Original Message-----
From: snort-users-admin () lists sourceforge net
[mailto:snort-users-admin () lists sourceforge net] On Behalf Of
joel () cybrus net
Sent: Sunday, February 13, 2005 9:42 PM
To: snort-users () lists sourceforge net
Subject: FW: [Snort-users] SNORT Newbie

Ok, so that means that they were successful in gaining access to my
computer?  Is there anyway to check if my firewall has been corrupted or if
it's just faulty?

Thanks for the help.

Regards,
Joel

-----Original Message-----
From: snort-users-admin () lists sourceforge net
[mailto:snort-users-admin () lists sourceforge net]On Behalf Of Adam Kliarsky
Sent: Sunday, February 13, 2005 9:22 PM
To: joel () cybrus net; snort-users () lists sourceforge net
Subject: RE: [Snort-users] SNORT Newbie


Joel -
Snort uses class-types in it's rules to help classify attacks (alerts).
Normally these are defined in the classification.config file used by Snort.
Not sure how it's set up w/ Kerio.
There are several different class-types - 'successful-user' means that
according to the rule that was triggered, user privileges were gained in the
attack.

Hope that helps -

- Adam



-----Original Message-----
From: snort-users-admin () lists sourceforge net
[mailto:snort-users-admin () lists sourceforge net] On Behalf Of
joel () cybrus net
Sent: Sunday, February 13, 2005 8:01 PM
To: snort-users () lists sourceforge net
Subject: [Snort-users] SNORT Newbie

Hi,

I'm a total and complete newbie to Snort.  I know your level of knowledge is
WAY over my head.  But I've got a concern and I'm hoping you can help
explain something to me

I use Kerio Firewall w/ AVG anti-virus on my computer.  It appears that
Kerio uses Snort to prevent intrusions or something like that.

When I click on "Intrusions" within the Kerio program, and then click on the
details of the "High Priority Intrusions" and the "IDS details" window comes
up listing "Attacks" and "Class".  IE

Attack                                  Class
BACKDOOR Trojan active Whackjob successful-user


It's a rather long list, with most of the trojans being classed as
"successful-user".  What is this telling me?

Regards,
Joel



-------------------------------------------------------
SF email is sponsored by - The IT Product Guide Read honest & candid reviews
on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now.
http://ads.osdn.com/?ad_id=6595&alloc_id=14396&op=click
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users



-------------------------------------------------------
SF email is sponsored by - The IT Product Guide Read honest & candid reviews
on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now.
http://ads.osdn.com/?ad_id=6595&alloc_id=14396&op=click
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users
.    _____________________________________________________________

Anti-virus & anti-spam control solutions provided by www.Optrics.com




-------------------------------------------------------
SF email is sponsored by - The IT Product Guide Read honest & candid reviews
on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now.
http://ads.osdn.com/?ad_id=6595&alloc_id=14396&op=click
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users



-------------------------------------------------------
SF email is sponsored by - The IT Product Guide
Read honest & candid reviews on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now.
http://ads.osdn.com/?ad_id=6595&alloc_id=14396&op=click
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: