Snort mailing list archives
Re: checksum_mode
From: Bamm Visscher <bamm.visscher () gmail com>
Date: Mon, 5 Sep 2005 10:39:58 -0600
The option is most often used in my experience when replaying previously captured traffic (especially traffic that has been sanitized) and it's not normally something you need to deal with. See Richard Bejtlich's post on the subject [0]. Bammkkkk [0] http://taosecurity.blogspot.com/2005/04/using-snorts-k-option-i-was-looking.html On 9/5/05, Pablo Nebrera <pablonebrera () eneotecnologia com> wrote:
I don't understand this option in the snort configuration file. Does it check the checksum for every packet? What is the checksum of a packet? What does this option do exactly?? Thanks Pablo
-- sguil - The Analyst Console for NSM http://sguil.sf.net ------------------------------------------------------- SF.Net email is Sponsored by the Better Software Conference & EXPO September 19-22, 2005 * San Francisco, CA * Development Lifecycle Practices Agile & Plan-Driven Development * Managing Projects & Teams * Testing & QA Security * Process Improvement & Measurement * http://www.sqe.com/bsce5sf _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- checksum_mode Pablo Nebrera (Sep 05)
- Re: checksum_mode Jason Brvenik (Sep 05)
- Re: checksum_mode Bamm Visscher (Sep 05)