Snort mailing list archives

Re: checksum_mode


From: Bamm Visscher <bamm.visscher () gmail com>
Date: Mon, 5 Sep 2005 10:39:58 -0600

The option is most often used in my experience when replaying
previously captured traffic (especially traffic that has been
sanitized) and it's not normally something you need to deal with.  See
Richard Bejtlich's post on the subject [0].

Bammkkkk

[0] http://taosecurity.blogspot.com/2005/04/using-snorts-k-option-i-was-looking.html

On 9/5/05, Pablo Nebrera <pablonebrera () eneotecnologia com> wrote:


        I don't understand this option in the snort configuration file.
Does it check the checksum for every packet? What is the checksum of a
packet?

What does this option do exactly??

Thanks


Pablo

-- 
sguil - The Analyst Console for NSM
http://sguil.sf.net


-------------------------------------------------------
SF.Net email is Sponsored by the Better Software Conference & EXPO
September 19-22, 2005 * San Francisco, CA * Development Lifecycle Practices
Agile & Plan-Driven Development * Managing Projects & Teams * Testing & QA
Security * Process Improvement & Measurement * http://www.sqe.com/bsce5sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: