Snort mailing list archives

Re: Portscan on an Unaddressed sniffer port


From: Valter Santos <vsantola () sectoid com>
Date: Fri, 04 Nov 2005 01:09:22 +0000

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Timothy,

just fire up the scan against the network that the snort box is
monitoring, if everything is working okay snort should alert the
scanning attempts.

You don't scan ipless interfaces, they are ipless just to prevent stuff
like these :-)

have fun
/valter



Timothy A. Holmes wrote:
Hi folks:

I have an odd request -

I need to do some sort of scan on an unaddressed sniffing interface on a
SNORT box to test the installation to see if it is all working right.  I
have a port scanner on my UBUNTU laptop that I could use if I knew how
to address the port.

The management interface on the box (it's a FC4 box) is 192.168.0.28 and
that's eth1

The unaddressed port is eth0 on the same box

Any suggestions would be most welcome

TIM


Timothy A. Holmes
IT Manager / Network Admin / Web Master / Computer Teacher
 
Medina Christian Academy
A Higher Standard...
 
Jeremiah 33:3
Jeremiah 29:11
Esther 4:14




-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (GNU/Linux)

iD8DBQFDarTCR7pJvOKksgYRAttEAJoCUjOnpjqtNxTyCEQawZebcYyk+QCfbxLW
eaw0ccGpk9NrfmhoNSoDZTM=
=WuUc
-----END PGP SIGNATURE-----


-------------------------------------------------------
SF.Net email is sponsored by:
Tame your development challenges with Apache's Geronimo App Server. Download
it for free - -and be entered to win a 42" plasma tv or your very own
Sony(tm)PSP.  Click here to play: http://sourceforge.net/geronimo.php
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: