Snort mailing list archives

arpspoof preprocessor


From: Rob Ward <rob.ward () liverpool ac uk>
Date: Tue, 18 Apr 2006 12:35:46 +0100

Hi, I've been trying out the arpspoof preprocessor which seems to pick up problems we're having with default gateways being spoofed however it doesn't return any useful information such as IP and MAC addresses in the alert file. This is with Snort 2.4.3 - does anyone know if this has been developed further in snort 2.4.4 and if not could this be included?

Regards

Rob Ward
University of Liverpool
Computing Services Department

-------------------------------------------------------
This SF.Net email is sponsored by xPML, a groundbreaking scripting language
that extends applications into web and mobile media. Attend the live webcast
and join the prime developer group breaking into this new coding territory!
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=110944&bid=241720&dat=121642
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: