Snort mailing list archives
arpspoof preprocessor
From: Rob Ward <rob.ward () liverpool ac uk>
Date: Tue, 18 Apr 2006 12:35:46 +0100
Hi, I've been trying out the arpspoof preprocessor which seems to pick up problems we're having with default gateways being spoofed however it doesn't return any useful information such as IP and MAC addresses in the alert file. This is with Snort 2.4.3 - does anyone know if this has been developed further in snort 2.4.4 and if not could this be included?
Regards Rob Ward University of LiverpoolComputing Services Department
------------------------------------------------------- This SF.Net email is sponsored by xPML, a groundbreaking scripting language that extends applications into web and mobile media. Attend the live webcast and join the prime developer group breaking into this new coding territory! http://sel.as-us.falkag.net/sel?cmd=lnk&kid=110944&bid=241720&dat=121642 _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- arpspoof preprocessor Rob Ward (Apr 18)