Snort mailing list archives

Re: SNORT DNS TUNNELING


From: emmanuel <emmanuel.kacou () 2alsy org>
Date: Thu, 14 May 2015 07:20:30 +0000


thank you for allowing me to read the charter, however, I ask nothing of a home exercise this is a practical problem that I raised was how to test your dns rules as we would do with ICMP rules.
I understand that this is what was used the lists to the assistance.

cordially

Le 13/05/2015 23:55, Joel Esler (jesler) a écrit :
Emmanuel,

Please read the following link:

https://www.snort.org/faq/can-i-have-help-with-my-homework

--
*Joel Esler*
Open Source Manager
Threat Intelligence Team Lead
Talos Group


On May 13, 2015, at 2:19 AM, emmanuel <emmanuel.kacou () 2alsy org <mailto:emmanuel.kacou () 2alsy org>> wrote:


Hello every body;

I'm emmanuel from Ivory coste west AFRICA and since 3 days i'm studie snort.

i want to test  dns tunneling  with nort.

i got snort rules from snort.org <http://snort.org> and put it in rules directory.
i want to test if my rules are good or not by doing some lab with dns
tunneling
how can i do it.




------------------------------------------------------------------------------
One dashboard for servers and applications across Physical-Virtual-Cloud
Widest out-of-the-box monitoring support with 50+ applications
Performance metrics, stats and reports that give you Actionable Insights
Deep dive visibility with transaction tracing using APM Insight.
http://ad.doubleclick.net/ddm/clk/290420510;117567292;y
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!


------------------------------------------------------------------------------
One dashboard for servers and applications across Physical-Virtual-Cloud 
Widest out-of-the-box monitoring support with 50+ applications
Performance metrics, stats and reports that give you Actionable Insights
Deep dive visibility with transaction tracing using APM Insight.
http://ad.doubleclick.net/ddm/clk/290420510;117567292;y
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: