Snort mailing list archives

Re: Did SNORT Arp Spoofing (ps)


From: Chris Ditze-Stephan <chris.ditze-stephan () zentric de>
Date: Mon, 25 Apr 2016 05:45:04 +0000

Hi,

In case of misunderstandings an additional information:

During the one week without Snort there was no recognized arp spoofing on the network switch.
We are able to assign the switch port disabling with a started Snort.
Means: Snort seems to generate or provide any other service to do send packages with wrong MAC addresses.


-----Ursprüngliche Nachricht-----

Hello All,

my root server provider switched off the switch interface because my server sent packages with wrong MAC address.
I stopped SNORT and he switched on again.

I started SNORT again and the switch put off again the interface.

I let SNORT down for a week and again: The switch react.

Does anyone have an idea what's happened?

Best Regards

cds




------------------------------------------------------------------------------
Find and fix application performance issues faster with Applications Manager
Applications Manager provides deep performance insights into multiple tiers of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!


Current thread: