Snort mailing list archives

Re: snort not alerting on same ip ssh attack after restart


From: wkitty42 () windstream net
Date: Fri, 8 Apr 2016 14:53:11 -0400

On 04/08/2016 02:06 PM, John Devine wrote:
Hi all,

I am testing alerts on snort 2.9.2.2 on a box running debian by using a mock ssh
attack to trigger one of snort's default rules. The rule is generated after 5

i'm not aware of snort having any "default rules"... at least not by that type 
of naming... which rule are you talking about?

ssh attempts are made within 60 seconds. I am using snort as-is; I have created
no custom rules. I can reproduce this about once a day but after a reboot of the
box or restart of snort it will not generate an alert after using the same mock
ssh attack even when I 'attack' it from a different IP. My guess is that there

what IPs are you testing from?
which one works and which does not?
what is the IP of your snort box?
what are your HOME_NET and EXTERNAL_NET values?

is some default local event filter for a specific rule that prevents the alert
from generating again within a certain timeframe. I tried creating a global
event filter (event_filter gen_id 0, sig_id 0, type both, track by_src, count
-1, seconds 1) in the hope of circumventing all time limits and thresholds that
could be preventing snort from alerting. Is there a way to disable any default
filters that are preventing snort from generating multiples of the same alerts?

no... not without rewriting the rule... in your case, it would basically mean 
copying that rule to your local.rules file, modifying it as needed, making sure 
to change the SID number (very important) and commenting out the original rule 
in the original .rules file...

If that is even the problem. Essentially, I want snort to be able to generate
the same alert every time it happens which is currently does not.

post your answers to the above five questions to the list and let's see what we 
can do :)

-- 
  NOTE: No off-list assistance is given without prior approval.
        *Please keep mailing list traffic on the list* unless
        private contact is specifically requested and granted.

------------------------------------------------------------------------------
Find and fix application performance issues faster with Applications Manager
Applications Manager provides deep performance insights into multiple tiers of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial! http://pubads.g.doubleclick.net/
gampad/clk?id=1444514301&iu=/ca-pub-7940484522588532
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!


Current thread: