Intrusion Detection Systems mailing list archives
FW: Snort 1.6 and nmap 2.54beta1
From: brian.d.mila () lmco com (Mila, Brian D)
Date: Thu, 15 Jun 2000 16:30:16 -0400
Archive: http://msgs.securepoint.com/ids FAQ: http://www.ticm.com/kb/faq/idsfaq.html IDS: http://www-rnks.informatik.tu-cottbus.de/~sobirey/ids.html UNSUBSCRIBE: email "unsubscribe ids" to majordomo () uow edu au so it looks like I similarly alarmed people by forwarding the first message prematurely. Oh well, never hurts to upgrade ;) brian
-----Original Message----- From: Galileo [SMTP:galileo () MAILANDNEWS COM] Sent: Sunday, May 14, 2000 9:03 PM To: BUGTRAQ () SECURITYFOCUS COM Subject: Re: Snort 1.6 and nmap 2.54beta1What parameters had you given snort?-vl /temp/snort or just -l /temp/snortWhat ruleset are you using? (could be triggered by preprocessor)no rulset.If used with ruleset snort works fine. snort -vc snort-lib ( or 06082k.rules ) -l /temp/snort and everything is okay. I'm sorry abouth this it loks like I alarmed a lot of people without a reason since very few people use snort withouth a ruleset. When I found this I was playing with snort for the first time. It looks like when a ruleset is applied all errors disapear. for example -vdC after a couple of minutes gives a "garbled" screen and you have to logout to restore the screen or -vd gives this kind of error : "Got NULL ptr in PrintNetData" but still continues to work. But when a ruleset is applied no errors apear.What is your network topology?I don't realy have a network :) .One machine with a vmware virtual machine on top of it and virtual network betwen them.
Current thread:
- Detecting exploits/shellcode Jonas Eriksson (Jun 15)
- Re: Detecting exploits/shellcode diphen () agitation net (Jun 15)
- Re: Detecting exploits/shellcode Marco Vaz (Jun 15)
- FW: Snort 1.6 and nmap 2.54beta1 Mila, Brian D (Jun 15)
- <Possible follow-ups>
- Re: Detecting exploits/shellcode Marcus J. Ranum (Jun 15)
- Re: Detecting exploits/shellcode Ron Gula (Jun 15)
- Re: Detecting exploits/shellcode Max Vision (Jun 16)
- Re: Detecting exploits/shellcode Max Vision (Jun 17)
- Re: Detecting exploits/shellcode Ron Gula (Jun 15)
- Testing Message at 12:35 idsmlist owner (Jun 15)
- Testing Message at 15:45 idsmlist owner (Jun 16)
- Re: Detecting exploits/shellcode Robert Graham (Jun 15)
- Re: Detecting exploits/shellcode Mark.Teicher () predictive com (Jun 15)
- Re: Detecting exploits/shellcode John Bradberry (Jun 16)
- Re: Detecting exploits/shellcode turnere (Jun 16)
