Snort mailing list archives
Partial IP searching with ACID?
From: Kevin Brown <Kevin.M.Brown () asu edu>
Date: Mon, 13 Aug 2001 14:41:50 -0700
I'm currently running Snort 1.8b7, schema 103 in a Mysql db, Acid .9.6b14
with php 4.0.6. Is it possible to do searching with just partial IPs? (e.g
search for 224.226.x.x). I'm trying to find a list of infeceted hosts on my
network, but when I just enter a partial IP on the search page I get an
error:
Database ERROR:You have an error in your SQL syntax near ') )' at line 1
END OF LINE...
Begin Geek Code;
$_='while(read+STDIN,$_,2048){$a=29;$b=73;$c=142;$t=255;@t=map{$_%16or$t^=$c
^=(
$m=(11,10,116,100,11,122,20,100)[$_/16%8])&110;$t^=(72,@z=(64,72,$a^=12*($_%
16
-2?0:$m&17)),$b^=$_%64?12:0,@z)[$_%8]}(16..271);if((@a=unx"C*",$_)[20]&48){$
h
=5;$_=unxb24,join"",@b=map{xB8,unxb8,chr($_^$a[--$h+84])}@ARGV;s/...$/1$&/;$
d=unxV,xb25,$_;$e=256|(ord$b[4])<<9|ord$b[3];$d=$d>>8^($f=$t&($d>>12^$d>>4^
$d^$d/8))<<17,$e=$e>>8^($t&($g=($q=$e>>14&7^$e)^$q*8^$q<<6))<<9,$_=$t[$_]^
(($h>>=8)+=$f+(~$g&$t))for@a[128..$#a]}print+x"C*",@a}';s/x/pack+/g;eval
Current thread:
- Partial IP searching with ACID? Kevin Brown (Aug 13)
- Re: Partial IP searching with ACID? Phil Wood (Aug 13)
- <Possible follow-ups>
- RE: Partial IP searching with ACID? Kevin Brown (Aug 14)
- RE: Partial IP searching with ACID? Kevin Brown (Aug 14)
- RE: Partial IP searching with ACID? roman (Aug 14)
