Snort mailing list archives
Re: how to disable spp_porscan?
From: Phil Wood <cpw () lanl gov>
Date: Thu, 20 Dec 2001 08:58:00 -0700
Ok, show me what is in: include snort.conf-a21 If I had not seen that file name, in your included file, I would have asked you to: grep "preprocessor[ ]* portscan" * in /etc/snort On Thu, Dec 20, 2001 at 04:45:31PM +0100, Roberto Suarez Soto wrote:
On Dec/19, Phil Wood wrote:Lo and Behold, I had one file (the binary file from -b) show up in the /var/log/snort directory. I did a standard nmap of my system, and no portscans. Then, I enabled portscans in the sonrt.conf file, and restarted snort (same way). Lo and Behold, after running same nmap, I had a portscan file.Gasp. Running snort 1.8.3, in Linux 2.4.x too? I guess that's a misconfiguration on my part, then. Or maybe I just built it wrongly, or with some kind of weird option. Did you build your snort program? With any special options?
Nope.
So, my question still is what is in the include file? And/or, have you found that there is something different in the /etc/snort directory?Well, the include file has simply a list of the .rules files to include. I send it as attach, though I don't think (but I'm open to admit I'm wrong :-)) that it has anything to do with this case. The file included are the same downloaded from snort's homepage, with some alerts commented out, but no other modification. The file "local-first" which appears as first line of the file has several rules to ignore all traffic coming from the host itself, something like this: pass tcp XX.XX.XX.XX any -> $HOME_NET any pass udp XX.XX.XX.XX any -> $HOME_NET any pass icmp XX.XX.XX.XX any -> $HOME_NET any pass ip XX.XX.XX.XX any -> $HOME_NET any And this set of rules for each IP, of course. Nothing more. -- Roberto Suarez Soto Alfa21 Outsourcing robe () alfa21 com http://www.alfa21.com
include local-first include attack-responses.rules include backdoor.rules include bad-traffic.rules include ddos.rules include dns.rules include dos.rules include exploit.rules include finger.rules include ftp.rules include icmp.rules include info.rules include local.rules include misc.rules include netbios.rules include policy.rules include rpc.rules include rservices.rules include scan.rules include shellcode.rules include smtp.rules include snort.conf-a21 include sql.rules include telnet.rules include tftp.rules include web-attacks.rules include web-cgi.rules include web-coldfusion.rules include web-frontpage.rules include web-iis.rules include web-misc.rules include x11.rules
-- Phil Wood, cpw () lanl gov _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- how to disable spp_porscan? Roberto Suarez Soto (Dec 18)
- Re: how to disable spp_porscan? Chris Green (Dec 18)
- Re: how to disable spp_porscan? Roberto Suarez Soto (Dec 18)
- Re: how to disable spp_porscan? Phil Wood (Dec 18)
- Re: how to disable spp_porscan? Roberto Suarez Soto (Dec 19)
- Re: how to disable spp_porscan? Phil Wood (Dec 19)
- Re: how to disable spp_porscan? Roberto Suarez Soto (Dec 20)
- Re: how to disable spp_porscan? Phil Wood (Dec 20)
- Re: how to disable spp_porscan? Phil Wood (Dec 20)
- Re: how to disable spp_porscan? Roberto Suarez Soto (Dec 21)
- Re: how to disable spp_porscan? Roberto Suarez Soto (Dec 18)
- Re: how to disable spp_porscan? Chris Green (Dec 18)
- Re: how to disable spp_porscan? Roberto Suarez Soto (Dec 18)
- <Possible follow-ups>
- RE: how to disable spp_porscan? Steve Halligan (Dec 18)
- Re: how to disable spp_porscan? Roberto Suarez Soto (Dec 18)
- Re: how to disable spp_porscan? Chris Green (Dec 18)
- Re: how to disable spp_porscan? Roberto Suarez Soto (Dec 19)
- Re: how to disable spp_porscan? Phil Wood (Dec 19)
- Re: how to disable spp_porscan? Roberto Suarez Soto (Dec 20)
- Re: how to disable spp_porscan? Roberto Suarez Soto (Dec 18)
