Snort mailing list archives
BPF filters and Demarc
From: Gary Danko <GDanko () proflowers com>
Date: Mon, 28 Jul 2003 16:01:05 -0700
I tried launching snort from the command line with and without the switch
for the BPF filter file. Here are my results.
Without:
[root@ids1 conf]$ /usr/local/bin/snort -o -de -i eth1 -c
/usr/local/demarc/conf/snorteth1-a.conf Running in IDS
mode
Log directory = /var/log/snort
Initializing Network Interface eth1
OpenPcap() device eth1 network lookup:
eth1: no IPv4 address assigned
--== Initializing Snort ==--
Rule application order changed to Pass->Alert->Log
Initializing Output Plugins!
Decoding Ethernet on interface eth1
Initializing Preprocessors!
Initializing Plug-ins!
Parsing Rules file /usr/local/demarc/conf/snorteth1-a.conf
+++++++++++++++++++++++++++++++++++++++++++++++++++
Initializing rule chains...
No arguments to frag2 directive, setting defaults to:
Fragment timeout: 60 seconds
Fragment memory cap: 4194304 bytes
Fragment min_ttl: 0
Fragment ttl_limit: 5
Fragment Problems: 0
Self preservation threshold: 500
Self preservation period: 90
Suspend threshold: 1000
Suspend period: 30
Stream4 config:
Stateful inspection: ACTIVE
Session statistics: INACTIVE
Session timeout: 30 seconds
Session memory cap: 8388608 bytes
State alerts: INACTIVE
Evasion alerts: INACTIVE
Scan alerts: ACTIVE
Log Flushed Streams: INACTIVE
MinTTL: 1
TTL Limit: 5
Async Link: 0
State Protection: 0
Self preservation threshold: 50
Self preservation period: 90
Suspend threshold: 200
Suspend period: 30
Stream4_reassemble config:
Server reassembly: INACTIVE
Client reassembly: ACTIVE
Reassembler alerts: ACTIVE
Ports: 21 23 25 53 80 110 111 143 513 1433
Emergency Ports: 21 23 25 53 80 110 111 143 513 1433
http_decode arguments:
Unicode decoding
IIS alternate Unicode decoding
IIS double encoding vuln
Flip backslash to slash
Include additional whitespace separators
Ports to decode http on: 80
rpc_decode arguments:
Ports to decode RPC on: 111 32771
alert_fragments: INACTIVE
alert_large_fragments: ACTIVE
alert_incomplete: ACTIVE
alert_multiple_requests: ACTIVE
telnet_decode arguments:
Ports to decode telnet on: 21 23 25 119
database: compiled support for ( mysql )
database: configured to use mysql
database: user = snort
database: database name = snort
database: password is set
database: host = 10.1.30.60
database: sensor name = ids1
database: sensor id = 2
database: schema version = 106
database: using the "log" facility
0 Snort rules read...
0 Option Chains linked into 0 Chain Headers
0 Dynamic rules
+++++++++++++++++++++++++++++++++++++++++++++++++++
Rule application order: ->pass->activation->dynamic->alert->log
--== Initialization Complete ==--
-*> Snort! <*-
Version 2.0.0 (Build 72)
By Martin Roesch (roesch () sourcefire com, www.snort.org)
And with:
[root@ids1 conf]$ /usr/local/bin/snort -F
/usr/local/demarc/conf/bpf-filters.conf -o -de -i eth1 -c
/usr/local/demarc/conf/snorteth1-a.conf
Running in IDS mode
Log directory = /var/log/snort
Initializing Network Interface eth1
OpenPcap() device eth1 network lookup:
eth1: no IPv4 address assigned
ERROR: OpenPcap() FSM compilation failed:
PCAP command: %s
Fatal Error, Quitting..
Here is the contents of my bpf filter:
[root@ids1 conf]$ more bpf-filters.conf
!host 192.168.1.10
!host 10.2.20.20
!host 10.2.20.30
-------------------------------------------------------
This SF.Net email sponsored by: Free pre-built ASP.NET sites including
Data Reports, E-commerce, Portals, and Forums are available now.
Download today and enter to win an XBOX or Visual Studio .NET.
http://aspnet.click-url.com/go/psa00100003ave/direct;at.aspnet_072303_01/01
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- BPF filters and Demarc Gary Danko (Jul 28)
- <Possible follow-ups>
- BPF filters and Demarc Gary Danko (Jul 28)
- Re: BPF filters and Demarc Erek Adams (Jul 29)
- RE: BPF filters and Demarc Gary Danko (Jul 28)
